Re: [PATCH net] ipv6: Change allocation flags to match rcu_read_lock section requirements

From: Ido Schimmel

Date: Sun Jul 19 2026 - 08:55:29 EST


On Sun, Jul 19, 2026 at 01:57:59PM +0300, Nikola Z. Ivanov wrote:
> Since the call to __ip6_del_rt_siblings has been converted under
> rcu read lock and it only has one call point
> we should no longer block or yield.
>
> Our stack trace from the syzbot reproducer looks as follows:
>
> __ip6_del_rt_siblings
> rtnl_notify (Here we pass gfp_any() -> GFP_KERNEL)
> nlmsg_notify
> nlmsg_multicast
> nlmsg_multicast_filtered
> netlink_broadcast_filtered (GFP_KERNEL passed from earlier)
>
> netlink_broadcast_filtered can yield if GFP_KERNEL
> is passed, which we do not want to happen.
>
> Fix this by changing the allocation flag of rtnl_notify.
>
> Also change the flag passed to nlmsg_new. Even though it
> is not related to the syzbot generated bug it still falls
> under the same requirements.

I believe that the nlmsg_new() change is a no-op given that gfp_any()
evaluates to GFP_ATOMIC under spin_lock_bh(), but it makes
__ip6_del_rt_siblings() consistent with inet6_rt_notify() which already
uses GFP_ATOMIC for both nlmsg_new() and rtnl_notify().

>
> Reported-by: syzbot+84d4a405ed798b40c96d@xxxxxxxxxxxxxxxxxxxxxxxxx
> Closes: https://syzkaller.appspot.com/bug?extid=84d4a405ed798b40c96d
> Fixes: bd11ff421d36 ("ipv6: Get rid of RTNL for SIOCDELRT and RTM_DELROUTE.")
> Signed-off-by: Nikola Z. Ivanov <zlatistiv@xxxxxxxxx>

Reviewed-by: Ido Schimmel <idosch@xxxxxxxxxx>