NetBSD Problem Report #59340
From www@netbsd.org Tue Apr 22 05:30:00 2025
Return-Path: <www@netbsd.org>
Received: from mail.netbsd.org (mail.netbsd.org [199.233.217.200])
(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)
key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256
client-signature RSA-PSS (2048 bits) client-digest SHA256)
(Client CN "mail.NetBSD.org", Issuer "mail.NetBSD.org CA" (not verified))
by mollari.NetBSD.org (Postfix) with ESMTPS id C15801A9239
for <gnats-bugs@gnats.NetBSD.org>; Tue, 22 Apr 2025 05:30:00 +0000 (UTC)
Message-Id: <20250422052959.998551A923E@mollari.NetBSD.org>
Date: Tue, 22 Apr 2025 05:29:59 +0000 (UTC)
From: ozaki-r@iij.ad.jp
Reply-To: ozaki-r@iij.ad.jp
To: gnats-bugs@NetBSD.org
Subject: bridge: a race condition on bridge_stop
X-Send-Pr-Version: www-1.0
>Number: 59340
>Category: kern
>Synopsis: bridge: a race condition on bridge_stop
>Confidential: no
>Severity: serious
>Priority: medium
>Responsible: kern-bug-people
>State: closed
>Class: sw-bug
>Submitter-Id: net
>Arrival-Date: Tue Apr 22 05:35:00 +0000 2025
>Closed-Date: Thu Oct 02 00:58:30 +0000 2025
>Last-Modified: Thu Oct 02 00:58:30 +0000 2025
>Originator: Ryota Ozaki
>Release: -current
>Organization:
>Environment:
>Description:
bridge_stop tries to stop callout by calling callout_halt. However, callout_reset can be called after calling callout_halt, which is not expected, because there is a race condition (TOCTOU) on if_flags between bridge_stop and bridge_rtage_work that calls callout_reset.
>How-To-Repeat:
N/A
>Fix:
Ensure bridge_rtage_work not to call callout_reset before calling callout_halt in bridge_stop.
>Release-Note:
>Audit-Trail:
From: "Ryota Ozaki" <ozaki-r@netbsd.org>
To: gnats-bugs@gnats.NetBSD.org
Cc:
Subject: PR/59340 CVS commit: src/sys/net
Date: Tue, 22 Apr 2025 05:47:51 +0000
Module Name: src
Committed By: ozaki-r
Date: Tue Apr 22 05:47:51 UTC 2025
Modified Files:
src/sys/net: if_bridge.c if_bridgevar.h
Log Message:
bridge: resolve a race condition in bridge_stop()
Without BRIDGE_LOCK, the callout can be scheduled after callout_halt.
Note that we should avoid depending on IFF_RUNNING which can be racy.
Suggested by riastradh at https://mail-index.netbsd.org/source-changes-d/2025/04/16/msg014470.html
PR kern/59340
To generate a diff of this commit:
cvs rdiff -u -r1.198 -r1.199 src/sys/net/if_bridge.c
cvs rdiff -u -r1.39 -r1.40 src/sys/net/if_bridgevar.h
Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.
State-Changed-From-To: open->pending-pullups
State-Changed-By: ozaki-r@NetBSD.org
State-Changed-When: Mon, 12 May 2025 01:57:45 +0000
State-Changed-Why:
pullup-10 and pullup-9 done
From: "Martin Husemann" <martin@netbsd.org>
To: gnats-bugs@gnats.NetBSD.org
Cc:
Subject: PR/59340 CVS commit: [netbsd-10] src/sys/net
Date: Thu, 15 May 2025 17:58:18 +0000
Module Name: src
Committed By: martin
Date: Thu May 15 17:58:18 UTC 2025
Modified Files:
src/sys/net [netbsd-10]: if_bridge.c if_bridgevar.h
Log Message:
Pull up following revision(s) (requested by ozaki-r in ticket #1116):
sys/net/if_bridge.c: revision 1.199
sys/net/if_bridgevar.h: revision 1.40
bridge: resolve a race condition in bridge_stop()
Without BRIDGE_LOCK, the callout can be scheduled after callout_halt.
Note that we should avoid depending on IFF_RUNNING which can be racy.
Suggested by riastradh at
https://mail-index.netbsd.org/source-changes-d/2025/04/16/msg014470.html
PR kern/59340
To generate a diff of this commit:
cvs rdiff -u -r1.189.4.2 -r1.189.4.3 src/sys/net/if_bridge.c
cvs rdiff -u -r1.37.4.1 -r1.37.4.2 src/sys/net/if_bridgevar.h
Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.
From: "Martin Husemann" <martin@netbsd.org>
To: gnats-bugs@gnats.NetBSD.org
Cc:
Subject: PR/59340 CVS commit: [netbsd-9] src/sys/net
Date: Thu, 15 May 2025 18:01:49 +0000
Module Name: src
Committed By: martin
Date: Thu May 15 18:01:49 UTC 2025
Modified Files:
src/sys/net [netbsd-9]: if_bridge.c if_bridgevar.h
Log Message:
Pull up following revision(s) (requested by ozaki-r in ticket #1953):
sys/net/if_bridge.c: revision 1.199
sys/net/if_bridgevar.h: revision 1.40
bridge: resolve a race condition in bridge_stop()
Without BRIDGE_LOCK, the callout can be scheduled after callout_halt.
Note that we should avoid depending on IFF_RUNNING which can be racy.
Suggested by riastradh at
https://mail-index.netbsd.org/source-changes-d/2025/04/16/msg014470.html
PR kern/59340
To generate a diff of this commit:
cvs rdiff -u -r1.164.4.2 -r1.164.4.3 src/sys/net/if_bridge.c
cvs rdiff -u -r1.33 -r1.33.4.1 src/sys/net/if_bridgevar.h
Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.
State-Changed-From-To: pending-pullups->closed
State-Changed-By: ozaki-r@NetBSD.org
State-Changed-When: Thu, 02 Oct 2025 00:58:30 +0000
State-Changed-Why:
pullups complete.
>Unformatted:
(Contact us)
$NetBSD: query-full-pr,v 1.47 2022/09/11 19:34:41 kim Exp $
$NetBSD: gnats_config.sh,v 1.9 2014/08/02 14:16:04 spz Exp $
Copyright © 1994-2025
The NetBSD Foundation, Inc. ALL RIGHTS RESERVED.