mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
synced 2026-07-25 16:19:48 +02:00
netfilter: nf_conncount: callers must hold rcu read lock
[ Upstream commit64d7d5abe2] rcu_derefence_raw() should not have been used here, it concealed this bug. Its used because struct rb_node lacks __rcu annotated pointers, so plain rcu_derefence causes sparse warnings. The major tradeoff is that rcu_derefence_raw() doesn't warn when the caller isn't in a rcu read section. Extend the rcu read lock scope accordingly and cause sparse warnings, those warnings are the lesser evil. Fixes:11efd5cb04("openvswitch: Support conntrack zone limit") Closes: https://sashiko.dev/#/patchset/20260603230610.7900-1-fw%40strlen.de Signed-off-by: Florian Westphal <fw@strlen.de> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org> Signed-off-by: Sasha Levin <sashal@kernel.org>
This commit is contained in:
committed by
Greg Kroah-Hartman
parent
b4ccd6eef6
commit
afe2d8dfe6
@@ -499,7 +499,7 @@ count_tree(struct net *net,
|
||||
hash = jhash2(key, data->keylen, conncount_rnd) % CONNCOUNT_SLOTS;
|
||||
root = &data->root[hash];
|
||||
|
||||
parent = rcu_dereference_raw(root->rb_node);
|
||||
parent = rcu_dereference(root->rb_node);
|
||||
while (parent) {
|
||||
int diff;
|
||||
|
||||
@@ -507,9 +507,9 @@ count_tree(struct net *net,
|
||||
|
||||
diff = key_diff(key, rbconn->key, data->keylen);
|
||||
if (diff < 0) {
|
||||
parent = rcu_dereference_raw(parent->rb_left);
|
||||
parent = rcu_dereference(parent->rb_left);
|
||||
} else if (diff > 0) {
|
||||
parent = rcu_dereference_raw(parent->rb_right);
|
||||
parent = rcu_dereference(parent->rb_right);
|
||||
} else {
|
||||
int ret;
|
||||
|
||||
|
||||
@@ -2096,10 +2096,10 @@ static int ovs_ct_limit_get_zone_limit(struct net *net,
|
||||
} else {
|
||||
rcu_read_lock();
|
||||
limit = ct_limit_get(info, zone);
|
||||
rcu_read_unlock();
|
||||
|
||||
err = __ovs_ct_limit_get_zone_limit(
|
||||
net, info->data, zone, limit, reply);
|
||||
rcu_read_unlock();
|
||||
if (err)
|
||||
return err;
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user