Note: This is a beta release of Red Hat Bugzilla 5.0. The data contained within is a snapshot of the live data so any changes you make will not be reflected in the production Bugzilla. Also email is disabled so feel free to test any aspect of the site that you want. File any problems you find or give feedback here.
Bug 219488 - kernel panic removing devices from a teql queuing discipline
Summary: kernel panic removing devices from a teql queuing discipline
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: kernel
Version: 6
Hardware: i386
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Kernel Maintainer List
QA Contact: Brian Brock
URL:
Whiteboard:
Depends On:
Blocks: 427887
TreeView+ depends on / blocked
 
Reported: 2006-12-13 15:23 UTC by Tom Hughes
Modified: 2008-01-08 08:48 UTC (History)
3 users (show)

Fixed In Version: 2.6.23.8-34.fc7
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2008-01-08 08:48:23 UTC


Attachments (Terms of Use)
Kernel panic (deleted)
2006-12-13 15:23 UTC, Tom Hughes
no flags Details

Description Tom Hughes 2006-12-13 15:23:25 UTC
Description of problem:

Removing devices from a teql queuing discipline being used to equalise traffic
over a group of interfaces can cause the kernel to panic if there is traffic
going through the interface at the time.

Version-Release number of selected component (if applicable):

2.6.18-1.2849.fc6

How reproducible:

Very.

Steps to Reproduce:

1. Setup a teql0 interface with one or more underlying interfaces:

   modprobe sch-teql
   tc qdisc add dev eth0 root teql0
   tc qdisc add dev eth1 root teql1
   ifconfig teql0 inet ...

2. Send traffic through the teql0 interface (I use a flood ping):

   ping -s 1200 -f ...

3. Drop the underlying interface(s) from the equaliser:

   tc qdisc del dev eth0 root && tc qdisc del dev eth1 root
  
Actual results:

Kernel panics - the panic is attached.

Expected results:

Kernel doesn't panic.

Additional info:

Comment 1 Tom Hughes 2006-12-13 15:23:29 UTC
Created attachment 143525 [details]
Kernel panic

Comment 2 Tom Hughes 2006-12-13 15:29:35 UTC
The panic is in __teql_resolve (which has been inlined into teql_master_xmit) in
net/sched/sch_teql.c at this line:

	if (n && n->tbl == mn->tbl &&

Specifically the dereference of n->tbl is faulting as n is not valid.

Comment 3 Tom Hughes 2007-05-10 09:00:38 UTC
Any news on this?

Comment 4 Tom Hughes 2007-10-29 08:50:03 UTC
Still happening in F7 with kernel 2.6.22.9-91.fc7...

Comment 5 Chuck Ebbert 2007-10-29 18:00:26 UTC
Reported to netdev.


Comment 6 Jon Stanley 2008-01-08 01:55:11 UTC
(This is a mass-update to all current FC6 kernel bugs in NEW state)

Hello,

I'm reviewing this bug list as part of the kernel bug triage project, an attempt
to isolate current bugs in the Fedora kernel.

http://fedoraproject.org/wiki/KernelBugTriage

I am CC'ing myself to this bug, however this version of Fedora is no longer
maintained.

Please attempt to reproduce this bug with a current version of Fedora (presently
Fedora 8). If the bug no longer exists, please close the bug or I'll do so in a
few days if there is no further information lodged.

Thanks for using Fedora!

Comment 7 Tom Hughes 2008-01-08 08:48:23 UTC
This was fixed by the netdev guys and the fix made it into 2.6.23.4 and we have
been running 2.6.23.8-34.fc7 on the system in question since 13th December
without any problems.

In fact our ISP had some problems last night which meant this got throughly
exercised as my monitoring code took interfaces in and out of the bond on
several occasions without any panic.


Note You need to log in before you can comment on or make changes to this bug.