[PATCH net] ipv6: fix prefix route expiry in modify_prefix_route()

Qishuai Liu posted 1 patch 22 hours ago
net/ipv6/addrconf.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
[PATCH net] ipv6: fix prefix route expiry in modify_prefix_route()
Posted by Qishuai Liu 22 hours ago
modify_prefix_route() is given the lifetime in clock_t relative to now,
but fib6_set_expires() wants an absolute jiffies value. So when a
permanent address is changed to a finite valid_lft, the prefix route
ends up already expired and GC removes it.

Steps to reproduce:

  ip link add dummy9 type dummy
  ip link set dummy9 up
  ip -6 addr add 2001:db8:9::1/64 dev dummy9
  ip -6 addr change 2001:db8:9::1/64 dev dummy9 valid_lft 3600 preferred_lft 3600
  ip -6 route show dev dummy9    # expires is negative

Fixes: 8308f3ff1753 ("net/ipv6: Add support for specifying metric of connected routes")
Signed-off-by: Qishuai Liu <lqs@lqs.me>
---
 net/ipv6/addrconf.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/net/ipv6/addrconf.c b/net/ipv6/addrconf.c
index 9d89be7e0544..c90ee6dd7446 100644
--- a/net/ipv6/addrconf.c
+++ b/net/ipv6/addrconf.c
@@ -4874,7 +4874,7 @@ static int modify_prefix_route(struct net *net, struct inet6_ifaddr *ifp,
 			fib6_clean_expires(f6i);
 			fib6_may_remove_gc_list(net, f6i);
 		} else {
-			fib6_set_expires(f6i, expires);
+			fib6_set_expires(f6i, jiffies + clock_t_to_jiffies(expires));
 			fib6_add_gc_list(f6i);
 		}
 
-- 
2.43.0
Re: [PATCH net] ipv6: fix prefix route expiry in modify_prefix_route()
Posted by Hangbin Liu 10 hours ago
On Wed, Sep 23, 2026 at 01:20:48PM +0000, Qishuai Liu wrote:
> modify_prefix_route() is given the lifetime in clock_t relative to now,
> but fib6_set_expires() wants an absolute jiffies value. So when a
> permanent address is changed to a finite valid_lft, the prefix route
> ends up already expired and GC removes it.
> 
> Steps to reproduce:
> 
>   ip link add dummy9 type dummy
>   ip link set dummy9 up
>   ip -6 addr add 2001:db8:9::1/64 dev dummy9
>   ip -6 addr change 2001:db8:9::1/64 dev dummy9 valid_lft 3600 preferred_lft 3600
>   ip -6 route show dev dummy9    # expires is negative

nit: Does GC really removes it? I see the expires is negative, but the time
seems overflow and GC won't remove it.

> 
> Fixes: 8308f3ff1753 ("net/ipv6: Add support for specifying metric of connected routes")
> Signed-off-by: Qishuai Liu <lqs@lqs.me>
> ---
>  net/ipv6/addrconf.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/net/ipv6/addrconf.c b/net/ipv6/addrconf.c
> index 9d89be7e0544..c90ee6dd7446 100644
> --- a/net/ipv6/addrconf.c
> +++ b/net/ipv6/addrconf.c
> @@ -4874,7 +4874,7 @@ static int modify_prefix_route(struct net *net, struct inet6_ifaddr *ifp,
>  			fib6_clean_expires(f6i);
>  			fib6_may_remove_gc_list(net, f6i);
>  		} else {
> -			fib6_set_expires(f6i, expires);
> +			fib6_set_expires(f6i, jiffies + clock_t_to_jiffies(expires));
>  			fib6_add_gc_list(f6i);
>  		}

The code looks good to me.

Reviewed-by: Hangbin Liu <liuhangbin@kylinos.cn>
Re: [PATCH net] ipv6: fix prefix route expiry in modify_prefix_route()
Posted by Qishuai Liu 8 hours ago
On Thu, Sep 24, 2026 at 10:18 AM Hangbin Liu <hangbin.liu@linux.dev> wrote:
>
> On Wed, Sep 23, 2026 at 01:20:48PM +0000, Qishuai Liu wrote:
> > modify_prefix_route() is given the lifetime in clock_t relative to now,
> > but fib6_set_expires() wants an absolute jiffies value. So when a
> > permanent address is changed to a finite valid_lft, the prefix route
> > ends up already expired and GC removes it.
>
> nit: Does GC really removes it? I see the expires is negative, but the time
> seems overflow and GC won't remove it.

Yes, it is removed once the fib6 GC runs, i.e. within gc_interval if
the GC timer is already armed by another expiring route, or right away
with "sysctl -w net.ipv6.route.flush=1".
Re: [PATCH net] ipv6: fix prefix route expiry in modify_prefix_route()
Posted by Hangbin Liu 41 minutes ago
On Thu, Sep 24, 2026 at 12:35:18PM +0900, Qishuai Liu wrote:
> On Thu, Sep 24, 2026 at 10:18 AM Hangbin Liu <hangbin.liu@linux.dev> wrote:
> >
> > On Wed, Sep 23, 2026 at 01:20:48PM +0000, Qishuai Liu wrote:
> > > modify_prefix_route() is given the lifetime in clock_t relative to now,
> > > but fib6_set_expires() wants an absolute jiffies value. So when a
> > > permanent address is changed to a finite valid_lft, the prefix route
> > > ends up already expired and GC removes it.
> >
> > nit: Does GC really removes it? I see the expires is negative, but the time
> > seems overflow and GC won't remove it.
> 
> Yes, it is removed once the fib6 GC runs, i.e. within gc_interval if
> the GC timer is already armed by another expiring route, or right away
> with "sysctl -w net.ipv6.route.flush=1".

Ah, yes.

Thanks
Hangbin