Re: [PATCH nf v3 1/1] netfilter: x_tables: avoid holding mutex over faultable user copies

From: zihan xi

Date: Thu Oct 08 2026 - 21:10:04 EST


On Fri, Oct 9, 2026 at 8:14 AM Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx> wrote:
>
> On Fri, Oct 09, 2026 at 02:07:35AM +0200, Florian Westphal wrote:
> > Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx> wrote:
> > > > The ebtables GET paths use a separate ebt_mutex and are outside this
> > > > IPv4/IPv6/ARP series.
> > >
> > > I keep spinning on this, and I am not sure this fix is the right thing
> > > to do. There is no single caller of this pagefault_disable/enable() mm
> > > subsystem function in the net folder.
> >
> > See:
> >
> > https://lore.kernel.org/all/CAL4Wiir+CBGE=hXxHEBkyk0Au9B6G3=AdHFd5botrC-FF5BM5w@xxxxxxxxxxxxxx/raw
> >
> > Quote:
> > | We have many places where copy_{from,to}_user() runs while a mutex or
> > | a socket lock is held, and some of these locks are global.
>
> Indeed.
>
> > So I would not spend too much time on this, especially not for the
> > xtables get/setsockopt APIs.
>
> OK, I'll drop this patch in patchwork then.
>
> Thanks Florian.

Thanks Florian and Pablo for the discussion.

Understood. I'll drop this series and won't this approach further.

Best regards,
Zihan