diff mbox

[net-2.6] ipv6: fix missing in6_ifa_put in addrconf

Message ID 20101116062921.31164.70903.stgit@jf-dev1-dcblab
State Accepted, archived
Delegated to: David Miller
Headers show

Commit Message

John Fastabend Nov. 16, 2010, 6:29 a.m. UTC
Fix ref count bug introduced by

commit 2de795707294972f6c34bae9de713e502c431296
Author: Lorenzo Colitti <lorenzo@google.com>
Date:   Wed Oct 27 18:16:49 2010 +0000

ipv6: addrconf: don't remove address state on ifdown if the address
is being kept


Fix logic so that addrconf_ifdown() decrements the inet6_ifaddr
refcnt correctly with in6_ifa_put().

Reported-by: Stephen Hemminger <shemminger@vyatta.com>
Signed-off-by: John Fastabend <john.r.fastabend@intel.com>
---

 net/ipv6/addrconf.c |    6 +++---
 1 files changed, 3 insertions(+), 3 deletions(-)


--
To unsubscribe from this list: send the line "unsubscribe netdev" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html

Comments

Eric Dumazet Nov. 16, 2010, 6:37 a.m. UTC | #1
Le lundi 15 novembre 2010 à 22:29 -0800, John Fastabend a écrit :
> Fix ref count bug introduced by
> 
> commit 2de795707294972f6c34bae9de713e502c431296
> Author: Lorenzo Colitti <lorenzo@google.com>
> Date:   Wed Oct 27 18:16:49 2010 +0000
> 
> ipv6: addrconf: don't remove address state on ifdown if the address
> is being kept
> 
> 
> Fix logic so that addrconf_ifdown() decrements the inet6_ifaddr
> refcnt correctly with in6_ifa_put().
> 
> Reported-by: Stephen Hemminger <shemminger@vyatta.com>
> Signed-off-by: John Fastabend <john.r.fastabend@intel.com>
> ---
> 
>  net/ipv6/addrconf.c |    6 +++---
>  1 files changed, 3 insertions(+), 3 deletions(-)
> 
> diff --git a/net/ipv6/addrconf.c b/net/ipv6/addrconf.c
> index b41ce0f..aaa3ca4 100644
> --- a/net/ipv6/addrconf.c
> +++ b/net/ipv6/addrconf.c
> @@ -2754,13 +2754,13 @@ static int addrconf_ifdown(struct net_device *dev, int how)
>  			ifa->state = INET6_IFADDR_STATE_DEAD;
>  			spin_unlock_bh(&ifa->state_lock);
>  
> -			if (state == INET6_IFADDR_STATE_DEAD) {
> -				in6_ifa_put(ifa);
> -			} else {
> +			if (state != INET6_IFADDR_STATE_DEAD) {
>  				__ipv6_ifa_notify(RTM_DELADDR, ifa);
>  				atomic_notifier_call_chain(&inet6addr_chain,
>  							   NETDEV_DOWN, ifa);
>  			}
> +
> +			in6_ifa_put(ifa);
>  			write_lock_bh(&idev->lock);
>  		}
>  	}
> 

Acked-by: Eric Dumazet <eric.dumazet@gmail.com>

Thanks again John


--
To unsubscribe from this list: send the line "unsubscribe netdev" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
David Miller Nov. 16, 2010, 5:35 p.m. UTC | #2
From: John Fastabend <john.r.fastabend@intel.com>
Date: Mon, 15 Nov 2010 22:29:21 -0800

> Fix ref count bug introduced by
> 
> commit 2de795707294972f6c34bae9de713e502c431296
> Author: Lorenzo Colitti <lorenzo@google.com>
> Date:   Wed Oct 27 18:16:49 2010 +0000
> 
> ipv6: addrconf: don't remove address state on ifdown if the address
> is being kept
> 
> 
> Fix logic so that addrconf_ifdown() decrements the inet6_ifaddr
> refcnt correctly with in6_ifa_put().
> 
> Reported-by: Stephen Hemminger <shemminger@vyatta.com>
> Signed-off-by: John Fastabend <john.r.fastabend@intel.com>

Applied, thanks a lot.
--
To unsubscribe from this list: send the line "unsubscribe netdev" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Anders Franzen Nov. 17, 2010, 3:20 p.m. UTC | #3
Hi, I was hunting for a bug that a colleague discovered.
When we exit a network namespace, the ns was hanging with dangling
references to dev lo.

When I saw the patch below, I fetched the latest net-next from Daves
repository.

And the problem is gone. Was this really the fix, since it seems to me
that this is a fix to a recently added patch (dont remove address ....).

Did you fix anything else in the Ipv6 addrconf w.r.g dev_hold/dev_put?

netns still have problems with slab corruption during exit though:

 Nov 17 15:00:20 p04 user.err kernel: Slab corruption: size-4096
start=ffff88000612a000, len=4096
Nov 17 15:00:20 p04 user.err kernel: 020: 6b 6b 6b 6b 6b 6b
Nov 17 15:00:20 p04 user.info kernel:  6b 6b 00 00 00 00 00 00 00
Nov 17 15:00:20 p04 user.info kernel:  00

BR
  Anders


On Tue, 2010-11-16 at 07:37 +0100, Eric Dumazet wrote:
> Le lundi 15 novembre 2010 à 22:29 -0800, John Fastabend a écrit :
> > Fix ref count bug introduced by
> > 
> > commit 2de795707294972f6c34bae9de713e502c431296
> > Author: Lorenzo Colitti <lorenzo@google.com>
> > Date:   Wed Oct 27 18:16:49 2010 +0000
> > 
> > ipv6: addrconf: don't remove address state on ifdown if the address
> > is being kept
> > 
> > 
> > Fix logic so that addrconf_ifdown() decrements the inet6_ifaddr
> > refcnt correctly with in6_ifa_put().
> > 
> > Reported-by: Stephen Hemminger <shemminger@vyatta.com>
> > Signed-off-by: John Fastabend <john.r.fastabend@intel.com>
> > ---
> > 
> >  net/ipv6/addrconf.c |    6 +++---
> >  1 files changed, 3 insertions(+), 3 deletions(-)
> > 
> > diff --git a/net/ipv6/addrconf.c b/net/ipv6/addrconf.c
> > index b41ce0f..aaa3ca4 100644
> > --- a/net/ipv6/addrconf.c
> > +++ b/net/ipv6/addrconf.c
> > @@ -2754,13 +2754,13 @@ static int addrconf_ifdown(struct net_device *dev, int how)
> >  			ifa->state = INET6_IFADDR_STATE_DEAD;
> >  			spin_unlock_bh(&ifa->state_lock);
> >  
> > -			if (state == INET6_IFADDR_STATE_DEAD) {
> > -				in6_ifa_put(ifa);
> > -			} else {
> > +			if (state != INET6_IFADDR_STATE_DEAD) {
> >  				__ipv6_ifa_notify(RTM_DELADDR, ifa);
> >  				atomic_notifier_call_chain(&inet6addr_chain,
> >  							   NETDEV_DOWN, ifa);
> >  			}
> > +
> > +			in6_ifa_put(ifa);
> >  			write_lock_bh(&idev->lock);
> >  		}
> >  	}
> > 
> 
> Acked-by: Eric Dumazet <eric.dumazet@gmail.com>
> 
> Thanks again John
> 
> 
> --
> To unsubscribe from this list: send the line "unsubscribe netdev" in
> the body of a message to majordomo@vger.kernel.org
> More majordomo info at  http://vger.kernel.org/majordomo-info.html


--
To unsubscribe from this list: send the line "unsubscribe netdev" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Eric Dumazet Nov. 17, 2010, 3:38 p.m. UTC | #4
Le mercredi 17 novembre 2010 à 16:20 +0100, Anders Franzen a écrit :
> Hi, I was hunting for a bug that a colleague discovered.
> When we exit a network namespace, the ns was hanging with dangling
> references to dev lo.
> 
> When I saw the patch below, I fetched the latest net-next from Daves
> repository.
> 
> And the problem is gone. Was this really the fix, since it seems to me
> that this is a fix to a recently added patch (dont remove address ....).
> 
> Did you fix anything else in the Ipv6 addrconf w.r.g dev_hold/dev_put?
> 
> netns still have problems with slab corruption during exit though:
> 
>  Nov 17 15:00:20 p04 user.err kernel: Slab corruption: size-4096
> start=ffff88000612a000, len=4096
> Nov 17 15:00:20 p04 user.err kernel: 020: 6b 6b 6b 6b 6b 6b
> Nov 17 15:00:20 p04 user.info kernel:  6b 6b 00 00 00 00 00 00 00
> Nov 17 15:00:20 p04 user.info kernel:  00
> 
> BR
>   Anders
> 
> 

Hi Anders

Several patches of interest :


commit 9d82ca98f71fd686ef2f3017c5e3e6a4871b6e46
(ipv6: fix missing in6_ifa_put in addrconf)

commit 332dd96f7ac15e937088fe11f15cfe0210e8edd1
(net/dst: dst_dev_event() called after other notifiers)

commit ef885afbf8a37689afc1d9d545e2f3e7a8276c17
(net: use rcu_barrier() in rollback_registered_many)


--
To unsubscribe from this list: send the line "unsubscribe netdev" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
diff mbox

Patch

diff --git a/net/ipv6/addrconf.c b/net/ipv6/addrconf.c
index b41ce0f..aaa3ca4 100644
--- a/net/ipv6/addrconf.c
+++ b/net/ipv6/addrconf.c
@@ -2754,13 +2754,13 @@  static int addrconf_ifdown(struct net_device *dev, int how)
 			ifa->state = INET6_IFADDR_STATE_DEAD;
 			spin_unlock_bh(&ifa->state_lock);
 
-			if (state == INET6_IFADDR_STATE_DEAD) {
-				in6_ifa_put(ifa);
-			} else {
+			if (state != INET6_IFADDR_STATE_DEAD) {
 				__ipv6_ifa_notify(RTM_DELADDR, ifa);
 				atomic_notifier_call_chain(&inet6addr_chain,
 							   NETDEV_DOWN, ifa);
 			}
+
+			in6_ifa_put(ifa);
 			write_lock_bh(&idev->lock);
 		}
 	}