Received: by 2002:a05:6358:5282:b0:b5:90e7:25cb with SMTP id g2csp2817001rwa; Mon, 22 Aug 2022 14:33:37 -0700 (PDT) X-Google-Smtp-Source: AA6agR6LrbmlvNC2cypEjwjhe8XYozgJTAtCmoRQOqB8aIP+xph9t+CeDBbRCdPxp4VoqRKD2shI X-Received: by 2002:a17:906:ef8c:b0:730:ebff:9e19 with SMTP id ze12-20020a170906ef8c00b00730ebff9e19mr13946757ejb.300.1661204017363; Mon, 22 Aug 2022 14:33:37 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1661204017; cv=none; d=google.com; s=arc-20160816; b=vG3ydIhIHzr1tEDBf3aENjmK5A6OUkT2r1amajFNxQ+OoGhCmfzVHyTExB5yW3apsp jFAl9ctCBP4tCBYJzorF6xb61gLPfUQQZhOx0wKLEkWWeAW6letdUvg9Ce/o4BShFXqr 35Epw6/O6SqitFIGKZO/J6JaSgBbz2JmwGQri3MEljE07tik+cIjFSh5Q7uxXnEXD9qE FGSkTSSzLFsiWllHUBgWip83pojdouy1oLVeIXLIEareTm68ge0pjSgID5hYcsZPkhQ3 9qRHKpHvUezDJ5Ti2rd8lIV16xSy8R9iokSeh60LEVfAdoGB4Qxk6cbkJknOuP1niYmc 0qrA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:user-agent:in-reply-to:content-transfer-encoding :content-disposition:mime-version:references:message-id:subject:cc :to:from:date; bh=QHaeWYNIjnz7WsjsjLwGSP076Ru5CEqPayejJjqMruk=; b=f8K8IkeJDkprRMR0zvwtKe/zQbuG8WbB7nj5FJR+yj5VQbCGJoBfj1KkyZ9fb8wZNc peNDQHlxJJON0lphMzTjzBq8937UClmVy4hgmNzz/ttMumXjfi9V1W0al2WSs9V4gHel mmDK3idpWDrLTS+hbWhbb3v5a3IigJ72kMffSrfh44m6Cv1z99WGDFHYEHSXC0VcwVpR rxYR89SE7Qq1oFPieUbvTZAX5vvaSLhYAOlTP7dE9vW72s+f/saKHeNHIUiA/ouZ5/el L06VMDL7R+icaharJ3Fzez6QEpNNBTMQdpSjoRWq0HfVlQehdbiSZ7ofxOOPsnqqXNh/ WPGQ== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id dr21-20020a170907721500b0073d931b8e1dsi1050894ejc.728.2022.08.22.14.33.11; Mon, 22 Aug 2022 14:33:37 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S237635AbiHVUlp convert rfc822-to-8bit (ORCPT + 99 others); Mon, 22 Aug 2022 16:41:45 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:37370 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S237572AbiHVUln (ORCPT ); Mon, 22 Aug 2022 16:41:43 -0400 Received: from Chamillionaire.breakpoint.cc (Chamillionaire.breakpoint.cc [IPv6:2a0a:51c0:0:12e:520::1]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 37E5A4507A; Mon, 22 Aug 2022 13:41:41 -0700 (PDT) Received: from fw by Chamillionaire.breakpoint.cc with local (Exim 4.92) (envelope-from ) id 1oQEES-0006XR-Th; Mon, 22 Aug 2022 22:41:12 +0200 Date: Mon, 22 Aug 2022 22:41:12 +0200 From: Florian Westphal To: Gabriel Ryan Cc: Florian Westphal , Abhishek Shah , coreteam@netfilter.org, davem@davemloft.net, edumazet@google.com, kadlec@netfilter.org, kuba@kernel.org, netdev@vger.kernel.org, netfilter-devel@vger.kernel.org, pabeni@redhat.com, pablo@netfilter.org, linux-kernel@vger.kernel.org Subject: Re: data-race in nf_tables_newtable / nf_tables_newtable Message-ID: <20220822204112.GA19050@breakpoint.cc> References: <20220819123542.GA2461@breakpoint.cc> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: 8BIT In-Reply-To: User-Agent: Mutt/1.10.1 (2018-07-13) X-Spam-Status: No, score=-2.6 required=5.0 tests=BAYES_00,RCVD_IN_DNSWL_LOW, SPF_HELO_PASS,SPF_PASS,T_SCC_BODY_TEXT_LINE autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Gabriel Ryan wrote: > Hi Florian, > > I just looked at the lock event trace from our report and it looks > like two distinct commit mutexes were held when the race was > triggered. I think the race is probably on the table_handle variable > on net/netfilter/nf_tables_api.c:1221, and not the table->handle field > being written to. See https://patchwork.ozlabs.org/project/netfilter-devel/patch/20220821085939.571378-1-pablo@netfilter.org/ which makes table_handle per netns.