cls_flower: use tcf_exts_get_net() before call_rcu()

This change “cls_flower: use tcf_exts_get_net() before call_rcu()” (commit 0dadc11) in Linux kernel is authored by Cong Wang <xiyou.wangcong [at]> on Mon Nov 6 13:47:24 2017 -0800.

Description of "cls_flower: use tcf_exts_get_net() before call_rcu()"

The change “cls_flower: use tcf_exts_get_net() before call_rcu()” introduces changes as follows.

cls_flower: use tcf_exts_get_net() before call_rcu()

Hold netns refcnt before call_rcu() and release it after
the tcf_exts_destroy() is done.

Note, on ->destroy() path we have to respect the return value
of tcf_exts_get_net(), on other paths it should always return
true, so we don't need to care.

Cc: Lucas Bates <>
Cc: Jamal Hadi Salim <>
Cc: Jiri Pirko <>
Signed-off-by: Cong Wang <>
Signed-off-by: David S. Miller <>

Linux kernel releases containing commit 0dadc11

The Linux kernel releases containing this commit are as follows.

Linux kernel code changes from "cls_flower: use tcf_exts_get_net() before call_rcu()"

There are 16 lines of Linux source code added/deleted in this change. Code changes to Linux kernel are as follows.

 net/sched/cls_flower.c | 16 +++++++++++++---
 1 file changed, 13 insertions(+), 3 deletions(-)
diff --git a/net/sched/cls_flower.c b/net/sched/cls_flower.c
index 5b5722c8b32c..7a838d1c1c00 100644
--- a/net/sched/cls_flower.c
+++ b/net/sched/cls_flower.c
@@ -218,13 +218,19 @@ static int fl_init(struct tcf_proto *tp)
 	return 0;
+static void __fl_destroy_filter(struct cls_fl_filter *f)
+	tcf_exts_destroy(&f->exts);
+	tcf_exts_put_net(&f->exts);
+	kfree(f);
 static void fl_destroy_filter_work(struct work_struct *work)
 	struct cls_fl_filter *f = container_of(work, struct cls_fl_filter, work);
-	tcf_exts_destroy(&f->exts);
-	kfree(f);
+	__fl_destroy_filter(f);
@@ -318,7 +324,10 @@ static void __fl_delete(struct tcf_proto *tp, struct cls_fl_filter *f)
 	if (!tc_skip_hw(f->flags))
 		fl_hw_destroy_filter(tp, f);
 	tcf_unbind_filter(tp, &f->res);
-	call_rcu(&f->rcu, fl_destroy_filter);
+	if (tcf_exts_get_net(&f->exts))
+		call_rcu(&f->rcu, fl_destroy_filter);
+	else
+		__fl_destroy_filter(f);
 static void fl_destroy_sleepable(struct work_struct *work)
@@ -988,6 +997,7 @@ static int fl_change(struct net *net, struct sk_buff *in_skb,
 		idr_replace_ext(&head->handle_idr, fnew, fnew->handle);
 		list_replace_rcu(&fold->list, &fnew->list);
 		tcf_unbind_filter(tp, &fold->res);
+		tcf_exts_get_net(&fold->exts);
 		call_rcu(&fold->rcu, fl_destroy_filter);
 	} else {
 		list_add_tail_rcu(&fnew->list, &head->filters);

The commit for this change in Linux stable tree is 0dadc11 (patch).

Last modified: 2020/02/09