Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1407108

[PATCH 3.19.y-ckt 39/40] net: bridge: fix old ioctl unlocked net device walk

From Kamal Mostafa <kamal@canonical.com>
Newsgroups linux.kernel
Subject [PATCH 3.19.y-ckt 39/40] net: bridge: fix old ioctl unlocked net device walk
Date 2016-05-25 19:40 +0200
Message-ID <rCKWL-3Lh-37@gated-at.bofh.it> (permalink)
References <rCKWJ-3Lh-7@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


3.19.8-ckt22 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Nikolay Aleksandrov <nikolay@cumulusnetworks.com>

[ Upstream commit 31ca0458a61a502adb7ed192bf9716c6d05791a5 ]

get_bridge_ifindices() is used from the old "deviceless" bridge ioctl
calls which aren't called with rtnl held. The comment above says that it is
called with rtnl but that is not really the case.
Here's a sample output from a test ASSERT_RTNL() which I put in
get_bridge_ifindices and executed "brctl show":
[  957.422726] RTNL: assertion failed at net/bridge//br_ioctl.c (30)
[  957.422925] CPU: 0 PID: 1862 Comm: brctl Tainted: G        W  O
4.6.0-rc4+ #157
[  957.423009] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996),
BIOS 1.8.1-20150318_183358- 04/01/2014
[  957.423009]  0000000000000000 ffff880058adfdf0 ffffffff8138dec5
0000000000000400
[  957.423009]  ffffffff81ce8380 ffff880058adfe58 ffffffffa05ead32
0000000000000001
[  957.423009]  00007ffec1a444b0 0000000000000400 ffff880053c19130
0000000000008940
[  957.423009] Call Trace:
[  957.423009]  [<ffffffff8138dec5>] dump_stack+0x85/0xc0
[  957.423009]  [<ffffffffa05ead32>]
br_ioctl_deviceless_stub+0x212/0x2e0 [bridge]
[  957.423009]  [<ffffffff81515beb>] sock_ioctl+0x22b/0x290
[  957.423009]  [<ffffffff8126ba75>] do_vfs_ioctl+0x95/0x700
[  957.423009]  [<ffffffff8126c159>] SyS_ioctl+0x79/0x90
[  957.423009]  [<ffffffff8163a4c0>] entry_SYSCALL_64_fastpath+0x23/0xc1

Since it only reads bridge ifindices, we can use rcu to safely walk the net
device list. Also remove the wrong rtnl comment above.

Signed-off-by: Nikolay Aleksandrov <nikolay@cumulusnetworks.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 net/bridge/br_ioctl.c | 5 +++--
 1 file changed, 3 insertions(+), 2 deletions(-)

diff --git a/net/bridge/br_ioctl.c b/net/bridge/br_ioctl.c
index 8d423bc..f876f70 100644
--- a/net/bridge/br_ioctl.c
+++ b/net/bridge/br_ioctl.c
@@ -21,18 +21,19 @@
 #include <asm/uaccess.h>
 #include "br_private.h"
 
-/* called with RTNL */
 static int get_bridge_ifindices(struct net *net, int *indices, int num)
 {
 	struct net_device *dev;
 	int i = 0;
 
-	for_each_netdev(net, dev) {
+	rcu_read_lock();
+	for_each_netdev_rcu(net, dev) {
 		if (i >= num)
 			break;
 		if (dev->priv_flags & IFF_EBRIDGE)
 			indices[i++] = dev->ifindex;
 	}
+	rcu_read_unlock();
 
 	return i;
 }
-- 
2.7.4

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

[3.19.y-ckt stable] Linux 3.19.8-ckt22 stable review Kamal Mostafa <kamal@canonical.com> - 2016-05-25 19:40 +0200
  [PATCH 3.19.y-ckt 29/40] ipv4/fib: don't warn when primary address is missing if in_dev is dead Kamal Mostafa <kamal@canonical.com> - 2016-05-25 19:40 +0200
  [PATCH 3.19.y-ckt 39/40] net: bridge: fix old ioctl unlocked net device walk Kamal Mostafa <kamal@canonical.com> - 2016-05-25 19:40 +0200
  [PATCH 3.19.y-ckt 26/40] route: do not cache fib route info on local routes with oif Kamal Mostafa <kamal@canonical.com> - 2016-05-25 19:40 +0200
  [PATCH 3.19.y-ckt 20/40] net: fec: only clear a queue's work bit if the queue was emptied Kamal Mostafa <kamal@canonical.com> - 2016-05-25 19:40 +0200
  [PATCH 3.19.y-ckt 10/40] get_rock_ridge_filename(): handle malformed NM entries Kamal Mostafa <kamal@canonical.com> - 2016-05-25 19:40 +0200
  [PATCH 3.19.y-ckt 30/40] bpf: fix double-fdput in replace_map_fd_with_map_ptr() Kamal Mostafa <kamal@canonical.com> - 2016-05-25 19:40 +0200
  [PATCH 3.19.y-ckt 19/40] nf_conntrack: avoid kernel pointer value leak in slab name Kamal Mostafa <kamal@canonical.com> - 2016-05-25 19:40 +0200
  [PATCH 3.19.y-ckt 15/40] tools lib traceevent: Free filter tokens in process_filter() Kamal Mostafa <kamal@canonical.com> - 2016-05-25 19:40 +0200
  [PATCH 3.19.y-ckt 02/40] [3.19-stable only] fix backport "IB/security: restrict use of the write() interface" Kamal Mostafa <kamal@canonical.com> - 2016-05-25 19:40 +0200
  [PATCH 3.19.y-ckt 21/40] net/mlx4_en: Fix endianness bug in IPV6 csum calculation Kamal Mostafa <kamal@canonical.com> - 2016-05-25 19:40 +0200
    RE: [PATCH 3.19.y-ckt 21/40] net/mlx4_en: Fix endianness bug in IPV6  csum calculation Tariq Toukan <tariqt@mellanox.com> - 2016-05-26 11:00 +0200
  [PATCH 3.19.y-ckt 23/40] tcp: refresh skb timestamp at retransmit time Kamal Mostafa <kamal@canonical.com> - 2016-05-25 19:40 +0200
  [PATCH 3.19.y-ckt 25/40] decnet: Do not build routes to devices without decnet private data. Kamal Mostafa <kamal@canonical.com> - 2016-05-25 19:40 +0200
  [PATCH 3.19.y-ckt 31/40] net_sched: introduce qdisc_replace() helper Kamal Mostafa <kamal@canonical.com> - 2016-05-25 19:40 +0200
  [PATCH 3.19.y-ckt 34/40] sch_dsmark: update backlog as well Kamal Mostafa <kamal@canonical.com> - 2016-05-25 19:40 +0200
  [PATCH 3.19.y-ckt 40/40] net: fix a kernel infoleak in x25 module Kamal Mostafa <kamal@canonical.com> - 2016-05-25 19:40 +0200
  [PATCH 3.19.y-ckt 24/40] arm64: bpf: jit JMP_JSET_{X,K} Kamal Mostafa <kamal@canonical.com> - 2016-05-25 19:40 +0200
  [PATCH 3.19.y-ckt 28/40] vlan: pull on __vlan_insert_tag error path and fix csum correction Kamal Mostafa <kamal@canonical.com> - 2016-05-25 19:40 +0200
  [PATCH 3.19.y-ckt 18/40] ocfs2: fix posix_acl_create deadlock Kamal Mostafa <kamal@canonical.com> - 2016-05-25 19:40 +0200
  [PATCH 3.19.y-ckt 16/40] tools lib traceevent: Do not reassign parg after collapse_tree() Kamal Mostafa <kamal@canonical.com> - 2016-05-25 19:50 +0200
  [PATCH 3.19.y-ckt 03/40] Revert "usb: hub: do not clear BOS field during reset device" Kamal Mostafa <kamal@canonical.com> - 2016-05-25 19:50 +0200
  [PATCH 3.19.y-ckt 09/40] drm/radeon: fix PLL sharing on DCE6.1 (v2) Kamal Mostafa <kamal@canonical.com> - 2016-05-25 19:50 +0200
  [PATCH 3.19.y-ckt 13/40] drm/i915: Bail out of pipe config compute loop on LPT Kamal Mostafa <kamal@canonical.com> - 2016-05-25 19:50 +0200
  [PATCH 3.19.y-ckt 01/40] compiler-gcc: integrate the various compiler-gcc[345].h files Kamal Mostafa <kamal@canonical.com> - 2016-05-25 19:50 +0200
  [PATCH 3.19.y-ckt 06/40] regmap: spmi: Fix regmap_spmi_ext_read in multi-byte case Kamal Mostafa <kamal@canonical.com> - 2016-05-25 19:50 +0200
  [PATCH 3.19.y-ckt 14/40] ALSA: hda - Fix subwoofer pin on ASUS N751 and N551 Kamal Mostafa <kamal@canonical.com> - 2016-05-25 19:50 +0200
  [PATCH 3.19.y-ckt 12/40] Input: max8997-haptic - fix NULL pointer dereference Kamal Mostafa <kamal@canonical.com> - 2016-05-25 19:50 +0200
  [PATCH 3.19.y-ckt 05/40] regulator: s2mps11: Fix invalid selector mask and voltages for buck9 Kamal Mostafa <kamal@canonical.com> - 2016-05-25 19:50 +0200
  [PATCH 3.19.y-ckt 08/40] crypto: hash - Fix page length clamping in hash walk Kamal Mostafa <kamal@canonical.com> - 2016-05-25 19:50 +0200
  [PATCH 3.19.y-ckt 04/40] [3.19-stable] x86: LLVMLinux: Fix "incomplete type const struct x86cpu_device_id" Kamal Mostafa <kamal@canonical.com> - 2016-05-25 19:50 +0200
  [PATCH 3.19.y-ckt 11/40] ALSA: hda - Fix white noise on Asus UX501VW headset Kamal Mostafa <kamal@canonical.com> - 2016-05-25 19:50 +0200

csiph-web