mirror of
				https://git.kernel.org/pub/scm/linux/kernel/git/chenhuacai/linux-loongson
				synced 2025-10-31 03:13:59 +00:00 
			
		
		
		
	 9ac0be9d4f
			
		
	
	
		9ac0be9d4f
		
	
	
	
	
		
			
			commit 8d5cf596d1 started to add statically
allocated ax25_protocol's to list. However kfree() was still in place waiting
for unsuspecting ones on module removal.
Steps to reproduce:
	modprobe netrom
	rmmod netrom
P.S.: code would benefit greatly from list_add/list_del usage
kernel BUG at mm/slab.c:592!
invalid opcode: 0000 [1] PREEMPT SMP 
CPU 0 
Modules linked in: netrom ax25 af_packet usbcore rtc_cmos rtc_core rtc_lib
Pid: 4477, comm: rmmod Not tainted 2.6.23-rc3-bloat #2
RIP: 0010:[<ffffffff802ac646>]  [<ffffffff802ac646>] kfree+0x1c6/0x260
RSP: 0000:ffff810079a05e48  EFLAGS: 00010046
RAX: 0000000000000000 RBX: 0000000000000000 RCX: ffff81000000c000
RDX: ffff81007e552458 RSI: 0000000000000000 RDI: 000000000000805d
RBP: ffff810079a05e88 R08: 0000000000000001 R09: 0000000000000000
R10: 0000000000000001 R11: 0000000000000000 R12: ffffffff8805d080
R13: ffffffff8805d080 R14: 0000000000000000 R15: 0000000000000282
FS:  00002b73fc98aae0(0000) GS:ffffffff805dc000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 000000008005003b
CR2: 000000000053f3b8 CR3: 0000000079ff2000 CR4: 00000000000006e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000400
Process rmmod (pid: 4477, threadinfo ffff810079a04000, task ffff8100775aa480)
Stack:  ffff810079a05e68 0000000000000246 ffffffff8804eca0 0000000000000000
 ffffffff8805d080 00000000000000cf 0000000000000000 0000000000000880
 ffff810079a05eb8 ffffffff8803ec90 ffff810079a05eb8 0000000000000000
Call Trace:
 [<ffffffff8803ec90>] :ax25:ax25_protocol_release+0xa0/0xb0
 [<ffffffff88056ecb>] :netrom:nr_exit+0x6b/0xf0
 [<ffffffff80268bf0>] sys_delete_module+0x170/0x1f0
 [<ffffffff8025da35>] trace_hardirqs_on+0xd5/0x170
 [<ffffffff804835aa>] trace_hardirqs_on_thunk+0x35/0x37
 [<ffffffff8020c13e>] system_call+0x7e/0x83
Code: 0f 0b eb fe 66 66 90 66 66 90 48 8b 52 10 48 8b 02 25 00 40 
RIP  [<ffffffff802ac646>] kfree+0x1c6/0x260
 RSP <ffff810079a05e48>
Kernel panic - not syncing: Fatal exception
Signed-off-by: Alexey Dobriyan <adobriyan@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
		
	
			
		
			
				
	
	
		
			223 lines
		
	
	
		
			5.1 KiB
		
	
	
	
		
			C
		
	
	
	
	
	
			
		
		
	
	
			223 lines
		
	
	
		
			5.1 KiB
		
	
	
	
		
			C
		
	
	
	
	
	
| /*
 | |
|  * This program is free software; you can redistribute it and/or modify
 | |
|  * it under the terms of the GNU General Public License as published by
 | |
|  * the Free Software Foundation; either version 2 of the License, or
 | |
|  * (at your option) any later version.
 | |
|  *
 | |
|  * Copyright (C) Jonathan Naylor G4KLX (g4klx@g4klx.demon.co.uk)
 | |
|  */
 | |
| #include <linux/errno.h>
 | |
| #include <linux/types.h>
 | |
| #include <linux/socket.h>
 | |
| #include <linux/in.h>
 | |
| #include <linux/kernel.h>
 | |
| #include <linux/module.h>
 | |
| #include <linux/spinlock.h>
 | |
| #include <linux/timer.h>
 | |
| #include <linux/string.h>
 | |
| #include <linux/sockios.h>
 | |
| #include <linux/net.h>
 | |
| #include <net/ax25.h>
 | |
| #include <linux/inet.h>
 | |
| #include <linux/netdevice.h>
 | |
| #include <linux/skbuff.h>
 | |
| #include <net/sock.h>
 | |
| #include <asm/uaccess.h>
 | |
| #include <asm/system.h>
 | |
| #include <linux/fcntl.h>
 | |
| #include <linux/mm.h>
 | |
| #include <linux/interrupt.h>
 | |
| 
 | |
| static struct ax25_protocol *protocol_list;
 | |
| static DEFINE_RWLOCK(protocol_list_lock);
 | |
| 
 | |
| static HLIST_HEAD(ax25_linkfail_list);
 | |
| static DEFINE_SPINLOCK(linkfail_lock);
 | |
| 
 | |
| static struct listen_struct {
 | |
| 	struct listen_struct *next;
 | |
| 	ax25_address  callsign;
 | |
| 	struct net_device *dev;
 | |
| } *listen_list = NULL;
 | |
| static DEFINE_SPINLOCK(listen_lock);
 | |
| 
 | |
| /*
 | |
|  * Do not register the internal protocols AX25_P_TEXT, AX25_P_SEGMENT,
 | |
|  * AX25_P_IP or AX25_P_ARP ...
 | |
|  */
 | |
| void ax25_register_pid(struct ax25_protocol *ap)
 | |
| {
 | |
| 	write_lock_bh(&protocol_list_lock);
 | |
| 	ap->next = protocol_list;
 | |
| 	protocol_list = ap;
 | |
| 	write_unlock_bh(&protocol_list_lock);
 | |
| }
 | |
| 
 | |
| EXPORT_SYMBOL_GPL(ax25_register_pid);
 | |
| 
 | |
| void ax25_protocol_release(unsigned int pid)
 | |
| {
 | |
| 	struct ax25_protocol *s, *protocol;
 | |
| 
 | |
| 	write_lock_bh(&protocol_list_lock);
 | |
| 	protocol = protocol_list;
 | |
| 	if (protocol == NULL) {
 | |
| 		write_unlock_bh(&protocol_list_lock);
 | |
| 		return;
 | |
| 	}
 | |
| 
 | |
| 	if (protocol->pid == pid) {
 | |
| 		protocol_list = protocol->next;
 | |
| 		write_unlock_bh(&protocol_list_lock);
 | |
| 		return;
 | |
| 	}
 | |
| 
 | |
| 	while (protocol != NULL && protocol->next != NULL) {
 | |
| 		if (protocol->next->pid == pid) {
 | |
| 			s = protocol->next;
 | |
| 			protocol->next = protocol->next->next;
 | |
| 			write_unlock_bh(&protocol_list_lock);
 | |
| 			return;
 | |
| 		}
 | |
| 
 | |
| 		protocol = protocol->next;
 | |
| 	}
 | |
| 	write_unlock_bh(&protocol_list_lock);
 | |
| }
 | |
| 
 | |
| EXPORT_SYMBOL(ax25_protocol_release);
 | |
| 
 | |
| void ax25_linkfail_register(struct ax25_linkfail *lf)
 | |
| {
 | |
| 	spin_lock_bh(&linkfail_lock);
 | |
| 	hlist_add_head(&lf->lf_node, &ax25_linkfail_list);
 | |
| 	spin_unlock_bh(&linkfail_lock);
 | |
| }
 | |
| 
 | |
| EXPORT_SYMBOL(ax25_linkfail_register);
 | |
| 
 | |
| void ax25_linkfail_release(struct ax25_linkfail *lf)
 | |
| {
 | |
| 	spin_lock_bh(&linkfail_lock);
 | |
| 	hlist_del_init(&lf->lf_node);
 | |
| 	spin_unlock_bh(&linkfail_lock);
 | |
| }
 | |
| 
 | |
| EXPORT_SYMBOL(ax25_linkfail_release);
 | |
| 
 | |
| int ax25_listen_register(ax25_address *callsign, struct net_device *dev)
 | |
| {
 | |
| 	struct listen_struct *listen;
 | |
| 
 | |
| 	if (ax25_listen_mine(callsign, dev))
 | |
| 		return 0;
 | |
| 
 | |
| 	if ((listen = kmalloc(sizeof(*listen), GFP_ATOMIC)) == NULL)
 | |
| 		return -ENOMEM;
 | |
| 
 | |
| 	listen->callsign = *callsign;
 | |
| 	listen->dev      = dev;
 | |
| 
 | |
| 	spin_lock_bh(&listen_lock);
 | |
| 	listen->next = listen_list;
 | |
| 	listen_list  = listen;
 | |
| 	spin_unlock_bh(&listen_lock);
 | |
| 
 | |
| 	return 0;
 | |
| }
 | |
| 
 | |
| EXPORT_SYMBOL(ax25_listen_register);
 | |
| 
 | |
| void ax25_listen_release(ax25_address *callsign, struct net_device *dev)
 | |
| {
 | |
| 	struct listen_struct *s, *listen;
 | |
| 
 | |
| 	spin_lock_bh(&listen_lock);
 | |
| 	listen = listen_list;
 | |
| 	if (listen == NULL) {
 | |
| 		spin_unlock_bh(&listen_lock);
 | |
| 		return;
 | |
| 	}
 | |
| 
 | |
| 	if (ax25cmp(&listen->callsign, callsign) == 0 && listen->dev == dev) {
 | |
| 		listen_list = listen->next;
 | |
| 		spin_unlock_bh(&listen_lock);
 | |
| 		kfree(listen);
 | |
| 		return;
 | |
| 	}
 | |
| 
 | |
| 	while (listen != NULL && listen->next != NULL) {
 | |
| 		if (ax25cmp(&listen->next->callsign, callsign) == 0 && listen->next->dev == dev) {
 | |
| 			s = listen->next;
 | |
| 			listen->next = listen->next->next;
 | |
| 			spin_unlock_bh(&listen_lock);
 | |
| 			kfree(s);
 | |
| 			return;
 | |
| 		}
 | |
| 
 | |
| 		listen = listen->next;
 | |
| 	}
 | |
| 	spin_unlock_bh(&listen_lock);
 | |
| }
 | |
| 
 | |
| EXPORT_SYMBOL(ax25_listen_release);
 | |
| 
 | |
| int (*ax25_protocol_function(unsigned int pid))(struct sk_buff *, ax25_cb *)
 | |
| {
 | |
| 	int (*res)(struct sk_buff *, ax25_cb *) = NULL;
 | |
| 	struct ax25_protocol *protocol;
 | |
| 
 | |
| 	read_lock(&protocol_list_lock);
 | |
| 	for (protocol = protocol_list; protocol != NULL; protocol = protocol->next)
 | |
| 		if (protocol->pid == pid) {
 | |
| 			res = protocol->func;
 | |
| 			break;
 | |
| 		}
 | |
| 	read_unlock(&protocol_list_lock);
 | |
| 
 | |
| 	return res;
 | |
| }
 | |
| 
 | |
| int ax25_listen_mine(ax25_address *callsign, struct net_device *dev)
 | |
| {
 | |
| 	struct listen_struct *listen;
 | |
| 
 | |
| 	spin_lock_bh(&listen_lock);
 | |
| 	for (listen = listen_list; listen != NULL; listen = listen->next)
 | |
| 		if (ax25cmp(&listen->callsign, callsign) == 0 &&
 | |
| 		    (listen->dev == dev || listen->dev == NULL)) {
 | |
| 			spin_unlock_bh(&listen_lock);
 | |
| 			return 1;
 | |
| 	}
 | |
| 	spin_unlock_bh(&listen_lock);
 | |
| 
 | |
| 	return 0;
 | |
| }
 | |
| 
 | |
| void ax25_link_failed(ax25_cb *ax25, int reason)
 | |
| {
 | |
| 	struct ax25_linkfail *lf;
 | |
| 	struct hlist_node *node;
 | |
| 
 | |
| 	spin_lock_bh(&linkfail_lock);
 | |
| 	hlist_for_each_entry(lf, node, &ax25_linkfail_list, lf_node)
 | |
| 		lf->func(ax25, reason);
 | |
| 	spin_unlock_bh(&linkfail_lock);
 | |
| }
 | |
| 
 | |
| int ax25_protocol_is_registered(unsigned int pid)
 | |
| {
 | |
| 	struct ax25_protocol *protocol;
 | |
| 	int res = 0;
 | |
| 
 | |
| 	read_lock_bh(&protocol_list_lock);
 | |
| 	for (protocol = protocol_list; protocol != NULL; protocol = protocol->next)
 | |
| 		if (protocol->pid == pid) {
 | |
| 			res = 1;
 | |
| 			break;
 | |
| 		}
 | |
| 	read_unlock_bh(&protocol_list_lock);
 | |
| 
 | |
| 	return res;
 | |
| }
 |