Message ID | cd8564ffa3d8254cce8995c95c218a56a6bd8797.1572516054.git.lukas@wunner.de |
---|---|
State | Accepted |
Delegated to: | Pablo Neira |
Headers | show |
Series | [nf] netfilter: nf_tables: Align nft_expr private data to 64-bit | expand |
On Thu, Oct 31, 2019 at 11:06:24AM +0100, Lukas Wunner wrote: > Invoking the following commands on a 32-bit architecture with strict > alignment requirements (such as an ARMv7-based Raspberry Pi) results > in an alignment exception: Ugh, looks like "git commit" ate the commands as they were prefixed by a hash mark (i.e. intended for execution as root): # nft add table ip test-ip4 # nft add chain ip test-ip4 output { type filter hook output priority 0; } # nft add rule ip test-ip4 output quota 1025 bytes > Alignment trap: not handling instruction e1b26f9f at [<7f4473f8>] > Unhandled fault: alignment exception (0x001) at 0xb832e824 > Internal error: : 1 [#1] PREEMPT SMP ARM > Hardware name: BCM2835 > [<7f4473fc>] (nft_quota_do_init [nft_quota]) > [<7f447448>] (nft_quota_init [nft_quota]) > [<7f4260d0>] (nf_tables_newrule [nf_tables]) > [<7f4168dc>] (nfnetlink_rcv_batch [nfnetlink]) > [<7f416bd0>] (nfnetlink_rcv [nfnetlink]) > [<8078b334>] (netlink_unicast) > [<8078b664>] (netlink_sendmsg) > [<8071b47c>] (sock_sendmsg) > [<8071bd18>] (___sys_sendmsg) > [<8071ce3c>] (__sys_sendmsg) > [<8071ce94>] (sys_sendmsg) > > The reason is that nft_quota_do_init() calls atomic64_set() on an > atomic64_t which is only aligned to 32-bit, not 64-bit, because it > succeeds struct nft_expr in memory which only contains a 32-bit pointer. > Fix by aligning the nft_expr private data to 64-bit. > > Fixes: 96518518cc41 ("netfilter: add nftables") > Signed-off-by: Lukas Wunner <lukas@wunner.de> > Cc: stable@vger.kernel.org # v3.13+ > --- > include/net/netfilter/nf_tables.h | 3 ++- > 1 file changed, 2 insertions(+), 1 deletion(-) > > diff --git a/include/net/netfilter/nf_tables.h b/include/net/netfilter/nf_tables.h > index 001d294..2d0275f 100644 > --- a/include/net/netfilter/nf_tables.h > +++ b/include/net/netfilter/nf_tables.h > @@ -820,7 +820,8 @@ struct nft_expr_ops { > */ > struct nft_expr { > const struct nft_expr_ops *ops; > - unsigned char data[]; > + unsigned char data[] > + __attribute__((aligned(__alignof__(u64)))); > }; > > static inline void *nft_expr_priv(const struct nft_expr *expr) > -- > 2.20.1
On Thu, Oct 31, 2019 at 11:45:42AM +0100, Lukas Wunner wrote: > On Thu, Oct 31, 2019 at 11:06:24AM +0100, Lukas Wunner wrote: > > Invoking the following commands on a 32-bit architecture with strict > > alignment requirements (such as an ARMv7-based Raspberry Pi) results > > in an alignment exception: > > Ugh, looks like "git commit" ate the commands as they were prefixed by a > hash mark (i.e. intended for execution as root): > > # nft add table ip test-ip4 > # nft add chain ip test-ip4 output { type filter hook output priority 0; } > # nft add rule ip test-ip4 output quota 1025 bytes Applied and amended the commit to include this, thanks.
diff --git a/include/net/netfilter/nf_tables.h b/include/net/netfilter/nf_tables.h index 001d294..2d0275f 100644 --- a/include/net/netfilter/nf_tables.h +++ b/include/net/netfilter/nf_tables.h @@ -820,7 +820,8 @@ struct nft_expr_ops { */ struct nft_expr { const struct nft_expr_ops *ops; - unsigned char data[]; + unsigned char data[] + __attribute__((aligned(__alignof__(u64)))); }; static inline void *nft_expr_priv(const struct nft_expr *expr)
Invoking the following commands on a 32-bit architecture with strict alignment requirements (such as an ARMv7-based Raspberry Pi) results in an alignment exception: Alignment trap: not handling instruction e1b26f9f at [<7f4473f8>] Unhandled fault: alignment exception (0x001) at 0xb832e824 Internal error: : 1 [#1] PREEMPT SMP ARM Hardware name: BCM2835 [<7f4473fc>] (nft_quota_do_init [nft_quota]) [<7f447448>] (nft_quota_init [nft_quota]) [<7f4260d0>] (nf_tables_newrule [nf_tables]) [<7f4168dc>] (nfnetlink_rcv_batch [nfnetlink]) [<7f416bd0>] (nfnetlink_rcv [nfnetlink]) [<8078b334>] (netlink_unicast) [<8078b664>] (netlink_sendmsg) [<8071b47c>] (sock_sendmsg) [<8071bd18>] (___sys_sendmsg) [<8071ce3c>] (__sys_sendmsg) [<8071ce94>] (sys_sendmsg) The reason is that nft_quota_do_init() calls atomic64_set() on an atomic64_t which is only aligned to 32-bit, not 64-bit, because it succeeds struct nft_expr in memory which only contains a 32-bit pointer. Fix by aligning the nft_expr private data to 64-bit. Fixes: 96518518cc41 ("netfilter: add nftables") Signed-off-by: Lukas Wunner <lukas@wunner.de> Cc: stable@vger.kernel.org # v3.13+ --- include/net/netfilter/nf_tables.h | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-)