[PATCH net v2 0/3] ipv4: handle nexthop group shrink races

From: Daehyeon Ko

Date: Fri Oct 02 2026 - 00:55:49 EST


fib_info_num_path() and fib_info_nhc() can observe different RCU
generations of a replaceable nexthop group. An indexed consumer can
therefore accept an index from a larger group and receive NULL after a
concurrent shrink.

Patch 1 is unchanged from v1. Patch 2 addresses the analogous
fib_dump_info_fnhe() race Ido identified. Auditing the remaining
accessor pairs found the same issue in the RCU-only hardware-flag
notification path, fixed by patch 3. Separate patches retain the
correct Fixes tag for each concurrency boundary.

Thanks to Ido for the review and follow-up pointer.

---
v2:
- Carry Ido's Reviewed-by on unchanged patch 1.
- Add separate exception-dump and notification-sizing fixes.

v1: https://lore.kernel.org/netdev/20261001010550.2742297-1-4ncienth@xxxxxxxxx/
review: https://lore.kernel.org/netdev/20261001170513.GA1657889@shredder/

Validation:
- Patch 1 retains its deterministic vulnerable/fixed result.
- Patches 2 and 3 are source-audited only. No new allyesconfig or
allmodconfig W=1 build or runtime test was run.

Daehyeon Ko (3):
ipv4: stop PMTU walk when nexthop group shrinks
ipv4: stop exception dump when nexthop group shrinks
ipv4: stop route notification sizing when nexthop group shrinks

net/ipv4/fib_semantics.c | 3 +++
net/ipv4/route.c | 5 +++++
2 files changed, 8 insertions(+)


base-commit: 28bc1ef699610ee09ce3d46a00552f5a0a0144bd
--
2.55.0