From: Gao feng <gaofeng@cn.fujitsu.com>
To: George Spelvin <linux@horizon.com>
Cc: bp@alien8.de, kaber@trash.net, linux-kernel@vger.kernel.org,
netfilter@vger.kernel.org, pablo@netfilter.org
Subject: Re: v3.10-rc7 oops soon after boot
Date: Mon, 24 Jun 2013 17:52:08 +0800 [thread overview]
Message-ID: <51C816C8.4080709@cn.fujitsu.com> (raw)
In-Reply-To: <20130624094145.2576.qmail@science.horizon.com>
[-- Attachment #1: Type: text/plain, Size: 969 bytes --]
On 06/24/2013 05:41 PM, George Spelvin wrote:
>> Please try the patch below,
>> I think this bug is introduced by me :(
>>
>> Thanks!
>
> Well, you changed it, but it still crashes.
>
> It's now at del_timer+0x9/0x58, with the code being:
This one should work.
Thanks for your quickly reply.
>
> 3f 00 55 53 48 89 fb 48 83 ec 10 <48> 83 3f 00 48 c7 47
>
> The backtrace is
> <IRQ>
> ? ulog_send+0x21/0x76
> ? ulog_timer+0x2d/0x39
> ? ulog_send+0x76/0x76
> ? call_timer_fn.isra
> ? run_timer_softirq
> ? __do_softirq
> ? irq_exit
> ? do_IRQ
> ? common_interrupt
> <EOI>
>
> (To give a faster response, I just transcribed a few key
> sections. Is that enough of a clue, or do you need more?)
> --
> To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
> the body of a message to majordomo@vger.kernel.org
> More majordomo info at http://vger.kernel.org/majordomo-info.html
> Please read the FAQ at http://www.tux.org/lkml/
>
[-- Attachment #2: 0001-netfilter-ipt_ULOG-fix-incorrect-setting-of-ulog-tim.patch --]
[-- Type: text/x-patch, Size: 1627 bytes --]
>From f22cb6a9a52497364605c25930ba470ee180ca58 Mon Sep 17 00:00:00 2001
From: Gao feng <gaofeng@cn.fujitsu.com>
Date: Mon, 24 Jun 2013 17:04:02 +0800
Subject: [PATCH] netfilter: ipt_ULOG: fix incorrect setting of ulog timer
The parameter of setup_timer should be &ulog->nlgroup[i].
the incorrect parameter will cause kernel panic in
ulog_timer.
Bug introducted in commit 355430671ad93546b34b4e91bdf720f3a704efa4
"netfilter: ipt_ULOG: add net namespace support for ipt_ULOG"
ebt_ULOG doesn't have this problem.
Reported-by: Borislav Petkov <bp@alien8.de>
Signed-off-by: Gao feng <gaofeng@cn.fujitsu.com>
---
net/ipv4/netfilter/ipt_ULOG.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
diff --git a/net/ipv4/netfilter/ipt_ULOG.c b/net/ipv4/netfilter/ipt_ULOG.c
index ff4b781..1345c20 100644
--- a/net/ipv4/netfilter/ipt_ULOG.c
+++ b/net/ipv4/netfilter/ipt_ULOG.c
@@ -133,7 +133,7 @@ static void ulog_timer(unsigned long data)
/* lock to protect against somebody modifying our structure
* from ipt_ulog_target at the same time */
spin_lock_bh(&ulog->lock);
- ulog_send(ulog, data);
+ ulog_send(ulog, *(unsigned int *)data);
spin_unlock_bh(&ulog->lock);
}
@@ -408,7 +408,8 @@ static int __net_init ulog_tg_net_init(struct net *net)
spin_lock_init(&ulog->lock);
/* initialize ulog_buffers */
for (i = 0; i < ULOG_MAXNLGROUPS; i++)
- setup_timer(&ulog->ulog_buffers[i].timer, ulog_timer, i);
+ setup_timer(&ulog->ulog_buffers[i].timer, ulog_timer,
+ (unsigned long)&ulog->nlgroup[i]);
ulog->nflognl = netlink_kernel_create(net, NETLINK_NFLOG, &cfg);
if (!ulog->nflognl)
--
1.8.1.4
next prev parent reply other threads:[~2013-06-24 9:50 UTC|newest]
Thread overview: 16+ messages / expand[flat|nested] mbox.gz Atom feed top
2013-06-24 6:49 v3.10-rc7 oops soon after boot George Spelvin
2013-06-24 7:03 ` George Spelvin
2013-06-24 7:33 ` Borislav Petkov
2013-06-24 8:47 ` George Spelvin
2013-06-24 9:12 ` Gao feng
2013-06-24 9:41 ` George Spelvin
2013-06-24 9:52 ` Gao feng [this message]
2013-06-24 10:01 ` George Spelvin
2013-06-24 11:34 ` Pablo Neira Ayuso
2013-06-24 15:10 ` Pablo Neira Ayuso
2013-06-24 16:13 ` Borislav Petkov
2013-06-24 22:17 ` George Spelvin
2013-06-24 22:34 ` Borislav Petkov
2013-06-25 1:36 ` Gao feng
2013-06-25 6:17 ` Gao feng
2013-06-26 6:28 ` George Spelvin
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=51C816C8.4080709@cn.fujitsu.com \
--to=gaofeng@cn.fujitsu.com \
--cc=bp@alien8.de \
--cc=kaber@trash.net \
--cc=linux-kernel@vger.kernel.org \
--cc=linux@horizon.com \
--cc=netfilter@vger.kernel.org \
--cc=pablo@netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).