Thread (16 messages) 16 messages, 8 authors, 2017-10-26

Re: v4.14-rc3/arm64 DABT exception in atomic_inc() / __skb_clone()

From: Willem de Bruijn <willemdebruijn.kernel@gmail.com>
Date: 2017-10-25 18:24:47
Also in: linux-arm-kernel, lkml

On Sat, Oct 21, 2017 at 9:56 PM, Wei Wei [off-list ref] wrote:
I have uploaded the VM core dump [1]. And I don’t know if these logs are helpful in the case of
failing to get the C reproducer currently.

[1] https://github.com/dotweiba/skb_clone_atomic_inc_bug/blob/master/vmcore.gz
Thanks. So this would be the atomic_inc on shb_shinfo(skb)->dataref, which
matches the __ll_sc_atomic_add in Mark's trace.

Debugging with crash shows 0xffff800071bb3180 and 0xffff800071bb2c80
to be valid skbuffs of len 40, no sk, both pointing to the same head.

That is indeed unaligned:  head = 0xffff8000327c80c9 "", end = 256, giving
skb_shared_info at 0xffff8000327c81c9 and  &skb_shared_info(skb)->dataref
at 0xffff8000327c81c9 + 36 == 0xffff8000327c81ed
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help