Re: [PATCH nf v3 1/1] netfilter: x_tables: avoid holding mutex over faultable user copies
From: Pablo Neira Ayuso
Date: Thu Oct 08 2026 - 20:15:15 EST
On Fri, Oct 09, 2026 at 02:07:35AM +0200, Florian Westphal wrote:
> Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx> wrote:
> > > The ebtables GET paths use a separate ebt_mutex and are outside this
> > > IPv4/IPv6/ARP series.
> >
> > I keep spinning on this, and I am not sure this fix is the right thing
> > to do. There is no single caller of this pagefault_disable/enable() mm
> > subsystem function in the net folder.
>
> See:
>
> https://lore.kernel.org/all/CAL4Wiir+CBGE=hXxHEBkyk0Au9B6G3=AdHFd5botrC-FF5BM5w@xxxxxxxxxxxxxx/raw
>
> Quote:
> | We have many places where copy_{from,to}_user() runs while a mutex or
> | a socket lock is held, and some of these locks are global.
Indeed.
> So I would not spend too much time on this, especially not for the
> xtables get/setsockopt APIs.
OK, I'll drop this patch in patchwork then.
Thanks Florian.