From: Jesper Dangaard Brouer <brouer@redhat.com>
To: Eric Dumazet <eric.dumazet@gmail.com>
Cc: Florian Westphal <fw@strlen.de>,
netdev@vger.kernel.org, brouer@redhat.com
Subject: Re: [PATCH net] inet: frag: make sure forced eviction removes all frags
Date: Fri, 7 Mar 2014 09:56:05 +0100 [thread overview]
Message-ID: <20140307095605.1d382db0@redhat.com> (raw)
In-Reply-To: <1394127382.27473.40.camel@edumazet-glaptop2.roam.corp.google.com>
On Thu, 06 Mar 2014 09:36:22 -0800
Eric Dumazet <eric.dumazet@gmail.com> wrote:
> On Thu, 2014-03-06 at 18:06 +0100, Florian Westphal wrote:
> > Quoting Alexander Aring:
> > While fragmentation and unloading of 6lowpan module I got this kernel Oops
> > after few seconds:
> >
> > BUG: unable to handle kernel paging request at f88bbc30
> > [..]
> > Modules linked in: ipv6 [last unloaded: 6lowpan]
> > Call Trace:
> > [<c012af4c>] ? call_timer_fn+0x54/0xb3
> > [<c012aef8>] ? process_timeout+0xa/0xa
> > [<c012b66b>] run_timer_softirq+0x140/0x15f
> >
> > Problem is that incomplete frags are still around after unload; when
> > their frag expire timer fires, we get crash.
> >
> > When a netns is removed (also done when unloading module), inet_frag
> > calls the evictor with 'force' argument to purge remaining frags.
> >
> > The evictor loop terminates when accounted memory ('work') drops to 0
> > or the lru-list becomes empty. However, the mem accounting is done
> > via percpu counters and may not be accurate, i.e. loop may terminate
> > prematurely.
> >
> > Alter evictor to only stop once the lru list is empty when force is
> > requested.
> >
> > Reported-by: Phoebe Buckheister <phoebe.buckheister@itwm.fraunhofer.de>
> > Reported-by: Alexander Aring <alex.aring@gmail.com>
> > Tested-by: Alexander Aring <alex.aring@gmail.com>
> > Signed-off-by: Florian Westphal <fw@strlen.de>
> > ---
> >
> > diff --git a/net/ipv4/inet_fragment.c b/net/ipv4/inet_fragment.c
> > index 322dceb..3b01959 100644
> > --- a/net/ipv4/inet_fragment.c
> > +++ b/net/ipv4/inet_fragment.c
> > @@ -208,7 +208,7 @@ int inet_frag_evictor(struct netns_frags *nf, struct inet_frags *f, bool force)
> > }
> >
> > work = frag_mem_limit(nf) - nf->low_thresh;
> > - while (work > 0) {
> > + while (work > 0 || force) {
> > spin_lock(&nf->lru_lock);
> >
> > if (list_empty(&nf->lru_list)) {
>
> Fixes: 6d7b857d541e ("net: use lib/percpu_counter API for fragmentation mem accounting")
> Cc: Jesper Dangaard Brouer <brouer@redhat.com>
> Acked-by: Eric Dumazet <edumazet@google.com>
Thanks for CC'ing me, and adding the "Fixes" tag (but which DaveM forgot
to pickup in the commit...)
Thanks for fixing this Florian. Using the empty LRU list is this case
is a good solution, in this case.
In other situations, people should look at using percpu_counter_sum(),
when wanting an accurate read via percpu_counters. (Here frag_mem_limit()
uses percpu_counter_read() which caused the issue).
--
Best regards,
Jesper Dangaard Brouer
MSc.CS, Sr. Network Kernel Developer at Red Hat
Author of http://www.iptv-analyzer.org
LinkedIn: http://www.linkedin.com/in/brouer
next prev parent reply other threads:[~2014-03-07 8:56 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-03-06 17:06 [PATCH net] inet: frag: make sure forced eviction removes all frags Florian Westphal
2014-03-06 17:36 ` Eric Dumazet
2014-03-07 8:56 ` Jesper Dangaard Brouer [this message]
2014-03-07 18:09 ` David Miller
2014-03-06 20:29 ` David Miller
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20140307095605.1d382db0@redhat.com \
--to=brouer@redhat.com \
--cc=eric.dumazet@gmail.com \
--cc=fw@strlen.de \
--cc=netdev@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).