[PATCH] fix ZOMBIE state bug in PPPOE driver

Subsystems: networking drivers, ppp over ethernet, the rest

STALE5076d

3 messages, 3 authors, 2012-09-19 · open the first message on its own page

[PATCH] fix ZOMBIE state bug in PPPOE driver

From: Xiaodong Xu <hidden>
Date: 2012-09-16 02:31:06

Hi All,

I found a bug in kernel PPPOE driver.
When PPPOE is running over a virtual ethernet interface (e.g., a
bonding interface) and the user tries to delete the interface in case
the PPPOE state is ZOMBIE, the kernel will loop infinitely while
unregistering net_device for the reference count is not reset to zero
which should be done by dev_put().

The following patch could fix this issue:

$ git diff
diff --git a/drivers/net/ppp/pppoe.c b/drivers/net/ppp/pppoe.c
index cbf7047..20f31d0 100644
--- a/drivers/net/ppp/pppoe.c
+++ b/drivers/net/ppp/pppoe.c
@@ -570,7 +570,7 @@ static int pppoe_release(struct socket *sock)

        po = pppox_sk(sk);

-       if (sk->sk_state & (PPPOX_CONNECTED | PPPOX_BOUND)) {
+       if (sk->sk_state & (PPPOX_CONNECTED | PPPOX_BOUND | PPPOX_ZOMBIE)) {
                dev_put(po->pppoe_dev);
                po->pppoe_dev = NULL;
        }
Thanks.

Regards,
Xiaodong Xu

Re: [PATCH] fix ZOMBIE state bug in PPPOE driver

From: Cong Wang <hidden>
Date: 2012-09-17 03:35:45

On Sun, Sep 16, 2012 at 10:30 AM, Xiaodong Xu [off-list ref] wrote:
Hi All,

I found a bug in kernel PPPOE driver.
When PPPOE is running over a virtual ethernet interface (e.g., a
bonding interface) and the user tries to delete the interface in case
the PPPOE state is ZOMBIE, the kernel will loop infinitely while
unregistering net_device for the reference count is not reset to zero
which should be done by dev_put().

The following patch could fix this issue:
You missed your Signed-off-by, please read
Documentation/SubmittingPatches and check your patch with
scripts/checkpatch.pl before sending.

Re: [PATCH] fix ZOMBIE state bug in PPPOE driver

From: David Miller <davem@davemloft.net>
Date: 2012-09-19 20:26:25

From: Xiaodong Xu <redacted>
Date: Sun, 16 Sep 2012 10:30:53 +0800
Hi All,

I found a bug in kernel PPPOE driver.
When PPPOE is running over a virtual ethernet interface (e.g., a
bonding interface) and the user tries to delete the interface in case
the PPPOE state is ZOMBIE, the kernel will loop infinitely while
unregistering net_device for the reference count is not reset to zero
which should be done by dev_put().

The following patch could fix this issue:

$ git diff
Please read Documentation/SubmittingPatches in the kernel source tree
to learn how to properly submit a patch.

In particular your patch was missing a proper signoff and your Subject
line is incorrectly specified.

Thanks.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help