RE: [PATCH net v2 1/2] tipc: unlink publications without a node lookup

From: Tung Quang Nguyen

Date: Mon Oct 05 2026 - 00:08:49 EST


>Subject: [PATCH net v2 1/2] tipc: unlink publications without a node lookup
>
>The two remote-publication removal paths remove a publication from the
>name table and call tipc_node_unsubscribe() before scheduling it for freeing.
>
>tipc_node_unsubscribe() looks up the publishing node by address and returns
>without unlinking when the node has already disappeared from the hash. The
>publication is then freed while its binding_node remains linked, so a later
>publication-list traversal can access freed memory.
>
>Both paths already run under nametbl_lock. Unlink binding_node directly
>under that lock instead of performing another node lookup. For a valid remote
>publication, binding_node is either on the node publication list or is initialized
>as an empty list when subscription failed. Remove the now-unused helper and
>address arguments.
>

This does not fix the root cause of this issue: Not holding proper lock in tipc_node_write_unlock().
I will post fix for this issue. Thanks for your report.