Netdev List
 help / color / mirror / Atom feed
From: Eric Dumazet <eric.dumazet@gmail.com>
To: David Miller <davem@davemloft.net>
Cc: mroos@linux.ee, netdev@vger.kernel.org
Subject: Re: 3.3-rc3+ Crash in __neigh_for_each_release
Date: Tue, 21 Feb 2012 21:46:49 +0100	[thread overview]
Message-ID: <1329857209.18384.53.camel@edumazet-laptop> (raw)
In-Reply-To: <1329851756.18384.47.camel@edumazet-laptop>

Le mardi 21 février 2012 à 20:15 +0100, Eric Dumazet a écrit :
> Le mardi 21 février 2012 à 14:07 -0500, David Miller a écrit :
> > From: Eric Dumazet <eric.dumazet@gmail.com>
> > Date: Tue, 21 Feb 2012 20:03:24 +0100
> > 
> > > But I dont know enough this code to know if the following patch is the
> > > way to fix this. (and __neigh_for_each_release() can also be deleted if
> > > no users left in tree)
> > 
> > I think instead of removing the code, we need to have it iterate over
> > "arp_tbl" but only invoke the callback for devices which are of type
> > ATM.
> 
> That makes sense...
> 
> Or invoke callback for all entries, and filter in callback non ATM ones.
> 
> 

What about following patch ?

Meelis, can you test it please ?

[PATCH] atm: clip: remove clip_tbl

Commit 32092ecf0644 (atm: clip: Use device neigh support on top of
"arp_tbl".) introduced a bug since clip_tbl is zeroed : Crash occurs in
__neigh_for_each_release()

idle_timer_check() must use instead arp_tbl and neigh_check_cb() should
ignore non clip neighbours.

Idea from David Miller.

Reported-by: Meelis Roos <mroos@linux.ee>
Signed-off-by: Eric Dumazet <eric.dumazet@gmail.com>
---
 net/atm/clip.c |   10 ++++++----
 1 file changed, 6 insertions(+), 4 deletions(-)

diff --git a/net/atm/clip.c b/net/atm/clip.c
index c12c258..127fe70 100644
--- a/net/atm/clip.c
+++ b/net/atm/clip.c
@@ -46,8 +46,8 @@
 
 static struct net_device *clip_devs;
 static struct atm_vcc *atmarpd;
-static struct neigh_table clip_tbl;
 static struct timer_list idle_timer;
+static const struct neigh_ops clip_neigh_ops;
 
 static int to_atmarpd(enum atmarp_ctrl_type type, int itf, __be32 ip)
 {
@@ -123,6 +123,8 @@ static int neigh_check_cb(struct neighbour *n)
 	struct atmarp_entry *entry = neighbour_priv(n);
 	struct clip_vcc *cv;
 
+	if (n->ops != &clip_neigh_ops)
+		return 0;
 	for (cv = entry->vccs; cv; cv = cv->next) {
 		unsigned long exp = cv->last_use + cv->idle_timeout;
 
@@ -154,10 +156,10 @@ static int neigh_check_cb(struct neighbour *n)
 
 static void idle_timer_check(unsigned long dummy)
 {
-	write_lock(&clip_tbl.lock);
-	__neigh_for_each_release(&clip_tbl, neigh_check_cb);
+	write_lock(&arp_tbl.lock);
+	__neigh_for_each_release(&arp_tbl, neigh_check_cb);
 	mod_timer(&idle_timer, jiffies + CLIP_CHECK_INTERVAL * HZ);
-	write_unlock(&clip_tbl.lock);
+	write_unlock(&arp_tbl.lock);
 }
 
 static int clip_arp_rcv(struct sk_buff *skb)

  reply	other threads:[~2012-02-21 20:46 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2012-02-20 12:02 3.3-rc3+ Crash in __neigh_for_each_release Meelis Roos
2012-02-20 12:04 ` Meelis Roos
2012-02-21 19:03 ` Eric Dumazet
2012-02-21 19:07   ` David Miller
2012-02-21 19:15     ` Eric Dumazet
2012-02-21 20:46       ` Eric Dumazet [this message]
2012-02-21 22:46         ` David Miller
2012-02-22  7:19         ` mroos
2012-02-22  7:21           ` Eric Dumazet
2012-02-22  7:24           ` David Miller

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1329857209.18384.53.camel@edumazet-laptop \
    --to=eric.dumazet@gmail.com \
    --cc=davem@davemloft.net \
    --cc=mroos@linux.ee \
    --cc=netdev@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox