Patch Detail
get:
Show a patch.
patch:
Update a patch.
put:
Update a patch.
GET /api/1.1/patches/2230250/?format=api
{ "id": 2230250, "url": "http://patchwork.ozlabs.org/api/1.1/patches/2230250/?format=api", "web_url": "http://patchwork.ozlabs.org/project/netfilter-devel/patch/20260429141055.85052-5-ja@ssi.bg/", "project": { "id": 26, "url": "http://patchwork.ozlabs.org/api/1.1/projects/26/?format=api", "name": "Netfilter Development", "link_name": "netfilter-devel", "list_id": "netfilter-devel.vger.kernel.org", "list_email": "netfilter-devel@vger.kernel.org", "web_url": null, "scm_url": null, "webscm_url": null }, "msgid": "<20260429141055.85052-5-ja@ssi.bg>", "date": "2026-04-29T14:10:51", "name": "[PATCHv2,nf,4/8] ipvs: do not leak dest after get from dest trash", "commit_ref": null, "pull_url": null, "state": "new", "archived": false, "hash": "e1eb8b740227d9e712b08820ffefd42e5d5dba3e", "submitter": { "id": 2825, "url": "http://patchwork.ozlabs.org/api/1.1/people/2825/?format=api", "name": "Julian Anastasov", "email": "ja@ssi.bg" }, "delegate": null, "mbox": "http://patchwork.ozlabs.org/project/netfilter-devel/patch/20260429141055.85052-5-ja@ssi.bg/mbox/", "series": [ { "id": 502075, "url": "http://patchwork.ozlabs.org/api/1.1/series/502075/?format=api", "web_url": "http://patchwork.ozlabs.org/project/netfilter-devel/list/?series=502075", "date": "2026-04-29T14:10:47", "name": "IPVS fixes for nf", "version": 1, "mbox": "http://patchwork.ozlabs.org/series/502075/mbox/" } ], "comments": "http://patchwork.ozlabs.org/api/patches/2230250/comments/", "check": "pending", "checks": "http://patchwork.ozlabs.org/api/patches/2230250/checks/", "tags": {}, "headers": { "Return-Path": "\n <netfilter-devel+bounces-12291-incoming=patchwork.ozlabs.org@vger.kernel.org>", "X-Original-To": [ "incoming@patchwork.ozlabs.org", "netfilter-devel@vger.kernel.org" ], "Delivered-To": "patchwork-incoming@legolas.ozlabs.org", "Authentication-Results": [ "legolas.ozlabs.org;\n\tdkim=pass (4096-bit key;\n unprotected) header.d=ssi.bg header.i=@ssi.bg header.a=rsa-sha256\n header.s=ssi header.b=lL1CGDvl;\n\tdkim-atps=neutral", "legolas.ozlabs.org;\n spf=pass (sender SPF authorized) smtp.mailfrom=vger.kernel.org\n (client-ip=2600:3c09:e001:a7::12fc:5321; helo=sto.lore.kernel.org;\n envelope-from=netfilter-devel+bounces-12291-incoming=patchwork.ozlabs.org@vger.kernel.org;\n receiver=patchwork.ozlabs.org)", "smtp.subspace.kernel.org;\n\tdkim=pass (4096-bit key) header.d=ssi.bg header.i=@ssi.bg header.b=\"lL1CGDvl\"", "smtp.subspace.kernel.org;\n arc=none smtp.client-ip=193.238.174.39", "smtp.subspace.kernel.org;\n dmarc=pass (p=reject dis=none) header.from=ssi.bg", "smtp.subspace.kernel.org;\n spf=pass smtp.mailfrom=ssi.bg" ], "Received": [ "from sto.lore.kernel.org (sto.lore.kernel.org\n [IPv6:2600:3c09:e001:a7::12fc:5321])\n\t(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)\n\t key-exchange x25519 server-signature ECDSA (secp384r1) server-digest SHA384)\n\t(No client certificate requested)\n\tby legolas.ozlabs.org (Postfix) with ESMTPS id 4g5K7g5Wtyz1yHX\n\tfor <incoming@patchwork.ozlabs.org>; Thu, 30 Apr 2026 00:14:55 +1000 (AEST)", "from smtp.subspace.kernel.org (conduit.subspace.kernel.org\n [100.90.174.1])\n\tby sto.lore.kernel.org (Postfix) with ESMTP id 112B0300B9FE\n\tfor <incoming@patchwork.ozlabs.org>; Wed, 29 Apr 2026 14:14:44 +0000 (UTC)", "from localhost.localdomain (localhost.localdomain [127.0.0.1])\n\tby smtp.subspace.kernel.org (Postfix) with ESMTP id 35D073FE341;\n\tWed, 29 Apr 2026 14:14:37 +0000 (UTC)", "from mx.ssi.bg (mx.ssi.bg [193.238.174.39])\n\t(using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits))\n\t(No client certificate requested)\n\tby smtp.subspace.kernel.org (Postfix) with ESMTPS id B327D277C9D;\n\tWed, 29 Apr 2026 14:14:33 +0000 (UTC)", "from mx.ssi.bg (localhost [127.0.0.1])\n\tby mx.ssi.bg (Potsfix) with ESMTP id 8008821A73;\n\tWed, 29 Apr 2026 17:14:11 +0300 (EEST)", "from box.ssi.bg (box.ssi.bg [193.238.174.46])\n\tby mx.ssi.bg (Potsfix) with ESMTPS;\n\tWed, 29 Apr 2026 17:14:10 +0300 (EEST)", "from ja.ssi.bg (unknown [213.16.62.126])\n\tby box.ssi.bg (Potsfix) with ESMTPSA id D693B62AE2;\n\tWed, 29 Apr 2026 17:14:09 +0300 (EEST)", "from ja.home.ssi.bg (localhost.localdomain [127.0.0.1])\n\tby ja.ssi.bg (8.18.1/8.18.1) with ESMTP id 63TEBMIP085098;\n\tWed, 29 Apr 2026 17:11:22 +0300", "(from root@localhost)\n\tby ja.home.ssi.bg (8.18.1/8.18.1/Submit) id 63TEBMDZ085097;\n\tWed, 29 Apr 2026 17:11:22 +0300" ], "ARC-Seal": "i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116;\n\tt=1777472075; cv=none;\n b=jsUd8TYaoEYn732wljxDxh53GyonEI8urjTxfDWGslGJf8kbM0BOHDGOpab0vAzBqti9VHn7QSJir0knk2Gyg7mKxfKi1ewJOkDi3NEYpHWDQ1NFzBJyIQKttTVplLUb0eFZswFZ1hW0Bso7D2kVOJzG2VHvoCDol0I0Q91RjyA=", "ARC-Message-Signature": "i=1; a=rsa-sha256; d=subspace.kernel.org;\n\ts=arc-20240116; t=1777472075; c=relaxed/simple;\n\tbh=dTo9HHruW8QVv/6+G5t8xN35S3zWzyhJt4phdhyCqTE=;\n\th=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References:\n\t MIME-Version;\n b=mKzaZUb4C2qIRZqHgxMAaAbCJ6AZwtUBn/E2SpQB/e3yF6t3yYeNMRrKCEXimCRXqxOKxYNDDST1UP9/aVPx7Jv5wlWphtbqfA4ot63Hx6ApZ4S2+McNTD+WWH5dd1Vbo2F8bhatOeXNLEvqbseWBs9D18Sr71/GpfFr/NW/4SA=", "ARC-Authentication-Results": "i=1; smtp.subspace.kernel.org;\n dmarc=pass (p=reject dis=none) header.from=ssi.bg;\n spf=pass smtp.mailfrom=ssi.bg;\n dkim=pass (4096-bit key) header.d=ssi.bg header.i=@ssi.bg header.b=lL1CGDvl;\n arc=none smtp.client-ip=193.238.174.39", "DKIM-Signature": "v=1; a=rsa-sha256; c=relaxed/relaxed; d=ssi.bg; h=cc:cc\n\t:content-transfer-encoding:date:from:from:in-reply-to:message-id\n\t:mime-version:references:reply-to:subject:subject:to:to; s=ssi;\n\t bh=+5l6HjIa6pEN1i6IQbOcoo3u2ww0YtZrxpJ29skJSz0=; b=lL1CGDvlbthX\n\traUjuGFSummZQkxq0baV/vrrR5TCfOWjtoq+ZAKUcXWuFS6Zh2NNxnq1tGJQhnvk\n\tZgjIjuAIHSzm7R9njqdnArqIbuWJwN8zSZGFpvLzGbcX4ZlKbTznkl85GLA1JkP0\n\tjYKaT6/OkffO9VStSsYbd9YwKipb4k3dVGdUaTYuZ6Qw+THbaQ9mk/MyJpzLJFcB\n\tPeLhrfLMnhCNh8cmd/PX0llnoGNlQ4euxeyJn/UTymBNn7KXqxG3s//NUeL0gNtL\n\tivESio5JZRgEc05uMZ6khMu60bvgD7SaIYPgBlttwAPdZPy0zXrxm5J6SxJClSbH\n\tar8CLjAPtlKvs3yx5qQ0ofjAc9azdfWUnGBXnOfUHuSwaolCwSxppKjLp1bvfY4t\n\tCKTwH3/Z52FLxcZ+yhXCcmO/1iTbL11A+tVUAKUN7U8YENS+UN83bth9wLq9/RXB\n\tNMOI2hVOmFU3VlRJruWV3md/qYgO0WGhZXJUBNL5pDm8R0eK0SkoLZTM9iImUsq3\n\tIjXVTPI9P9s2QwiU9MMNGwUcIGktU6FrBkSihJ+n8ce/c6poR79BmS/yBzcFEjfg\n\tiDHWBhhy8++C288U0yMADe4h1BB31HfQ+dbRWT91qnJViHM228oJW3I9TrRssLcK\n\tOxAdaKIpqQD3EmDb76a9VGGgywPQVhE=", "From": "Julian Anastasov <ja@ssi.bg>", "To": "Simon Horman <horms@verge.net.au>", "Cc": "Pablo Neira Ayuso <pablo@netfilter.org>, Florian Westphal <fw@strlen.de>,\n Waiman Long <longman@redhat.com>, lvs-devel@vger.kernel.org,\n netfilter-devel@vger.kernel.org", "Subject": "[PATCHv2 nf 4/8] ipvs: do not leak dest after get from dest trash", "Date": "Wed, 29 Apr 2026 17:10:51 +0300", "Message-ID": "<20260429141055.85052-5-ja@ssi.bg>", "X-Mailer": "git-send-email 2.53.0", "In-Reply-To": "<20260429141055.85052-1-ja@ssi.bg>", "References": "<20260429141055.85052-1-ja@ssi.bg>", "Precedence": "bulk", "X-Mailing-List": "netfilter-devel@vger.kernel.org", "List-Id": "<netfilter-devel.vger.kernel.org>", "List-Subscribe": "<mailto:netfilter-devel+subscribe@vger.kernel.org>", "List-Unsubscribe": "<mailto:netfilter-devel+unsubscribe@vger.kernel.org>", "MIME-Version": "1.0", "Content-Transfer-Encoding": "8bit" }, "content": "Sashiko warns about leaked dest if ip_vs_start_estimator()\nfails in ip_vs_add_dest(). Add ip_vs_trash_put_dest() to\nput back the dest into dest trash.\n\nLink: https://sashiko.dev/#/patchset/20260428175725.72050-1-ja%40ssi.bg\nFixes: 705dd3444081 (\"ipvs: use kthreads for stats estimation\")\nSigned-off-by: Julian Anastasov <ja@ssi.bg>\n---\n net/netfilter/ipvs/ip_vs_ctl.c | 37 ++++++++++++++++++++++------------\n 1 file changed, 24 insertions(+), 13 deletions(-)", "diff": "diff --git a/net/netfilter/ipvs/ip_vs_ctl.c b/net/netfilter/ipvs/ip_vs_ctl.c\nindex caec516856e9..d81077c2457a 100644\n--- a/net/netfilter/ipvs/ip_vs_ctl.c\n+++ b/net/netfilter/ipvs/ip_vs_ctl.c\n@@ -1102,6 +1102,24 @@ ip_vs_trash_get_dest(struct ip_vs_service *svc, int dest_af,\n \treturn dest;\n }\n \n+/* Put destination in trash */\n+static void ip_vs_trash_put_dest(struct netns_ipvs *ipvs,\n+\t\t\t\t struct ip_vs_dest *dest, unsigned long istart,\n+\t\t\t\t bool cleanup)\n+{\n+\tspin_lock_bh(&ipvs->dest_trash_lock);\n+\tIP_VS_DBG_BUF(3, \"Moving dest %s:%u into trash, dest->refcnt=%d\\n\",\n+\t\t IP_VS_DBG_ADDR(dest->af, &dest->addr), ntohs(dest->port),\n+\t\t refcount_read(&dest->refcnt));\n+\tif (list_empty(&ipvs->dest_trash) && !cleanup)\n+\t\tmod_timer(&ipvs->dest_trash_timer,\n+\t\t\t jiffies + (IP_VS_DEST_TRASH_PERIOD >> 1));\n+\t/* dest lives in trash with reference */\n+\tlist_add(&dest->t_list, &ipvs->dest_trash);\n+\tdest->idle_start = istart;\n+\tspin_unlock_bh(&ipvs->dest_trash_lock);\n+}\n+\n static void ip_vs_dest_rcu_free(struct rcu_head *head)\n {\n \tstruct ip_vs_dest *dest;\n@@ -1461,9 +1479,12 @@ ip_vs_add_dest(struct ip_vs_service *svc, struct ip_vs_dest_user_kern *udest)\n \t\t\t ntohs(dest->vport));\n \n \t\tret = ip_vs_start_estimator(svc->ipvs, &dest->stats);\n+\t\t/* On error put back dest into the trash */\n \t\tif (ret < 0)\n-\t\t\treturn ret;\n-\t\t__ip_vs_update_dest(svc, dest, udest, 1);\n+\t\t\tip_vs_trash_put_dest(svc->ipvs, dest, dest->idle_start,\n+\t\t\t\t\t false);\n+\t\telse\n+\t\t\t__ip_vs_update_dest(svc, dest, udest, 1);\n \t} else {\n \t\t/*\n \t\t * Allocate and initialize the dest structure\n@@ -1533,17 +1554,7 @@ static void __ip_vs_del_dest(struct netns_ipvs *ipvs, struct ip_vs_dest *dest,\n \t */\n \tip_vs_rs_unhash(dest);\n \n-\tspin_lock_bh(&ipvs->dest_trash_lock);\n-\tIP_VS_DBG_BUF(3, \"Moving dest %s:%u into trash, dest->refcnt=%d\\n\",\n-\t\t IP_VS_DBG_ADDR(dest->af, &dest->addr), ntohs(dest->port),\n-\t\t refcount_read(&dest->refcnt));\n-\tif (list_empty(&ipvs->dest_trash) && !cleanup)\n-\t\tmod_timer(&ipvs->dest_trash_timer,\n-\t\t\t jiffies + (IP_VS_DEST_TRASH_PERIOD >> 1));\n-\t/* dest lives in trash with reference */\n-\tlist_add(&dest->t_list, &ipvs->dest_trash);\n-\tdest->idle_start = 0;\n-\tspin_unlock_bh(&ipvs->dest_trash_lock);\n+\tip_vs_trash_put_dest(ipvs, dest, 0, cleanup);\n \n \t/* Queue up delayed work to expire all no destination connections.\n \t * No-op when CONFIG_SYSCTL is disabled.\n", "prefixes": [ "PATCHv2", "nf", "4/8" ] }