[PATCH net v2 0/3] ipv4: handle nexthop group shrink races
From: Daehyeon Ko
Date: Fri Oct 02 2026 - 00:55:49 EST
fib_info_num_path() and fib_info_nhc() can observe different RCU
generations of a replaceable nexthop group. An indexed consumer can
therefore accept an index from a larger group and receive NULL after a
concurrent shrink.
Patch 1 is unchanged from v1. Patch 2 addresses the analogous
fib_dump_info_fnhe() race Ido identified. Auditing the remaining
accessor pairs found the same issue in the RCU-only hardware-flag
notification path, fixed by patch 3. Separate patches retain the
correct Fixes tag for each concurrency boundary.
Thanks to Ido for the review and follow-up pointer.
---
v2:
- Carry Ido's Reviewed-by on unchanged patch 1.
- Add separate exception-dump and notification-sizing fixes.
v1: https://lore.kernel.org/netdev/20261001010550.2742297-1-4ncienth@xxxxxxxxx/
review: https://lore.kernel.org/netdev/20261001170513.GA1657889@shredder/
Validation:
- Patch 1 retains its deterministic vulnerable/fixed result.
- Patches 2 and 3 are source-audited only. No new allyesconfig or
allmodconfig W=1 build or runtime test was run.
Daehyeon Ko (3):
ipv4: stop PMTU walk when nexthop group shrinks
ipv4: stop exception dump when nexthop group shrinks
ipv4: stop route notification sizing when nexthop group shrinks
net/ipv4/fib_semantics.c | 3 +++
net/ipv4/route.c | 5 +++++
2 files changed, 8 insertions(+)
base-commit: 28bc1ef699610ee09ce3d46a00552f5a0a0144bd
--
2.55.0