From: joeyli <jlee@suse.com>
To: Valentin Kleibel <valentin@vrvis.at>
Cc: Chun-Yi Lee <joeyli.kernel@gmail.com>,
Justin Sanders <justin@coraid.com>, Jens Axboe <axboe@kernel.dk>,
Pavel Emelianov <xemul@openvz.org>,
Kirill Korotaev <dev@openvz.org>,
"David S . Miller" <davem@davemloft.net>,
Nicolai Stange <nstange@suse.com>,
Greg KH <gregkh@linuxfoundation.org>,
linux-block@vger.kernel.org, linux-kernel@vger.kernel.org
Subject: Re: [PATCH v2] aoe: fix the potential use-after-free problem in more places
Date: Wed, 2 Oct 2024 13:53:38 +0800 [thread overview]
Message-ID: <20241002055338.GI3296@linux-l9pv.suse> (raw)
In-Reply-To: <9371a3ab-3637-4106-bee5-9280abb5f5ae@vrvis.at>
Hi Valentin,
On Thu, Sep 12, 2024 at 12:58:46PM +0200, Valentin Kleibel wrote:
> > Then Nicolai Stange found more places in aoe have potential use-after-free
> > problem with tx(). e.g. revalidate(), aoecmd_ata_rw(), resend(), probe()
> > and aoecmd_cfg_rsp(). Those functions also use aoenet_xmit() to push
> > packet to tx queue. So they should also use dev_hold() to increase the
> > refcnt of skb->dev.
>
> We've tested your patch on our servers and ran into an issue.
> With heavy I/O load the aoe device had stale I/Os (e.g. rsync waiting
> indefinetly on one core) that can be "fixed" by running aoe-revalidate on
> that device.
>
> Additionally when trying to shut down the system we see the message:
> unregister_netdevice: waiting for XXX to become free. Usage Count = XXXXX
> on aoe devices with a usage count somewhere in the millions.
> This has been the same as without the patch, i assume the fix is still
> incomplete.
>
For the reference count debugging, I have sent a patch series here:
[RFC PATCH 0/2] tracking the references of net_device in aoe
https://lore.kernel.org/lkml/20241002040616.25193-1-jlee@suse.com/T/#t
Base on my testing, the number of dev_hold(nd) and dev_put(nd) are balance
in aoe after the this 'aoe: fix the potential use-after-free problem in more places'
patch be applied on v6.11 kernel. I have tested add/modify/delete files in remote
target by aoe. My testing is not a heavy I/O testing. But the result is
balance.
Could you please help to try the above debug patch series for looking at the
refcnt value in aoe in your side?
Thanks a lot!
Joey Lee
next prev parent reply other threads:[~2024-10-02 5:53 UTC|newest]
Thread overview: 24+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-09-12 10:29 [PATCH v2] aoe: fix the potential use-after-free problem in more places Chun-Yi Lee
2024-09-12 10:58 ` Valentin Kleibel
2024-09-16 9:23 ` joeyli
2024-10-02 5:53 ` joeyli [this message]
2024-11-04 13:38 ` Valentin Kleibel
2024-11-11 13:53 ` joeyli
2024-09-12 11:01 ` Greg KH
-- strict thread matches above, loose matches on Subject: below --
2024-06-24 6:44 Chun-Yi Lee
2024-06-24 7:05 ` Greg KH
2024-06-24 11:00 ` joeyli
2024-06-24 8:40 ` Markus Elfring
2024-06-24 11:01 ` joeyli
2024-06-24 11:43 ` Markus Elfring
2024-06-24 11:54 ` joeyli
2024-06-24 12:45 ` Greg KH
2024-06-24 9:27 ` Markus Elfring
2024-06-24 11:04 ` joeyli
2024-06-24 11:28 ` Markus Elfring
2024-06-24 11:45 ` joeyli
2024-06-25 10:48 ` kernel test robot
2024-06-13 4:15 Chun-Yi Lee
2024-05-14 15:18 Chun-Yi Lee
2024-05-14 15:34 ` Markus Elfring
2024-05-15 5:09 ` joeyli
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20241002055338.GI3296@linux-l9pv.suse \
--to=jlee@suse.com \
--cc=axboe@kernel.dk \
--cc=davem@davemloft.net \
--cc=dev@openvz.org \
--cc=gregkh@linuxfoundation.org \
--cc=joeyli.kernel@gmail.com \
--cc=justin@coraid.com \
--cc=linux-block@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=nstange@suse.com \
--cc=valentin@vrvis.at \
--cc=xemul@openvz.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.