<div dir="ltr">Thanks for the review.<br><br>I kept the break-then-remove pattern because destroy looks up a<br>single matching entry. TAILQ_FOREACH_SAFE is the right tool when the<br>loop must continue after removing the current node (e.g. flush).<br>Here the iteration should stop once the handle is found.<br><br>This file still uses <sys/queue.h>, and glibc has no<br>TAILQ_FOREACH_SAFE. Switching to RTE_TAILQ_FOREACH_SAFE would mix<br>the two until your queue macro cleanup lands.<br><br>Thanks,<br>Zhang Tengfei</div><br><div class="gmail_quote gmail_quote_container"><div dir="ltr" class="gmail_attr">Stephen Hemminger <<a href="mailto:stephen@networkplumber.org">stephen@networkplumber.org</a>> 于2026年9月10日周四 23:53写道:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">On Thu, 10 Sep 2026 21:39:41 +0800<br>
Zhang Tengfei <<a href="mailto:zhtfdev@gmail.com" target="_blank">zhtfdev@gmail.com</a>> wrote:<br>
<br>
> TAILQ_FOREACH advances via the current node's next pointer. Removing<br>
> and freeing that node inside the loop reads freed memory on the next<br>
> iteration.<br>
> <br>
> Find the matching entry first, then remove it after the loop.<br>
> <br>
> Fixes: e342da2d438f ("net/txgbe: support destroying consistent filter")<br>
> Cc: <a href="mailto:stable@dpdk.org" target="_blank">stable@dpdk.org</a><br>
> <br>
<br>
OK, another option would be to use TAILQ_FOREACH_SAFE which several other<br>
drivers do. I have a patch series to cleanup the queue macros but waiting.<br>
</blockquote></div>