[PATCH net v3 0/3] ipv6: fix address publication races with addrconf_ifdown

From: Daehyeon Ko

Date: Fri Oct 09 2026 - 01:41:47 EST


The first patch serializes address publication with device teardown by
taking idev->lock before the address hash lock. It uses READ_ONCE() for
the initial lockless state checks and rechecks both dead and disable_ipv6
before publishing.

The second patch handles an address captured by the per-device snapshot
after the initial hash scan. It removes the address from the hash in the
existing list-removal block, after delete notification and before dropping
the list reference.

The third patch initializes a temporary address's public-ifaddr reference
before publishing the object. This closes the remaining interval in which
ifdown could miss the reference and a later store could leak it.

The original deterministic test used a direct internal caller, kprobes and
atomic rendezvous at existing instruction boundaries; it did not add delays
to addrconf.c. A real RA separately reached ipv6_add_addr() with
can_block=false. No new kernel build or runtime test was run for v3.

Changes in v3:
- Use READ_ONCE() for patch 1's initial lockless state checks.
- Add a third patch that passes ifpub through ifa6_config, as suggested by
Ido after the Sashiko review.
- Move patch 2's unhash into the existing lower !keep block and use
73a8bd74e261 as its Fixes commit.
- Rebase onto current net while preserving the v2 cover and first two patch
subjects.

Link: https://lore.kernel.org/r/20261004183639.3773498-1-4ncienth@xxxxxxxxx
Link: https://lore.kernel.org/r/179122559913.434549.12720841717630168470@xxxxxxxxxx
Link: https://lore.kernel.org/r/20261007164548.GA1153540@shredder
Link: https://lore.kernel.org/r/20261007164635.GC1153540@shredder

Daehyeon Ko (3):
ipv6: serialize address publication with device teardown
ipv6: remove ifaddr from hash during ifdown list cleanup
ipv6: initialize temporary ifaddr before publication

include/net/addrconf.h | 1 +
net/ipv6/addrconf.c | 25 +++++++++++++++++++------
2 files changed, 20 insertions(+), 6 deletions(-)


base-commit: af32da41b0327b9c6a37856ba82b6760d6c8d10e
--
2.55.0