Netfilter-Devel Archive on lore.kernel.org
 help / color / Atom feed
* [PATCH nf] netfilter: nf_tables: Align nft_expr private data to 64-bit
@ 2019-10-31 10:06 Lukas Wunner
  2019-10-31 10:45 ` Lukas Wunner
  0 siblings, 1 reply; 3+ messages in thread
From: Lukas Wunner @ 2019-10-31 10:06 UTC (permalink / raw)
  To: Pablo Neira Ayuso, Jozsef Kadlecsik, Florian Westphal; +Cc: netfilter-devel

Invoking the following commands on a 32-bit architecture with strict
alignment requirements (such as an ARMv7-based Raspberry Pi) results
in an alignment exception:

Alignment trap: not handling instruction e1b26f9f at [<7f4473f8>]
Unhandled fault: alignment exception (0x001) at 0xb832e824
Internal error: : 1 [#1] PREEMPT SMP ARM
Hardware name: BCM2835
[<7f4473fc>] (nft_quota_do_init [nft_quota])
[<7f447448>] (nft_quota_init [nft_quota])
[<7f4260d0>] (nf_tables_newrule [nf_tables])
[<7f4168dc>] (nfnetlink_rcv_batch [nfnetlink])
[<7f416bd0>] (nfnetlink_rcv [nfnetlink])
[<8078b334>] (netlink_unicast)
[<8078b664>] (netlink_sendmsg)
[<8071b47c>] (sock_sendmsg)
[<8071bd18>] (___sys_sendmsg)
[<8071ce3c>] (__sys_sendmsg)
[<8071ce94>] (sys_sendmsg)

The reason is that nft_quota_do_init() calls atomic64_set() on an
atomic64_t which is only aligned to 32-bit, not 64-bit, because it
succeeds struct nft_expr in memory which only contains a 32-bit pointer.
Fix by aligning the nft_expr private data to 64-bit.

Fixes: 96518518cc41 ("netfilter: add nftables")
Signed-off-by: Lukas Wunner <lukas@wunner.de>
Cc: stable@vger.kernel.org # v3.13+
---
 include/net/netfilter/nf_tables.h | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/include/net/netfilter/nf_tables.h b/include/net/netfilter/nf_tables.h
index 001d294..2d0275f 100644
--- a/include/net/netfilter/nf_tables.h
+++ b/include/net/netfilter/nf_tables.h
@@ -820,7 +820,8 @@ struct nft_expr_ops {
  */
 struct nft_expr {
 	const struct nft_expr_ops	*ops;
-	unsigned char			data[];
+	unsigned char			data[]
+		__attribute__((aligned(__alignof__(u64))));
 };
 
 static inline void *nft_expr_priv(const struct nft_expr *expr)
-- 
2.20.1


^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH nf] netfilter: nf_tables: Align nft_expr private data to 64-bit
  2019-10-31 10:06 [PATCH nf] netfilter: nf_tables: Align nft_expr private data to 64-bit Lukas Wunner
@ 2019-10-31 10:45 ` Lukas Wunner
  2019-11-04 19:18   ` Pablo Neira Ayuso
  0 siblings, 1 reply; 3+ messages in thread
From: Lukas Wunner @ 2019-10-31 10:45 UTC (permalink / raw)
  To: Pablo Neira Ayuso, Jozsef Kadlecsik, Florian Westphal; +Cc: netfilter-devel

On Thu, Oct 31, 2019 at 11:06:24AM +0100, Lukas Wunner wrote:
> Invoking the following commands on a 32-bit architecture with strict
> alignment requirements (such as an ARMv7-based Raspberry Pi) results
> in an alignment exception:

Ugh, looks like "git commit" ate the commands as they were prefixed by a
hash mark (i.e. intended for execution as root):

# nft add table ip test-ip4
# nft add chain ip test-ip4 output { type filter hook output priority 0; }
# nft add rule  ip test-ip4 output quota 1025 bytes


> Alignment trap: not handling instruction e1b26f9f at [<7f4473f8>]
> Unhandled fault: alignment exception (0x001) at 0xb832e824
> Internal error: : 1 [#1] PREEMPT SMP ARM
> Hardware name: BCM2835
> [<7f4473fc>] (nft_quota_do_init [nft_quota])
> [<7f447448>] (nft_quota_init [nft_quota])
> [<7f4260d0>] (nf_tables_newrule [nf_tables])
> [<7f4168dc>] (nfnetlink_rcv_batch [nfnetlink])
> [<7f416bd0>] (nfnetlink_rcv [nfnetlink])
> [<8078b334>] (netlink_unicast)
> [<8078b664>] (netlink_sendmsg)
> [<8071b47c>] (sock_sendmsg)
> [<8071bd18>] (___sys_sendmsg)
> [<8071ce3c>] (__sys_sendmsg)
> [<8071ce94>] (sys_sendmsg)
> 
> The reason is that nft_quota_do_init() calls atomic64_set() on an
> atomic64_t which is only aligned to 32-bit, not 64-bit, because it
> succeeds struct nft_expr in memory which only contains a 32-bit pointer.
> Fix by aligning the nft_expr private data to 64-bit.
> 
> Fixes: 96518518cc41 ("netfilter: add nftables")
> Signed-off-by: Lukas Wunner <lukas@wunner.de>
> Cc: stable@vger.kernel.org # v3.13+
> ---
>  include/net/netfilter/nf_tables.h | 3 ++-
>  1 file changed, 2 insertions(+), 1 deletion(-)
> 
> diff --git a/include/net/netfilter/nf_tables.h b/include/net/netfilter/nf_tables.h
> index 001d294..2d0275f 100644
> --- a/include/net/netfilter/nf_tables.h
> +++ b/include/net/netfilter/nf_tables.h
> @@ -820,7 +820,8 @@ struct nft_expr_ops {
>   */
>  struct nft_expr {
>  	const struct nft_expr_ops	*ops;
> -	unsigned char			data[];
> +	unsigned char			data[]
> +		__attribute__((aligned(__alignof__(u64))));
>  };
>  
>  static inline void *nft_expr_priv(const struct nft_expr *expr)
> -- 
> 2.20.1

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH nf] netfilter: nf_tables: Align nft_expr private data to 64-bit
  2019-10-31 10:45 ` Lukas Wunner
@ 2019-11-04 19:18   ` Pablo Neira Ayuso
  0 siblings, 0 replies; 3+ messages in thread
From: Pablo Neira Ayuso @ 2019-11-04 19:18 UTC (permalink / raw)
  To: Lukas Wunner; +Cc: Jozsef Kadlecsik, Florian Westphal, netfilter-devel

On Thu, Oct 31, 2019 at 11:45:42AM +0100, Lukas Wunner wrote:
> On Thu, Oct 31, 2019 at 11:06:24AM +0100, Lukas Wunner wrote:
> > Invoking the following commands on a 32-bit architecture with strict
> > alignment requirements (such as an ARMv7-based Raspberry Pi) results
> > in an alignment exception:
> 
> Ugh, looks like "git commit" ate the commands as they were prefixed by a
> hash mark (i.e. intended for execution as root):
> 
> # nft add table ip test-ip4
> # nft add chain ip test-ip4 output { type filter hook output priority 0; }
> # nft add rule  ip test-ip4 output quota 1025 bytes

Applied and amended the commit to include this, thanks.

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, back to index

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2019-10-31 10:06 [PATCH nf] netfilter: nf_tables: Align nft_expr private data to 64-bit Lukas Wunner
2019-10-31 10:45 ` Lukas Wunner
2019-11-04 19:18   ` Pablo Neira Ayuso

Netfilter-Devel Archive on lore.kernel.org

Archives are clonable:
	git clone --mirror https://lore.kernel.org/netfilter-devel/0 netfilter-devel/git/0.git

	# If you have public-inbox 1.1+ installed, you may
	# initialize and index your mirror using the following commands:
	public-inbox-init -V2 netfilter-devel netfilter-devel/ https://lore.kernel.org/netfilter-devel \
		netfilter-devel@vger.kernel.org
	public-inbox-index netfilter-devel

Example config snippet for mirrors

Newsgroup available over NNTP:
	nntp://nntp.lore.kernel.org/org.kernel.vger.netfilter-devel


AGPL code for this site: git clone https://public-inbox.org/public-inbox.git