Module Name:    src
Committed By:   ozaki-r
Date:           Tue May 16 07:25:57 UTC 2017

Modified Files:
        src/sys/netipsec: ipsec.c key.c

Log Message:
Fix diagnostic assertion failure in ipsec_init_policy

  panic: kernel diagnostic assertion "!cpu_softintr_p()" failed: file 
"../../../../netipsec/ipsec.c", line 1277
  cpu7: Begin traceback...
  vpanic() at netbsd:vpanic+0x140
  ch_voltag_convert_in() at netbsd:ch_voltag_convert_in
  ipsec_init_policy() at netbsd:ipsec_init_policy+0x149
  in_pcballoc() at netbsd:in_pcballoc+0x1c5
  tcp_attach_wrapper() at netbsd:tcp_attach_wrapper+0x1e1
  sonewconn() at netbsd:sonewconn+0x1ea
  syn_cache_get() at netbsd:syn_cache_get+0x15f
  tcp_input() at netbsd:tcp_input+0x1689
  ipintr() at netbsd:ipintr+0xa88
  softint_dispatch() at netbsd:softint_dispatch+0xd3
  DDB lost frame for netbsd:Xsoftintr+0x4f, trying 0xfffffe811d337ff0
  Xsoftintr() at netbsd:Xsoftintr+0x4f

Reported by msaitoh@


To generate a diff of this commit:
cvs rdiff -u -r1.90 -r1.91 src/sys/netipsec/ipsec.c
cvs rdiff -u -r1.127 -r1.128 src/sys/netipsec/key.c

Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.

Modified files:

Index: src/sys/netipsec/ipsec.c
diff -u src/sys/netipsec/ipsec.c:1.90 src/sys/netipsec/ipsec.c:1.91
--- src/sys/netipsec/ipsec.c:1.90	Tue May 16 03:05:28 2017
+++ src/sys/netipsec/ipsec.c	Tue May 16 07:25:57 2017
@@ -1,4 +1,4 @@
-/*	$NetBSD: ipsec.c,v 1.90 2017/05/16 03:05:28 ozaki-r Exp $	*/
+/*	$NetBSD: ipsec.c,v 1.91 2017/05/16 07:25:57 ozaki-r Exp $	*/
 /*	$FreeBSD: /usr/local/www/cvsroot/FreeBSD/src/sys/netipsec/ipsec.c,v 1.2.2.2 2003/07/01 01:38:13 sam Exp $	*/
 /*	$KAME: ipsec.c,v 1.103 2001/05/24 07:14:18 sakane Exp $	*/
 
@@ -32,7 +32,7 @@
  */
 
 #include <sys/cdefs.h>
-__KERNEL_RCSID(0, "$NetBSD: ipsec.c,v 1.90 2017/05/16 03:05:28 ozaki-r Exp $");
+__KERNEL_RCSID(0, "$NetBSD: ipsec.c,v 1.91 2017/05/16 07:25:57 ozaki-r Exp $");
 
 /*
  * IPsec controller part.
@@ -1265,7 +1265,7 @@ static void
 ipsec_delpcbpolicy(struct inpcbpolicy *p)
 {
 
-	kmem_free(p, sizeof(*p));
+	kmem_intr_free(p, sizeof(*p));
 }
 
 /* initialize policy in PCB */
@@ -1274,11 +1274,14 @@ ipsec_init_policy(struct socket *so, str
 {
 	struct inpcbpolicy *new;
 
-	KASSERT(!cpu_softintr_p());
 	KASSERT(so != NULL);
 	KASSERT(policy != NULL);
 
-	new = kmem_zalloc(sizeof(*new), KM_SLEEP);
+	new = kmem_intr_zalloc(sizeof(*new), KM_NOSLEEP);
+	if (new == NULL) {
+		ipseclog((LOG_DEBUG, "%s: No more memory.\n", __func__));
+		return ENOBUFS;
+	}
 
 	if (IPSEC_PRIVILEGED_SO(so))
 		new->priv = 1;

Index: src/sys/netipsec/key.c
diff -u src/sys/netipsec/key.c:1.127 src/sys/netipsec/key.c:1.128
--- src/sys/netipsec/key.c:1.127	Tue May 16 03:05:28 2017
+++ src/sys/netipsec/key.c	Tue May 16 07:25:57 2017
@@ -1,4 +1,4 @@
-/*	$NetBSD: key.c,v 1.127 2017/05/16 03:05:28 ozaki-r Exp $	*/
+/*	$NetBSD: key.c,v 1.128 2017/05/16 07:25:57 ozaki-r Exp $	*/
 /*	$FreeBSD: src/sys/netipsec/key.c,v 1.3.2.3 2004/02/14 22:23:23 bms Exp $	*/
 /*	$KAME: key.c,v 1.191 2001/06/27 10:46:49 sakane Exp $	*/
 
@@ -32,7 +32,7 @@
  */
 
 #include <sys/cdefs.h>
-__KERNEL_RCSID(0, "$NetBSD: key.c,v 1.127 2017/05/16 03:05:28 ozaki-r Exp $");
+__KERNEL_RCSID(0, "$NetBSD: key.c,v 1.128 2017/05/16 07:25:57 ozaki-r Exp $");
 
 /*
  * This code is referd to RFC 2367
@@ -1459,8 +1459,9 @@ key_newsp(const char* where, int tag)
 {
 	struct secpolicy *newsp = NULL;
 
-	newsp = kmem_zalloc(sizeof(struct secpolicy), KM_SLEEP);
-	newsp->refcnt = 1;
+	newsp = kmem_intr_zalloc(sizeof(struct secpolicy), KM_NOSLEEP);
+	if (newsp != NULL)
+		newsp->refcnt = 1;
 
 	KEYDEBUG_PRINTF(KEYDEBUG_IPSEC_STAMP,
 	    "DP from %s:%u return SP:%p\n", where, tag, newsp);

Reply via email to