Netdev List
 help / color / mirror / Atom feed
From: Harald Welte <laforge@netfilter.org>
To: David Miller <davem@davemloft.net>
Cc: netdev@oss.sgi.com,
	Netfilter Development Mailinglist
	<netfilter-devel@lists.netfilter.org>
Subject: [PATCH 2.6] fix deadlock with ip_queue and tcp local input path
Date: Mon, 30 May 2005 20:06:54 +0200	[thread overview]
Message-ID: <20050530180654.GX22760@sunbeam.de.gnumonks.org> (raw)
In-Reply-To: <20050526142420.GD13114@sunbeam.de.gnumonks.org>


[-- Attachment #1.1: Type: text/plain, Size: 1232 bytes --]

On Thu, May 26, 2005 at 04:24:21PM +0200, Harald Welte wrote:
 
> When we have ip_queue being used from LOCAL_IN, then we end up with a
> situation where the verdicts coming back from userspace traverse the TCP
> input path from syscall context.  While this seems to work most of the
> time, there's an ungly deadlock:
> 
> syscall context is interrupted by the timer interrupt.  When the timer
> interrupt leaves, the timer softirq get's scheduled and calls
> tcp_delack_timer() and alike.  They themselves do bh_lock_sock(sk),
> which is already held from somewhere else[1] -> boom.

I've now tested the suggested solution by Patrick McHardy and Herbert Xu to
simply use local_bh_{en,dis}able().

Please apply the following patch to mainline.

btw: How do we get this into 2.6.11.x ?

Signed-off-by: Harald Welte <laforge@netfilter.org>

-- 
- Harald Welte <laforge@netfilter.org>                 http://netfilter.org/
============================================================================
  "Fragmentation is like classful addressing -- an interesting early
   architectural error that shows how much experimentation was going
   on while IP was being designed."                    -- Paul Vixie

[-- Attachment #1.2: queue-local-reinject-smp-deadlock-fix-localbhdisable.patch --]
[-- Type: text/plain, Size: 1384 bytes --]

Index: linux-2.6.10/net/ipv4/netfilter/ip_queue.c
===================================================================
--- linux-2.6.10.orig/net/ipv4/netfilter/ip_queue.c	2005-05-27 09:44:32.000000000 +0200
+++ linux-2.6.10/net/ipv4/netfilter/ip_queue.c	2005-05-27 09:47:13.000000000 +0200
@@ -3,6 +3,7 @@
  * communicating with userspace via netlink.
  *
  * (C) 2000-2002 James Morris <jmorris@intercode.com.au>
+ * (C) 2003-2005 Netfilter Core Team <coreteam@netfilter.org>
  *
  * This program is free software; you can redistribute it and/or modify
  * it under the terms of the GNU General Public License version 2 as
@@ -14,6 +15,7 @@
  *             Zander).
  * 2000-08-01: Added Nick Williams' MAC support.
  * 2002-06-25: Code cleanup.
+ * 2005-05-26: local_bh_{disable,enable} around nf_reinject (Harald Welte)
  *
  */
 #include <linux/module.h>
@@ -66,7 +68,15 @@
 static void
 ipq_issue_verdict(struct ipq_queue_entry *entry, int verdict)
 {
+	/* TCP input path (and probably other bits) assume to be called
+	 * from softirq context, not from syscall, like ipq_issue_verdict is
+	 * called.  TCP input path deadlocks with locks taken from timer
+	 * softirq, e.g.  We therefore emulate this by local_bh_disable() */
+
+	local_bh_disable();
 	nf_reinject(entry->skb, entry->info, verdict);
+	local_bh_enable();
+
 	kfree(entry);
 }
 

[-- Attachment #2: Type: application/pgp-signature, Size: 189 bytes --]

  parent reply	other threads:[~2005-05-30 18:06 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2005-05-26 14:24 [PATCH 2.6] fix deadlock with ip_queue and tcp local input path Harald Welte
2005-05-26 20:52 ` David S. Miller
2005-05-26 20:58   ` Harald Welte
2005-05-26 21:01     ` David S. Miller
2005-05-26 21:38 ` Herbert Xu
2005-05-27  7:37   ` Harald Welte
2005-05-30 18:06 ` Harald Welte [this message]
2005-05-30 22:26   ` David S. Miller

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20050530180654.GX22760@sunbeam.de.gnumonks.org \
    --to=laforge@netfilter.org \
    --cc=davem@davemloft.net \
    --cc=netdev@oss.sgi.com \
    --cc=netfilter-devel@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox