* ipset causing a kernel crash
@ 2013-09-09 8:00 Yoann Juet
2013-09-09 10:51 ` Jozsef Kadlecsik
0 siblings, 1 reply; 5+ messages in thread
From: Yoann Juet @ 2013-09-09 8:00 UTC (permalink / raw)
To: netfilter
[-- Attachment #1.1: Type: text/plain, Size: 459 bytes --]
Hi all,
We've experienced a recent kernel crash on a captive portal server
running debian/wheezy with a standard kernel 3.2.0-4. The crash seems to
be related to ipset that we're using to check bitmaps {ip,mac}. It has
not been seen before on this production server.
Thanks for your help,
Regards,
--
Université de Nantes - Direction des Systèmes d'Information
IM jabber: yoann.juet@univ-nantes.fr
Tél: 02.53.48.49.26 - Fax: 02.53.48.49.09
[-- Attachment #1.2: bug.txt --]
[-- Type: text/plain, Size: 9193 bytes --]
Sep 8 21:04:01 p1 kernel: [1245305.746885] ------------[ cut here ]------------
Sep 8 21:04:01 p1 kernel: [1245305.747344] kernel BUG at /build/linux-s5x2oE/linux-3.2.46/net/netfilter/ipset/ip_set_core.c:317!
Sep 8 21:04:01 p1 kernel: [1245305.748212] invalid opcode: 0000 [#1] SMP
Sep 8 21:04:01 p1 kernel: [1245305.748623] CPU 2
Sep 8 21:04:01 p1 kernel: [1245305.748697] Modules linked in: ip_vs crc32c libcrc32c ipt_LOG xt_set ip_set_bitmap_ipmac ip_set nfnetlink xt_TPROXY nf_tproxy_core xt_socket ipt_REDIRECT xt_mark xt_tcpudp xt_limit xt_state ip6table_filter ip6_tables iptable_mangle iptable_filter nf_nat_ftp iptable_nat nf_nat nf_conntrack_irc nf_conntrack_ftp nf_conntrack_ipv4 nf_defrag_ipv4 ip_tables x_tables ext2 mbcache nf_conntrack_ipv6 nf_defrag_ipv6 nf_conntrack psmouse snd_pcm snd_page_alloc evdev i2c_piix4 serio_raw virtio_balloon i2c_core processor snd_timer snd soundcore pcspkr thermal_sys button xfs dm_mod ata_generic virtio_blk virtio_net floppy ata_piix libata uhci_hcd ehci_hcd scsi_mod virtio_pci virtio_ring virtio usbcore usb_common [last unloaded: scsi_wait_scan]
Sep 8 21:04:01 p1 kernel: [1245305.749268]
Sep 8 21:04:01 p1 kernel: [1245305.749268] Pid: 29834, comm: ipset Not tainted 3.2.0-4-amd64 #1 Debian 3.2.46-1 Bochs Bochs
Sep 8 21:04:01 p1 kernel: [1245305.749268] RIP: 0010:[<ffffffffa02a1087>] [<ffffffffa02a1087>] ip_set_put_byindex+0x30/0x46 [ip_set]
Sep 8 21:04:01 p1 kernel: [1245305.749268] RSP: 0018:ffff8800d799fa38 EFLAGS: 00010246
Sep 8 21:04:01 p1 kernel: [1245305.749268] RAX: ffff8801188627c0 RBX: 0000000000000000 RCX: 0000000000000002
Sep 8 21:04:01 p1 kernel: [1245305.749268] RDX: 0000000000000000 RSI: 0000000000000016 RDI: ffffffffa02a5034
Sep 8 21:04:01 p1 kernel: [1245305.749268] RBP: ffff8801152f6c00 R08: 0000000000000004 R09: 0000000000000002
Sep 8 21:04:01 p1 kernel: [1245305.749268] R10: 0000000000000246 R11: 0000000000000246 R12: ffff8800bfc0f580
Sep 8 21:04:01 p1 kernel: [1245305.749268] R13: 0000000000000e80 R14: ffff8801149956c0 R15: ffff8800d799fae0
Sep 8 21:04:01 p1 kernel: [1245305.749268] FS: 00007f437895b700(0000) GS:ffff88011fd00000(0000) knlGS:0000000000000000
Sep 8 21:04:01 p1 kernel: [1245305.749268] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
Sep 8 21:04:01 p1 kernel: [1245305.749268] CR2: 00007f4378536cb0 CR3: 00000000cd4aa000 CR4: 00000000000006e0
Sep 8 21:04:01 p1 kernel: [1245305.749268] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
Sep 8 21:04:01 p1 kernel: [1245305.749268] DR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000400
Sep 8 21:04:01 p1 kernel: [1245305.749268] Process ipset (pid: 29834, threadinfo ffff8800d799e000, task ffff880117ccea70)
Sep 8 21:04:01 p1 kernel: [1245305.749268] Stack:
Sep 8 21:04:01 p1 kernel: [1245305.749268] ffff8801149956c0 ffffffffa02a10ae 0000000000000002 ffffffff812ad5bd
Sep 8 21:04:01 p1 kernel: [1245305.749268] ffffffff810364e8 ffffffa68134d81c 0000000000000246 ffff8801152f6c00
Sep 8 21:04:01 p1 kernel: [1245305.749268] ffff8801179da400 ffff8800c0e20e00 ffffffffa02a10b2 ffffffff812adf7d
Sep 8 21:04:01 p1 kernel: [1245305.749268] Call Trace:
Sep 8 21:04:01 p1 kernel: [1245305.749268] [<ffffffffa02a10ae>] ? ip_set_dump_done+0x11/0x15 [ip_set]
Sep 8 21:04:01 p1 kernel: [1245305.749268] [<ffffffff812ad5bd>] ? netlink_dump+0x16f/0x1ce
Sep 8 21:04:01 p1 kernel: [1245305.749268] [<ffffffff810364e8>] ? should_resched+0x5/0x23
Sep 8 21:04:01 p1 kernel: [1245305.749268] [<ffffffffa02a10b2>] ? ip_set_dump_done+0x15/0x15 [ip_set]
Sep 8 21:04:01 p1 kernel: [1245305.749268] [<ffffffff812adf7d>] ? netlink_dump_start+0xf1/0x118
Sep 8 21:04:01 p1 kernel: [1245305.749268] [<ffffffffa02a109d>] ? ip_set_put_byindex+0x46/0x46 [ip_set]
Sep 8 21:04:01 p1 kernel: [1245305.749268] [<ffffffffa02972ac>] ? nfnetlink_rcv_msg+0x1b6/0x1fe [nfnetlink]
Sep 8 21:04:01 p1 kernel: [1245305.749268] [<ffffffffa029712e>] ? nfnetlink_rcv_msg+0x38/0x1fe [nfnetlink]
Sep 8 21:04:01 p1 kernel: [1245305.749268] [<ffffffffa02970f6>] ? nfnl_lock+0xc/0xc [nfnetlink]
Sep 8 21:04:01 p1 kernel: [1245305.749268] [<ffffffff812af559>] ? netlink_rcv_skb+0x36/0x7a
Sep 8 21:04:01 p1 kernel: [1245305.749268] [<ffffffff812af090>] ? netlink_unicast+0xe6/0x14e
Sep 8 21:04:01 p1 kernel: [1245305.749268] [<ffffffff812af36c>] ? netlink_sendmsg+0x274/0x2ac
Sep 8 21:04:01 p1 kernel: [1245305.749268] [<ffffffff810364e8>] ? should_resched+0x5/0x23
Sep 8 21:04:01 p1 kernel: [1245305.749268] [<ffffffff8127e831>] ? sock_sendmsg+0xc1/0xde
Sep 8 21:04:01 p1 kernel: [1245305.749268] [<ffffffff810f267c>] ? mem_cgroup_update_page_stat+0x17/0xd4
Sep 8 21:04:01 p1 kernel: [1245305.749268] [<ffffffff810d0c6b>] ? handle_pte_fault+0x298/0x79f
Sep 8 21:04:01 p1 kernel: [1245305.749268] [<ffffffff810364e8>] ? should_resched+0x5/0x23
Sep 8 21:04:01 p1 kernel: [1245305.749268] [<ffffffff8134d81c>] ? _cond_resched+0x7/0x1c
Sep 8 21:04:01 p1 kernel: [1245305.749268] [<ffffffff8127d27f>] ? copy_from_user+0x18/0x30
Sep 8 21:04:01 p1 kernel: [1245305.749268] [<ffffffff812800c7>] ? sys_sendto+0xf7/0x137
Sep 8 21:04:01 p1 kernel: [1245305.749268] [<ffffffff810fb5b2>] ? fget_light+0x2e/0x7b
Sep 8 21:04:01 p1 kernel: [1245305.749268] [<ffffffff81353b52>] ? system_call_fastpath+0x16/0x1b
Sep 8 21:04:01 p1 kernel: [1245305.749268] Code: 00 00 53 0f b7 df 48 83 3c d8 00 74 32 48 c7 c7 34 50 2a a0 e8 f0 db 0a e1 48 8b 05 84 42 00 00 48 8b 04 d8 8b 50 24 85 d2 75 02 <0f> 0b ff ca 48 c7 c7 34 50 2a a0 89 50 24 5b e9 a2 db 0a e1 5b
Sep 8 21:04:01 p1 kernel: [1245305.749268] RIP [<ffffffffa02a1087>] ip_set_put_byindex+0x30/0x46 [ip_set]
Sep 8 21:04:01 p1 kernel: [1245305.749268] RSP <ffff8800d799fa38>
Sep 8 21:04:01 p1 kernel: [1245305.783960] ---[ end trace cf0b8013a04e3016 ]---
Sep 8 21:04:01 p1 kernel: [1245305.784351] Kernel panic - not syncing: Fatal exception in interrupt
Sep 8 21:04:01 p1 kernel: [1245305.784739] Pid: 29834, comm: ipset Tainted: G D 3.2.0-4-amd64 #1 Debian 3.2.46-1
Sep 8 21:04:01 p1 kernel: [1245305.785471] Call Trace:
Sep 8 21:04:01 p1 kernel: [1245305.785836] [<ffffffff813481ed>] ? panic+0x95/0x1a2
Sep 8 21:04:01 p1 kernel: [1245305.786190] [<ffffffff8134eb77>] ? _raw_spin_unlock_irqrestore+0xe/0xf
Sep 8 21:04:01 p1 kernel: [1245305.786732] [<ffffffff8134f986>] ? oops_end+0xa9/0xb6
Sep 8 21:04:01 p1 kernel: [1245305.787252] [<ffffffff8100e961>] ? do_invalid_op+0x87/0x91
Sep 8 21:04:01 p1 kernel: [1245305.787673] [<ffffffffa02a1087>] ? ip_set_put_byindex+0x30/0x46 [ip_set]
Sep 8 21:04:01 p1 kernel: [1245305.788167] [<ffffffff811bf17c>] ? __nla_put+0xd/0x20
Sep 8 21:04:01 p1 kernel: [1245305.788604] [<ffffffff811bf1bf>] ? nla_put+0x30/0x34
Sep 8 21:04:01 p1 kernel: [1245305.789044] [<ffffffffa02ad7b9>] ? bitmap_ipmac_tlist+0x1ed/0x216 [ip_set_bitmap_ipmac]
Sep 8 21:04:01 p1 kernel: [1245305.789725] [<ffffffff81355b2b>] ? invalid_op+0x1b/0x20
Sep 8 21:04:01 p1 kernel: [1245305.790105] [<ffffffffa02a1087>] ? ip_set_put_byindex+0x30/0x46 [ip_set]
Sep 8 21:04:01 p1 kernel: [1245305.790597] [<ffffffffa02a1075>] ? ip_set_put_byindex+0x1e/0x46 [ip_set]
Sep 8 21:04:01 p1 kernel: [1245305.791107] [<ffffffffa02a10ae>] ? ip_set_dump_done+0x11/0x15 [ip_set]
Sep 8 21:04:01 p1 kernel: [1245305.791760] [<ffffffff812ad5bd>] ? netlink_dump+0x16f/0x1ce
Sep 8 21:04:01 p1 kernel: [1245305.792559] [<ffffffff810364e8>] ? should_resched+0x5/0x23
Sep 8 21:04:01 p1 kernel: [1245305.793085] [<ffffffffa02a10b2>] ? ip_set_dump_done+0x15/0x15 [ip_set]
Sep 8 21:04:01 p1 kernel: [1245305.793480] [<ffffffff812adf7d>] ? netlink_dump_start+0xf1/0x118
Sep 8 21:04:01 p1 kernel: [1245305.793885] [<ffffffffa02a109d>] ? ip_set_put_byindex+0x46/0x46 [ip_set]
Sep 8 21:04:01 p1 kernel: [1245305.794299] [<ffffffffa02972ac>] ? nfnetlink_rcv_msg+0x1b6/0x1fe [nfnetlink]
Sep 8 21:04:01 p1 kernel: [1245305.794972] [<ffffffffa029712e>] ? nfnetlink_rcv_msg+0x38/0x1fe [nfnetlink]
Sep 8 21:04:01 p1 kernel: [1245305.795571] [<ffffffffa02970f6>] ? nfnl_lock+0xc/0xc [nfnetlink]
Sep 8 21:04:01 p1 kernel: [1245305.796036] [<ffffffff812af559>] ? netlink_rcv_skb+0x36/0x7a
Sep 8 21:04:01 p1 kernel: [1245305.796484] [<ffffffff812af090>] ? netlink_unicast+0xe6/0x14e
Sep 8 21:04:01 p1 kernel: [1245305.796899] [<ffffffff812af36c>] ? netlink_sendmsg+0x274/0x2ac
Sep 8 21:04:01 p1 kernel: [1245305.797279] [<ffffffff810364e8>] ? should_resched+0x5/0x23
Sep 8 21:04:01 p1 kernel: [1245305.797738] [<ffffffff8127e831>] ? sock_sendmsg+0xc1/0xde
Sep 8 21:04:01 p1 kernel: [1245305.798113] [<ffffffff810f267c>] ? mem_cgroup_update_page_stat+0x17/0xd4
Sep 8 21:04:01 p1 kernel: [1245305.798503] [<ffffffff810d0c6b>] ? handle_pte_fault+0x298/0x79f
Sep 8 21:04:01 p1 kernel: [1245305.798943] [<ffffffff810364e8>] ? should_resched+0x5/0x23
Sep 8 21:04:01 p1 kernel: [1245305.799331] [<ffffffff8134d81c>] ? _cond_resched+0x7/0x1c
Sep 8 21:04:01 p1 kernel: [1245305.799734] [<ffffffff8127d27f>] ? copy_from_user+0x18/0x30
Sep 8 21:04:01 p1 kernel: [1245305.800149] [<ffffffff812800c7>] ? sys_sendto+0xf7/0x137
[-- Attachment #1.3: yoann_juet.vcf --]
[-- Type: text/x-vcard, Size: 377 bytes --]
begin:vcard
fn:Yoann Juet
n:Juet;Yoann
org;quoted-printable;quoted-printable:Direction des Syst=C3=A8mes d'Information;P=C3=B4le R=C3=A9seau
adr;quoted-printable:BP 92208;;2 rue de la Houssini=C3=A8re;Nantes Cedex 3;;44322;France
email;internet:yoann.juet@univ-nantes.fr
tel;work:02.53.48.49.26
tel;fax:02.53.48.49.09
tel;cell:06.73.15.42.19
version:2.1
end:vcard
[-- Attachment #2: S/MIME Cryptographic Signature --]
[-- Type: application/pkcs7-signature, Size: 3256 bytes --]
^ permalink raw reply [flat|nested] 5+ messages in thread* Re: ipset causing a kernel crash 2013-09-09 8:00 ipset causing a kernel crash Yoann Juet @ 2013-09-09 10:51 ` Jozsef Kadlecsik 2013-09-09 13:06 ` Yoann Juet 0 siblings, 1 reply; 5+ messages in thread From: Jozsef Kadlecsik @ 2013-09-09 10:51 UTC (permalink / raw) To: Yoann Juet; +Cc: netfilter On Mon, 9 Sep 2013, Yoann Juet wrote: > We've experienced a recent kernel crash on a captive portal server running > debian/wheezy with a standard kernel 3.2.0-4. The crash seems to be related to > ipset that we're using to check bitmaps {ip,mac}. It has not been seen before > on this production server. A cleanup part is missing for the bitmap:ip,mac type with timeout in the 3.2 kernel tree: diff --git a/net/netfilter/ipset/ip_set_bitmap_ipmac.c b/net/netfilter/ipset/ip_set_bitmap_ipmac.c index 56096f5..725e431 100644 --- a/net/netfilter/ipset/ip_set_bitmap_ipmac.c +++ b/net/netfilter/ipset/ip_set_bitmap_ipmac.c @@ -333,7 +333,11 @@ bitmap_ipmac_tlist(const struct ip_set *set, nla_put_failure: nla_nest_cancel(skb, nested); ipset_nest_end(skb, atd); - return -EMSGSIZE; + if (unlikely(id == first)) { + cb->args[2] = 0; + return -EMSGSIZE; + } + return 0; } static int However, the missing part caused incomplete listing only. This case seems to be different. So does the patch above help? Best regards, Jozsef - E-mail : kadlec@blackhole.kfki.hu, kadlecsik.jozsef@wigner.mta.hu PGP key : http://www.kfki.hu/~kadlec/pgp_public_key.txt Address : Wigner Research Centre for Physics, Hungarian Academy of Sciences H-1525 Budapest 114, POB. 49, Hungary ^ permalink raw reply related [flat|nested] 5+ messages in thread
* Re: ipset causing a kernel crash 2013-09-09 10:51 ` Jozsef Kadlecsik @ 2013-09-09 13:06 ` Yoann Juet 2013-09-09 16:23 ` Jozsef Kadlecsik 0 siblings, 1 reply; 5+ messages in thread From: Yoann Juet @ 2013-09-09 13:06 UTC (permalink / raw) To: Jozsef Kadlecsik; +Cc: netfilter [-- Attachment #1.1: Type: text/plain, Size: 1682 bytes --] On 09/09/13 12:51, Jozsef Kadlecsik wrote: > On Mon, 9 Sep 2013, Yoann Juet wrote: > >> We've experienced a recent kernel crash on a captive portal server running >> debian/wheezy with a standard kernel 3.2.0-4. The crash seems to be related to >> ipset that we're using to check bitmaps {ip,mac}. It has not been seen before >> on this production server. > > A cleanup part is missing for the bitmap:ip,mac type with timeout in the > 3.2 kernel tree: > > diff --git a/net/netfilter/ipset/ip_set_bitmap_ipmac.c b/net/netfilter/ipset/ip_set_bitmap_ipmac.c > index 56096f5..725e431 100644 > --- a/net/netfilter/ipset/ip_set_bitmap_ipmac.c > +++ b/net/netfilter/ipset/ip_set_bitmap_ipmac.c > @@ -333,7 +333,11 @@ bitmap_ipmac_tlist(const struct ip_set *set, > nla_put_failure: > nla_nest_cancel(skb, nested); > ipset_nest_end(skb, atd); > - return -EMSGSIZE; > + if (unlikely(id == first)) { > + cb->args[2] = 0; > + return -EMSGSIZE; > + } > + return 0; > } > > static int > > However, the missing part caused incomplete listing only. This case seems > to be different. So does the patch above help? > > Best regards, > Jozsef > - > E-mail : kadlec@blackhole.kfki.hu, kadlecsik.jozsef@wigner.mta.hu > PGP key : http://www.kfki.hu/~kadlec/pgp_public_key.txt > Address : Wigner Research Centre for Physics, Hungarian Academy of Sciences > H-1525 Budapest 114, POB. 49, Hungary > I'll make a try. I keep you in touch if the crash re-appears. Thanks Jozsef, Regards -- Université de Nantes - Direction des Systèmes d'Information IM jabber: yoann.juet@univ-nantes.fr Tél: 02.53.48.49.26 - Fax: 02.53.48.49.09 [-- Attachment #1.2: yoann_juet.vcf --] [-- Type: text/x-vcard, Size: 377 bytes --] begin:vcard fn:Yoann Juet n:Juet;Yoann org;quoted-printable;quoted-printable:Direction des Syst=C3=A8mes d'Information;P=C3=B4le R=C3=A9seau adr;quoted-printable:BP 92208;;2 rue de la Houssini=C3=A8re;Nantes Cedex 3;;44322;France email;internet:yoann.juet@univ-nantes.fr tel;work:02.53.48.49.26 tel;fax:02.53.48.49.09 tel;cell:06.73.15.42.19 version:2.1 end:vcard [-- Attachment #2: S/MIME Cryptographic Signature --] [-- Type: application/pkcs7-signature, Size: 3256 bytes --] ^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: ipset causing a kernel crash 2013-09-09 13:06 ` Yoann Juet @ 2013-09-09 16:23 ` Jozsef Kadlecsik 2013-09-11 6:04 ` Yoann Juet 0 siblings, 1 reply; 5+ messages in thread From: Jozsef Kadlecsik @ 2013-09-09 16:23 UTC (permalink / raw) To: Yoann Juet; +Cc: netfilter On Mon, 9 Sep 2013, Yoann Juet wrote: > On 09/09/13 12:51, Jozsef Kadlecsik wrote: > > On Mon, 9 Sep 2013, Yoann Juet wrote: > > > > > We've experienced a recent kernel crash on a captive portal server running > > > debian/wheezy with a standard kernel 3.2.0-4. The crash seems to be > > > related to > > > ipset that we're using to check bitmaps {ip,mac}. It has not been seen > > > before > > > on this production server. > > > > A cleanup part is missing for the bitmap:ip,mac type with timeout in the > > 3.2 kernel tree: > > > > diff --git a/net/netfilter/ipset/ip_set_bitmap_ipmac.c > > b/net/netfilter/ipset/ip_set_bitmap_ipmac.c > > index 56096f5..725e431 100644 > > --- a/net/netfilter/ipset/ip_set_bitmap_ipmac.c > > +++ b/net/netfilter/ipset/ip_set_bitmap_ipmac.c > > @@ -333,7 +333,11 @@ bitmap_ipmac_tlist(const struct ip_set *set, > > nla_put_failure: > > nla_nest_cancel(skb, nested); > > ipset_nest_end(skb, atd); > > - return -EMSGSIZE; > > + if (unlikely(id == first)) { > > + cb->args[2] = 0; > > + return -EMSGSIZE; > > + } > > + return 0; > > } > > > > static int > > > > However, the missing part caused incomplete listing only. This case seems > > to be different. So does the patch above help? > > I'll make a try. I keep you in touch if the crash re-appears. Re-checking again, you need the next patch: diff --git a/kernel/net/netfilter/ipset/ip_set_core.c b/kernel/net/netfilter/ipset/ip_set_core.c index b5d380c..c3eabfd 100644 --- a/kernel/net/netfilter/ipset/ip_set_core.c +++ b/kernel/net/netfilter/ipset/ip_set_core.c @@ -1148,6 +1148,7 @@ release_refcount: if (ret || !cb->args[2]) { pr_debug("release set %s\n", ip_set_list[index]->name); ip_set_put_byindex(index); + cb->args[2] = 0; } out: if (nlh) { Best regards, Jozsef - E-mail : kadlec@blackhole.kfki.hu, kadlecsik.jozsef@wigner.mta.hu PGP key : http://www.kfki.hu/~kadlec/pgp_public_key.txt Address : Wigner Research Centre for Physics, Hungarian Academy of Sciences H-1525 Budapest 114, POB. 49, Hungary ^ permalink raw reply related [flat|nested] 5+ messages in thread
* Re: ipset causing a kernel crash 2013-09-09 16:23 ` Jozsef Kadlecsik @ 2013-09-11 6:04 ` Yoann Juet 0 siblings, 0 replies; 5+ messages in thread From: Yoann Juet @ 2013-09-11 6:04 UTC (permalink / raw) To: Jozsef Kadlecsik; +Cc: netfilter [-- Attachment #1.1: Type: text/plain, Size: 2739 bytes --] On 09/09/13 18:23, Jozsef Kadlecsik wrote: > On Mon, 9 Sep 2013, Yoann Juet wrote: > >> On 09/09/13 12:51, Jozsef Kadlecsik wrote: >>> On Mon, 9 Sep 2013, Yoann Juet wrote: >>> >>>> We've experienced a recent kernel crash on a captive portal server running >>>> debian/wheezy with a standard kernel 3.2.0-4. The crash seems to be >>>> related to >>>> ipset that we're using to check bitmaps {ip,mac}. It has not been seen >>>> before >>>> on this production server. >>> >>> A cleanup part is missing for the bitmap:ip,mac type with timeout in the >>> 3.2 kernel tree: >>> >>> diff --git a/net/netfilter/ipset/ip_set_bitmap_ipmac.c >>> b/net/netfilter/ipset/ip_set_bitmap_ipmac.c >>> index 56096f5..725e431 100644 >>> --- a/net/netfilter/ipset/ip_set_bitmap_ipmac.c >>> +++ b/net/netfilter/ipset/ip_set_bitmap_ipmac.c >>> @@ -333,7 +333,11 @@ bitmap_ipmac_tlist(const struct ip_set *set, >>> nla_put_failure: >>> nla_nest_cancel(skb, nested); >>> ipset_nest_end(skb, atd); >>> - return -EMSGSIZE; >>> + if (unlikely(id == first)) { >>> + cb->args[2] = 0; >>> + return -EMSGSIZE; >>> + } >>> + return 0; >>> } >>> >>> static int >>> >>> However, the missing part caused incomplete listing only. This case seems >>> to be different. So does the patch above help? >> >> I'll make a try. I keep you in touch if the crash re-appears. > > Re-checking again, you need the next patch: > > diff --git a/kernel/net/netfilter/ipset/ip_set_core.c b/kernel/net/netfilter/ipset/ip_set_core.c > index b5d380c..c3eabfd 100644 > --- a/kernel/net/netfilter/ipset/ip_set_core.c > +++ b/kernel/net/netfilter/ipset/ip_set_core.c > @@ -1148,6 +1148,7 @@ release_refcount: > if (ret || !cb->args[2]) { > pr_debug("release set %s\n", ip_set_list[index]->name); > ip_set_put_byindex(index); > + cb->args[2] = 0; > } > out: > if (nlh) { > > Best regards, > Jozsef > - > E-mail : kadlec@blackhole.kfki.hu, kadlecsik.jozsef@wigner.mta.hu > PGP key : http://www.kfki.hu/~kadlec/pgp_public_key.txt > Address : Wigner Research Centre for Physics, Hungarian Academy of Sciences > H-1525 Budapest 114, POB. 49, Hungary > -- > To unsubscribe from this list: send the line "unsubscribe netfilter" in > the body of a message to majordomo@vger.kernel.org > More majordomo info at http://vger.kernel.org/majordomo-info.html > You've found the solution. I also made a try with a kernel 3.10 that implements this patch. All is ok under load, no more crash. Thank you for your precious help, Best regards, -- Université de Nantes - Direction des Systèmes d'Information IM jabber: yoann.juet@univ-nantes.fr Tél: 02.53.48.49.26 - Fax: 02.53.48.49.09 [-- Attachment #1.2: yoann_juet.vcf --] [-- Type: text/x-vcard, Size: 377 bytes --] begin:vcard fn:Yoann Juet n:Juet;Yoann org;quoted-printable;quoted-printable:Direction des Syst=C3=A8mes d'Information;P=C3=B4le R=C3=A9seau adr;quoted-printable:BP 92208;;2 rue de la Houssini=C3=A8re;Nantes Cedex 3;;44322;France email;internet:yoann.juet@univ-nantes.fr tel;work:02.53.48.49.26 tel;fax:02.53.48.49.09 tel;cell:06.73.15.42.19 version:2.1 end:vcard [-- Attachment #2: S/MIME Cryptographic Signature --] [-- Type: application/pkcs7-signature, Size: 3256 bytes --] ^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2013-09-11 6:04 UTC | newest] Thread overview: 5+ messages (download: mbox.gz follow: Atom feed -- links below jump to the message on this page -- 2013-09-09 8:00 ipset causing a kernel crash Yoann Juet 2013-09-09 10:51 ` Jozsef Kadlecsik 2013-09-09 13:06 ` Yoann Juet 2013-09-09 16:23 ` Jozsef Kadlecsik 2013-09-11 6:04 ` Yoann Juet
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox