Patch Detail
get:
Show a patch.
patch:
Update a patch.
put:
Update a patch.
GET /api/1.1/patches/2230382/?format=api
{ "id": 2230382, "url": "http://patchwork.ozlabs.org/api/1.1/patches/2230382/?format=api", "web_url": "http://patchwork.ozlabs.org/project/netfilter-devel/patch/20260429175613.1459342-3-tristmd@gmail.com/", "project": { "id": 26, "url": "http://patchwork.ozlabs.org/api/1.1/projects/26/?format=api", "name": "Netfilter Development", "link_name": "netfilter-devel", "list_id": "netfilter-devel.vger.kernel.org", "list_email": "netfilter-devel@vger.kernel.org", "web_url": null, "scm_url": null, "webscm_url": null }, "msgid": "<20260429175613.1459342-3-tristmd@gmail.com>", "date": "2026-04-29T17:56:12", "name": "[2/2] netfilter: ip6_tables: allocate hook ops before making table visible", "commit_ref": null, "pull_url": null, "state": "new", "archived": false, "hash": "b71007aac7a6733e7b78a34768ad3df1e53de668", "submitter": { "id": 93179, "url": "http://patchwork.ozlabs.org/api/1.1/people/93179/?format=api", "name": "Tristan Madani", "email": "tristmd@gmail.com" }, "delegate": null, "mbox": "http://patchwork.ozlabs.org/project/netfilter-devel/patch/20260429175613.1459342-3-tristmd@gmail.com/mbox/", "series": [ { "id": 502119, "url": "http://patchwork.ozlabs.org/api/1.1/series/502119/?format=api", "web_url": "http://patchwork.ozlabs.org/project/netfilter-devel/list/?series=502119", "date": "2026-04-29T17:56:10", "name": "netfilter: fix NULL ops race in iptable lazy init", "version": 1, "mbox": "http://patchwork.ozlabs.org/series/502119/mbox/" } ], "comments": "http://patchwork.ozlabs.org/api/patches/2230382/comments/", "check": "pending", "checks": "http://patchwork.ozlabs.org/api/patches/2230382/checks/", "tags": {}, "headers": { "Return-Path": "\n <netfilter-devel+bounces-12303-incoming=patchwork.ozlabs.org@vger.kernel.org>", "X-Original-To": [ "incoming@patchwork.ozlabs.org", "netfilter-devel@vger.kernel.org" ], "Delivered-To": "patchwork-incoming@legolas.ozlabs.org", "Authentication-Results": [ "legolas.ozlabs.org;\n\tdkim=pass (2048-bit key;\n unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256\n header.s=20251104 header.b=cOCqCjDy;\n\tdkim-atps=neutral", "legolas.ozlabs.org;\n spf=pass (sender SPF authorized) smtp.mailfrom=vger.kernel.org\n (client-ip=172.105.105.114; helo=tor.lore.kernel.org;\n envelope-from=netfilter-devel+bounces-12303-incoming=patchwork.ozlabs.org@vger.kernel.org;\n receiver=patchwork.ozlabs.org)", "smtp.subspace.kernel.org;\n\tdkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com\n header.b=\"cOCqCjDy\"", "smtp.subspace.kernel.org;\n arc=none smtp.client-ip=209.85.221.51", "smtp.subspace.kernel.org;\n dmarc=pass (p=none dis=none) header.from=gmail.com", "smtp.subspace.kernel.org;\n spf=pass smtp.mailfrom=gmail.com" ], "Received": [ "from tor.lore.kernel.org (tor.lore.kernel.org [172.105.105.114])\n\t(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)\n\t key-exchange x25519)\n\t(No client certificate requested)\n\tby legolas.ozlabs.org (Postfix) with ESMTPS id 4g5Q4R2yhGz1xqf\n\tfor <incoming@patchwork.ozlabs.org>; Thu, 30 Apr 2026 03:57:27 +1000 (AEST)", "from smtp.subspace.kernel.org (conduit.subspace.kernel.org\n [100.90.174.1])\n\tby tor.lore.kernel.org (Postfix) with ESMTP id 6DD1A30406B1\n\tfor <incoming@patchwork.ozlabs.org>; Wed, 29 Apr 2026 17:56:36 +0000 (UTC)", "from localhost.localdomain (localhost.localdomain [127.0.0.1])\n\tby smtp.subspace.kernel.org (Postfix) with ESMTP id 28F4641C2F6;\n\tWed, 29 Apr 2026 17:56:20 +0000 (UTC)", "from mail-wr1-f51.google.com (mail-wr1-f51.google.com\n [209.85.221.51])\n\t(using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits))\n\t(No client certificate requested)\n\tby smtp.subspace.kernel.org (Postfix) with ESMTPS id 07662413234\n\tfor <netfilter-devel@vger.kernel.org>; Wed, 29 Apr 2026 17:56:17 +0000 (UTC)", "by mail-wr1-f51.google.com with SMTP id\n ffacd0b85a97d-43cfd832155so59306f8f.1\n for <netfilter-devel@vger.kernel.org>;\n Wed, 29 Apr 2026 10:56:17 -0700 (PDT)", "from debian.. ([2001:41d0:303:db6b::])\n by smtp.gmail.com with ESMTPSA id\n ffacd0b85a97d-447b3d48517sm6183750f8f.5.2026.04.29.10.56.15\n (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);\n Wed, 29 Apr 2026 10:56:15 -0700 (PDT)" ], "ARC-Seal": "i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116;\n\tt=1777485379; cv=none;\n b=V16CCXBjX0MG/sOZYjfvbFbl/wYrClriNRC5CMpJvTfB1qA9as8cizvn6OKgPNwyH4b9ag68wTU0JCIkUasRgGcAX6Pw3TUh7jsGC0nzdTgN9eZx4IipUBdsOBVbnOT/GzT8KLcqDdU+iZoJiFId8N4ehMRTFPjVEkFETZHmnP0=", "ARC-Message-Signature": "i=1; a=rsa-sha256; d=subspace.kernel.org;\n\ts=arc-20240116; t=1777485379; c=relaxed/simple;\n\tbh=hPxaXd3xjy2aLoQlfjNn2TCMZsSvXUAXKxOi1BUCOho=;\n\th=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References:\n\t MIME-Version;\n b=Eo2V1V8gHAOSietNt2HPKoWQfZUdSriT7TYLipFyLR8+KcMxtITMROlK1EcZcOCO19ksf4uFlMfu61BdA4J/OhntwwZjLEqF3I+Y23va5MlHxhbqzRxE/+HclzwHALfleh9pFwhZcald9Lazhk2uwuxkyhRVJChY6smMJSa1BcY=", "ARC-Authentication-Results": "i=1; smtp.subspace.kernel.org;\n dmarc=pass (p=none dis=none) header.from=gmail.com;\n spf=pass smtp.mailfrom=gmail.com;\n dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com\n header.b=cOCqCjDy; arc=none smtp.client-ip=209.85.221.51", "DKIM-Signature": "v=1; a=rsa-sha256; c=relaxed/relaxed;\n d=gmail.com; s=20251104; t=1777485376; x=1778090176;\n darn=vger.kernel.org;\n h=content-transfer-encoding:mime-version:references:in-reply-to\n :message-id:date:subject:cc:to:from:from:to:cc:subject:date\n :message-id:reply-to;\n bh=m+m+c0QFSmHtefs8UGhgSoeILNWZg2rQuDAplxBi5ys=;\n b=cOCqCjDy12B6ro9esSG+onM18Ju1+DNt8/lJj8j5rlGgFor/h5mlDqT3erRDdbA+ES\n gHnNUhRutovnkf/sUDku21JaD+l5b3ZO7HzsvKFyA+v1p8eOYzU+H/FXzPAMhg2ke7yG\n UNeh6nngm5LEjC2jXkbTF3ix0qJV3IHHLcfDQX/YcUUl2BwRkS8XkBfbgD6gMUlnw+ji\n lC5Ht0vquY4rWMH8MPLqKQAS/TYI6O7AFSiq9VyoMmWuzZPY4MDdk5o1k7fLD+0zEts9\n TKqYWefBXPw6owlzPTYACRXr2GBB3VqLj7eitM5b9JV8SJJyPi5S7jhq1CfRZOEhEsBv\n eMzg==", "X-Google-DKIM-Signature": "v=1; a=rsa-sha256; c=relaxed/relaxed;\n d=1e100.net; s=20251104; t=1777485376; x=1778090176;\n h=content-transfer-encoding:mime-version:references:in-reply-to\n :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from\n :to:cc:subject:date:message-id:reply-to;\n bh=m+m+c0QFSmHtefs8UGhgSoeILNWZg2rQuDAplxBi5ys=;\n b=QV3RC+kvGMOhgNRirjuGfWlIa6PKv2iJc4lYp0F+JfYUVI/gWrfbqXRWHm9iqjINc8\n moCZTFNmk+K4XhJS5EjwaPcgd5U27sZgNftsKNnpNBiZX7irmVQ7PCRfQa0bC32NjgCc\n 4HjsN6eWnQ34vQ751svLiizo9beCm+4pSU74Gf5vZx6OQuSnPR3Uu2XnmXG24Vxw0ngM\n qZEGGerWxR7a4vrZjuBXiYznGceigRSGqAmk7KVpqZSpiOIZp7+8BipDMn35D52txtS9\n QJVmCmFSvifZrHznkAEYE75OsEAn5ZQW9SUtOQnL4xRzP4elsjC0ZPGnkDYwp71isMzU\n 9NLA==", "X-Forwarded-Encrypted": "i=1;\n AFNElJ/Oc1OkdX4TmHTCiNk7ylq7tIsryK3HrRGHYAH4wbgoB9HSJKH0XpPUJnuiTVbwTT6w6V276DtKtmn2TNyXn7k=@vger.kernel.org", "X-Gm-Message-State": "AOJu0YxbjVS9SCXTkyTKSvo8pnEM+YgNf9VVSdgnb0Su8NwTTSYUGUL5\n\tZtJAwmZRt/YA+7knNnOFwbsk8DQMgEt4PvX3noz4pSlnby+2yPBrDxI=", "X-Gm-Gg": "AeBDiesS4xiUB53ALca6LBpaa9OOwkcqWd4m4dWTQUpD+P+mvqMynQLwJMgu6cz1XDD\n\tlk7meWAv7KH3q+1c5pDrUcyWaBBH+cN6SKgUm1Os67NtSt8NfjSPKL3jP0XVrkYxlJY1Hm4t51V\n\tHw0RC6fcDpoMCxzIzqawjrzftPyrVv4lE3eDp9EvGlawILvxNMlDyIVxhwgYkXIt45bb11708rL\n\tGcUxPM8xQuZHBRmaOSYjyHOGu6bcmU37UlFGv7CRrTWCphEtkJPq4K3iGuOmAbWoX/7tDPMUzwz\n\tDvPiAVZ2xBmMdm36eciT4EgjpD55Fo08ymu15M7OmRxnKN1kzLjS/J4TeznSa+hREpXV0+NzGlq\n\tdoRG8mYzP77H3/gZAAAitHiLRD3Ak7RNo1VMiomJ6xu7DLub8z6gjiVs8AITHg5azY33slwarUo\n\tGVsIXjAtDUhBzQSg==", "X-Received": "by 2002:a5d:5848:0:b0:441:2473:c30a with SMTP id\n ffacd0b85a97d-446496d79aemr15475160f8f.31.1777485376333;\n Wed, 29 Apr 2026 10:56:16 -0700 (PDT)", "From": "Tristan Madani <tristmd@gmail.com>", "To": "Pablo Neira Ayuso <pablo@netfilter.org>", "Cc": "Florian Westphal <fw@strlen.de>,\n\tPhil Sutter <phil@nwl.cc>,\n\tnetfilter-devel@vger.kernel.org,\n\tnetdev@vger.kernel.org,\n\tstable@vger.kernel.org,\n\tlinux-kernel@vger.kernel.org,\n\tTristan Madani <tristan@talencesecurity.com>", "Subject": "[PATCH 2/2] netfilter: ip6_tables: allocate hook ops before making\n table visible", "Date": "Wed, 29 Apr 2026 17:56:12 +0000", "Message-ID": "<20260429175613.1459342-3-tristmd@gmail.com>", "X-Mailer": "git-send-email 2.47.3", "In-Reply-To": "<20260429175613.1459342-1-tristmd@gmail.com>", "References": "<20260429175613.1459342-1-tristmd@gmail.com>", "Precedence": "bulk", "X-Mailing-List": "netfilter-devel@vger.kernel.org", "List-Id": "<netfilter-devel.vger.kernel.org>", "List-Subscribe": "<mailto:netfilter-devel+subscribe@vger.kernel.org>", "List-Unsubscribe": "<mailto:netfilter-devel+unsubscribe@vger.kernel.org>", "MIME-Version": "1.0", "Content-Transfer-Encoding": "8bit" }, "content": "From: Tristan Madani <tristan@talencesecurity.com>\n\nip6t_register_table() first calls xt_register_table() which adds the\ntable to the per-netns list, making it visible to other code paths. Only\nafter that does it allocate the per-net copy of hook ops via\nkmemdup_array(). This leaves a window where the table is findable via\nxt_find_table() but has ops=NULL.\n\nIf cleanup_net runs during this window (racing namespace teardown\nagainst lazy table init), ip6t_unregister_table_pre_exit() finds the\ntable via xt_find_table() and passes the NULL ops pointer to\nnf_unregister_net_hooks(), causing a general protection fault when it\ndereferences ops[0].pf.\n\nFix this by allocating the ops array before calling xt_register_table(),\nso the table is never visible in the list with a NULL ops pointer.\n\nFixes: ee177a54413a (\"netfilter: ip6_tables: pass table pointer via nf_hook_ops\")\nCc: stable@vger.kernel.org\nSigned-off-by: Tristan Madani <tristan@talencesecurity.com>\n---\n net/ipv6/netfilter/ip6_tables.c | 28 ++++++++++++++++------------\n 1 file changed, 16 insertions(+), 12 deletions(-)", "diff": "diff --git a/net/ipv6/netfilter/ip6_tables.c b/net/ipv6/netfilter/ip6_tables.c\nindex d585ac3c11133..17143277637a5 100644\n--- a/net/ipv6/netfilter/ip6_tables.c\n+++ b/net/ipv6/netfilter/ip6_tables.c\n@@ -1754,6 +1754,21 @@ int ip6t_register_table(struct net *net, const struct xt_table *table,\n \t\treturn ret;\n \t}\n \n+\tif (template_ops) {\n+\t\tnum_ops = hweight32(table->valid_hooks);\n+\t\tif (num_ops == 0) {\n+\t\t\txt_free_table_info(newinfo);\n+\t\t\treturn -EINVAL;\n+\t\t}\n+\n+\t\tops = kmemdup_array(template_ops, num_ops, sizeof(*ops),\n+\t\t\t\t GFP_KERNEL);\n+\t\tif (!ops) {\n+\t\t\txt_free_table_info(newinfo);\n+\t\t\treturn -ENOMEM;\n+\t\t}\n+\t}\n+\n \tnew_table = xt_register_table(net, table, &bootstrap, newinfo);\n \tif (IS_ERR(new_table)) {\n \t\tstruct ip6t_entry *iter;\n@@ -1761,24 +1776,13 @@ int ip6t_register_table(struct net *net, const struct xt_table *table,\n \t\txt_entry_foreach(iter, loc_cpu_entry, newinfo->size)\n \t\t\tcleanup_entry(iter, net);\n \t\txt_free_table_info(newinfo);\n+\t\tkfree(ops);\n \t\treturn PTR_ERR(new_table);\n \t}\n \n \tif (!template_ops)\n \t\treturn 0;\n \n-\tnum_ops = hweight32(table->valid_hooks);\n-\tif (num_ops == 0) {\n-\t\tret = -EINVAL;\n-\t\tgoto out_free;\n-\t}\n-\n-\tops = kmemdup_array(template_ops, num_ops, sizeof(*ops), GFP_KERNEL);\n-\tif (!ops) {\n-\t\tret = -ENOMEM;\n-\t\tgoto out_free;\n-\t}\n-\n \tfor (i = 0; i < num_ops; i++)\n \t\tops[i].priv = new_table;\n \n", "prefixes": [ "2/2" ] }