Re: [PATCH nf v3 1/1] netfilter: x_tables: avoid holding mutex over faultable user copies
From: Florian Westphal
Date: Thu Oct 08 2026 - 20:08:01 EST
Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx> wrote:
> > The ebtables GET paths use a separate ebt_mutex and are outside this
> > IPv4/IPv6/ARP series.
>
> I keep spinning on this, and I am not sure this fix is the right thing
> to do. There is no single caller of this pagefault_disable/enable() mm
> subsystem function in the net folder.
See:
https://lore.kernel.org/all/CAL4Wiir+CBGE=hXxHEBkyk0Au9B6G3=AdHFd5botrC-FF5BM5w@xxxxxxxxxxxxxx/raw
Quote:
| We have many places where copy_{from,to}_user() runs while a mutex or
| a socket lock is held, and some of these locks are global.
So I would not spend too much time on this, especially not for the
xtables get/setsockopt APIs.