{"id":807542,"url":"http://patchwork.ozlabs.org/api/1.0/patches/807542/?format=json","project":{"id":7,"url":"http://patchwork.ozlabs.org/api/1.0/projects/7/?format=json","name":"Linux network development","link_name":"netdev","list_id":"netdev.vger.kernel.org","list_email":"netdev@vger.kernel.org","web_url":null,"scm_url":null,"webscm_url":null},"msgid":"<1504086545-7777-10-git-send-email-nikolay@cumulusnetworks.com>","date":"2017-08-30T09:49:05","name":"[net,9/9] sch_tbf: fix two null pointer dereferences on init failure","commit_ref":null,"pull_url":null,"state":"accepted","archived":true,"hash":"d0baef1632e53bac677ea0c174b8769c8162de0b","submitter":{"id":66448,"url":"http://patchwork.ozlabs.org/api/1.0/people/66448/?format=json","name":"Nikolay Aleksandrov","email":"nikolay@cumulusnetworks.com"},"delegate":{"id":34,"url":"http://patchwork.ozlabs.org/api/1.0/users/34/?format=json","username":"davem","first_name":"David","last_name":"Miller","email":"davem@davemloft.net"},"mbox":"http://patchwork.ozlabs.org/project/netdev/patch/1504086545-7777-10-git-send-email-nikolay@cumulusnetworks.com/mbox/","series":[{"id":565,"url":"http://patchwork.ozlabs.org/api/1.0/series/565/?format=json","date":"2017-08-30T09:48:56","name":"net/sched: init failure fixes","version":1,"mbox":"http://patchwork.ozlabs.org/series/565/mbox/"}],"check":"pending","checks":"http://patchwork.ozlabs.org/api/patches/807542/checks/","tags":{},"headers":{"Return-Path":"<netdev-owner@vger.kernel.org>","X-Original-To":"patchwork-incoming@ozlabs.org","Delivered-To":"patchwork-incoming@ozlabs.org","Authentication-Results":["ozlabs.org;\n\tspf=none (mailfrom) smtp.mailfrom=vger.kernel.org\n\t(client-ip=209.132.180.67; helo=vger.kernel.org;\n\tenvelope-from=netdev-owner@vger.kernel.org;\n\treceiver=<UNKNOWN>)","ozlabs.org; dkim=pass (1024-bit key;\n\tunprotected) header.d=cumulusnetworks.com\n\theader.i=@cumulusnetworks.com header.b=\"VXtG00nj\"; \n\tdkim-atps=neutral"],"Received":["from vger.kernel.org (vger.kernel.org [209.132.180.67])\n\tby ozlabs.org (Postfix) with ESMTP id 3xj11v1GlMz9sNn\n\tfor <patchwork-incoming@ozlabs.org>;\n\tWed, 30 Aug 2017 19:49:39 +1000 (AEST)","(majordomo@vger.kernel.org) by vger.kernel.org via listexpand\n\tid S1751947AbdH3Jth (ORCPT <rfc822;patchwork-incoming@ozlabs.org>);\n\tWed, 30 Aug 2017 05:49:37 -0400","from mail-wr0-f179.google.com ([209.85.128.179]:37516 \"EHLO\n\tmail-wr0-f179.google.com\" rhost-flags-OK-OK-OK-OK) by vger.kernel.org\n\twith ESMTP id S1751944AbdH3Jte (ORCPT\n\t<rfc822;netdev@vger.kernel.org>); Wed, 30 Aug 2017 05:49:34 -0400","by mail-wr0-f179.google.com with SMTP id k9so4664072wre.4\n\tfor <netdev@vger.kernel.org>; Wed, 30 Aug 2017 02:49:33 -0700 (PDT)","from debil.mediahub-bg.com (46-10-142-144.ip.btc-net.bg.\n\t[46.10.142.144]) by smtp.gmail.com with ESMTPSA id\n\to206sm1113294wmo.10.2017.08.30.02.49.30\n\t(version=TLS1_2 cipher=ECDHE-RSA-AES128-SHA bits=128/128);\n\tWed, 30 Aug 2017 02:49:31 -0700 (PDT)"],"DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed;\n\td=cumulusnetworks.com; s=google;\n\th=from:to:cc:subject:date:message-id:in-reply-to:references;\n\tbh=HSzA/bvJY/hmPfXDxIhI5rP08iz9sAPmxHkD0j4b3f0=;\n\tb=VXtG00njT4RJ/yHf2vCQRFPxJU/q1M+H4zr07PN3LYFQY7/5OIF/CJDAuP0lE1e4LM\n\tT22nWE6n8LtYgkDSWqbYgdXUjUa88lRWVdc2BdS4z5whY7CF7zwgCwfNAhS4Wz5um5VO\n\tppSb6GE8DcKrCZ83vA4Uz1KuOkEhOWKxa0DqA=","X-Google-DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed;\n\td=1e100.net; s=20161025;\n\th=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to\n\t:references;\n\tbh=HSzA/bvJY/hmPfXDxIhI5rP08iz9sAPmxHkD0j4b3f0=;\n\tb=tWcEqJoxUXX2ksiS4OSFFDbZcVTNISh82oH3jErZX4IB/gJwmZSkC7ORfvzO6WCtQa\n\t2SNsWfl0zQVg25nIRhPGeLXYcQaRESPoQZ0f2NkP/xIzaIH5/5wyV65sFTRBnLtL9jRQ\n\tbe4+flNC3PoA5fSbj1Oug7s2D37xI4A7HRLPMYW2g3gsdeXbkTKV24fN+U2h6kDaSmLq\n\tINR+3sE3+YjqOIl7Gp/PpPVxMKhLMd39Ntb71XubA/8hZ0jLtgZMkp/0fCci6AZEOqm5\n\tXOYtPGjl8kOzezYuhAejzQ2aXP2yr4kmCm3t1qvZrcQrudwjw1WwHQzTpPwS1I8GpV1W\n\tu0yQ==","X-Gm-Message-State":"AHYfb5jss6VfPA2YONoSnYs3OhVOznDS7OTHbO7wtrXj/CW3DkH3Btz2\n\t83rcMkDxbOdQ1LxZqUA=","X-Received":"by 10.223.131.130 with SMTP id 2mr679581wre.202.1504086572337;\n\tWed, 30 Aug 2017 02:49:32 -0700 (PDT)","From":"Nikolay Aleksandrov <nikolay@cumulusnetworks.com>","To":"netdev@vger.kernel.org","Cc":"edumazet@google.com, jhs@mojatatu.com, xiyou.wangcong@gmail.com,\n\tjiri@resnulli.us, roopa@cumulusnetworks.com,\n\tNikolay Aleksandrov <nikolay@cumulusnetworks.com>","Subject":"[PATCH net 9/9] sch_tbf: fix two null pointer dereferences on init\n\tfailure","Date":"Wed, 30 Aug 2017 12:49:05 +0300","Message-Id":"<1504086545-7777-10-git-send-email-nikolay@cumulusnetworks.com>","X-Mailer":"git-send-email 2.1.4","In-Reply-To":"<1504086545-7777-1-git-send-email-nikolay@cumulusnetworks.com>","References":"<1504086545-7777-1-git-send-email-nikolay@cumulusnetworks.com>","Sender":"netdev-owner@vger.kernel.org","Precedence":"bulk","List-ID":"<netdev.vger.kernel.org>","X-Mailing-List":"netdev@vger.kernel.org"},"content":"sch_tbf calls qdisc_watchdog_cancel() in both its ->reset and ->destroy\ncallbacks but it may fail before the timer is initialized due to missing\noptions (either not supplied by user-space or set as a default qdisc),\nalso q->qdisc is used by ->reset and ->destroy so we need it initialized.\n\nReproduce:\n$ sysctl net.core.default_qdisc=tbf\n$ ip l set ethX up\n\nCrash log:\n[  959.160172] BUG: unable to handle kernel NULL pointer dereference at 0000000000000018\n[  959.160323] IP: qdisc_reset+0xa/0x5c\n[  959.160400] PGD 59cdb067\n[  959.160401] P4D 59cdb067\n[  959.160466] PUD 59ccb067\n[  959.160532] PMD 0\n[  959.160597]\n[  959.160706] Oops: 0000 [#1] SMP\n[  959.160778] Modules linked in: sch_tbf sch_sfb sch_prio sch_netem\n[  959.160891] CPU: 2 PID: 1562 Comm: ip Not tainted 4.13.0-rc6+ #62\n[  959.160998] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.7.5-20140531_083030-gandalf 04/01/2014\n[  959.161157] task: ffff880059c9a700 task.stack: ffff8800376d0000\n[  959.161263] RIP: 0010:qdisc_reset+0xa/0x5c\n[  959.161347] RSP: 0018:ffff8800376d3610 EFLAGS: 00010286\n[  959.161531] RAX: ffffffffa001b1dd RBX: ffff8800373a2800 RCX: 0000000000000000\n[  959.161733] RDX: ffffffff8215f160 RSI: ffffffff8215f160 RDI: 0000000000000000\n[  959.161939] RBP: ffff8800376d3618 R08: 00000000014080c0 R09: 00000000ffffffff\n[  959.162141] R10: ffff8800376d3578 R11: 0000000000000020 R12: ffffffffa001d2c0\n[  959.162343] R13: ffff880037538000 R14: 00000000ffffffff R15: 0000000000000001\n[  959.162546] FS:  00007fcc5126b740(0000) GS:ffff88005d900000(0000) knlGS:0000000000000000\n[  959.162844] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[  959.163030] CR2: 0000000000000018 CR3: 000000005abc4000 CR4: 00000000000406e0\n[  959.163233] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n[  959.163436] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n[  959.163638] Call Trace:\n[  959.163788]  tbf_reset+0x19/0x64 [sch_tbf]\n[  959.163957]  qdisc_destroy+0x8b/0xe5\n[  959.164119]  qdisc_create_dflt+0x86/0x94\n[  959.164284]  ? dev_activate+0x129/0x129\n[  959.164449]  attach_one_default_qdisc+0x36/0x63\n[  959.164623]  netdev_for_each_tx_queue+0x3d/0x48\n[  959.164795]  dev_activate+0x4b/0x129\n[  959.164957]  __dev_open+0xe7/0x104\n[  959.165118]  __dev_change_flags+0xc6/0x15c\n[  959.165287]  dev_change_flags+0x25/0x59\n[  959.165451]  do_setlink+0x30c/0xb3f\n[  959.165613]  ? check_chain_key+0xb0/0xfd\n[  959.165782]  rtnl_newlink+0x3a4/0x729\n[  959.165947]  ? rtnl_newlink+0x117/0x729\n[  959.166121]  ? ns_capable_common+0xd/0xb1\n[  959.166288]  ? ns_capable+0x13/0x15\n[  959.166450]  rtnetlink_rcv_msg+0x188/0x197\n[  959.166617]  ? rcu_read_unlock+0x3e/0x5f\n[  959.166783]  ? rtnl_newlink+0x729/0x729\n[  959.166948]  netlink_rcv_skb+0x6c/0xce\n[  959.167113]  rtnetlink_rcv+0x23/0x2a\n[  959.167273]  netlink_unicast+0x103/0x181\n[  959.167439]  netlink_sendmsg+0x326/0x337\n[  959.167607]  sock_sendmsg_nosec+0x14/0x3f\n[  959.167772]  sock_sendmsg+0x29/0x2e\n[  959.167932]  ___sys_sendmsg+0x209/0x28b\n[  959.168098]  ? do_raw_spin_unlock+0xcd/0xf8\n[  959.168267]  ? _raw_spin_unlock+0x27/0x31\n[  959.168432]  ? __handle_mm_fault+0x651/0xdb1\n[  959.168602]  ? check_chain_key+0xb0/0xfd\n[  959.168773]  __sys_sendmsg+0x45/0x63\n[  959.168934]  ? __sys_sendmsg+0x45/0x63\n[  959.169100]  SyS_sendmsg+0x19/0x1b\n[  959.169260]  entry_SYSCALL_64_fastpath+0x23/0xc2\n[  959.169432] RIP: 0033:0x7fcc5097e690\n[  959.169592] RSP: 002b:00007ffd0d5c7b48 EFLAGS: 00000246 ORIG_RAX: 000000000000002e\n[  959.169887] RAX: ffffffffffffffda RBX: ffffffff810d278c RCX: 00007fcc5097e690\n[  959.170089] RDX: 0000000000000000 RSI: 00007ffd0d5c7b90 RDI: 0000000000000003\n[  959.170292] RBP: ffff8800376d3f98 R08: 0000000000000001 R09: 0000000000000003\n[  959.170494] R10: 00007ffd0d5c7910 R11: 0000000000000246 R12: 0000000000000006\n[  959.170697] R13: 000000000066f1a0 R14: 00007ffd0d5cfc40 R15: 0000000000000000\n[  959.170900]  ? trace_hardirqs_off_caller+0xa7/0xcf\n[  959.171076] Code: 00 41 c7 84 24 14 01 00 00 00 00 00 00 41 c7 84 24\n98 00 00 00 00 00 00 00 41 5c 41 5d 41 5e 5d c3 66 66 66 66 90 55 48 89\ne5 53 <48> 8b 47 18 48 89 fb 48 8b 40 48 48 85 c0 74 02 ff d0 48 8b bb\n[  959.171637] RIP: qdisc_reset+0xa/0x5c RSP: ffff8800376d3610\n[  959.171821] CR2: 0000000000000018\n\nFixes: 87b60cfacf9f (\"net_sched: fix error recovery at qdisc creation\")\nFixes: 0fbbeb1ba43b (\"[PKT_SCHED]: Fix missing qdisc_destroy() in qdisc_create_dflt()\")\nSigned-off-by: Nikolay Aleksandrov <nikolay@cumulusnetworks.com>\n---\n net/sched/sch_tbf.c | 5 +++--\n 1 file changed, 3 insertions(+), 2 deletions(-)","diff":"diff --git a/net/sched/sch_tbf.c b/net/sched/sch_tbf.c\nindex b2e4b6ad241a..493270f0d5b0 100644\n--- a/net/sched/sch_tbf.c\n+++ b/net/sched/sch_tbf.c\n@@ -425,12 +425,13 @@ static int tbf_init(struct Qdisc *sch, struct nlattr *opt)\n {\n \tstruct tbf_sched_data *q = qdisc_priv(sch);\n \n+\tqdisc_watchdog_init(&q->watchdog, sch);\n+\tq->qdisc = &noop_qdisc;\n+\n \tif (opt == NULL)\n \t\treturn -EINVAL;\n \n \tq->t_c = ktime_get_ns();\n-\tqdisc_watchdog_init(&q->watchdog, sch);\n-\tq->qdisc = &noop_qdisc;\n \n \treturn tbf_change(sch, opt);\n }\n","prefixes":["net","9/9"]}