Thread (1 message) 1 message, 1 author, 2007-03-12

Re: lockdep question (was Re: IPoIB caused a kernel: BUG: softlockup detected on CPU#0!)

From: Michael S. Tsirkin <hidden>
Date: 2007-03-12 14:19:35
Also in: lkml

Quoting Ingo Molnar [off-list ref]:
Subject: Re: lockdep question (was Re: IPoIB caused a kernel: BUG: softlockup detected on CPU#0!)


* Michael S. Tsirkin [off-list ref] wrote:
quoted
quoted
could you turn on CONFIG_SLAB_DEBUG as well?

that should catch certain types of use-after-free accesses, and 
lockdep will also warn if a still locked object is freed.
Hmm, no, this does not look like use-after-free. I enabled 
CONFIG_SLAB_DEBUG, and I still see the same message, so the memory was 
not overwritten by slab debugger.
that's still not conclusive - the memory might not have been allocated 
by slab again to detect it. Your magic-number check definitely shows 
some sort of corruption going on, right?
Not necessarily in such a direct way.

I currently think we are somehow getting neighbours where
neigh->dev points to a loopback device - that's type 772,
and this seems to make sense.
I printed out the device name and sure enough it is "lo".

Is it true that sticking the following

static int ipoib_neigh_setup_dev(struct net_device *dev,
				 struct neigh_parms *parms)
{
	parms->neigh_destructor = ipoib_neigh_destructor;

	return 0;
}

in dev->neigh_setup, as ipoib does, guarantees that neighbour->dev will point to
the current device for any neighbour which ipoib_neigh_destructor gets?

That's the assumption IPoIB makes, and it seems broken in this instance.

How could that be?

-- 
MST
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help