From: Steffen Klassert <steffen.klassert@secunet.com>
To: Xianpeng Zhao <673321875@qq.com>
Cc: netdev <netdev@vger.kernel.org>, alan <alan@lxorguk.ukuu.org.uk>
Subject: Re: Fw:[Bug 70471] xfrm policy node will double unlink.
Date: Tue, 18 Feb 2014 09:37:38 +0100 [thread overview]
Message-ID: <20140218083737.GB32371@secunet.com> (raw)
In-Reply-To: <tencent_0D7FA5355C7998793C100B23@qq.com>
On Tue, Feb 18, 2014 at 10:55:57AM +0800, Xianpeng Zhao wrote:
> Hi Group,
> I found a problem about xfrm policy.
>
> In corner case, xfrm policy node will be double unlinked from the list.
>
> The scenario like this:
> In thread context, After removed the node from list, before remove the xfrm policy expire timer. At this point, a timer interrupt come, and call the run_timer_softirq to execute the xfrm_policy_timer to remove the expired policy node; because this policy node had already removed from list. this remove will cause the node double unlinked.
Good catch!
I wonder why I've never seen this. Do you have a reproducer for this bug?
Looks like it is sufficient to reinitialize the bydst hlist in
__xfrm_policy_unlink(). Then hlist_unhashed() will notice that
this policy is not linked.
Does the patch below help?
diff --git a/net/xfrm/xfrm_policy.c b/net/xfrm/xfrm_policy.c
index 121399d..225f439 100644
--- a/net/xfrm/xfrm_policy.c
+++ b/net/xfrm/xfrm_policy.c
@@ -1156,7 +1156,7 @@ static struct xfrm_policy *__xfrm_policy_unlink(struct xfrm_policy *pol,
if (hlist_unhashed(&pol->bydst))
return NULL;
- hlist_del(&pol->bydst);
+ hlist_del_init(&pol->bydst);
hlist_del(&pol->byidx);
list_del(&pol->walk.all);
net->xfrm.policy_count[dir]--;
next prev parent reply other threads:[~2014-02-18 8:37 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-02-18 2:55 Fw:[Bug 70471] xfrm policy node will double unlink Xianpeng Zhao
2014-02-18 8:37 ` Steffen Klassert [this message]
2014-02-19 2:07 ` Xianpeng Zhao
2014-02-19 11:43 ` Steffen Klassert
2014-02-20 2:01 ` Xianpeng Zhao
2014-02-21 7:35 ` Steffen Klassert
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20140218083737.GB32371@secunet.com \
--to=steffen.klassert@secunet.com \
--cc=673321875@qq.com \
--cc=alan@lxorguk.ukuu.org.uk \
--cc=netdev@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.