NetBSD Problem Report #59340

From www@netbsd.org  Tue Apr 22 05:30:00 2025
Return-Path: <www@netbsd.org>
Received: from mail.netbsd.org (mail.netbsd.org [199.233.217.200])
	(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)
	 key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256
	 client-signature RSA-PSS (2048 bits) client-digest SHA256)
	(Client CN "mail.NetBSD.org", Issuer "mail.NetBSD.org CA" (not verified))
	by mollari.NetBSD.org (Postfix) with ESMTPS id C15801A9239
	for <gnats-bugs@gnats.NetBSD.org>; Tue, 22 Apr 2025 05:30:00 +0000 (UTC)
Message-Id: <20250422052959.998551A923E@mollari.NetBSD.org>
Date: Tue, 22 Apr 2025 05:29:59 +0000 (UTC)
From: ozaki-r@iij.ad.jp
Reply-To: ozaki-r@iij.ad.jp
To: gnats-bugs@NetBSD.org
Subject: bridge: a race condition on bridge_stop
X-Send-Pr-Version: www-1.0

>Number:         59340
>Category:       kern
>Synopsis:       bridge: a race condition on bridge_stop
>Confidential:   no
>Severity:       serious
>Priority:       medium
>Responsible:    kern-bug-people
>State:          closed
>Class:          sw-bug
>Submitter-Id:   net
>Arrival-Date:   Tue Apr 22 05:35:00 +0000 2025
>Closed-Date:    Thu Oct 02 00:58:30 +0000 2025
>Last-Modified:  Thu Oct 02 00:58:30 +0000 2025
>Originator:     Ryota Ozaki
>Release:        -current
>Organization:
>Environment:
>Description:
bridge_stop tries to stop callout by calling callout_halt.  However, callout_reset can be called after calling callout_halt, which is not expected, because there is a race condition (TOCTOU) on if_flags between bridge_stop and bridge_rtage_work that calls callout_reset.
>How-To-Repeat:
N/A
>Fix:
Ensure bridge_rtage_work not to call callout_reset before calling callout_halt in bridge_stop.

>Release-Note:

>Audit-Trail:
From: "Ryota Ozaki" <ozaki-r@netbsd.org>
To: gnats-bugs@gnats.NetBSD.org
Cc: 
Subject: PR/59340 CVS commit: src/sys/net
Date: Tue, 22 Apr 2025 05:47:51 +0000

 Module Name:	src
 Committed By:	ozaki-r
 Date:		Tue Apr 22 05:47:51 UTC 2025

 Modified Files:
 	src/sys/net: if_bridge.c if_bridgevar.h

 Log Message:
 bridge: resolve a race condition in bridge_stop()

 Without BRIDGE_LOCK, the callout can be scheduled after callout_halt.

 Note that we should avoid depending on IFF_RUNNING which can be racy.
 Suggested by riastradh at https://mail-index.netbsd.org/source-changes-d/2025/04/16/msg014470.html

 PR kern/59340


 To generate a diff of this commit:
 cvs rdiff -u -r1.198 -r1.199 src/sys/net/if_bridge.c
 cvs rdiff -u -r1.39 -r1.40 src/sys/net/if_bridgevar.h

 Please note that diffs are not public domain; they are subject to the
 copyright notices on the relevant files.

State-Changed-From-To: open->pending-pullups
State-Changed-By: ozaki-r@NetBSD.org
State-Changed-When: Mon, 12 May 2025 01:57:45 +0000
State-Changed-Why:
pullup-10 and pullup-9 done


From: "Martin Husemann" <martin@netbsd.org>
To: gnats-bugs@gnats.NetBSD.org
Cc: 
Subject: PR/59340 CVS commit: [netbsd-10] src/sys/net
Date: Thu, 15 May 2025 17:58:18 +0000

 Module Name:	src
 Committed By:	martin
 Date:		Thu May 15 17:58:18 UTC 2025

 Modified Files:
 	src/sys/net [netbsd-10]: if_bridge.c if_bridgevar.h

 Log Message:
 Pull up following revision(s) (requested by ozaki-r in ticket #1116):

 	sys/net/if_bridge.c: revision 1.199
 	sys/net/if_bridgevar.h: revision 1.40

 bridge: resolve a race condition in bridge_stop()
 Without BRIDGE_LOCK, the callout can be scheduled after callout_halt.

 Note that we should avoid depending on IFF_RUNNING which can be racy.
 Suggested by riastradh at

 https://mail-index.netbsd.org/source-changes-d/2025/04/16/msg014470.html

 PR kern/59340


 To generate a diff of this commit:
 cvs rdiff -u -r1.189.4.2 -r1.189.4.3 src/sys/net/if_bridge.c
 cvs rdiff -u -r1.37.4.1 -r1.37.4.2 src/sys/net/if_bridgevar.h

 Please note that diffs are not public domain; they are subject to the
 copyright notices on the relevant files.

From: "Martin Husemann" <martin@netbsd.org>
To: gnats-bugs@gnats.NetBSD.org
Cc: 
Subject: PR/59340 CVS commit: [netbsd-9] src/sys/net
Date: Thu, 15 May 2025 18:01:49 +0000

 Module Name:	src
 Committed By:	martin
 Date:		Thu May 15 18:01:49 UTC 2025

 Modified Files:
 	src/sys/net [netbsd-9]: if_bridge.c if_bridgevar.h

 Log Message:
 Pull up following revision(s) (requested by ozaki-r in ticket #1953):

 	sys/net/if_bridge.c: revision 1.199
 	sys/net/if_bridgevar.h: revision 1.40

 bridge: resolve a race condition in bridge_stop()
 Without BRIDGE_LOCK, the callout can be scheduled after callout_halt.

 Note that we should avoid depending on IFF_RUNNING which can be racy.
 Suggested by riastradh at

 https://mail-index.netbsd.org/source-changes-d/2025/04/16/msg014470.html

 PR kern/59340


 To generate a diff of this commit:
 cvs rdiff -u -r1.164.4.2 -r1.164.4.3 src/sys/net/if_bridge.c
 cvs rdiff -u -r1.33 -r1.33.4.1 src/sys/net/if_bridgevar.h

 Please note that diffs are not public domain; they are subject to the
 copyright notices on the relevant files.

State-Changed-From-To: pending-pullups->closed
State-Changed-By: ozaki-r@NetBSD.org
State-Changed-When: Thu, 02 Oct 2025 00:58:30 +0000
State-Changed-Why:
pullups complete.


>Unformatted:

NetBSD Home
NetBSD PR Database Search

(Contact us) $NetBSD: query-full-pr,v 1.47 2022/09/11 19:34:41 kim Exp $
$NetBSD: gnats_config.sh,v 1.9 2014/08/02 14:16:04 spz Exp $
Copyright © 1994-2025 The NetBSD Foundation, Inc. ALL RIGHTS RESERVED.