From: Dan Carpenter <dan.carpenter@linaro.org>
To: lars@oddbit.com, Duoming Zhou <duoming@zju.edu.cn>
Cc: linux-hams@vger.kernel.org, netdev@vger.kernel.org
Subject: Re: [PATCH v4] ax25: Fix refcount imbalance on inbound connections
Date: Thu, 23 May 2024 18:05:34 +0300 [thread overview]
Message-ID: <8fe7e2fe-3b73-45aa-b10c-23b592c6dd05@moroto.mountain> (raw)
In-Reply-To: <20240522183133.729159-2-lars@oddbit.com>
On Wed, May 22, 2024 at 02:31:34PM -0400, lars@oddbit.com wrote:
> From: Lars Kellogg-Stedman <lars@oddbit.com>
>
> When releasing a socket in ax25_release(), we call netdev_put() to
> decrease the refcount on the associated ax.25 device. However, the
> execution path for accepting an incoming connection never calls
> netdev_hold(). This imbalance leads to refcount errors, and ultimately
> to kernel crashes.
>
> A typical call trace for the above situation looks like this:
>
> Call Trace:
> <TASK>
> ? show_regs+0x64/0x70
> ? __warn+0x83/0x120
> ? refcount_warn_saturate+0xb2/0x100
> ? report_bug+0x158/0x190
> ? prb_read_valid+0x20/0x30
> ? handle_bug+0x3e/0x70
> ? exc_invalid_op+0x1c/0x70
> ? asm_exc_invalid_op+0x1f/0x30
> ? refcount_warn_saturate+0xb2/0x100
> ? refcount_warn_saturate+0xb2/0x100
> ax25_release+0x2ad/0x360
> __sock_release+0x35/0xa0
> sock_close+0x19/0x20
> [...]
>
> On reboot (or any attempt to remove the interface), the kernel gets
> stuck in an infinite loop:
>
> unregister_netdevice: waiting for ax0 to become free. Usage count = 0
>
> This patch corrects these issues by ensuring that we call netdev_hold()
> and ax25_dev_hold() for new connections in ax25_accept().
>
> Fixes: 7d8a3a477b ("ax25: Fix ax25 session cleanup problems")
I thought the fixes tag was:
Fixes: 9fd75b66b8f6 ("ax25: Fix refcount leaks caused by ax25_cb_del()")
I've already said that I don't think the patch is correct and offered
an alternative which takes a reference in accept() but also adds a
matching put()... But I can't really test my patch so if we're going to
do something that we know is wrong, I'd prefer to just revert Duoming's
patch.
regards,
dan carpenter
next prev parent reply other threads:[~2024-05-23 15:05 UTC|newest]
Thread overview: 15+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-05-22 18:31 [PATCH v4] ax25: Fix refcount imbalance on inbound connections lars
2024-05-23 15:05 ` Dan Carpenter [this message]
2024-05-23 15:22 ` Dan Cross
2024-05-23 18:23 ` Dan Carpenter
2024-05-23 20:39 ` Dan Cross
2024-05-24 15:25 ` Lars Kellogg-Stedman
2024-05-24 15:47 ` Dan Cross
2024-05-27 6:54 ` Dan Carpenter
2024-05-28 9:40 ` Paolo Abeni
2024-05-28 16:06 ` Lars Kellogg-Stedman
2024-05-29 14:34 ` Dan Carpenter
2024-05-29 14:54 ` Lars Kellogg-Stedman
2024-05-29 15:20 ` Dan Carpenter
2024-05-29 15:01 ` duoming
2024-05-29 15:22 ` Dan Carpenter
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=8fe7e2fe-3b73-45aa-b10c-23b592c6dd05@moroto.mountain \
--to=dan.carpenter@linaro.org \
--cc=duoming@zju.edu.cn \
--cc=lars@oddbit.com \
--cc=linux-hams@vger.kernel.org \
--cc=netdev@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox