From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1752587AbdK1O6m (ORCPT ); Tue, 28 Nov 2017 09:58:42 -0500 Received: from shards.monkeyblade.net ([184.105.139.130]:42596 "EHLO shards.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1752370AbdK1O6l (ORCPT ); Tue, 28 Nov 2017 09:58:41 -0500 Date: Tue, 28 Nov 2017 09:58:37 -0500 (EST) Message-Id: <20171128.095837.899409439582426451.davem@davemloft.net> To: tommi.t.rantala@nokia.com Cc: jon.maloy@ericsson.com, ying.xue@windriver.com, netdev@vger.kernel.org, tipc-discussion@lists.sourceforge.net, linux-kernel@vger.kernel.org Subject: Re: [PATCH] tipc: call tipc_rcv() only if bearer is up in tipc_udp_recv() From: David Miller In-Reply-To: <20171128125315.25334-1-tommi.t.rantala@nokia.com> References: <20171128125315.25334-1-tommi.t.rantala@nokia.com> X-Mailer: Mew version 6.7 on Emacs 24.5 / Mule 6.0 (HANACHIRUSATO) Mime-Version: 1.0 Content-Type: Text/Plain; charset=us-ascii Content-Transfer-Encoding: 7bit X-Greylist: Sender succeeded SMTP AUTH, not delayed by milter-greylist-4.5.12 (shards.monkeyblade.net [149.20.54.216]); Tue, 28 Nov 2017 06:58:39 -0800 (PST) Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org From: Tommi Rantala Date: Tue, 28 Nov 2017 14:53:15 +0200 > Call tipc_rcv() only if bearer is up in tipc_udp_recv(). > Fixes a rare TIPC div-by-zero crash in tipc_node_calculate_timer(): > > We're enabling a bearer, but it's not yet up and fully initialized. > At the same time we receive a discovery packet, and in tipc_udp_recv() > we end up calling tipc_rcv() with the not-yet-initialized bearer, > causing later a div-by-zero crash in tipc_node_calculate_timer(). You're also now ignoring any error being returned by tipc_udp_rcast_disc(). > - > - if (unlikely(msg_user(hdr) == LINK_CONFIG)) { > - err = tipc_udp_rcast_disc(b, skb); > - if (err) > - goto rcu_out; > + } else { > + if (unlikely(b && msg_user(hdr) == LINK_CONFIG)) > + tipc_udp_rcast_disc(b, skb); > + kfree_skb(skb); > } Either put the 'err' propagation back or clearly explain in your commit log message why this part of the change if absolutely essential for this bug fix. Thank you.