[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <aUqVmHOvUe0KTFWB@strlen.de>
Date: Tue, 23 Dec 2025 14:14:00 +0100
From: Florian Westphal <fw@...len.de>
To: Jozsef Kadlecsik <kadlec@...ckhole.kfki.hu>
Cc: syzbot <syzbot+ff16b505ec9152e5f448@...kaller.appspotmail.com>,
coreteam@...filter.org, davem@...emloft.net, edumazet@...gle.com,
horms@...nel.org, kuba@...nel.org, linux-kernel@...r.kernel.org,
netdev@...r.kernel.org, netfilter-devel@...r.kernel.org,
pabeni@...hat.com, pablo@...filter.org, phil@....cc,
syzkaller-bugs@...glegroups.com
Subject: Re: [syzbot] [netfilter?] possible deadlock in
nf_tables_dumpreset_obj
Jozsef Kadlecsik <kadlec@...ckhole.kfki.hu> wrote:
> > Not yet sure how to avoid it.
> > Maybe we could get rid of 'lock(nfnl_subsys_ipset);'
> > from the xt_set module call paths.
>
> I don't know how calling it could be avoided: userspace commands (ipset +
> iptables checkentry using ipset match/target) are serialized by
> nfnl_subsys_ipset.
Ok, thanks Jozsef. In that case its much simpler to leave ipset
alone and add a new reset serialization mutex in nf_tables.
Powered by blists - more mailing lists