Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 05 Jul 2012 12:18:20 -0700
From:      Xin Li <delphij@delphij.net>
To:        Mikolaj Golub <trociny@freebsd.org>
Cc:        d@delphij.net, freebsd-virtualization@FreeBSD.org
Subject:   Re: GPF when doing jail -r, possibly an use-after-free
Message-ID:  <4FF5E87C.2020908@delphij.net>
In-Reply-To: <86wr2kau38.fsf@in138.ua3>
References:  <4FF32FC4.6020701@delphij.net> <86wr2kau38.fsf@in138.ua3>

next in thread | previous in thread | raw e-mail | index | archive | help
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Hi, Mikolaj,

On 07/04/12 00:00, Mikolaj Golub wrote:
> Is this observed after destroying epair? There is an issue with
> epair: on destroy, when epair_clone_destroy() calls
> ether_ifdetach() for its second half it does not switch to its vnet
> and if_detach_internal() can't find the interface and just returns.
> As a result V_ifnet list is left with dead reference.

Yes.

> http://lists.freebsd.org/pipermail/freebsd-virtualization/2011-January/000628.html
>
>  Here is an updated patch against CURRENT:
> 
> http://people.freebsd.org/~trociny/if_epair.c.epair_clone_destroy.1.patch

Your
> 
patch did fixed the problem, thanks!  Are you going to commit it
against -HEAD and then MFC after a while?

Cheers,
- -- 
Xin LI <delphij@delphij.net>	https://www.delphij.net/
FreeBSD - The Power to Serve!		Live free or die
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.19 (FreeBSD)

iQEcBAEBCAAGBQJP9eh8AAoJEG80Jeu8UPuzrKQH/3HT/qdW1r8a/sS9XSVK1OFZ
u5M1GUUsrfCpcEYcn1YMgfJKvicy2H56OCHUNwEHfJkngqAvVZD0nZu+dcS7UTQZ
djWHnkealtKg+57jG/FdL+tt8wViq8anYN2I0UUqGqne/tVHkbS9VY0KTr1b9JRv
CNkBMKEJ3ii7eWNft+8c8cRXlOOFbGGuYVOdE8vVB7YDTOkeCGwwbJaLNXheMyld
yNYc4ZNLD8f/TUuxKvbN4Ee514SfvjWsJa9CgiGWTD4u74Brml3zSUGWdWChINqV
uZ14VYzIPmXiPAD1fqidSPPJQ0QpAy1sdwSVnKOkoQ5/zbZzKUXoNGCB+K0z460=
=qZ5q
-----END PGP SIGNATURE-----



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?4FF5E87C.2020908>