Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1635527

[PATCH 3.12 74/86] ip6mr: fix notification device destruction

From Jiri Slaby <jslaby@suse.cz>
Newsgroups linux.kernel
Subject [PATCH 3.12 74/86] ip6mr: fix notification device destruction
Date 2017-05-04 11:20 +0200
Message-ID <tDl5w-1sT-15@gated-at.bofh.it> (permalink)
References <tDkVQ-1oS-3@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


From: Nikolay Aleksandrov <nikolay@cumulusnetworks.com>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

[ Upstream commit 723b929ca0f79c0796f160c2eeda4597ee98d2b8 ]

Andrey Konovalov reported a BUG caused by the ip6mr code which is caused
because we call unregister_netdevice_many for a device that is already
being destroyed. In IPv4's ipmr that has been resolved by two commits
long time ago by introducing the "notify" parameter to the delete
function and avoiding the unregister when called from a notifier, so
let's do the same for ip6mr.

The trace from Andrey:
------------[ cut here ]------------
kernel BUG at net/core/dev.c:6813!
invalid opcode: 0000 [#1] SMP KASAN
Modules linked in:
CPU: 1 PID: 1165 Comm: kworker/u4:3 Not tainted 4.11.0-rc7+ #251
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Bochs
01/01/2011
Workqueue: netns cleanup_net
task: ffff880069208000 task.stack: ffff8800692d8000
RIP: 0010:rollback_registered_many+0x348/0xeb0 net/core/dev.c:6813
RSP: 0018:ffff8800692de7f0 EFLAGS: 00010297
RAX: ffff880069208000 RBX: 0000000000000002 RCX: 0000000000000001
RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffff88006af90569
RBP: ffff8800692de9f0 R08: ffff8800692dec60 R09: 0000000000000000
R10: 0000000000000006 R11: 0000000000000000 R12: ffff88006af90070
R13: ffff8800692debf0 R14: dffffc0000000000 R15: ffff88006af90000
FS:  0000000000000000(0000) GS:ffff88006cb00000(0000)
knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007fe7e897d870 CR3: 00000000657e7000 CR4: 00000000000006e0
Call Trace:
 unregister_netdevice_many.part.105+0x87/0x440 net/core/dev.c:7881
 unregister_netdevice_many+0xc8/0x120 net/core/dev.c:7880
 ip6mr_device_event+0x362/0x3f0 net/ipv6/ip6mr.c:1346
 notifier_call_chain+0x145/0x2f0 kernel/notifier.c:93
 __raw_notifier_call_chain kernel/notifier.c:394
 raw_notifier_call_chain+0x2d/0x40 kernel/notifier.c:401
 call_netdevice_notifiers_info+0x51/0x90 net/core/dev.c:1647
 call_netdevice_notifiers net/core/dev.c:1663
 rollback_registered_many+0x919/0xeb0 net/core/dev.c:6841
 unregister_netdevice_many.part.105+0x87/0x440 net/core/dev.c:7881
 unregister_netdevice_many net/core/dev.c:7880
 default_device_exit_batch+0x4fa/0x640 net/core/dev.c:8333
 ops_exit_list.isra.4+0x100/0x150 net/core/net_namespace.c:144
 cleanup_net+0x5a8/0xb40 net/core/net_namespace.c:463
 process_one_work+0xc04/0x1c10 kernel/workqueue.c:2097
 worker_thread+0x223/0x19c0 kernel/workqueue.c:2231
 kthread+0x35e/0x430 kernel/kthread.c:231
 ret_from_fork+0x31/0x40 arch/x86/entry/entry_64.S:430
Code: 3c 32 00 0f 85 70 0b 00 00 48 b8 00 02 00 00 00 00 ad de 49 89
47 78 e9 93 fe ff ff 49 8d 57 70 49 8d 5f 78 eb 9e e8 88 7a 14 fe <0f>
0b 48 8b 9d 28 fe ff ff e8 7a 7a 14 fe 48 b8 00 00 00 00 00
RIP: rollback_registered_many+0x348/0xeb0 RSP: ffff8800692de7f0
---[ end trace e0b29c57e9b3292c ]---

Reported-by: Andrey Konovalov <andreyknvl@google.com>
Signed-off-by: Nikolay Aleksandrov <nikolay@cumulusnetworks.com>
Tested-by: Andrey Konovalov <andreyknvl@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
---
 net/ipv6/ip6mr.c | 13 ++++++-------
 1 file changed, 6 insertions(+), 7 deletions(-)

diff --git a/net/ipv6/ip6mr.c b/net/ipv6/ip6mr.c
index 56aa540d77f6..2dcb19cb8f61 100644
--- a/net/ipv6/ip6mr.c
+++ b/net/ipv6/ip6mr.c
@@ -776,7 +776,8 @@ failure:
  *	Delete a VIF entry
  */
 
-static int mif6_delete(struct mr6_table *mrt, int vifi, struct list_head *head)
+static int mif6_delete(struct mr6_table *mrt, int vifi, int notify,
+		       struct list_head *head)
 {
 	struct mif_device *v;
 	struct net_device *dev;
@@ -822,7 +823,7 @@ static int mif6_delete(struct mr6_table *mrt, int vifi, struct list_head *head)
 					     dev->ifindex, &in6_dev->cnf);
 	}
 
-	if (v->flags & MIFF_REGISTER)
+	if ((v->flags & MIFF_REGISTER) && !notify)
 		unregister_netdevice_queue(dev, head);
 
 	dev_put(dev);
@@ -1332,7 +1333,6 @@ static int ip6mr_device_event(struct notifier_block *this,
 	struct mr6_table *mrt;
 	struct mif_device *v;
 	int ct;
-	LIST_HEAD(list);
 
 	if (event != NETDEV_UNREGISTER)
 		return NOTIFY_DONE;
@@ -1341,10 +1341,9 @@ static int ip6mr_device_event(struct notifier_block *this,
 		v = &mrt->vif6_table[0];
 		for (ct = 0; ct < mrt->maxvif; ct++, v++) {
 			if (v->dev == dev)
-				mif6_delete(mrt, ct, &list);
+				mif6_delete(mrt, ct, 1, NULL);
 		}
 	}
-	unregister_netdevice_many(&list);
 
 	return NOTIFY_DONE;
 }
@@ -1549,7 +1548,7 @@ static void mroute_clean_tables(struct mr6_table *mrt, bool all)
 	for (i = 0; i < mrt->maxvif; i++) {
 		if (!all && (mrt->vif6_table[i].flags & VIFF_STATIC))
 			continue;
-		mif6_delete(mrt, i, &list);
+		mif6_delete(mrt, i, 0, &list);
 	}
 	unregister_netdevice_many(&list);
 
@@ -1702,7 +1701,7 @@ int ip6_mroute_setsockopt(struct sock *sk, int optname, char __user *optval, uns
 		if (copy_from_user(&mifi, optval, sizeof(mifi_t)))
 			return -EFAULT;
 		rtnl_lock();
-		ret = mif6_delete(mrt, mifi, NULL);
+		ret = mif6_delete(mrt, mifi, 0, NULL);
 		rtnl_unlock();
 		return ret;
 
-- 
2.12.2

Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

[PATCH 3.12 00/86] 3.12.74-stable review Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
  [PATCH 3.12 01/86] drm/vmwgfx: NULL pointer dereference in vmw_surface_define_ioctl() Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
    [PATCH 3.12 04/86] drm/vmwgfx: fix integer overflow in vmw_surface_define_ioctl() Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
    [PATCH 3.12 81/86] ALSA: seq: Don't break snd_use_lock_sync() loop by timeout Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
    [PATCH 3.12 25/86] perf/x86: Avoid exposing wrong/stale data in intel_pmu_lbr_read_32() Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
    [PATCH 3.12 03/86] drm/vmwgfx: Remove getparam error message Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
    [PATCH 3.12 05/86] Reset TreeId to zero on SMB2 TREE_CONNECT Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
    [PATCH 3.12 85/86] nfsd: check for oversized NFSv2/v3 arguments Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
    [PATCH 3.12 59/86] kvm: arm/arm64: Fix locking for kvm_free_stage2_pgd Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
    [PATCH 3.12 26/86] x86/vdso: Plug race between mapping and ELF header setup Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
    [PATCH 3.12 82/86] MIPS: KGDB: Use kernel context for sleeping threads Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
    [PATCH 3.12 31/86] xen, fbfront: fix connecting to backend Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
    [PATCH 3.12 56/86] ACPI / power: Avoid maybe-uninitialized warning Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
    [PATCH 3.12 78/86] MIPS: Fix crash registers on non-crashing CPUs Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
    [PATCH 3.12 28/86] iscsi-target: Drop work-around for legacy GlobalSAN initiator Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
    [PATCH 3.12 29/86] scsi: sr: Sanity check returned mode data Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
    [PATCH 3.12 83/86] p9_client_readdir() fix Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
    [PATCH 3.12 06/86] ptrace: fix PTRACE_LISTEN race corrupting task->state Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
    [PATCH 3.12 80/86] xen/x86: don't lose event interrupts Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
    [PATCH 3.12 55/86] Input: elantech - add Fujitsu Lifebook E547 to force crc_enabled Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
    [PATCH 3.12 77/86] md:raid1: fix a dead loop when read from a WriteMostly disk Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
    [PATCH 3.12 63/86] net/packet: fix overflow in check for tp_frame_nr Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
    [PATCH 3.12 72/86] net: ipv4: fix multipath RTM_GETROUTE behavior when iif is given Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
    [PATCH 3.12 61/86] powerpc: Reject binutils 2.24 when building little endian Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
    [PATCH 3.12 75/86] ipv6: check raw payload size correctly in ioctl Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
    [PATCH 3.12 60/86] block: fix del_gendisk() vs blkdev_ioctl crash Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
    [PATCH 3.12 33/86] char: lack of bool string made CONFIG_DEVPORT always on Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
    [PATCH 3.12 74/86] ip6mr: fix notification device destruction Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
    [PATCH 3.12 66/86] tty: nozomi: avoid a harmless gcc warning Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
    [PATCH 3.12 67/86] hostap: avoid uninitialized variable use in hfa384x_get_rid Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
    [PATCH 3.12 64/86] net/packet: fix overflow in check for tp_reserve Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
    [PATCH 3.12 76/86] ext4: check if in-inode xattr is corrupted in ext4_expand_extra_isize_ea() Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
    [PATCH 3.12 45/86] net: ipv6: check route protocol when deleting routes Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
    [PATCH 3.12 46/86] KEYS: Disallow keyrings beginning with '.' to be joined as session keyrings Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
    [PATCH 3.12 65/86] netfilter: arp_tables: fix invoking 32bit "iptable -P INPUT ACCEPT" failed in 64bit kernel Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
    [PATCH 3.12 42/86] rtl8150: Use heap buffers for all register access Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
    [PATCH 3.12 30/86] scsi: sd: Fix capacity calculation with 32-bit sector_t Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
    [PATCH 3.12 39/86] mm: Tighten x86 /dev/mem with zeroing reads Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
    [PATCH 3.12 43/86] catc: Combine failure cleanup code in catc_probe() Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
    [PATCH 3.12 51/86] cifs: Do not send echoes before Negotiate is complete Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
    [PATCH 3.12 40/86] virtio-console: avoid DMA from stack Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
    [PATCH 3.12 69/86] net: neigh: guard against NULL solicit() method Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
    [PATCH 3.12 49/86] tracing: Allocate the snapshot buffer before enabling probe Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
    [PATCH 3.12 50/86] ring-buffer: Have ring_buffer_iter_empty() return true when empty Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
    [PATCH 3.12 53/86] Drivers: hv: don't leak memory in vmbus_establish_gpadl() Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
    [PATCH 3.12 62/86] ping: implement proper locking Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
    [PATCH 3.12 79/86] RDS: Fix the atomicity for congestion map update Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
    [PATCH 3.12 84/86] Input: i8042 - add Clevo P650RS to the i8042 reset list Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
    [PATCH 3.12 52/86] CIFS: remove bad_network_name flag Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
    [PATCH 3.12 54/86] Drivers: hv: get rid of timeout in vmbus_open() Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
    [PATCH 3.12 47/86] KEYS: Change the name of the dead type to ".dead" to prevent user access Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
    [PATCH 3.12 41/86] pegasus: Use heap buffers for all register access Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
    [PATCH 3.12 37/86] ext4: fix inode checksum calculation problem if i_extra_size is small Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
    [PATCH 3.12 38/86] platform/x86: acer-wmi: setup accelerometer when machine has appropriate notify event Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
    [PATCH 3.12 71/86] l2tp: take reference on sessions being dumped Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
    [PATCH 3.12 68/86] gfs2: avoid uninitialized variable warning Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
    [PATCH 3.12 70/86] net: phy: handle state correctly in phy_stop_machine Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
    [PATCH 3.12 58/86] x86/mce/AMD: Give a name to MCA bank 3 when accessed with legacy MSRs Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
    [PATCH 3.12 73/86] sctp: listen on the sock only when it's state is listening or closed Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
    [PATCH 3.12 18/86] usb: dwc3: gadget: delay unmap of bounced requests Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
    [PATCH 3.12 32/86] char: Drop bogus dependency of DEVPORT on !M68K Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
    [PATCH 3.12 36/86] dvb-usb-v2: avoid use-after-free Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
    [PATCH 3.12 14/86] metag/usercopy: Add missing fixups Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
    [PATCH 3.12 10/86] metag/usercopy: Add early abort to copy_to_user Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
    [PATCH 3.12 21/86] usb: hub: Wait for connection to be reestablished after port reset Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
    [PATCH 3.12 13/86] metag/usercopy: Fix src fixup in from user rapf loops Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
    [PATCH 3.12 23/86] net/mlx4_core: Fix racy CQ (Completion Queue) free Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
    [PATCH 3.12 34/86] zram: do not use copy_page with non-page aligned address Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
    [PATCH 3.12 19/86] mtd: bcm47xxpart: fix parsing first block after aligned TRX Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
    [PATCH 3.12 16/86] s390/decompressor: fix initrd corruption caused by bss clear Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
    [PATCH 3.12 08/86] metag/usercopy: Drop unused macros Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
    [PATCH 3.12 24/86] Input: xpad - add support for Razer Wildcat gamepad Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
    [PATCH 3.12 44/86] catc: Use heap buffer for memory size test Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
    [PATCH 3.12 35/86] powerpc: Disable HFSCR[TM] if TM is not supported Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
    [PATCH 3.12 15/86] powerpc: Don't try to fix up misaligned load-with-reservation instructions Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
    [PATCH 3.12 07/86] ring-buffer: Fix return value check in test_ringbuffer() Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
    [PATCH 3.12 17/86] mm/mempolicy.c: fix error handling in set_mempolicy and mbind. Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
    [PATCH 3.12 09/86] metag/usercopy: Fix alignment error checking Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
    [PATCH 3.12 22/86] net/mlx4_en: Fix bad WQE issue Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
    [PATCH 3.12 20/86] net/packet: fix overflow in check for priv area size Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
    [PATCH 3.12 12/86] metag/usercopy: Set flags before ADDZ Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
    [PATCH 3.12 11/86] metag/usercopy: Zero rest of buffer from copy_from_user Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
  Re: [PATCH 3.12 00/86] 3.12.74-stable review Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
  Re: [PATCH 3.12 00/86] 3.12.74-stable review Guenter Roeck <linux@roeck-us.net> - 2017-05-04 18:00 +0200
    Re: [PATCH 3.12 00/86] 3.12.74-stable review Jiri Slaby <jslaby@suse.cz> - 2017-05-09 21:00 +0200
  Re: [PATCH 3.12 00/86] 3.12.74-stable review Shuah Khan <shuahkh@osg.samsung.com> - 2017-05-04 21:00 +0200

csiph-web