Received: by 10.213.65.68 with SMTP id h4csp2114575imn; Sun, 8 Apr 2018 20:04:51 -0700 (PDT) X-Google-Smtp-Source: AIpwx49Og44QYF8iIaF9Xxk2RofNdjOm5FQyW+wxbHZGgEn0vr1nQpYsM7+BZ1yIUHSJ0ThKQ7TR X-Received: by 10.98.60.207 with SMTP id b76mr28046053pfk.118.1523243091738; Sun, 08 Apr 2018 20:04:51 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1523243091; cv=none; d=google.com; s=arc-20160816; b=KCC/hvQyFANE+QzD7neefDqbCwZXMAWAFPKvEvsxnkgost/0kZVGpg4M9a7dZpfHsd lgzePk/82i2ggJXJtyKbRvpwt0cL4rOBbkz36CpIm2a0qsd4ChpbQLAJ2nohfnqKYS16 TOE4+KN/gFnMyBskYzkL5QQAtbo792jg2Agmes6/5EScx6ToSHa6Cgl1CNg+N/4lNHGc cB2ngkWCaVKtzf+Q4euTiaPwcxkXaZft6Bx0v3JZrGNB4+c9B7qZKROfq2rtbh/sdjCw dsDZwKnVXseVPiS529a9qTbuyJJTun+52BK5AUkfHEe7cMrCDW43Xj5g36m5ZGarsx9F 8RqA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:mime-version:content-transfer-encoding :spamdiagnosticmetadata:spamdiagnosticoutput:content-language :accept-language:in-reply-to:references:message-id:date:thread-index :thread-topic:subject:cc:to:from:dkim-signature :arc-authentication-results; bh=Oo6K1AURdv37HGXcYzUo02YUdWsfHu3JUUKvzXhPQWw=; b=ECVvCAfYofzht4ucs8BDwpck1hDBqqk1auhXrvO/cCAJeUBZbWxojmKafwgOnxF7bS tn+JtlYshy/kQy/PrrYLySrh6tHG6TUDby3YHf3c2E2bo/MOp3bqFAZArxBc8KaT2abD aj6qSgc2gWW3xa+u63gMs7FtK2ymxWfh5i6TFBREbvhzRhLP6rG8ObtMb31JN4wvAviJ 8SsInUGSTbG7KvohG8eEPSOLS1wflaviEFureFFarqlp41+D/vtbmnqDBygzFUNnROtz GPIPZdZK7PgJteX/KamaUDbdHsu6FZNvvIQn99EBxW8oUghqCzigz8Vi1QjtUOP7WeRw QoWQ== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@microsoft.com header.s=selector1 header.b=joYDN01h; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=microsoft.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id c12-v6si12980878pll.498.2018.04.08.20.04.14; Sun, 08 Apr 2018 20:04:51 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@microsoft.com header.s=selector1 header.b=joYDN01h; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=microsoft.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S932621AbeDIAgR (ORCPT + 99 others); Sun, 8 Apr 2018 20:36:17 -0400 Received: from mail-cys01nam02on0106.outbound.protection.outlook.com ([104.47.37.106]:1992 "EHLO NAM02-CY1-obe.outbound.protection.outlook.com" rhost-flags-OK-OK-OK-FAIL) by vger.kernel.org with ESMTP id S1756700AbeDIAgO (ORCPT ); Sun, 8 Apr 2018 20:36:14 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=Oo6K1AURdv37HGXcYzUo02YUdWsfHu3JUUKvzXhPQWw=; b=joYDN01h0d8K7EN5yw2xMakXj2C2340qJunJpQxWNS7GGA6sBlZ7A5vJi4A2mJxnfjfJcAbJz0V784XN4AZgicwOl+2D3eK1qdiI4F1GAXF85fYfSl9ZvydwIMzVTq9bgv1sO4Or+08FNeEtUpwMr3T0Yytzt6eyJOxSTi4EyzU= Received: from DM5PR2101MB1032.namprd21.prod.outlook.com (52.132.128.13) by DM5PR2101MB1015.namprd21.prod.outlook.com (52.132.133.37) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.696.0; Mon, 9 Apr 2018 00:36:11 +0000 Received: from DM5PR2101MB1032.namprd21.prod.outlook.com ([fe80::8109:aef0:a777:7059]) by DM5PR2101MB1032.namprd21.prod.outlook.com ([fe80::8109:aef0:a777:7059%2]) with mapi id 15.20.0696.003; Mon, 9 Apr 2018 00:36:11 +0000 From: Sasha Levin To: "stable@vger.kernel.org" , "linux-kernel@vger.kernel.org" CC: Xin Long , "David S . Miller" , Sasha Levin Subject: [PATCH AUTOSEL for 4.4 057/162] dccp: call inet_add_protocol after register_pernet_subsys in dccp_v4_init Thread-Topic: [PATCH AUTOSEL for 4.4 057/162] dccp: call inet_add_protocol after register_pernet_subsys in dccp_v4_init Thread-Index: AQHTz5mrrZZndyU7cEWJn7bCpnwPMQ== Date: Mon, 9 Apr 2018 00:28:23 +0000 Message-ID: <20180409002738.163941-57-alexander.levin@microsoft.com> References: <20180409002738.163941-1-alexander.levin@microsoft.com> In-Reply-To: <20180409002738.163941-1-alexander.levin@microsoft.com> Accept-Language: en-US Content-Language: en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: x-originating-ip: [52.168.54.252] x-ms-publictraffictype: Email x-microsoft-exchange-diagnostics: 1;DM5PR2101MB1015;7:wF9UZK1O7WfvKKECzC7x/6M5Ou9TbjUY10EY/LY0vUCfO25kx19m0Yvq8d8YgEFxK4sGCylBdgcs4SmdxxCJk4kRkvUzZraQ7rXcHojVgaiYYHtPKeEQJrBkB/qHMu5FryY4BEmszSt2dm4CAxQ+jcaxF9U7B769+wo4HA91KsGqhXSJ7srSuI7GnPziY4X79F71Y7y2MOqt8I2PEn4/Pd5KXxQFZOxzpWHy+ep7+zavk4VVQ/DMfD8NaF7vZJEU;20:mLXeEsSTt7JTnvvX0TUQ86iO7qgdOarPfJUCL3ONp1R8uoIbjSorDERDYvV0EcySxwnNh6/7bWD8uVDVsu4noWb/D2/t4/J2vnL8axEKBGm0BbvLEOsZuUNsYnWrZRf9lJalzrAko4/5FrZardHVcXS1n3Tm15BW0SMLxRVC3fA= x-ms-office365-filtering-ht: Tenant X-MS-Office365-Filtering-Correlation-Id: 6d58481b-2c20-47c0-8bc0-08d59db1e46e x-microsoft-antispam: UriScan:;BCL:0;PCL:0;RULEID:(7020095)(4652020)(48565401081)(5600026)(4604075)(3008032)(4534165)(4627221)(201703031133081)(201702281549075)(2017052603328)(7193020);SRVR:DM5PR2101MB1015; x-ms-traffictypediagnostic: DM5PR2101MB1015: authentication-results: spf=none (sender IP is ) smtp.mailfrom=Alexander.Levin@microsoft.com; x-microsoft-antispam-prvs: x-exchange-antispam-report-test: UriScan:(28532068793085)(89211679590171)(85827821059158); x-exchange-antispam-report-cfa-test: BCL:0;PCL:0;RULEID:(8211001083)(61425038)(6040522)(2401047)(8121501046)(5005006)(3231221)(944501327)(52105095)(3002001)(93006095)(93001095)(10201501046)(6055026)(61426038)(61427038)(6041310)(20161123560045)(20161123564045)(20161123558120)(20161123562045)(201703131423095)(201702281528075)(20161123555045)(201703061421075)(201703061406153)(6072148)(201708071742011);SRVR:DM5PR2101MB1015;BCL:0;PCL:0;RULEID:;SRVR:DM5PR2101MB1015; x-forefront-prvs: 0637FCE711 x-forefront-antispam-report: SFV:NSPM;SFS:(10019020)(396003)(39860400002)(39380400002)(376002)(346002)(366004)(189003)(199004)(53936002)(4326008)(478600001)(72206003)(3280700002)(2616005)(14454004)(305945005)(5250100002)(3660700001)(2501003)(2900100001)(54906003)(110136005)(86362001)(1076002)(107886003)(6506007)(36756003)(446003)(68736007)(6512007)(7736002)(486006)(2906002)(5660300001)(6436002)(3846002)(86612001)(6486002)(66066001)(11346002)(476003)(6666003)(59450400001)(26005)(10090500001)(316002)(22452003)(8676002)(81156014)(81166006)(6116002)(105586002)(99286004)(186003)(106356001)(76176011)(39060400002)(25786009)(97736004)(10290500003)(102836004)(8936002)(22906009)(217873001);DIR:OUT;SFP:1102;SCL:1;SRVR:DM5PR2101MB1015;H:DM5PR2101MB1032.namprd21.prod.outlook.com;FPR:;SPF:None;LANG:en;PTR:InfoNoRecords;MX:1;A:1; received-spf: None (protection.outlook.com: microsoft.com does not designate permitted sender hosts) x-microsoft-antispam-message-info: hiUVsXYalumlqE1vrJmEHgBT1Q+RD9eaDnmYb3GEI9kJIgTznpumU6w1uGLT5tcy68WGzlNLVlC/Vnnb+zEtj3dHcVQhKLtsZ9XPN6xHsx0RI5c/94mqe6+nT5vdpjOD76MpupM1wxQBUcACQHRyRsd+eaoHvDcNiR9s88BDygs7ZLEt5YZO0FS24oP3eZDosH9XYAD2jB/nJXOknH9EB9yVWDaJZqEehmhSIEMJ5uAlLS4dP9Q+jOlpNZLodde1O53O4cfQyHDJeubHKFjbj5lD8ntuTJkoA4DOkPI44fWpM0Mw0oIRZqvbpxOdhD6r46X1vIxkVAdcc+YXbiKUedcbk8WEP9FtmJYhwL9LczqUB+hmYN9k1kglOSzGs7/phNg7IAfhFRPW/dG+Qg+kfOcxtuKv8IwnRhxCYWpANs0= spamdiagnosticoutput: 1:99 spamdiagnosticmetadata: NSPM Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 X-OriginatorOrg: microsoft.com X-MS-Exchange-CrossTenant-Network-Message-Id: 6d58481b-2c20-47c0-8bc0-08d59db1e46e X-MS-Exchange-CrossTenant-originalarrivaltime: 09 Apr 2018 00:28:23.7550 (UTC) X-MS-Exchange-CrossTenant-fromentityheader: Hosted X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47 X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM5PR2101MB1015 Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org From: Xin Long [ Upstream commit d5494acb88aa9dd1325079c9b8855008a52c19b3 ] Now dccp_ipv4 works as a kernel module. During loading this module, if one dccp packet is being recieved after inet_add_protocol but before register_pernet_subsys in which v4_ctl_sk is initialized, a null pointer dereference may be triggered because of init_net.dccp.v4_ctl_sk is 0x0. Jianlin found this issue when the following call trace occurred: [ 171.950177] BUG: unable to handle kernel NULL pointer dereference at 000= 0000000000110 [ 171.951007] IP: [] dccp_v4_ctl_send_reset+0xc4/0x220 [= dccp_ipv4] [...] [ 171.984629] Call Trace: [ 171.984859] [ 171.985061] [ 171.985213] [] dccp_v4_rcv+0x383/0x3f9 [dccp_ipv4] [ 171.985711] [] ip_local_deliver_finish+0xb4/0x1f0 [ 171.986309] [] ip_local_deliver+0x59/0xd0 [ 171.986852] [] ? update_curr+0x104/0x190 [ 171.986956] [] ip_rcv_finish+0x8a/0x350 [ 171.986956] [] ip_rcv+0x2b6/0x410 [ 171.986956] [] ? task_cputime+0x44/0x80 [ 171.986956] [] __netif_receive_skb_core+0x572/0x7c0 [ 171.986956] [] ? trigger_load_balance+0x61/0x1e0 [ 171.986956] [] __netif_receive_skb+0x18/0x60 [ 171.986956] [] process_backlog+0xae/0x180 [ 171.986956] [] net_rx_action+0x16d/0x380 [ 171.986956] [] __do_softirq+0xef/0x280 [ 171.986956] [] call_softirq+0x1c/0x30 This patch is to move inet_add_protocol after register_pernet_subsys in dccp_v4_init, so that v4_ctl_sk is initialized before any incoming dccp packets are processed. Reported-by: Jianlin Shi Signed-off-by: Xin Long Signed-off-by: David S. Miller Signed-off-by: Sasha Levin --- net/dccp/ipv4.c | 17 +++++++++-------- 1 file changed, 9 insertions(+), 8 deletions(-) diff --git a/net/dccp/ipv4.c b/net/dccp/ipv4.c index 6eb2bbf9873b..dfda437cd86b 100644 --- a/net/dccp/ipv4.c +++ b/net/dccp/ipv4.c @@ -1033,33 +1033,34 @@ static int __init dccp_v4_init(void) { int err =3D proto_register(&dccp_v4_prot, 1); =20 - if (err !=3D 0) + if (err) goto out; =20 - err =3D inet_add_protocol(&dccp_v4_protocol, IPPROTO_DCCP); - if (err !=3D 0) - goto out_proto_unregister; - inet_register_protosw(&dccp_v4_protosw); =20 err =3D register_pernet_subsys(&dccp_v4_ops); if (err) goto out_destroy_ctl_sock; + + err =3D inet_add_protocol(&dccp_v4_protocol, IPPROTO_DCCP); + if (err) + goto out_proto_unregister; + out: return err; +out_proto_unregister: + unregister_pernet_subsys(&dccp_v4_ops); out_destroy_ctl_sock: inet_unregister_protosw(&dccp_v4_protosw); - inet_del_protocol(&dccp_v4_protocol, IPPROTO_DCCP); -out_proto_unregister: proto_unregister(&dccp_v4_prot); goto out; } =20 static void __exit dccp_v4_exit(void) { + inet_del_protocol(&dccp_v4_protocol, IPPROTO_DCCP); unregister_pernet_subsys(&dccp_v4_ops); inet_unregister_protosw(&dccp_v4_protosw); - inet_del_protocol(&dccp_v4_protocol, IPPROTO_DCCP); proto_unregister(&dccp_v4_prot); } =20 --=20 2.15.1