Patch Detail
get:
Show a patch.
patch:
Update a patch.
put:
Update a patch.
GET /api/patches/807540/?format=api
{ "id": 807540, "url": "http://patchwork.ozlabs.org/api/patches/807540/?format=api", "web_url": "http://patchwork.ozlabs.org/project/netdev/patch/1504086545-7777-4-git-send-email-nikolay@cumulusnetworks.com/", "project": { "id": 7, "url": "http://patchwork.ozlabs.org/api/projects/7/?format=api", "name": "Linux network development", "link_name": "netdev", "list_id": "netdev.vger.kernel.org", "list_email": "netdev@vger.kernel.org", "web_url": null, "scm_url": null, "webscm_url": null, "list_archive_url": "", "list_archive_url_format": "", "commit_url_format": "" }, "msgid": "<1504086545-7777-4-git-send-email-nikolay@cumulusnetworks.com>", "list_archive_url": null, "date": "2017-08-30T09:48:59", "name": "[net,3/9] sch_hhf: fix null pointer dereference on init failure", "commit_ref": null, "pull_url": null, "state": "accepted", "archived": true, "hash": "cfa7a0ce715bcc74aff8dc6ee8a5280b319dbd76", "submitter": { "id": 66448, "url": "http://patchwork.ozlabs.org/api/people/66448/?format=api", "name": "Nikolay Aleksandrov", "email": "nikolay@cumulusnetworks.com" }, "delegate": { "id": 34, "url": "http://patchwork.ozlabs.org/api/users/34/?format=api", "username": "davem", "first_name": "David", "last_name": "Miller", "email": "davem@davemloft.net" }, "mbox": "http://patchwork.ozlabs.org/project/netdev/patch/1504086545-7777-4-git-send-email-nikolay@cumulusnetworks.com/mbox/", "series": [ { "id": 565, "url": "http://patchwork.ozlabs.org/api/series/565/?format=api", "web_url": "http://patchwork.ozlabs.org/project/netdev/list/?series=565", "date": "2017-08-30T09:48:56", "name": "net/sched: init failure fixes", "version": 1, "mbox": "http://patchwork.ozlabs.org/series/565/mbox/" } ], "comments": "http://patchwork.ozlabs.org/api/patches/807540/comments/", "check": "pending", "checks": "http://patchwork.ozlabs.org/api/patches/807540/checks/", "tags": {}, "related": [], "headers": { "Return-Path": "<netdev-owner@vger.kernel.org>", "X-Original-To": "patchwork-incoming@ozlabs.org", "Delivered-To": "patchwork-incoming@ozlabs.org", "Authentication-Results": [ "ozlabs.org;\n\tspf=none (mailfrom) smtp.mailfrom=vger.kernel.org\n\t(client-ip=209.132.180.67; helo=vger.kernel.org;\n\tenvelope-from=netdev-owner@vger.kernel.org;\n\treceiver=<UNKNOWN>)", "ozlabs.org; dkim=pass (1024-bit key;\n\tunprotected) header.d=cumulusnetworks.com\n\theader.i=@cumulusnetworks.com header.b=\"PNFx2mKM\"; \n\tdkim-atps=neutral" ], "Received": [ "from vger.kernel.org (vger.kernel.org [209.132.180.67])\n\tby ozlabs.org (Postfix) with ESMTP id 3xj11l6yC0z9t0F\n\tfor <patchwork-incoming@ozlabs.org>;\n\tWed, 30 Aug 2017 19:49:31 +1000 (AEST)", "(majordomo@vger.kernel.org) by vger.kernel.org via listexpand\n\tid S1751929AbdH3Jta (ORCPT <rfc822;patchwork-incoming@ozlabs.org>);\n\tWed, 30 Aug 2017 05:49:30 -0400", "from mail-wr0-f182.google.com ([209.85.128.182]:33271 \"EHLO\n\tmail-wr0-f182.google.com\" rhost-flags-OK-OK-OK-OK) by vger.kernel.org\n\twith ESMTP id S1751319AbdH3JtY (ORCPT\n\t<rfc822;netdev@vger.kernel.org>); Wed, 30 Aug 2017 05:49:24 -0400", "by mail-wr0-f182.google.com with SMTP id k94so16997911wrc.0\n\tfor <netdev@vger.kernel.org>; Wed, 30 Aug 2017 02:49:24 -0700 (PDT)", "from debil.mediahub-bg.com (46-10-142-144.ip.btc-net.bg.\n\t[46.10.142.144]) by smtp.gmail.com with ESMTPSA id\n\to206sm1113294wmo.10.2017.08.30.02.49.20\n\t(version=TLS1_2 cipher=ECDHE-RSA-AES128-SHA bits=128/128);\n\tWed, 30 Aug 2017 02:49:21 -0700 (PDT)" ], "DKIM-Signature": "v=1; a=rsa-sha256; c=relaxed/relaxed;\n\td=cumulusnetworks.com; s=google;\n\th=from:to:cc:subject:date:message-id:in-reply-to:references;\n\tbh=s+XW4TtkexVF+YJ+BgQQnu5URF0fTjiC7y9WOs3g03Y=;\n\tb=PNFx2mKMHRVXQZdaVkfB8c7z8MIWDI0E+xejcdqsZ2dXYCUvGsWeEnbk/pPGrKiszO\n\t1b1oOE9YJcQyaPHiFlt3Y43rj49382qnCu5ljBl4ZryrJPCKdt+QH1vLz6zB+QWRCq2/\n\tOXeSmwlncvAtq42sgSy37WiYPlvNS1BNoixyY=", "X-Google-DKIM-Signature": "v=1; a=rsa-sha256; c=relaxed/relaxed;\n\td=1e100.net; s=20161025;\n\th=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to\n\t:references;\n\tbh=s+XW4TtkexVF+YJ+BgQQnu5URF0fTjiC7y9WOs3g03Y=;\n\tb=fKsI8w2hPPZhxl7ucyNpOvP2A9oIgDYHCqILat5IoADoy5FVZukBMaI05ADDP19wwk\n\tgvBLJGgJzJf57/+pqdn60dKKU+2AFzzFxLZqxN5IeiRU+NTuoRpNzau4mR5tPBQFHpqD\n\tfSHgnwFpmQtvC4Q1KWj3Dig1eSwLTzq6FKzlITusjFjs61KQSozvK7rJCy901NZThwsU\n\twoJxXpVIag64DaLCtFxLSiRXy3NGIu3Jw8VMeb9xSl4SPT8WFkUNc0L3zTAgzAVFvkH1\n\tGMK9hNi/FrfjZYZNaNEimU8yzOLGN5SXAyWFUmDpYJspt9DIxrNW9+Lgykj3oR1MQkN9\n\ttwPA==", "X-Gm-Message-State": "AHYfb5gagFpaxFYrBQPx/6JcrIDqzNMivn93tQrlui7sFQtIHXtG2Xye\n\tr+YtjL09/9zUcy3a+Xo=", "X-Received": "by 10.223.131.130 with SMTP id 2mr679290wre.202.1504086562962;\n\tWed, 30 Aug 2017 02:49:22 -0700 (PDT)", "From": "Nikolay Aleksandrov <nikolay@cumulusnetworks.com>", "To": "netdev@vger.kernel.org", "Cc": "edumazet@google.com, jhs@mojatatu.com, xiyou.wangcong@gmail.com,\n\tjiri@resnulli.us, roopa@cumulusnetworks.com,\n\tNikolay Aleksandrov <nikolay@cumulusnetworks.com>", "Subject": "[PATCH net 3/9] sch_hhf: fix null pointer dereference on init\n\tfailure", "Date": "Wed, 30 Aug 2017 12:48:59 +0300", "Message-Id": "<1504086545-7777-4-git-send-email-nikolay@cumulusnetworks.com>", "X-Mailer": "git-send-email 2.1.4", "In-Reply-To": "<1504086545-7777-1-git-send-email-nikolay@cumulusnetworks.com>", "References": "<1504086545-7777-1-git-send-email-nikolay@cumulusnetworks.com>", "Sender": "netdev-owner@vger.kernel.org", "Precedence": "bulk", "List-ID": "<netdev.vger.kernel.org>", "X-Mailing-List": "netdev@vger.kernel.org" }, "content": "If sch_hhf fails in its ->init() function (either due to wrong\nuser-space arguments as below or memory alloc failure of hh_flows) it\nwill do a null pointer deref of q->hh_flows in its ->destroy() function.\n\nTo reproduce the crash:\n$ tc qdisc add dev eth0 root hhf quantum 2000000 non_hh_weight 10000000\n\nCrash log:\n[ 690.654882] BUG: unable to handle kernel NULL pointer dereference at (null)\n[ 690.655565] IP: hhf_destroy+0x48/0xbc\n[ 690.655944] PGD 37345067\n[ 690.655948] P4D 37345067\n[ 690.656252] PUD 58402067\n[ 690.656554] PMD 0\n[ 690.656857]\n[ 690.657362] Oops: 0000 [#1] SMP\n[ 690.657696] Modules linked in:\n[ 690.658032] CPU: 3 PID: 920 Comm: tc Not tainted 4.13.0-rc6+ #57\n[ 690.658525] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.7.5-20140531_083030-gandalf 04/01/2014\n[ 690.659255] task: ffff880058578000 task.stack: ffff88005acbc000\n[ 690.659747] RIP: 0010:hhf_destroy+0x48/0xbc\n[ 690.660146] RSP: 0018:ffff88005acbf9e0 EFLAGS: 00010246\n[ 690.660601] RAX: 0000000000000000 RBX: 0000000000000020 RCX: 0000000000000000\n[ 690.661155] RDX: 0000000000000000 RSI: 0000000000000001 RDI: ffffffff821f63f0\n[ 690.661710] RBP: ffff88005acbfa08 R08: ffffffff81b10a90 R09: 0000000000000000\n[ 690.662267] R10: 00000000f42b7019 R11: ffff880058578000 R12: 00000000ffffffea\n[ 690.662820] R13: ffff8800372f6400 R14: 0000000000000000 R15: 0000000000000000\n[ 690.663769] FS: 00007f8ae5e8b740(0000) GS:ffff88005d980000(0000) knlGS:0000000000000000\n[ 690.667069] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 690.667965] CR2: 0000000000000000 CR3: 0000000058523000 CR4: 00000000000406e0\n[ 690.668918] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n[ 690.669945] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n[ 690.671003] Call Trace:\n[ 690.671743] qdisc_create+0x377/0x3fd\n[ 690.672534] tc_modify_qdisc+0x4d2/0x4fd\n[ 690.673324] rtnetlink_rcv_msg+0x188/0x197\n[ 690.674204] ? rcu_read_unlock+0x3e/0x5f\n[ 690.675091] ? rtnl_newlink+0x729/0x729\n[ 690.675877] netlink_rcv_skb+0x6c/0xce\n[ 690.676648] rtnetlink_rcv+0x23/0x2a\n[ 690.677405] netlink_unicast+0x103/0x181\n[ 690.678179] netlink_sendmsg+0x326/0x337\n[ 690.678958] sock_sendmsg_nosec+0x14/0x3f\n[ 690.679743] sock_sendmsg+0x29/0x2e\n[ 690.680506] ___sys_sendmsg+0x209/0x28b\n[ 690.681283] ? __handle_mm_fault+0xc7d/0xdb1\n[ 690.681915] ? check_chain_key+0xb0/0xfd\n[ 690.682449] __sys_sendmsg+0x45/0x63\n[ 690.682954] ? __sys_sendmsg+0x45/0x63\n[ 690.683471] SyS_sendmsg+0x19/0x1b\n[ 690.683974] entry_SYSCALL_64_fastpath+0x23/0xc2\n[ 690.684516] RIP: 0033:0x7f8ae529d690\n[ 690.685016] RSP: 002b:00007fff26d2d6b8 EFLAGS: 00000246 ORIG_RAX: 000000000000002e\n[ 690.685931] RAX: ffffffffffffffda RBX: ffffffff810d278c RCX: 00007f8ae529d690\n[ 690.686573] RDX: 0000000000000000 RSI: 00007fff26d2d700 RDI: 0000000000000003\n[ 690.687047] RBP: ffff88005acbff98 R08: 0000000000000001 R09: 0000000000000000\n[ 690.687519] R10: 00007fff26d2d480 R11: 0000000000000246 R12: 0000000000000002\n[ 690.687996] R13: 0000000001258070 R14: 0000000000000001 R15: 0000000000000000\n[ 690.688475] ? trace_hardirqs_off_caller+0xa7/0xcf\n[ 690.688887] Code: 00 00 e8 2a 02 ae ff 49 8b bc 1d 60 02 00 00 48 83\nc3 08 e8 19 02 ae ff 48 83 fb 20 75 dc 45 31 f6 4d 89 f7 4d 03 bd 20 02\n00 00 <49> 8b 07 49 39 c7 75 24 49 83 c6 10 49 81 fe 00 40 00 00 75 e1\n[ 690.690200] RIP: hhf_destroy+0x48/0xbc RSP: ffff88005acbf9e0\n[ 690.690636] CR2: 0000000000000000\n\nFixes: 87b60cfacf9f (\"net_sched: fix error recovery at qdisc creation\")\nFixes: 10239edf86f1 (\"net-qdisc-hhf: Heavy-Hitter Filter (HHF) qdisc\")\nSigned-off-by: Nikolay Aleksandrov <nikolay@cumulusnetworks.com>\n---\n net/sched/sch_hhf.c | 3 +++\n 1 file changed, 3 insertions(+)", "diff": "diff --git a/net/sched/sch_hhf.c b/net/sched/sch_hhf.c\nindex 51d3ba682af9..73a53c08091b 100644\n--- a/net/sched/sch_hhf.c\n+++ b/net/sched/sch_hhf.c\n@@ -477,6 +477,9 @@ static void hhf_destroy(struct Qdisc *sch)\n \t\tkvfree(q->hhf_valid_bits[i]);\n \t}\n \n+\tif (!q->hh_flows)\n+\t\treturn;\n+\n \tfor (i = 0; i < HH_FLOWS_CNT; i++) {\n \t\tstruct hh_flow_state *flow, *next;\n \t\tstruct list_head *head = &q->hh_flows[i];\n", "prefixes": [ "net", "3/9" ] }