Skip to content
  1. Nov 29, 2017
  2. Nov 28, 2017
  3. Nov 27, 2017
  4. Nov 26, 2017
  5. Nov 25, 2017
    • Roman Kapl's avatar
      net: sched: crash on blocks with goto chain action · a60b3f51
      Roman Kapl authored
      tcf_block_put_ext has assumed that all filters (and thus their goto
      actions) are destroyed in RCU callback and thus can not race with our
      list iteration. However, that is not true during netns cleanup (see
      tcf_exts_get_net comment).
      
      Prevent the user after free by holding all chains (except 0, that one is
      already held). foreach_safe is not enough in this case.
      
      To reproduce, run the following in a netns and then delete the ns:
          ip link add dtest type dummy
          tc qdisc add dev dtest ingress
          tc filter add dev dtest chain 1 parent ffff: handle 1 prio 1 flower action goto chain 2
      
      Fixes: 822e86d9
      
       ("net_sched: remove tcf_block_put_deferred()")
      Signed-off-by: default avatarRoman Kapl <code@rkapl.cz>
      Acked-by: default avatarJiri Pirko <jiri@mellanox.com>
      Signed-off-by: default avatarDavid S. Miller <davem@davemloft.net>
      a60b3f51