forked from luck/tmp_suning_uos_patched
9ac0be9d4f
commit 8d5cf596d1
started to add statically
allocated ax25_protocol's to list. However kfree() was still in place waiting
for unsuspecting ones on module removal.
Steps to reproduce:
modprobe netrom
rmmod netrom
P.S.: code would benefit greatly from list_add/list_del usage
kernel BUG at mm/slab.c:592!
invalid opcode: 0000 [1] PREEMPT SMP
CPU 0
Modules linked in: netrom ax25 af_packet usbcore rtc_cmos rtc_core rtc_lib
Pid: 4477, comm: rmmod Not tainted 2.6.23-rc3-bloat #2
RIP: 0010:[<ffffffff802ac646>] [<ffffffff802ac646>] kfree+0x1c6/0x260
RSP: 0000:ffff810079a05e48 EFLAGS: 00010046
RAX: 0000000000000000 RBX: 0000000000000000 RCX: ffff81000000c000
RDX: ffff81007e552458 RSI: 0000000000000000 RDI: 000000000000805d
RBP: ffff810079a05e88 R08: 0000000000000001 R09: 0000000000000000
R10: 0000000000000001 R11: 0000000000000000 R12: ffffffff8805d080
R13: ffffffff8805d080 R14: 0000000000000000 R15: 0000000000000282
FS: 00002b73fc98aae0(0000) GS:ffffffff805dc000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 000000008005003b
CR2: 000000000053f3b8 CR3: 0000000079ff2000 CR4: 00000000000006e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000400
Process rmmod (pid: 4477, threadinfo ffff810079a04000, task ffff8100775aa480)
Stack: ffff810079a05e68 0000000000000246 ffffffff8804eca0 0000000000000000
ffffffff8805d080 00000000000000cf 0000000000000000 0000000000000880
ffff810079a05eb8 ffffffff8803ec90 ffff810079a05eb8 0000000000000000
Call Trace:
[<ffffffff8803ec90>] :ax25:ax25_protocol_release+0xa0/0xb0
[<ffffffff88056ecb>] :netrom:nr_exit+0x6b/0xf0
[<ffffffff80268bf0>] sys_delete_module+0x170/0x1f0
[<ffffffff8025da35>] trace_hardirqs_on+0xd5/0x170
[<ffffffff804835aa>] trace_hardirqs_on_thunk+0x35/0x37
[<ffffffff8020c13e>] system_call+0x7e/0x83
Code: 0f 0b eb fe 66 66 90 66 66 90 48 8b 52 10 48 8b 02 25 00 40
RIP [<ffffffff802ac646>] kfree+0x1c6/0x260
RSP <ffff810079a05e48>
Kernel panic - not syncing: Fatal exception
Signed-off-by: Alexey Dobriyan <adobriyan@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
223 lines
5.1 KiB
C
223 lines
5.1 KiB
C
/*
|
|
* This program is free software; you can redistribute it and/or modify
|
|
* it under the terms of the GNU General Public License as published by
|
|
* the Free Software Foundation; either version 2 of the License, or
|
|
* (at your option) any later version.
|
|
*
|
|
* Copyright (C) Jonathan Naylor G4KLX (g4klx@g4klx.demon.co.uk)
|
|
*/
|
|
#include <linux/errno.h>
|
|
#include <linux/types.h>
|
|
#include <linux/socket.h>
|
|
#include <linux/in.h>
|
|
#include <linux/kernel.h>
|
|
#include <linux/module.h>
|
|
#include <linux/spinlock.h>
|
|
#include <linux/timer.h>
|
|
#include <linux/string.h>
|
|
#include <linux/sockios.h>
|
|
#include <linux/net.h>
|
|
#include <net/ax25.h>
|
|
#include <linux/inet.h>
|
|
#include <linux/netdevice.h>
|
|
#include <linux/skbuff.h>
|
|
#include <net/sock.h>
|
|
#include <asm/uaccess.h>
|
|
#include <asm/system.h>
|
|
#include <linux/fcntl.h>
|
|
#include <linux/mm.h>
|
|
#include <linux/interrupt.h>
|
|
|
|
static struct ax25_protocol *protocol_list;
|
|
static DEFINE_RWLOCK(protocol_list_lock);
|
|
|
|
static HLIST_HEAD(ax25_linkfail_list);
|
|
static DEFINE_SPINLOCK(linkfail_lock);
|
|
|
|
static struct listen_struct {
|
|
struct listen_struct *next;
|
|
ax25_address callsign;
|
|
struct net_device *dev;
|
|
} *listen_list = NULL;
|
|
static DEFINE_SPINLOCK(listen_lock);
|
|
|
|
/*
|
|
* Do not register the internal protocols AX25_P_TEXT, AX25_P_SEGMENT,
|
|
* AX25_P_IP or AX25_P_ARP ...
|
|
*/
|
|
void ax25_register_pid(struct ax25_protocol *ap)
|
|
{
|
|
write_lock_bh(&protocol_list_lock);
|
|
ap->next = protocol_list;
|
|
protocol_list = ap;
|
|
write_unlock_bh(&protocol_list_lock);
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(ax25_register_pid);
|
|
|
|
void ax25_protocol_release(unsigned int pid)
|
|
{
|
|
struct ax25_protocol *s, *protocol;
|
|
|
|
write_lock_bh(&protocol_list_lock);
|
|
protocol = protocol_list;
|
|
if (protocol == NULL) {
|
|
write_unlock_bh(&protocol_list_lock);
|
|
return;
|
|
}
|
|
|
|
if (protocol->pid == pid) {
|
|
protocol_list = protocol->next;
|
|
write_unlock_bh(&protocol_list_lock);
|
|
return;
|
|
}
|
|
|
|
while (protocol != NULL && protocol->next != NULL) {
|
|
if (protocol->next->pid == pid) {
|
|
s = protocol->next;
|
|
protocol->next = protocol->next->next;
|
|
write_unlock_bh(&protocol_list_lock);
|
|
return;
|
|
}
|
|
|
|
protocol = protocol->next;
|
|
}
|
|
write_unlock_bh(&protocol_list_lock);
|
|
}
|
|
|
|
EXPORT_SYMBOL(ax25_protocol_release);
|
|
|
|
void ax25_linkfail_register(struct ax25_linkfail *lf)
|
|
{
|
|
spin_lock_bh(&linkfail_lock);
|
|
hlist_add_head(&lf->lf_node, &ax25_linkfail_list);
|
|
spin_unlock_bh(&linkfail_lock);
|
|
}
|
|
|
|
EXPORT_SYMBOL(ax25_linkfail_register);
|
|
|
|
void ax25_linkfail_release(struct ax25_linkfail *lf)
|
|
{
|
|
spin_lock_bh(&linkfail_lock);
|
|
hlist_del_init(&lf->lf_node);
|
|
spin_unlock_bh(&linkfail_lock);
|
|
}
|
|
|
|
EXPORT_SYMBOL(ax25_linkfail_release);
|
|
|
|
int ax25_listen_register(ax25_address *callsign, struct net_device *dev)
|
|
{
|
|
struct listen_struct *listen;
|
|
|
|
if (ax25_listen_mine(callsign, dev))
|
|
return 0;
|
|
|
|
if ((listen = kmalloc(sizeof(*listen), GFP_ATOMIC)) == NULL)
|
|
return -ENOMEM;
|
|
|
|
listen->callsign = *callsign;
|
|
listen->dev = dev;
|
|
|
|
spin_lock_bh(&listen_lock);
|
|
listen->next = listen_list;
|
|
listen_list = listen;
|
|
spin_unlock_bh(&listen_lock);
|
|
|
|
return 0;
|
|
}
|
|
|
|
EXPORT_SYMBOL(ax25_listen_register);
|
|
|
|
void ax25_listen_release(ax25_address *callsign, struct net_device *dev)
|
|
{
|
|
struct listen_struct *s, *listen;
|
|
|
|
spin_lock_bh(&listen_lock);
|
|
listen = listen_list;
|
|
if (listen == NULL) {
|
|
spin_unlock_bh(&listen_lock);
|
|
return;
|
|
}
|
|
|
|
if (ax25cmp(&listen->callsign, callsign) == 0 && listen->dev == dev) {
|
|
listen_list = listen->next;
|
|
spin_unlock_bh(&listen_lock);
|
|
kfree(listen);
|
|
return;
|
|
}
|
|
|
|
while (listen != NULL && listen->next != NULL) {
|
|
if (ax25cmp(&listen->next->callsign, callsign) == 0 && listen->next->dev == dev) {
|
|
s = listen->next;
|
|
listen->next = listen->next->next;
|
|
spin_unlock_bh(&listen_lock);
|
|
kfree(s);
|
|
return;
|
|
}
|
|
|
|
listen = listen->next;
|
|
}
|
|
spin_unlock_bh(&listen_lock);
|
|
}
|
|
|
|
EXPORT_SYMBOL(ax25_listen_release);
|
|
|
|
int (*ax25_protocol_function(unsigned int pid))(struct sk_buff *, ax25_cb *)
|
|
{
|
|
int (*res)(struct sk_buff *, ax25_cb *) = NULL;
|
|
struct ax25_protocol *protocol;
|
|
|
|
read_lock(&protocol_list_lock);
|
|
for (protocol = protocol_list; protocol != NULL; protocol = protocol->next)
|
|
if (protocol->pid == pid) {
|
|
res = protocol->func;
|
|
break;
|
|
}
|
|
read_unlock(&protocol_list_lock);
|
|
|
|
return res;
|
|
}
|
|
|
|
int ax25_listen_mine(ax25_address *callsign, struct net_device *dev)
|
|
{
|
|
struct listen_struct *listen;
|
|
|
|
spin_lock_bh(&listen_lock);
|
|
for (listen = listen_list; listen != NULL; listen = listen->next)
|
|
if (ax25cmp(&listen->callsign, callsign) == 0 &&
|
|
(listen->dev == dev || listen->dev == NULL)) {
|
|
spin_unlock_bh(&listen_lock);
|
|
return 1;
|
|
}
|
|
spin_unlock_bh(&listen_lock);
|
|
|
|
return 0;
|
|
}
|
|
|
|
void ax25_link_failed(ax25_cb *ax25, int reason)
|
|
{
|
|
struct ax25_linkfail *lf;
|
|
struct hlist_node *node;
|
|
|
|
spin_lock_bh(&linkfail_lock);
|
|
hlist_for_each_entry(lf, node, &ax25_linkfail_list, lf_node)
|
|
lf->func(ax25, reason);
|
|
spin_unlock_bh(&linkfail_lock);
|
|
}
|
|
|
|
int ax25_protocol_is_registered(unsigned int pid)
|
|
{
|
|
struct ax25_protocol *protocol;
|
|
int res = 0;
|
|
|
|
read_lock_bh(&protocol_list_lock);
|
|
for (protocol = protocol_list; protocol != NULL; protocol = protocol->next)
|
|
if (protocol->pid == pid) {
|
|
res = 1;
|
|
break;
|
|
}
|
|
read_unlock_bh(&protocol_list_lock);
|
|
|
|
return res;
|
|
}
|