[PATCH nf v2 1/1] netfilter: snmp: Fix one possible panic when snmp_trap_helper fail to register

Subsystems: networking [general], the rest

STALE3420d

5 messages, 3 authors, 2017-03-21 · open the first message on its own page

[PATCH nf v2 1/1] netfilter: snmp: Fix one possible panic when snmp_trap_helper fail to register

From: <hidden>
Date: 2017-03-20 09:55:28

From: Gao Feng <redacted>

In the commit <93557f53e1fb> ("netfilter: nf_conntrack: nf_conntrack snmp
helper"), the snmp_helper is replaced by nf_nat_snmp_hook. So the
snmp_helper is never registered. But it still tries to unregister the
snmp_helper, it could cause the panic.

Now remove the useless snmp_helper and the unregister call in the
error handler.

Fixes: 93557f53e1fb ("netfilter: nf_conntrack: nf_conntrack snmp helper")

Signed-off-by: Gao Feng <redacted>
---
 v2: Add the SHA1 ID in the description, per Sergei
 v1: Initial version

 net/ipv4/netfilter/nf_nat_snmp_basic.c | 14 +-------------
 1 file changed, 1 insertion(+), 13 deletions(-)
diff --git a/net/ipv4/netfilter/nf_nat_snmp_basic.c b/net/ipv4/netfilter/nf_nat_snmp_basic.c
index c9b52c3..5787364 100644
--- a/net/ipv4/netfilter/nf_nat_snmp_basic.c
+++ b/net/ipv4/netfilter/nf_nat_snmp_basic.c
@@ -1260,16 +1260,6 @@ static int help(struct sk_buff *skb, unsigned int protoff,
 	.timeout	= 180,
 };
 
-static struct nf_conntrack_helper snmp_helper __read_mostly = {
-	.me			= THIS_MODULE,
-	.help			= help,
-	.expect_policy		= &snmp_exp_policy,
-	.name			= "snmp",
-	.tuple.src.l3num	= AF_INET,
-	.tuple.src.u.udp.port	= cpu_to_be16(SNMP_PORT),
-	.tuple.dst.protonum	= IPPROTO_UDP,
-};
-
 static struct nf_conntrack_helper snmp_trap_helper __read_mostly = {
 	.me			= THIS_MODULE,
 	.help			= help,
@@ -1294,10 +1284,8 @@ static int __init nf_nat_snmp_basic_init(void)
 	RCU_INIT_POINTER(nf_nat_snmp_hook, help);
 
 	ret = nf_conntrack_helper_register(&snmp_trap_helper);
-	if (ret < 0) {
-		nf_conntrack_helper_unregister(&snmp_helper);
+	if (ret < 0)
 		return ret;
-	}
 	return ret;
 }
 
-- 
1.9.1

Re: [PATCH nf v2 1/1] netfilter: snmp: Fix one possible panic when snmp_trap_helper fail to register

From: Sergei Shtylyov <hidden>
Date: 2017-03-20 10:09:28

On 3/20/2017 12:55 PM, fgao@ikuai8.com wrote:
From: Gao Feng <redacted>

In the commit <93557f53e1fb> ("netfilter: nf_conntrack: nf_conntrack snmp
    Angle brackets not needed. :-)
    The commit citing style is the same as for the Fixes: tag.
helper"), the snmp_helper is replaced by nf_nat_snmp_hook. So the
snmp_helper is never registered. But it still tries to unregister the
snmp_helper, it could cause the panic.

Now remove the useless snmp_helper and the unregister call in the
error handler.

Fixes: 93557f53e1fb ("netfilter: nf_conntrack: nf_conntrack snmp helper")

Signed-off-by: Gao Feng <redacted>
[...]

MBR, Sergei

Re: [PATCH nf v2 1/1] netfilter: snmp: Fix one possible panic when snmp_trap_helper fail to register

From: Feng Gao <hidden>
Date: 2017-03-20 10:17:45

On Mon, Mar 20, 2017 at 6:09 PM, Sergei Shtylyov
[off-list ref] wrote:
On 3/20/2017 12:55 PM, fgao@ikuai8.com wrote:
quoted
From: Gao Feng <redacted>

In the commit <93557f53e1fb> ("netfilter: nf_conntrack: nf_conntrack snmp

   Angle brackets not needed. :-)
   The commit citing style is the same as for the Fixes: tag.
The checkpatch.pl reports the following error, if remove the angle brackets.

ERROR: Please use git commit description style 'commit <12+ chars of
sha1> ("<title line>")' - ie: 'commit fatal: ambig ("evision or path
not in the working tree.")'
#7:
In the commit 93557f53e1fb ("netfilter: nf_conntrack: nf_conntrack snmp

total: 1 errors, 0 warnings, 0 checks, 27 lines checked


Regards
Feng
quoted
helper"), the snmp_helper is replaced by nf_nat_snmp_hook. So the
snmp_helper is never registered. But it still tries to unregister the
snmp_helper, it could cause the panic.

Now remove the useless snmp_helper and the unregister call in the
error handler.

Fixes: 93557f53e1fb ("netfilter: nf_conntrack: nf_conntrack snmp helper")

Signed-off-by: Gao Feng <redacted>
[...]

MBR, Sergei

Re: [PATCH nf v2 1/1] netfilter: snmp: Fix one possible panic when snmp_trap_helper fail to register

From: Sergei Shtylyov <hidden>
Date: 2017-03-20 16:35:43

On 03/20/2017 01:15 PM, Feng Gao wrote:
quoted
quoted
From: Gao Feng <redacted>

In the commit <93557f53e1fb> ("netfilter: nf_conntrack: nf_conntrack snmp

   Angle brackets not needed. :-)
   The commit citing style is the same as for the Fixes: tag.
The checkpatch.pl reports the following error, if remove the angle brackets.
    Because it stops recognizing the commit ID! :-)
ERROR: Please use git commit description style 'commit <12+ chars of
sha1> ("<title line>")' - ie: 'commit fatal: ambig ("evision or path
not in the working tree.")'
    So check the patch in the correct tree because that seems to be the 
problem... Angle brackets are surely not required.
#7:
In the commit 93557f53e1fb ("netfilter: nf_conntrack: nf_conntrack snmp

total: 1 errors, 0 warnings, 0 checks, 27 lines checked


Regards
Feng
[...]

MBR, Sergei

Re: [PATCH nf v2 1/1] netfilter: snmp: Fix one possible panic when snmp_trap_helper fail to register

From: Feng Gao <hidden>
Date: 2017-03-21 00:26:04

On Tue, Mar 21, 2017 at 12:35 AM, Sergei Shtylyov
[off-list ref] wrote:
On 03/20/2017 01:15 PM, Feng Gao wrote:
quoted
quoted
quoted
From: Gao Feng <redacted>

In the commit <93557f53e1fb> ("netfilter: nf_conntrack: nf_conntrack
snmp


   Angle brackets not needed. :-)
   The commit citing style is the same as for the Fixes: tag.

The checkpatch.pl reports the following error, if remove the angle
brackets.

   Because it stops recognizing the commit ID! :-)
quoted
ERROR: Please use git commit description style 'commit <12+ chars of
sha1> ("<title line>")' - ie: 'commit fatal: ambig ("evision or path
not in the working tree.")'

   So check the patch in the correct tree because that seems to be the
problem... Angle brackets are surely not required.
Actually I didn't add the angle brackets firstly, but it fail to pass
the check_patch.pl check.
So I had to modify it.

Ok, I removed the angle brackets now, just ignored the error report of
check_patch.pl.

Best Regards
Feng
quoted
#7:
In the commit 93557f53e1fb ("netfilter: nf_conntrack: nf_conntrack snmp

total: 1 errors, 0 warnings, 0 checks, 27 lines checked


Regards
Feng

[...]

MBR, Sergei
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help