On Thu, May 14, 2026 at 07:41:38PM +0200, Sven Eckelmann wrote:
> batadv_mcast_purge_orig() removes entries from RCU-protected hlists but
> does not wait for an RCU grace period before returning. Concurrent RCU
> readers may still accesses references to those entries at the point of
> removal. RCU-protected readers trying to operate on entries like
> orig->mcast_want_all_ipv6_node will then access already freed memory.

This one I don't really get yet. The mcat_want_all_* lists/entries should
be spinlock protected (&bat_priv->mcast.want_lists_lock), not RCU
protected?

We don't use RCU for these lists in the first place because within
the list changes / spinlocks &bat_priv->mcast.num_want_all_*
atomic counters are increased/decreased. And these atomic counters
are then used in fast path. Not those lists.

Reply via email to