Re: [patch 00/50] 2.6.25.6 -stable review

!MAILaRCHIVE_VOTE_RePLACE
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Marco Berizzi <pupilla@...>
Cc: David Miller <davem@...>, <linux-kernel@...>, <netdev@...>, Chris Wright <chrisw@...>
Date: Sunday, June 8, 2008 - 8:36 am

On Sun, Jun 08, 2008 at 01:56:01PM +0200, Marco Berizzi wrote:

Indeed. Most likely it was simply lost somewhere in the e-mail chain.
Then best thing to do is to retransmit it for next batch of patches.
Chris, here's the fix in question.

Thanks,
Willy
--

From 1ac06e0306d0192a7a4d9ea1c9e06d355ce7e7d3 Mon Sep 17 00:00:00 2001
From: Herbert Xu <herbert@gondor.apana.org.au>
Date: Tue, 20 May 2008 14:32:14 -0700
Subject: ipsec: Use the correct ip_local_out function

Because the IPsec output function xfrm_output_resume does its
own dst_output call it should always call __ip_local_output
instead of ip_local_output as the latter may invoke dst_output
directly.  Otherwise the return values from nf_hook and dst_output
may clash as they both use the value 1 but for different purposes.

When that clash occurs this can cause a packet to be used after
it has been freed which usually leads to a crash.  Because the
offending value is only returned from dst_output with qdiscs
such as HTB, this bug is normally not visible.

Thanks to Marco Berizzi for his perseverance in tracking this
down.

Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: David S. Miller <davem@davemloft.net>
---
 net/ipv4/route.c |    2 +-
 net/ipv6/route.c |    2 +-
 2 files changed, 2 insertions(+), 2 deletions(-)

diff --git a/net/ipv4/route.c b/net/ipv4/route.c
index 92f90ae..df41026 100644
--- a/net/ipv4/route.c
+++ b/net/ipv4/route.c
@@ -160,7 +160,7 @@ static struct dst_ops ipv4_dst_ops = {
 	.negative_advice =	ipv4_negative_advice,
 	.link_failure =		ipv4_link_failure,
 	.update_pmtu =		ip_rt_update_pmtu,
-	.local_out =		ip_local_out,
+	.local_out =		__ip_local_out,
 	.entry_size =		sizeof(struct rtable),
 	.entries =		ATOMIC_INIT(0),
 };
diff --git a/net/ipv6/route.c b/net/ipv6/route.c
index b7a4a87..48534c6 100644
--- a/net/ipv6/route.c
+++ b/net/ipv6/route.c
@@ -109,7 +109,7 @@ static struct dst_ops ip6_dst_ops_template = {
 	.negative_advice	=	ip6_negative_advice,
 	.link_failure		=	ip6_link_failure,
 	.update_pmtu		=	ip6_rt_update_pmtu,
-	.local_out		=	ip6_local_out,
+	.local_out		=	__ip6_local_out,
 	.entry_size		=	sizeof(struct rt6_info),
 	.entries		=	ATOMIC_INIT(0),
 };
-- 
1.5.3.8

--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: [patch 00/50] 2.6.25.6 -stable review, Marco Berizzi, (Sun Jun 8, 7:56 am)
Re: [patch 00/50] 2.6.25.6 -stable review, Willy Tarreau, (Sun Jun 8, 8:36 am)
Re: [patch 00/50] 2.6.25.6 -stable review, David Miller, (Sun Jun 8, 10:10 am)
Re: [patch 00/50] 2.6.25.6 -stable review, Jay Cliburn, (Sun Jun 8, 11:38 am)
Re: [patch 00/50] 2.6.25.6 -stable review, Jeff Garzik, (Sun Jun 8, 4:07 pm)
Re: [patch 00/50] 2.6.25.6 -stable review, David Miller, (Sun Jun 8, 10:26 pm)
Re: [patch 00/50] 2.6.25.6 -stable review, Willy Tarreau, (Sun Jun 8, 12:06 pm)
Re: [patch 00/50] 2.6.25.6 -stable review, Willy Tarreau, (Sun Jun 8, 10:19 am)