On 08.02.24 00:37, Pablo Neira Ayuso wrote: > From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx> > > The patch fdb8e12cc2cc ("netfilter: ipset: fix performance regression > in swap operation") missed to add the calls to gc cancellations > at the error path of create operations and at module unload. Also, > because the half of the destroy operations now executed by a > function registered by call_rcu(), neither NFNL_SUBSYS_IPSET mutex > or rcu read lock is held and therefore the checking of them results > false warnings. > > Reported-by: syzbot+52bbc0ad036f6f0d4a25@xxxxxxxxxxxxxxxxxxxxxxxxx > Reported-by: Brad Spengler <spender@xxxxxxxxxxxxxx> > Reported-by: Стас Ничипорович <stasn77@xxxxxxxxx> > Fixes: fdb8e12cc2cc ("netfilter: ipset: fix performance regression in swap operation") FWIW, in case anyone cares: that afaics should be Fixes: 97f7cf1cd80e ("netfilter: ipset: fix performance regression in swap operation") instead, as noted yesterday elsewhere[1]. Ciao, Thorsten [1] https://lore.kernel.org/all/07cf1cf8-825e-47b9-9837-f91ae958dd6b@xxxxxxxxxxxxx/