Netdev List
 help / color / mirror / Atom feed
* [Patch net] net_sched: fix struct tc_u_hnode layout in u32
@ 2015-03-10  0:03 Cong Wang
  2015-03-10  0:13 ` Eric Dumazet
  2015-03-10  3:45 ` David Miller
  0 siblings, 2 replies; 3+ messages in thread
From: Cong Wang @ 2015-03-10  0:03 UTC (permalink / raw)
  To: netdev; +Cc: Cong Wang, Jamal Hadi Salim, John Fastabend

We dynamically allocate divisor+1 entries for ->ht[] in tc_u_hnode:

  ht = kzalloc(sizeof(*ht) + divisor*sizeof(void *), GFP_KERNEL);

So ->ht is supposed to be the last field of this struct, however
this is broken, since an rcu head is appended after it.

Fixes: 1ce87720d456 ("net: sched: make cls_u32 lockless")
Cc: Jamal Hadi Salim <jhs@mojatatu.com>
Cc: John Fastabend <john.fastabend@gmail.com>
Signed-off-by: Cong Wang <xiyou.wangcong@gmail.com>
---
 net/sched/cls_u32.c | 5 ++++-
 1 file changed, 4 insertions(+), 1 deletion(-)

diff --git a/net/sched/cls_u32.c b/net/sched/cls_u32.c
index 09487af..95fdf4e 100644
--- a/net/sched/cls_u32.c
+++ b/net/sched/cls_u32.c
@@ -78,8 +78,11 @@ struct tc_u_hnode {
 	struct tc_u_common	*tp_c;
 	int			refcnt;
 	unsigned int		divisor;
-	struct tc_u_knode __rcu	*ht[1];
 	struct rcu_head		rcu;
+	/* The 'ht' field MUST be the last field in structure to allow for
+	 * more entries allocated at end of structure.
+	 */
+	struct tc_u_knode __rcu	*ht[1];
 };
 
 struct tc_u_common {
-- 
1.8.3.1

^ permalink raw reply related	[flat|nested] 3+ messages in thread

* Re: [Patch net] net_sched: fix struct tc_u_hnode layout in u32
  2015-03-10  0:03 [Patch net] net_sched: fix struct tc_u_hnode layout in u32 Cong Wang
@ 2015-03-10  0:13 ` Eric Dumazet
  2015-03-10  3:45 ` David Miller
  1 sibling, 0 replies; 3+ messages in thread
From: Eric Dumazet @ 2015-03-10  0:13 UTC (permalink / raw)
  To: Cong Wang; +Cc: netdev, Jamal Hadi Salim, John Fastabend

On Mon, 2015-03-09 at 17:03 -0700, Cong Wang wrote:
> We dynamically allocate divisor+1 entries for ->ht[] in tc_u_hnode:
> 
>   ht = kzalloc(sizeof(*ht) + divisor*sizeof(void *), GFP_KERNEL);
> 
> So ->ht is supposed to be the last field of this struct, however
> this is broken, since an rcu head is appended after it.
> 
> Fixes: 1ce87720d456 ("net: sched: make cls_u32 lockless")
> Cc: Jamal Hadi Salim <jhs@mojatatu.com>
> Cc: John Fastabend <john.fastabend@gmail.com>
> Signed-off-by: Cong Wang <xiyou.wangcong@gmail.com>
> ---
>  net/sched/cls_u32.c | 5 ++++-
>  1 file changed, 4 insertions(+), 1 deletion(-)
> 
> diff --git a/net/sched/cls_u32.c b/net/sched/cls_u32.c
> index 09487af..95fdf4e 100644
> --- a/net/sched/cls_u32.c
> +++ b/net/sched/cls_u32.c
> @@ -78,8 +78,11 @@ struct tc_u_hnode {
>  	struct tc_u_common	*tp_c;
>  	int			refcnt;
>  	unsigned int		divisor;
> -	struct tc_u_knode __rcu	*ht[1];
>  	struct rcu_head		rcu;
> +	/* The 'ht' field MUST be the last field in structure to allow for
> +	 * more entries allocated at end of structure.
> +	 */
> +	struct tc_u_knode __rcu	*ht[1];
>  };

Good catch.

Definitely a call to make this a flexible array in net-next (ht[]), so
that compiler would have catch the bug.

Acked-by: Eric Dumazet <edumazet@google.com>

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [Patch net] net_sched: fix struct tc_u_hnode layout in u32
  2015-03-10  0:03 [Patch net] net_sched: fix struct tc_u_hnode layout in u32 Cong Wang
  2015-03-10  0:13 ` Eric Dumazet
@ 2015-03-10  3:45 ` David Miller
  1 sibling, 0 replies; 3+ messages in thread
From: David Miller @ 2015-03-10  3:45 UTC (permalink / raw)
  To: xiyou.wangcong; +Cc: netdev, jhs, john.fastabend

From: Cong Wang <xiyou.wangcong@gmail.com>
Date: Mon,  9 Mar 2015 17:03:40 -0700

> We dynamically allocate divisor+1 entries for ->ht[] in tc_u_hnode:
> 
>   ht = kzalloc(sizeof(*ht) + divisor*sizeof(void *), GFP_KERNEL);
> 
> So ->ht is supposed to be the last field of this struct, however
> this is broken, since an rcu head is appended after it.
> 
> Fixes: 1ce87720d456 ("net: sched: make cls_u32 lockless")
> Cc: Jamal Hadi Salim <jhs@mojatatu.com>
> Cc: John Fastabend <john.fastabend@gmail.com>
> Signed-off-by: Cong Wang <xiyou.wangcong@gmail.com>

Applied and queued up for -stable, thanks.

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2015-03-10  3:45 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2015-03-10  0:03 [Patch net] net_sched: fix struct tc_u_hnode layout in u32 Cong Wang
2015-03-10  0:13 ` Eric Dumazet
2015-03-10  3:45 ` David Miller

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox