Received: by 2002:a05:7412:bb8d:b0:d7:7d3a:4fe2 with SMTP id js13csp468077rdb; Tue, 15 Aug 2023 02:11:52 -0700 (PDT) X-Google-Smtp-Source: AGHT+IFhTdXM5YuVaIzCZ2T1IUzkGIDwYgmO9guJzTKJGJ6JEeWL0kdzs/aFDSPtGZ4gZsxltxvY X-Received: by 2002:a05:6a00:23c6:b0:686:5f73:4eac with SMTP id g6-20020a056a0023c600b006865f734eacmr2284638pfc.13.1692090712290; Tue, 15 Aug 2023 02:11:52 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1692090712; cv=none; d=google.com; s=arc-20160816; b=rXV7gdhgfR07eqlHBZO9RPsy0W1psPcdR4EEX93yyaiSBMYo12vGXfrmtu1F38BG3N n5kYg6JACslOj/opUzg5n0hkMAmRCrF5CCmj3eWUAeGWRYzG7Qu5OsT5avVpGxIHOEXg W62trScz3IpfWMnkWrh/GqjHJmWg6MDPv/3nZMJ8pR3L4RyFgMMQDJAVXPFJFchka5Xv IKnmjsuJJKfTkHjbZpluN0CumClOWmrkKjC9OkKnmeMquFTzts16jQxj1lfrCK3hziG6 BFCFATdT/5+Ffk94DiTzDXW6UjeMDi4jxgKY4NfrMDHJL39Z6YRIkVB+d2a21jXx/h6u uAPw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:in-reply-to:content-disposition:mime-version :references:message-id:subject:cc:to:from:date; bh=HLkJ0cPY1S6WfQUO//7rMve1m4Ca0PyVr0hre3qsoyI=; fh=E/ME1I1Dk0AVL+lR6OsHeoqui3e5ehMvzcULWYkYl5M=; b=VEXNZql8qizuwsX79U0aIOlQnvA9hEs1wSlY5sjzui4iXkfEcLwmpk/AdEG2XDOW68 L2sE/kqPjCUnm3J9NN4lAKjeGLqjS0NqaSV/7PrkkarEnt1MI2RZv+JR6sw856gmgk1L jNjyI0hE8vLI5N3M9ohsRE2fxF4j6KwfJgxuCyvr4Qw3XF25Ausg3RASNtINftVj1P+f xJnZL6BbsRwlQBth1vGNIVPEOIa+LFZQKzg1e+1cr4LmMBwEcoivUOHA/wO52JcD99fu JsfRGDLlGR928yHWja6wk2hctPX6ve09G0aZjvrT6pksZ7iKQkduSbJesiZE0aBRgxJj P04A== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id s9-20020a056a00194900b006873f40fc77si9855710pfk.103.2023.08.15.02.11.38; Tue, 15 Aug 2023 02:11:52 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S235473AbjHOHw6 (ORCPT + 99 others); Tue, 15 Aug 2023 03:52:58 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:47254 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S235484AbjHOHwe (ORCPT ); Tue, 15 Aug 2023 03:52:34 -0400 Received: from 167-179-156-38.a7b39c.syd.nbn.aussiebb.net (167-179-156-38.a7b39c.syd.nbn.aussiebb.net [167.179.156.38]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 295821733; Tue, 15 Aug 2023 00:52:31 -0700 (PDT) Received: from loth.rohan.me.apana.org.au ([192.168.167.2]) by formenos.hmeau.com with smtp (Exim 4.94.2 #2 (Debian)) id 1qVoq8-003twA-AO; Tue, 15 Aug 2023 15:51:45 +0800 Received: by loth.rohan.me.apana.org.au (sSMTP sendmail emulation); Tue, 15 Aug 2023 15:51:44 +0800 Date: Tue, 15 Aug 2023 15:51:44 +0800 From: Herbert Xu To: Leon Romanovsky Cc: Florian Westphal , Dong Chenchen , steffen.klassert@secunet.com, davem@davemloft.net, edumazet@google.com, kuba@kernel.org, pabeni@redhat.com, timo.teras@iki.fi, yuehaibing@huawei.com, weiyongjun1@huawei.com, netdev@vger.kernel.org, linux-kernel@vger.kernel.org Subject: Re: [Patch net, v2] net: xfrm: skip policies marked as dead while reinserting policies Message-ID: References: <20230814140013.712001-1-dongchenchen2@huawei.com> <20230815060026.GE22185@unreal> <20230815060454.GA2833@breakpoint.cc> <20230815073033.GJ22185@unreal> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20230815073033.GJ22185@unreal> X-Spam-Status: No, score=2.7 required=5.0 tests=BAYES_00,HELO_DYNAMIC_IPADDR2, PDS_RDNS_DYNAMIC_FP,RCVD_IN_DNSWL_BLOCKED,RDNS_DYNAMIC,SPF_HELO_NONE, SPF_PASS,TVD_RCVD_IP,URIBL_BLOCKED autolearn=no autolearn_force=no version=3.4.6 X-Spam-Level: ** X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Tue, Aug 15, 2023 at 10:30:33AM +0300, Leon Romanovsky wrote: > > But policy has, and we are not interested in validity of it as first > check in if (...) will be true for policy->walk.dead. > > So it is safe to call to dir = xfrm_policy_id2dir(policy->index) even > for dead policy. If you dereference policy->index on a walker object it will read memory before the start of the walker object. That could do anything, perhaps even triggering a page fault. Cheers, -- Email: Herbert Xu Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt