]> git.ipfire.org Git - thirdparty/linux.git/commitdiff
xfrm: input: hold netns during deferred transport reinjection
authorZhengchuan Liang <zcliangcn@gmail.com>
Fri, 22 May 2026 09:31:55 +0000 (17:31 +0800)
committerSteffen Klassert <steffen.klassert@secunet.com>
Tue, 26 May 2026 08:35:30 +0000 (10:35 +0200)
Transport-mode reinjection stores a struct net pointer in skb->cb and
uses it later from xfrm_trans_reinject(). That pointer must stay valid
until the deferred callback runs.

Take a netns reference when queueing deferred reinjection work and drop
it after the callback completes. Use maybe_get_net() so the queueing
path does not revive a namespace that is already being torn down.

This keeps the existing workqueue design and fixes the netns lifetime
handling in one place for all users of xfrm_trans_queue_net().

Fixes: 7b3801927e52 ("xfrm: introduce xfrm_trans_queue_net")
Cc: stable@kernel.org
Reported-by: Yuan Tan <yuantan098@gmail.com>
Reported-by: Xin Liu <bird@lzu.edu.cn>
Co-developed-by: Luxing Yin <tr0jan@lzu.edu.cn>
Signed-off-by: Luxing Yin <tr0jan@lzu.edu.cn>
Signed-off-by: Zhengchuan Liang <zcliangcn@gmail.com>
Signed-off-by: Ren Wei <n05ec@lzu.edu.cn>
Assisted-by: Codex:gpt-5.4
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
net/xfrm/xfrm_input.c

index f65291eba1f68cb1368d9f75d95705d611ebe7ec..e4c2cd24936d3f8f94ce8b83e46a774e633ff3ac 100644 (file)
@@ -797,9 +797,12 @@ static void xfrm_trans_reinject(struct work_struct *work)
        spin_unlock_bh(&trans->queue_lock);
 
        local_bh_disable();
-       while ((skb = __skb_dequeue(&queue)))
-               XFRM_TRANS_SKB_CB(skb)->finish(XFRM_TRANS_SKB_CB(skb)->net,
-                                              NULL, skb);
+       while ((skb = __skb_dequeue(&queue))) {
+               struct net *net = XFRM_TRANS_SKB_CB(skb)->net;
+
+               XFRM_TRANS_SKB_CB(skb)->finish(net, NULL, skb);
+               put_net(net);
+       }
        local_bh_enable();
 }
 
@@ -808,6 +811,7 @@ int xfrm_trans_queue_net(struct net *net, struct sk_buff *skb,
                                       struct sk_buff *))
 {
        struct xfrm_trans_tasklet *trans;
+       struct net *hold_net;
 
        trans = this_cpu_ptr(&xfrm_trans_tasklet);
 
@@ -816,8 +820,12 @@ int xfrm_trans_queue_net(struct net *net, struct sk_buff *skb,
 
        BUILD_BUG_ON(sizeof(struct xfrm_trans_cb) > sizeof(skb->cb));
 
+       hold_net = maybe_get_net(net);
+       if (!hold_net)
+               return -ENODEV;
+
        XFRM_TRANS_SKB_CB(skb)->finish = finish;
-       XFRM_TRANS_SKB_CB(skb)->net = net;
+       XFRM_TRANS_SKB_CB(skb)->net = hold_net;
        spin_lock_bh(&trans->queue_lock);
        __skb_queue_tail(&trans->queue, skb);
        spin_unlock_bh(&trans->queue_lock);