Date: Thu, 05 Jul 2012 22:53:58 +0300 From: Mikolaj Golub <trociny@freebsd.org> To: d@delphij.net Cc: "Bjoern A. Zeeb" <bz@FreeBSD.org>, freebsd-virtualization@FreeBSD.org Subject: Re: GPF when doing jail -r, possibly an use-after-free Message-ID: <86r4sqasrt.fsf@kopusha.home.net> In-Reply-To: <4FF5E87C.2020908@delphij.net> (Xin Li's message of "Thu, 05 Jul 2012 12:18:20 -0700") References: <4FF32FC4.6020701@delphij.net> <86wr2kau38.fsf@in138.ua3> <4FF5E87C.2020908@delphij.net>
next in thread | previous in thread | raw e-mail | index | archive | help
On Thu, 05 Jul 2012 12:18:20 -0700 Xin Li wrote: XL> Hi, Mikolaj, XL> On 07/04/12 00:00, Mikolaj Golub wrote: >> Is this observed after destroying epair? There is an issue with >> epair: on destroy, when epair_clone_destroy() calls >> ether_ifdetach() for its second half it does not switch to its vnet >> and if_detach_internal() can't find the interface and just returns. >> As a result V_ifnet list is left with dead reference. XL> Yes. >> http://lists.freebsd.org/pipermail/freebsd-virtualization/2011-January/000628.html >> >> Here is an updated patch against CURRENT: >> >> http://people.freebsd.org/~trociny/if_epair.c.epair_clone_destroy.1.patch XL> Your >> XL> patch did fixed the problem, thanks! Are you going to commit it XL> against -HEAD and then MFC after a while? I would like Bjoern review it before me committing, or at least tell he does not mind, if he does not have time to review -) -- Mikolaj Golub
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?86r4sqasrt.fsf>