Netdev List
 help / color / mirror / Atom feed
From: Vlad Yasevich <vladislav.yasevich@hp.com>
To: davem@davemloft.net
Cc: netdev@vger.kernel.org, lksctp-developers@lists.sourceforge.net,
	Vlad Yasevich <vladislav.yasevich@hp.com>
Subject: [PATCH 07/14] SCTP: Fix a potential race between timers and receive path.
Date: Mon, 12 Nov 2007 11:38:22 -0500	[thread overview]
Message-ID: <11948855153314-git-send-email-vladislav.yasevich@hp.com> (raw)
In-Reply-To: <11948855091808-git-send-email-vladislav.yasevich@hp.com>

There is a possible race condition where the timer code will
free the association and the next packet in the queue will also
attempt to free the same association.

The example is, when we receive an ABORT at about the same time
as the retransmission timer fires.  If the timer wins the race,
it will free the association.  Once it releases the lock, the
queue processing will recieve the ABORT and will try to free
the association again.

Signed-off-by: Vlad Yasevich <vladislav.yasevich@hp.com>
---
 net/sctp/inqueue.c |    4 ++++
 1 files changed, 4 insertions(+), 0 deletions(-)

diff --git a/net/sctp/inqueue.c b/net/sctp/inqueue.c
index f10fe7f..cf4b7eb 100644
--- a/net/sctp/inqueue.c
+++ b/net/sctp/inqueue.c
@@ -90,6 +90,10 @@ void sctp_inq_free(struct sctp_inq *queue)
 void sctp_inq_push(struct sctp_inq *q, struct sctp_chunk *chunk)
 {
 	/* Directly call the packet handling routine. */
+	if (chunk->rcvr->dead) {
+		sctp_chunk_free(chunk);
+		return;
+	}
 
 	/* We are now calling this either from the soft interrupt
 	 * or from the backlog processing.
-- 
1.5.2.4


  parent reply	other threads:[~2007-11-12 16:38 UTC|newest]

Thread overview: 16+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2007-11-12 16:38 [GIT PATCHES v2] SCTP bug fixes Vlad Yasevich
2007-11-12 16:38 ` [PATCH 01/14] SCTP : Fix bad formatted comment in outqueue.c Vlad Yasevich
2007-11-12 16:38 ` [PATCH 02/14] SCTP : Fix to process bundled ASCONF chunk correctly Vlad Yasevich
2007-11-12 16:38 ` [PATCH 03/14] SCTP: Fix difference cases of retransmit Vlad Yasevich
2007-11-12 16:38 ` [PATCH 04/14] SCTP: Update RCU handling during the ADD-IP case Vlad Yasevich
2007-11-12 16:38 ` [PATCH 05/14] SCTP: Correctly disable ADD-IP when AUTH is not supported Vlad Yasevich
2007-11-12 16:38 ` [PATCH 06/14] SCTP: Allow ADD_IP to work with AUTH for backward compatibility Vlad Yasevich
2007-11-12 16:38 ` Vlad Yasevich [this message]
2007-11-12 16:38 ` [PATCH 08/14] SCTP: Use hashed lookup when looking for an association Vlad Yasevich
2007-11-12 16:38 ` [PATCH 09/14] SCTP: Convert custom hash lists to use hlist Vlad Yasevich
2007-11-12 16:38 ` [PATCH 10/14] SCTP: Make sctp_verify_param return multiple indications Vlad Yasevich
2007-11-12 16:38 ` [PATCH 11/14] SCTP: Fix PR-SCTP to deliver all the accumulated ordered chunks Vlad Yasevich
2007-11-12 16:38 ` [PATCH 12/14] SCTP: Clean-up some defines for regressions tests Vlad Yasevich
2007-11-12 16:38 ` [PATCH 13/14] SCTP: Always flush the queue when uncorcking Vlad Yasevich
2007-11-12 16:38 ` [PATCH 14/14] Fix memory leak in discard case of sctp_sf_abort_violation() Vlad Yasevich
2007-11-13  5:01 ` [GIT PATCHES v2] SCTP bug fixes David Miller

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=11948855153314-git-send-email-vladislav.yasevich@hp.com \
    --to=vladislav.yasevich@hp.com \
    --cc=davem@davemloft.net \
    --cc=lksctp-developers@lists.sourceforge.net \
    --cc=netdev@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox