On Sat, 7 Jun 2008, Patrick McHardy wrote:
Patrick McHardy wrote:
Chuck Ebbert wrote:
Reported at https://bugzilla.redhat.com/show_bug.cgi?id=449315
In find_appropriate_src():
hlist_for_each_entry_rcu(nat, n, &bysource[h], bysource) {
ct = nat->ct;
if (same_src(ct, tuple)) {
Dereference of ct in same_src() causes the oops. This only seems to
happen on heavily loaded firewall machines. Kernel 2.6.24.7 works.
The reporter identifies commit 4d354c5782dc352cec187845d17eedc2c2bfcf67
("[NETFILTER]: nf_nat: use RCU for bysource hash") as a possible cause
of the problem.
We have a similar looking report, but that one also affects 2.6.24:
http://bugzilla.kernel.org/show_bug.cgi?id=10875
Anyways, does this patch help? When reallocating storage
for a conntrack, it is replaced in the list before assigning
the nat->ct pointer.
I'm afraid we also need this one on top - when reallocating
an extension, we must not free the old storage since it may
still be used in a RCU read side.
It does not help here: 2.6.26-rc5 plus two above patches still crashes.
Best regards,
Krzysztof Olędzki