From: Arnaldo Carvalho de Melo <acme@kernel.org> Date: 2017-03-01 15:35:21
Em Wed, Mar 01, 2017 at 10:38:54AM +0100, Dmitry Vyukov escreveu:
Hello,
I've got the following report while running syzkaller fuzzer on
86292b33d4b79ee03e2f43ea0381ef85f077c760:
It seems that dccp_create_openreq_child needs to unlock the sock if
dccp_feat_activate_values fails.
Yeah, can you please use the patch below, that mimics the error paths in
sk_clone_new(), from where I think even the comment about it being a raw
copy came, but the bh_unlock_sock() didn't?
- Arnaldo
@@ -122,6 +122,7 @@ struct sock *dccp_create_openreq_child(const struct sock *sk,/* It is still raw copy of parent, so invalidate*destructorandmakeplainsk_free()*/newsk->sk_destruct=NULL;+bh_unlock_sock(newsk);sk_free(newsk);returnNULL;}
From: Arnaldo Carvalho de Melo <acme@kernel.org> Date: 2017-03-01 15:40:23
Em Wed, Mar 01, 2017 at 12:35:10PM -0300, Arnaldo Carvalho de Melo escreveu:
Em Wed, Mar 01, 2017 at 10:38:54AM +0100, Dmitry Vyukov escreveu:
quoted
Hello,
I've got the following report while running syzkaller fuzzer on
86292b33d4b79ee03e2f43ea0381ef85f077c760:
It seems that dccp_create_openreq_child needs to unlock the sock if
dccp_feat_activate_values fails.
Yeah, can you please use the patch below, that mimics the error paths in
sk_clone_new(), from where I think even the comment about it being a raw
@@ -122,6 +122,7 @@ struct sock *dccp_create_openreq_child(const struct sock *sk,/* It is still raw copy of parent, so invalidate*destructorandmakeplainsk_free()*/newsk->sk_destruct=NULL;+bh_unlock_sock(newsk);sk_free(newsk);returnNULL;}
On Wed, Mar 1, 2017 at 4:40 PM, Arnaldo Carvalho de Melo
[off-list ref] wrote:
Em Wed, Mar 01, 2017 at 12:35:10PM -0300, Arnaldo Carvalho de Melo escreveu:
quoted
Em Wed, Mar 01, 2017 at 10:38:54AM +0100, Dmitry Vyukov escreveu:
quoted
Hello,
I've got the following report while running syzkaller fuzzer on
86292b33d4b79ee03e2f43ea0381ef85f077c760:
It seems that dccp_create_openreq_child needs to unlock the sock if
dccp_feat_activate_values fails.
Yeah, can you please use the patch below, that mimics the error paths in
sk_clone_new(), from where I think even the comment about it being a raw
Argh, s/sk_clone_new()/sk_clone_lock()/g
Hi Arnaldo,
Could you send the patch?
We haven't seen these reports since we applied it.
Thanks!
- Arnaldo
quoted
copy came, but the bh_unlock_sock() didn't?
- Arnaldo
@@ -122,6 +122,7 @@ struct sock *dccp_create_openreq_child(const struct sock *sk,/* It is still raw copy of parent, so invalidate*destructorandmakeplainsk_free()*/newsk->sk_destruct=NULL;+bh_unlock_sock(newsk);sk_free(newsk);returnNULL;}
--
You received this message because you are subscribed to the Google Groups "syzkaller" group.
To unsubscribe from this group and stop receiving emails from it, send an email to syzkaller+unsubscribe@googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
On Wed, Mar 1, 2017 at 4:40 PM, Arnaldo Carvalho de Melo
[off-list ref] wrote:
quoted
Em Wed, Mar 01, 2017 at 12:35:10PM -0300, Arnaldo Carvalho de Melo escreveu:
quoted
Em Wed, Mar 01, 2017 at 10:38:54AM +0100, Dmitry Vyukov escreveu:
quoted
Hello,
I've got the following report while running syzkaller fuzzer on
86292b33d4b79ee03e2f43ea0381ef85f077c760:
It seems that dccp_create_openreq_child needs to unlock the sock if
dccp_feat_activate_values fails.
Yeah, can you please use the patch below, that mimics the error paths in
sk_clone_new(), from where I think even the comment about it being a raw
Argh, s/sk_clone_new()/sk_clone_lock()/g
Hi Arnaldo,
Could you send the patch?
We haven't seen these reports since we applied it.
It isn't necessary in the current tree.
Arnaldo created a helper sk_free_unlock_clone() which handles this situation
properly, and calls it from dccp_create_openreq_child().
On Wed, Mar 1, 2017 at 4:40 PM, Arnaldo Carvalho de Melo
[off-list ref] wrote:
quoted
Em Wed, Mar 01, 2017 at 12:35:10PM -0300, Arnaldo Carvalho de Melo escreveu:
quoted
Em Wed, Mar 01, 2017 at 10:38:54AM +0100, Dmitry Vyukov escreveu:
quoted
Hello,
I've got the following report while running syzkaller fuzzer on
86292b33d4b79ee03e2f43ea0381ef85f077c760:
It seems that dccp_create_openreq_child needs to unlock the sock if
dccp_feat_activate_values fails.
Yeah, can you please use the patch below, that mimics the error paths in
sk_clone_new(), from where I think even the comment about it being a raw
Argh, s/sk_clone_new()/sk_clone_lock()/g
Hi Arnaldo,
Could you send the patch?
We haven't seen these reports since we applied it.
It isn't necessary in the current tree.
Arnaldo created a helper sk_free_unlock_clone() which handles this situation
properly, and calls it from dccp_create_openreq_child().
On Wed, Mar 1, 2017 at 4:35 PM, Arnaldo Carvalho de Melo
[off-list ref] wrote:
quoted hunk
Em Wed, Mar 01, 2017 at 10:38:54AM +0100, Dmitry Vyukov escreveu:
quoted
Hello,
I've got the following report while running syzkaller fuzzer on
86292b33d4b79ee03e2f43ea0381ef85f077c760:
It seems that dccp_create_openreq_child needs to unlock the sock if
dccp_feat_activate_values fails.
Yeah, can you please use the patch below, that mimics the error paths in
sk_clone_new(), from where I think even the comment about it being a raw
copy came, but the bh_unlock_sock() didn't?
- Arnaldo
@@ -122,6 +122,7 @@ struct sock *dccp_create_openreq_child(const struct sock *sk,/* It is still raw copy of parent, so invalidate*destructorandmakeplainsk_free()*/newsk->sk_destruct=NULL;+bh_unlock_sock(newsk);sk_free(newsk);returnNULL;}
Applied the patch on bots. Will report if it happens again.