[PATCH net v2 0/2] tipc: fix publication lifetime races
From: Chengfeng Ye
Date: Thu Oct 01 2026 - 14:35:52 EST
Two races can leave the publication lists referring to objects with an
invalid lifetime.
First, tipc_node_unsubscribe() looks up the publishing node before
unlinking a publication. If the node has already been removed from the
hash, the lookup fails and the caller frees the publication while its
binding_node remains linked.
Second, tipc_publ_notify() retains the next publication from a failed
node's list across an unlocked interval. A concurrent withdrawal can
unlink and schedule that publication for freeing before the purge
iterator advances to it.
Patch 1 unlinks successfully removed remote publications directly under
nametbl_lock. Patch 2 moves the failed node's publications to a private
list and selects each publication under the same lock, so no publication
pointer is retained across an unlocked interval.
Changes in v2:
- Split the original fix into two patches.
- Add patch 1/2 to address the unlink-before-free issue reported by
Sashiko and remove the now-unused tipc_node_unsubscribe() helper.
- Add the decoded causal call trace requested by Tung Quang Nguyen.
- Explain the ordering of name-table updates around the node-down
publication snapshot.
v1:
https://lore.kernel.org/netdev/20260927180806.1315902-1-nicoyip.dev@xxxxxxxxx/
Chengfeng Ye (2):
tipc: unlink publications without a node lookup
tipc: serialize publication purging with name table updates
net/tipc/name_distr.c | 36 ++++++++++++++++++++++++------------
net/tipc/name_distr.h | 2 +-
net/tipc/node.c | 20 +-------------------
net/tipc/node.h | 1 -
4 files changed, 26 insertions(+), 33 deletions(-)
--
2.43.0