Commit c16f74dc authored by Zhengchuan Liang's avatar Zhengchuan Liang Committed by Steffen Klassert
Browse files

xfrm: input: hold netns during deferred transport reinjection



Transport-mode reinjection stores a struct net pointer in skb->cb and
uses it later from xfrm_trans_reinject(). That pointer must stay valid
until the deferred callback runs.

Take a netns reference when queueing deferred reinjection work and drop
it after the callback completes. Use maybe_get_net() so the queueing
path does not revive a namespace that is already being torn down.

This keeps the existing workqueue design and fixes the netns lifetime
handling in one place for all users of xfrm_trans_queue_net().

Fixes: 7b380192 ("xfrm: introduce xfrm_trans_queue_net")
Cc: stable@kernel.org
Reported-by: default avatarYuan Tan <yuantan098@gmail.com>
Reported-by: default avatarXin Liu <bird@lzu.edu.cn>
Co-developed-by: default avatarLuxing Yin <tr0jan@lzu.edu.cn>
Signed-off-by: default avatarLuxing Yin <tr0jan@lzu.edu.cn>
Signed-off-by: default avatarZhengchuan Liang <zcliangcn@gmail.com>
Signed-off-by: default avatarRen Wei <n05ec@lzu.edu.cn>
Assisted-by: Codex:gpt-5.4
Signed-off-by: default avatarSteffen Klassert <steffen.klassert@secunet.com>
parent 3e524173
Loading
Loading
Loading
Loading
+12 −4
Original line number Diff line number Diff line
@@ -797,9 +797,12 @@ static void xfrm_trans_reinject(struct work_struct *work)
	spin_unlock_bh(&trans->queue_lock);

	local_bh_disable();
	while ((skb = __skb_dequeue(&queue)))
		XFRM_TRANS_SKB_CB(skb)->finish(XFRM_TRANS_SKB_CB(skb)->net,
					       NULL, skb);
	while ((skb = __skb_dequeue(&queue))) {
		struct net *net = XFRM_TRANS_SKB_CB(skb)->net;

		XFRM_TRANS_SKB_CB(skb)->finish(net, NULL, skb);
		put_net(net);
	}
	local_bh_enable();
}

@@ -808,6 +811,7 @@ int xfrm_trans_queue_net(struct net *net, struct sk_buff *skb,
				       struct sk_buff *))
{
	struct xfrm_trans_tasklet *trans;
	struct net *hold_net;

	trans = this_cpu_ptr(&xfrm_trans_tasklet);

@@ -816,8 +820,12 @@ int xfrm_trans_queue_net(struct net *net, struct sk_buff *skb,

	BUILD_BUG_ON(sizeof(struct xfrm_trans_cb) > sizeof(skb->cb));

	hold_net = maybe_get_net(net);
	if (!hold_net)
		return -ENODEV;

	XFRM_TRANS_SKB_CB(skb)->finish = finish;
	XFRM_TRANS_SKB_CB(skb)->net = net;
	XFRM_TRANS_SKB_CB(skb)->net = hold_net;
	spin_lock_bh(&trans->queue_lock);
	__skb_queue_tail(&trans->queue, skb);
	spin_unlock_bh(&trans->queue_lock);