From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-5.5 required=3.0 tests=DKIM_SIGNED,DKIM_VALID, HEADER_FROM_DIFFERENT_DOMAINS,MAILING_LIST_MULTI,SIGNED_OFF_BY,SPF_PASS, USER_AGENT_MUTT autolearn=ham autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 062F0C43381 for ; Thu, 14 Feb 2019 18:24:49 +0000 (UTC) Received: from vger.kernel.org (vger.kernel.org [209.132.180.67]) by mail.kernel.org (Postfix) with ESMTP id C004E21B24 for ; Thu, 14 Feb 2019 18:24:48 +0000 (UTC) Authentication-Results: mail.kernel.org; dkim=pass (2048-bit key) header.d=messagingengine.com header.i=@messagingengine.com header.b="zUY1YXlS" Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S2405443AbfBNSYr (ORCPT ); Thu, 14 Feb 2019 13:24:47 -0500 Received: from out2-smtp.messagingengine.com ([66.111.4.26]:57609 "EHLO out2-smtp.messagingengine.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S2390464AbfBNSYr (ORCPT ); Thu, 14 Feb 2019 13:24:47 -0500 Received: from compute3.internal (compute3.nyi.internal [10.202.2.43]) by mailout.nyi.internal (Postfix) with ESMTP id DD3A22219D; Thu, 14 Feb 2019 13:24:45 -0500 (EST) Received: from mailfrontend2 ([10.202.2.163]) by compute3.internal (MEProxy); Thu, 14 Feb 2019 13:24:45 -0500 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to:x-me-proxy :x-me-proxy:x-me-sender:x-me-sender:x-sasl-enc; s=fm2; bh=ArrjYW 1h+G0BmJAlf2672lEVXzBVHgkAIjEp2K/by64=; b=zUY1YXlS6/ZUD3pHeyXomt eJ32Q1lt0R+pvZxDRWogEMsKTq2VrxvazNSSLPM0sy3onobbyhNq0Zef1t9BtEpG LN/joYv+uUB8Ppp3D5M+jeXICLxjqaMq1sIqOYFpkKUUIOhC2fPmKVkW8f0f8jQk 8sJTPADCxK/9owSgRSP5q6aJZZRsHhAT91Lg7tPC2rD9cbBRG5VK4WFtzLUZr3E9 dgQpf8bTRnUtErcZdDyQyJAGz8J37yiMmj5VkSEUnvhTaC6EKk8EysoFYcfY/UlT OFGfHvzZUhxPPVuEzH6Yz1+uB2tnasudDWLy0w0ZYp+3Ec8tyj7KxZFP7jkkI42g == X-ME-Sender: X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgedtledruddthedgudduvdcutefuodetggdotefrod ftvfcurfhrohhfihhlvgemucfhrghsthforghilhdpqfhuthenuceurghilhhouhhtmecu fedttdenucesvcftvggtihhpihgvnhhtshculddquddttddmnecujfgurhepfffhvffukf hfgggtuggjfgesthdtredttdervdenucfhrhhomhepkfguohcuufgthhhimhhmvghluceo ihguohhstghhsehiughoshgthhdrohhrgheqnecukfhppeduleefrdegjedrudeihedrvd ehudenucfrrghrrghmpehmrghilhhfrhhomhepihguohhstghhsehiughoshgthhdrohhr ghenucevlhhushhtvghrufhiiigvpedt X-ME-Proxy: Received: from localhost (unknown [193.47.165.251]) by mail.messagingengine.com (Postfix) with ESMTPA id ED48710312; Thu, 14 Feb 2019 13:24:43 -0500 (EST) Date: Thu, 14 Feb 2019 20:24:42 +0200 From: Ido Schimmel To: Vlad Buslov Cc: netdev@vger.kernel.org, jhs@mojatatu.com, xiyou.wangcong@gmail.com, jiri@resnulli.us, davem@davemloft.net, ast@kernel.org, daniel@iogearbox.net Subject: Re: [PATCH net-next v4 07/17] net: sched: protect filter_chain list with filter_chain_lock mutex Message-ID: <20190214182442.GA19269@splinter> References: <20190211085548.7190-1-vladbu@mellanox.com> <20190211085548.7190-8-vladbu@mellanox.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20190211085548.7190-8-vladbu@mellanox.com> User-Agent: Mutt/1.10.1 (2018-07-13) Sender: netdev-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: netdev@vger.kernel.org On Mon, Feb 11, 2019 at 10:55:38AM +0200, Vlad Buslov wrote: > Extend tcf_chain with new filter_chain_lock mutex. Always lock the chain > when accessing filter_chain list, instead of relying on rtnl lock. > Dereference filter_chain with tcf_chain_dereference() lockdep macro to > verify that all users of chain_list have the lock taken. > > Rearrange tp insert/remove code in tc_new_tfilter/tc_del_tfilter to execute > all necessary code while holding chain lock in order to prevent > invalidation of chain_info structure by potential concurrent change. This > also serializes calls to tcf_chain0_head_change(), which allows head change > callbacks to rely on filter_chain_lock for synchronization instead of rtnl > mutex. > > Signed-off-by: Vlad Buslov > Acked-by: Jiri Pirko With this sequence [1] I get the following trace [2]. Bisected it to this patch. Note that second filter is rejected by the device driver (that's the intention). I guess it is not properly removed from the filter chain in the error path? Thanks [1] # tc qdisc add dev swp3 clsact # tc filter add dev swp3 ingress pref 1 matchall skip_sw \ action mirred egress mirror dev swp7 # tc filter add dev swp3 ingress pref 2 matchall skip_sw \ action mirred egress mirror dev swp7 RTNETLINK answers: File exists We have an error talking to the kernel, -1 # tc qdisc del dev swp3 clsact [2] [ 70.545131] kasan: GPF could be caused by NULL-ptr deref or user memory access [ 70.553394] general protection fault: 0000 [#1] PREEMPT SMP KASAN PTI [ 70.560618] CPU: 2 PID: 2268 Comm: tc Not tainted 5.0.0-rc5-custom-02103-g415d39427317 #1304 [ 70.570065] Hardware name: Mellanox Technologies Ltd. MSN2100-CB2FO/SA001017, BIOS 5.6.5 06/07/2016 [ 70.580204] RIP: 0010:mall_reoffload+0x14a/0x760 [ 70.585382] Code: c1 0f 85 ba 05 00 00 31 c0 4d 8d 6c 24 34 b9 06 00 00 00 4c 89 ff f3 48 ab 4c 89 ea 48 b8 00 00 00 00 00 fc ff df 48 c1 ea 03 <0f> b6 14 02 4c 89 e8 83 e0 07 83 c0 03 38 d0 7c 08 84 d2 0f 85 bd [ 70.606382] RSP: 0018:ffff888231faefc0 EFLAGS: 00010207 [ 70.612235] RAX: dffffc0000000000 RBX: 1ffff110463f5dfe RCX: 0000000000000000 [ 70.620220] RDX: 0000000000000006 RSI: 1ffff110463f5e01 RDI: ffff888231faf040 [ 70.628206] RBP: ffff8881ef151a00 R08: 0000000000000000 R09: ffffed10463f5dfa [ 70.636192] R10: ffffed10463f5dfa R11: 0000000000000003 R12: 0000000000000000 [ 70.644177] R13: 0000000000000034 R14: 0000000000000000 R15: ffff888231faf010 [ 70.652163] FS: 00007f46b5bf0800(0000) GS:ffff888236c00000(0000) knlGS:0000000000000000 [ 70.661218] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 70.667649] CR2: 0000000001d590a8 CR3: 0000000231c3c000 CR4: 00000000001006e0 [ 70.675633] Call Trace: [ 70.693046] tcf_block_playback_offloads+0x94/0x230 [ 70.710617] __tcf_block_cb_unregister+0xf7/0x2d0 [ 70.734143] mlxsw_sp_setup_tc+0x20f/0x660 [ 70.738739] tcf_block_offload_unbind+0x22b/0x350 [ 70.748898] __tcf_block_put+0x203/0x630 [ 70.769700] tcf_block_put_ext+0x2f/0x40 [ 70.774098] clsact_destroy+0x7a/0xb0 [ 70.782604] qdisc_destroy+0x11a/0x5c0 [ 70.786810] qdisc_put+0x5a/0x70 [ 70.790435] notify_and_destroy+0x8e/0xa0 [ 70.794933] qdisc_graft+0xbb7/0xef0 [ 70.809009] tc_get_qdisc+0x518/0xa30 [ 70.821530] rtnetlink_rcv_msg+0x397/0xa20 [ 70.835510] netlink_rcv_skb+0x132/0x380 [ 70.848419] netlink_unicast+0x4c0/0x690 [ 70.866019] netlink_sendmsg+0x929/0xe10 [ 70.882134] sock_sendmsg+0xc8/0x110 [ 70.886144] ___sys_sendmsg+0x77a/0x8f0 [ 70.924064] __sys_sendmsg+0xf7/0x250 [ 70.955727] do_syscall_64+0x14d/0x610