Re: [PATCH net] net/sched: fix use-after-free in __tcf_action_put()

From: Jakub Kicinski

Date: Wed Oct 07 2026 - 20:35:13 EST


On Wed, 30 Sep 2026 21:18:40 +0000 Jérémy Jean wrote:
> {
> struct tcf_idrinfo *idrinfo = p->idrinfo;
>
> - if (refcount_dec_and_mutex_lock(&p->tcfa_refcnt, &idrinfo->lock)) {
> - if (bind)
> - atomic_dec(&p->tcfa_bindcnt);
> - idr_remove(&idrinfo->action_idr, p->tcfa_index);
> + mutex_lock(&idrinfo->lock);
> + if (bind)
> + atomic_dec(&p->tcfa_bindcnt);
> + if (!refcount_dec_and_test(&p->tcfa_refcnt)) {
> mutex_unlock(&idrinfo->lock);
> -
> - tcf_action_cleanup(p);
> - return 1;
> + return 0;
> }
>
> - if (bind)
> - atomic_dec(&p->tcfa_bindcnt);
> + idr_remove(&idrinfo->action_idr, p->tcfa_index);
> + mutex_unlock(&idrinfo->lock);
>
> - return 0;
> + tcf_action_cleanup(p);
> + return 1;
> }

Why did you decide to invert the condition?
If nothing else the diff would be more readable without that
--
pw-bot: cr