Re: CBQ(but probably u32 filter bug), kernel "freeze", at least from 3.2.0

3 messages, 3 authors, 2012-09-12 · open the first message on its own page

Re: CBQ(but probably u32 filter bug), kernel "freeze", at least from 3.2.0

From: Denys Fedoryshchenko <hidden>
Date: 2012-09-11 22:50:14

No problem, I reproduced the bug on my dev machine, but its always
better to have bug reporter adding its own 'Tested-by:' tag ;)

Thanks
Tested-by: Denys Fedoryschenko <redacted>

Thank you a lot, it fixes the problem!

---
Denys Fedoryshchenko, Network Engineer, Virtual ISP S.A.L.

[PATCH] net-sched: sch_cbq: avoid infinite loop

From: Eric Dumazet <hidden>
Date: 2012-09-11 23:11:16

From: Eric Dumazet <edumazet@google.com>

Its possible to setup a bad cbq configuration leading to
an infinite loop in cbq_classify()

DEV_OUT=eth0
ICMP="match ip protocol 1 0xff"
U32="protocol ip u32"
DST="match ip dst"
tc qdisc add dev $DEV_OUT root handle 1: cbq avpkt 1000 \
	bandwidth 100mbit
tc class add dev $DEV_OUT parent 1: classid 1:1 cbq \
	rate 512kbit allot 1500 prio 5 bounded isolated
tc filter add dev $DEV_OUT parent 1: prio 3 $U32 \
	$ICMP $DST 192.168.3.234 flowid 1:

Reported-by: Denys Fedoryschenko <redacted>
Tested-by: Denys Fedoryschenko <redacted>
Signed-off-by: Eric Dumazet <edumazet@google.com>
---
 net/sched/sch_cbq.c |    5 +++--
 1 file changed, 3 insertions(+), 2 deletions(-)
diff --git a/net/sched/sch_cbq.c b/net/sched/sch_cbq.c
index 6aabd77..564b9fc 100644
--- a/net/sched/sch_cbq.c
+++ b/net/sched/sch_cbq.c
@@ -250,10 +250,11 @@ cbq_classify(struct sk_buff *skb, struct Qdisc *sch, int *qerr)
 			else if ((cl = defmap[res.classid & TC_PRIO_MAX]) == NULL)
 				cl = defmap[TC_PRIO_BESTEFFORT];
 
-			if (cl == NULL || cl->level >= head->level)
+			if (cl == NULL)
 				goto fallback;
 		}
-
+		if (cl->level >= head->level)
+			goto fallback;
 #ifdef CONFIG_NET_CLS_ACT
 		switch (result) {
 		case TC_ACT_QUEUED:

Re: [PATCH] net-sched: sch_cbq: avoid infinite loop

From: David Miller <davem@davemloft.net>
Date: 2012-09-12 02:21:36

From: Eric Dumazet <redacted>
Date: Wed, 12 Sep 2012 01:11:12 +0200
From: Eric Dumazet <edumazet@google.com>

Its possible to setup a bad cbq configuration leading to
an infinite loop in cbq_classify()

DEV_OUT=eth0
ICMP="match ip protocol 1 0xff"
U32="protocol ip u32"
DST="match ip dst"
tc qdisc add dev $DEV_OUT root handle 1: cbq avpkt 1000 \
	bandwidth 100mbit
tc class add dev $DEV_OUT parent 1: classid 1:1 cbq \
	rate 512kbit allot 1500 prio 5 bounded isolated
tc filter add dev $DEV_OUT parent 1: prio 3 $U32 \
	$ICMP $DST 192.168.3.234 flowid 1:

Reported-by: Denys Fedoryschenko <redacted>
Tested-by: Denys Fedoryschenko <redacted>
Signed-off-by: Eric Dumazet <edumazet@google.com>
Applied and queued up for -stable, thanks Eric.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help