From nobody Sat Jul 25 03:46:49 2026 Received: from mail-wm1-f49.google.com (mail-wm1-f49.google.com [209.85.128.49]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8D7D838E8BB for ; Sun, 19 Jul 2026 10:58:12 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.49 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784458694; cv=none; b=TTa565wWatLEQsQlHAcnel7X6fDFgFDjmuzb/QRspeV298WxX029X950vw5B3ul/gZn5fft2fP0kzbUc6yyM4XNlodgs6rbGxCxURH8pV9bT/thVnNO27Uz/rO1Rq0jmA61pQTsinW/Jq5jeUWM1megN/pSzwgdTRrUCajnHPyE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784458694; c=relaxed/simple; bh=kG68kuGxwTUfYF9d6eeoBkKrI492WSL5nm8S3ECKohQ=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=CEEBhKEEqTLzyJGlLl7stuhm+a9vffLvP5xQ3gfkcG5g6Rsh4EvldmudvUIexeyMhfifZNbmWoZkBzOh3RL/QAUHS3gyjDJfH6R2vnLdDxt7rSt+8LPUeYSVmDpxRbmGJquYgzSZFv+4CPNxKNR+0+IbXqAzblEKvhixHXXOhuY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=ZBr7zHI3; arc=none smtp.client-ip=209.85.128.49 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="ZBr7zHI3" Received: by mail-wm1-f49.google.com with SMTP id 5b1f17b1804b1-49554ebb87dso7921045e9.3 for ; Sun, 19 Jul 2026 03:58:12 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784458691; x=1785063491; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=7HzRtazZ4L1gYUv2iM5Gcb2OTN39V4RyFH9aAlRzqso=; b=ZBr7zHI30EFKhzYd2TnU6qFjCU/DOAf6CABgZ1aDlLXBURtAELzLWPymhdiriiduKu 3VbtB0pWkQTRIZvIz3EaPPw2xcxDbNzIFei9e7BxrLpICwPBAl3l4BnLIWwg23hj+nJ+ 2zFBuIma7qShyfQ9fZeJunbfYwleSchnPT2eQx+4UmJnBzTFkj7k5Z00JARW1SyCLS6B mHYDWTb8wGNwbaa+XIJt5vEU4tWtiv7KI/vRTETYj4k3wd+9hkrB+8i+vnxa5RMnCJy7 09D2NLf/D8JKS7JTVGsvMzF63/UaU7WJJI3/a1tonoB5/Ar/3oGZHSGGfnx6EN73mNOY VB9g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784458691; x=1785063491; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=7HzRtazZ4L1gYUv2iM5Gcb2OTN39V4RyFH9aAlRzqso=; b=TqOy9ZVlE3k34o7n0ZnEO2m7OhrxSpaIVHO/GiXel3f0PSKy4iDpmZHITto87kvIcw /U+VGeoQRVDkmCiThw9ZVARQuvgZDYd/BCe3fzFh8NBcqrZhWjUP3iZ75HEHfzJHuCGo upvWPoWfFi6C5RG9O3C1giZ2eCxKz0ARZCVPYehTCuOi2ouPzIkm1KvoavvjXDM+jlr6 ncZQCuzJt84xZANuqRepqdx+H0Nja7NaLjJt7Qjft0Qf3KQY4I5EHdlJhm0wO6zNM4Yx M24Rg4QiNIQTuImcGU1I3CsLyuyoALDNxoYpwdcztdnrT1lGZNTfo9n41zWmk+3I0iKV x5Lg== X-Forwarded-Encrypted: i=1; AHgh+RoX8xBdij/LWeAaXoo0BjFu64RwkDmRV/RazoBo8MARcpahBc8e/CeR/pkGuq1t82DrUNGeEt3qgbwt4PA=@vger.kernel.org X-Gm-Message-State: AOJu0YydZXm9+0jXx7HctcSnDP5biv5JclOpjrxJqVf0gb5Y+VyRMscz TpRPOJx81v4wCy8ym6ATHJ12vuC//4Zzd1CFDL/GmiXJW1ONySDxk/zL X-Gm-Gg: AfdE7ckoM+kyz72hU/Du/yXsnWECTcPTXVHxD57l7YtiTyMAoLGpqKBteZ0XGgAGi8X ON3DGTqpIX+vbGbaGh85wLTfZ8phfvpE/5IEzsPPeL2yrsEjEdRGFia+dd55YiwLIESUrwcNuql UcnU4XDm/9XNw5Qw+xN8iYz3aMkOKm3/LXyVdtipWF5t35f4tRj2nZMWBA2VWnAjTfWDN2Y4RH9 39LHLQvO0QkRSQbT4vfmpJBkj+QJbtwyT8UlFWHm0QeM5uPjs7RdryUwXFYtRxukDYCLNiPC1in 667oBDG5t1EjgbJiQ4VszmbEL0ujFQBQqajiOsF+qOmRtOYAQbq/792CPmvzHouauowDWCMJ1da DBwaKJHhSRBTYCg7M327G7j0vZZ14VpPd9KrxuTBOuVNh1KAWacpDVMKtqqv/YZ+Kb06HizTcU9 Y1Dprfqfjt X-Received: by 2002:a05:600c:4703:b0:495:4e89:3f30 with SMTP id 5b1f17b1804b1-4954e893f8cmr84812365e9.15.1784458690612; Sun, 19 Jul 2026 03:58:10 -0700 (PDT) Received: from fedora-dev ([46.10.223.24]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-47f63e49ab8sm21094119f8f.5.2026.07.19.03.58.09 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 19 Jul 2026 03:58:10 -0700 (PDT) From: "Nikola Z. Ivanov" To: dsahern@kernel.org, idosch@nvidia.com, davem@davemloft.net, edumazet@google.com, kuba@kernel.org, pabeni@redhat.com, horms@kernel.org Cc: kuniyu@google.com, netdev@vger.kernel.org, linux-kernel@vger.kernel.org, "Nikola Z. Ivanov" , syzbot+84d4a405ed798b40c96d@syzkaller.appspotmail.com Subject: [PATCH net] ipv6: Change allocation flags to match rcu_read_lock section requirements Date: Sun, 19 Jul 2026 13:57:59 +0300 Message-ID: <20260719105759.558050-1-zlatistiv@gmail.com> X-Mailer: git-send-email 2.54.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Since the call to __ip6_del_rt_siblings has been converted under rcu read lock and it only has one call point we should no longer block or yield. Our stack trace from the syzbot reproducer looks as follows: __ip6_del_rt_siblings rtnl_notify (Here we pass gfp_any() -> GFP_KERNEL) nlmsg_notify nlmsg_multicast nlmsg_multicast_filtered netlink_broadcast_filtered (GFP_KERNEL passed from earlier) netlink_broadcast_filtered can yield if GFP_KERNEL is passed, which we do not want to happen. Fix this by changing the allocation flag of rtnl_notify. Also change the flag passed to nlmsg_new. Even though it is not related to the syzbot generated bug it still falls under the same requirements. Reported-by: syzbot+84d4a405ed798b40c96d@syzkaller.appspotmail.com Closes: https://syzkaller.appspot.com/bug?extid=3D84d4a405ed798b40c96d Fixes: bd11ff421d36 ("ipv6: Get rid of RTNL for SIOCDELRT and RTM_DELROUTE.= ") Signed-off-by: Nikola Z. Ivanov Reviewed-by: Ido Schimmel --- net/ipv6/route.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/net/ipv6/route.c b/net/ipv6/route.c index a1301334da48..fc42d67e5822 100644 --- a/net/ipv6/route.c +++ b/net/ipv6/route.c @@ -4022,7 +4022,7 @@ static int __ip6_del_rt_siblings(struct fib6_info *rt= , struct fib6_config *cfg) struct fib6_node *fn; =20 /* prefer to send a single notification with all hops */ - skb =3D nlmsg_new(rt6_nlmsg_size(rt), gfp_any()); + skb =3D nlmsg_new(rt6_nlmsg_size(rt), GFP_ATOMIC); if (skb) { u32 seq =3D info->nlh ? info->nlh->nlmsg_seq : 0; =20 @@ -4078,7 +4078,7 @@ static int __ip6_del_rt_siblings(struct fib6_info *rt= , struct fib6_config *cfg) =20 if (skb) { rtnl_notify(skb, net, info->portid, RTNLGRP_IPV6_ROUTE, - info->nlh, gfp_any()); + info->nlh, GFP_ATOMIC); } return err; } --=20 2.54.0