Thread (37 messages) 37 messages, 3 authors, 2018-03-05

Re: ppp/pppoe, still panic 4.15.3 in ppp_push

From: Denys Fedoryshchenko <hidden>
Date: 2018-03-01 20:07:09


On 2018-03-01 22:01, Guillaume Nault wrote:
quoted hunk ↗ jump to hunk
On Tue, Feb 27, 2018 at 07:56:27PM +0100, Guillaume Nault wrote:
quoted
On Tue, Feb 27, 2018 at 12:58:55PM +0200, Denys Fedoryshchenko wrote:
quoted
On 2018-02-23 12:07, Guillaume Nault wrote:
quoted
On Fri, Feb 23, 2018 at 11:41:43AM +0200, Denys Fedoryshchenko wrote:
quoted
On 2018-02-23 11:38, Guillaume Nault wrote:
quoted
On Thu, Feb 22, 2018 at 08:51:19PM +0200, Denys Fedoryshchenko wrote:
quoted
I'm using accel-ppp that has unit-cache option, i guess for
"reusing" ppp
interfaces (because creating a lot of interfaces on BRAS with 8k
users quite
expensive).
Maybe it is somehow related and can be that scenario causing this bug?
Indeed, it'd be interesting to know if unit-cache is part of the
equation (if it's workable for you to disable it).
Already did that and testing, unfortunately i had to disable KASAN
and full
refcount, as performance hit is too heavy for me. I will try to
enable KASAN
alone tomorrow.
Don't hesitate to post the result even if you can't afford enabling
KASAN.
Till now 4 days and no reboots.
That unit-cache information was very useful. I can now reproduce the
issue and work on a fix.
You can try the following patch.

Sorry for the delay, I'm a bit out of time these days.
diff --git a/drivers/net/ppp/ppp_generic.c b/drivers/net/ppp/ppp_generic.c
index 255a5def56e9..2acf4b0eabd1 100644
--- a/drivers/net/ppp/ppp_generic.c
+++ b/drivers/net/ppp/ppp_generic.c
@@ -3161,6 +3161,15 @@ ppp_connect_channel(struct channel *pch, int unit)
 		goto outl;

 	ppp_lock(ppp);
+	spin_lock_bh(&pch->downl);
+	if (!pch->chan) {
+		/* Don't connect unregistered channels */
+		ppp_unlock(ppp);
+		spin_unlock_bh(&pch->downl);
+		ret = -ENOTCONN;
+		goto outl;
+	}
+	spin_unlock_bh(&pch->downl);
 	if (pch->file.hdrlen > ppp->file.hdrlen)
 		ppp->file.hdrlen = pch->file.hdrlen;
 	hdrlen = pch->file.hdrlen + 2;	/* for protocol bytes */
Ok, i will try to test that at night.
Thanks a lot! For me also problem solved anyway by removing unit-cache, just i think it's nice to have bug fixed :)
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help