netfilter: nf_conntrack: fix BUG_ON while removing nf_conntrack with netns
canqun zhang reported that we're hitting BUG_ON in the nf_conntrack_destroy path when calling kfree_skb while rmmod'ing the nf_conntrack module. Currently, the nf_ct_destroy hook is being set to NULL in the destroy path of conntrack.init_net. However, this is a problem since init_net may be destroyed before any other existing netns (we cannot assume any specific ordering while releasing existing netns according to what I read in recent emails). Thanks to Gao feng for initial patch to address this issue. Reported-by: canqun zhang <canqunzhang@gmail.com> Acked-by: Gao feng <gaofeng@cn.fujitsu.com> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
This commit is contained in:
parent
4610476d89
commit
1e47ee8367
|
@ -31,6 +31,8 @@ extern void nf_conntrack_cleanup(struct net *net);
|
||||||
extern int nf_conntrack_proto_init(struct net *net);
|
extern int nf_conntrack_proto_init(struct net *net);
|
||||||
extern void nf_conntrack_proto_fini(struct net *net);
|
extern void nf_conntrack_proto_fini(struct net *net);
|
||||||
|
|
||||||
|
extern void nf_conntrack_cleanup_end(void);
|
||||||
|
|
||||||
extern bool
|
extern bool
|
||||||
nf_ct_get_tuple(const struct sk_buff *skb,
|
nf_ct_get_tuple(const struct sk_buff *skb,
|
||||||
unsigned int nhoff,
|
unsigned int nhoff,
|
||||||
|
|
|
@ -1376,11 +1376,12 @@ void nf_conntrack_cleanup(struct net *net)
|
||||||
synchronize_net();
|
synchronize_net();
|
||||||
nf_conntrack_proto_fini(net);
|
nf_conntrack_proto_fini(net);
|
||||||
nf_conntrack_cleanup_net(net);
|
nf_conntrack_cleanup_net(net);
|
||||||
|
}
|
||||||
|
|
||||||
if (net_eq(net, &init_net)) {
|
void nf_conntrack_cleanup_end(void)
|
||||||
RCU_INIT_POINTER(nf_ct_destroy, NULL);
|
{
|
||||||
nf_conntrack_cleanup_init_net();
|
RCU_INIT_POINTER(nf_ct_destroy, NULL);
|
||||||
}
|
nf_conntrack_cleanup_init_net();
|
||||||
}
|
}
|
||||||
|
|
||||||
void *nf_ct_alloc_hashtable(unsigned int *sizep, int nulls)
|
void *nf_ct_alloc_hashtable(unsigned int *sizep, int nulls)
|
||||||
|
|
|
@ -575,6 +575,7 @@ static int __init nf_conntrack_standalone_init(void)
|
||||||
static void __exit nf_conntrack_standalone_fini(void)
|
static void __exit nf_conntrack_standalone_fini(void)
|
||||||
{
|
{
|
||||||
unregister_pernet_subsys(&nf_conntrack_net_ops);
|
unregister_pernet_subsys(&nf_conntrack_net_ops);
|
||||||
|
nf_conntrack_cleanup_end();
|
||||||
}
|
}
|
||||||
|
|
||||||
module_init(nf_conntrack_standalone_init);
|
module_init(nf_conntrack_standalone_init);
|
||||||
|
|
Reference in New Issue