Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more

Commit 1e47ee83 authored by Pablo Neira Ayuso's avatar Pablo Neira Ayuso
Browse files

netfilter: nf_conntrack: fix BUG_ON while removing nf_conntrack with netns



canqun zhang reported that we're hitting BUG_ON in the
nf_conntrack_destroy path when calling kfree_skb while
rmmod'ing the nf_conntrack module.

Currently, the nf_ct_destroy hook is being set to NULL in the
destroy path of conntrack.init_net. However, this is a problem
since init_net may be destroyed before any other existing netns
(we cannot assume any specific ordering while releasing existing
netns according to what I read in recent emails).

Thanks to Gao feng for initial patch to address this issue.

Reported-by: default avatarcanqun zhang <canqunzhang@gmail.com>
Acked-by: default avatarGao feng <gaofeng@cn.fujitsu.com>
Signed-off-by: default avatarPablo Neira Ayuso <pablo@netfilter.org>
parent 4610476d
Loading
Loading
Loading
Loading
+2 −0
Original line number Diff line number Diff line
@@ -31,6 +31,8 @@ extern void nf_conntrack_cleanup(struct net *net);
extern int nf_conntrack_proto_init(struct net *net);
extern void nf_conntrack_proto_fini(struct net *net);

extern void nf_conntrack_cleanup_end(void);

extern bool
nf_ct_get_tuple(const struct sk_buff *skb,
		unsigned int nhoff,
+5 −4
Original line number Diff line number Diff line
@@ -1376,12 +1376,13 @@ void nf_conntrack_cleanup(struct net *net)
	synchronize_net();
	nf_conntrack_proto_fini(net);
	nf_conntrack_cleanup_net(net);
}

	if (net_eq(net, &init_net)) {
void nf_conntrack_cleanup_end(void)
{
	RCU_INIT_POINTER(nf_ct_destroy, NULL);
	nf_conntrack_cleanup_init_net();
}
}

void *nf_ct_alloc_hashtable(unsigned int *sizep, int nulls)
{
+1 −0
Original line number Diff line number Diff line
@@ -575,6 +575,7 @@ static int __init nf_conntrack_standalone_init(void)
static void __exit nf_conntrack_standalone_fini(void)
{
	unregister_pernet_subsys(&nf_conntrack_net_ops);
	nf_conntrack_cleanup_end();
}

module_init(nf_conntrack_standalone_init);