* [Patch net] net_sched: fix struct tc_u_hnode layout in u32
@ 2015-03-10 0:03 Cong Wang
2015-03-10 0:13 ` Eric Dumazet
2015-03-10 3:45 ` David Miller
0 siblings, 2 replies; 3+ messages in thread
From: Cong Wang @ 2015-03-10 0:03 UTC (permalink / raw)
To: netdev; +Cc: Cong Wang, Jamal Hadi Salim, John Fastabend
We dynamically allocate divisor+1 entries for ->ht[] in tc_u_hnode:
ht = kzalloc(sizeof(*ht) + divisor*sizeof(void *), GFP_KERNEL);
So ->ht is supposed to be the last field of this struct, however
this is broken, since an rcu head is appended after it.
Fixes: 1ce87720d456 ("net: sched: make cls_u32 lockless")
Cc: Jamal Hadi Salim <jhs@mojatatu.com>
Cc: John Fastabend <john.fastabend@gmail.com>
Signed-off-by: Cong Wang <xiyou.wangcong@gmail.com>
---
net/sched/cls_u32.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/net/sched/cls_u32.c b/net/sched/cls_u32.c
index 09487af..95fdf4e 100644
--- a/net/sched/cls_u32.c
+++ b/net/sched/cls_u32.c
@@ -78,8 +78,11 @@ struct tc_u_hnode {
struct tc_u_common *tp_c;
int refcnt;
unsigned int divisor;
- struct tc_u_knode __rcu *ht[1];
struct rcu_head rcu;
+ /* The 'ht' field MUST be the last field in structure to allow for
+ * more entries allocated at end of structure.
+ */
+ struct tc_u_knode __rcu *ht[1];
};
struct tc_u_common {
--
1.8.3.1
^ permalink raw reply related [flat|nested] 3+ messages in thread
* Re: [Patch net] net_sched: fix struct tc_u_hnode layout in u32
2015-03-10 0:03 [Patch net] net_sched: fix struct tc_u_hnode layout in u32 Cong Wang
@ 2015-03-10 0:13 ` Eric Dumazet
2015-03-10 3:45 ` David Miller
1 sibling, 0 replies; 3+ messages in thread
From: Eric Dumazet @ 2015-03-10 0:13 UTC (permalink / raw)
To: Cong Wang; +Cc: netdev, Jamal Hadi Salim, John Fastabend
On Mon, 2015-03-09 at 17:03 -0700, Cong Wang wrote:
> We dynamically allocate divisor+1 entries for ->ht[] in tc_u_hnode:
>
> ht = kzalloc(sizeof(*ht) + divisor*sizeof(void *), GFP_KERNEL);
>
> So ->ht is supposed to be the last field of this struct, however
> this is broken, since an rcu head is appended after it.
>
> Fixes: 1ce87720d456 ("net: sched: make cls_u32 lockless")
> Cc: Jamal Hadi Salim <jhs@mojatatu.com>
> Cc: John Fastabend <john.fastabend@gmail.com>
> Signed-off-by: Cong Wang <xiyou.wangcong@gmail.com>
> ---
> net/sched/cls_u32.c | 5 ++++-
> 1 file changed, 4 insertions(+), 1 deletion(-)
>
> diff --git a/net/sched/cls_u32.c b/net/sched/cls_u32.c
> index 09487af..95fdf4e 100644
> --- a/net/sched/cls_u32.c
> +++ b/net/sched/cls_u32.c
> @@ -78,8 +78,11 @@ struct tc_u_hnode {
> struct tc_u_common *tp_c;
> int refcnt;
> unsigned int divisor;
> - struct tc_u_knode __rcu *ht[1];
> struct rcu_head rcu;
> + /* The 'ht' field MUST be the last field in structure to allow for
> + * more entries allocated at end of structure.
> + */
> + struct tc_u_knode __rcu *ht[1];
> };
Good catch.
Definitely a call to make this a flexible array in net-next (ht[]), so
that compiler would have catch the bug.
Acked-by: Eric Dumazet <edumazet@google.com>
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [Patch net] net_sched: fix struct tc_u_hnode layout in u32
2015-03-10 0:03 [Patch net] net_sched: fix struct tc_u_hnode layout in u32 Cong Wang
2015-03-10 0:13 ` Eric Dumazet
@ 2015-03-10 3:45 ` David Miller
1 sibling, 0 replies; 3+ messages in thread
From: David Miller @ 2015-03-10 3:45 UTC (permalink / raw)
To: xiyou.wangcong; +Cc: netdev, jhs, john.fastabend
From: Cong Wang <xiyou.wangcong@gmail.com>
Date: Mon, 9 Mar 2015 17:03:40 -0700
> We dynamically allocate divisor+1 entries for ->ht[] in tc_u_hnode:
>
> ht = kzalloc(sizeof(*ht) + divisor*sizeof(void *), GFP_KERNEL);
>
> So ->ht is supposed to be the last field of this struct, however
> this is broken, since an rcu head is appended after it.
>
> Fixes: 1ce87720d456 ("net: sched: make cls_u32 lockless")
> Cc: Jamal Hadi Salim <jhs@mojatatu.com>
> Cc: John Fastabend <john.fastabend@gmail.com>
> Signed-off-by: Cong Wang <xiyou.wangcong@gmail.com>
Applied and queued up for -stable, thanks.
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2015-03-10 3:45 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2015-03-10 0:03 [Patch net] net_sched: fix struct tc_u_hnode layout in u32 Cong Wang
2015-03-10 0:13 ` Eric Dumazet
2015-03-10 3:45 ` David Miller
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox