[PATCH 2.4 NET] Fixes slab corruption in cbq_destroy

STALE7994d

2 messages, 2 authors, 2004-09-16 · open the first message on its own page

[PATCH 2.4 NET] Fixes slab corruption in cbq_destroy

From: Thomas Graf <tgraf@suug.ch>
Date: 2004-09-16 13:31:23

Backport of 2.6 patch:

Fixes slab corruption in cbq_destroy. cbq_destroy_filters and
qdisc_put_rtab(q->link.R_tab) are already called in cbq_destroy_class.
The latter lead to a slab corruption due to repeated freeing of
q->link.R_tab because q->link is part of q->classes.

--- linux-2.4.28-pre3-bk2.orig/net/sched/sch_cbq.c	2004-09-16 14:59:56.000000000 +0200
+++ linux-2.4.28-pre3-bk2/net/sched/sch_cbq.c	2004-09-16 15:01:53.000000000 +0200
@@ -1736,10 +1736,6 @@
 #ifdef CONFIG_NET_CLS_POLICE
 	q->rx_class = NULL;
 #endif
-	for (h = 0; h < 16; h++) {
-		for (cl = q->classes[h]; cl; cl = cl->next)
-			cbq_destroy_filters(cl);
-	}
 
 	for (h = 0; h < 16; h++) {
 		struct cbq_class *next;
@@ -1750,7 +1746,6 @@
 		}
 	}
 
-	qdisc_put_rtab(q->link.R_tab);
 	MOD_DEC_USE_COUNT;
 }
 

Re: [PATCH 2.4 NET] Fixes slab corruption in cbq_destroy

From: "David S. Miller" <davem@davemloft.net>
Date: 2004-09-16 20:29:59

On Thu, 16 Sep 2004 15:31:23 +0200
Thomas Graf [off-list ref] wrote:
Backport of 2.6 patch:
Also applied, thanks again.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help