From: Xin Long <lucien....@gmail.com> Date: Fri, 18 Aug 2017 11:01:36 +0800
> As we know in some target's checkentry it may dereference par.entryinfo > to check entry stuff inside. But when sched action calls xt_check_target, > par.entryinfo is set with NULL. It would cause kernel panic when calling > some targets. > > It can be reproduce with: > # tc qd add dev eth1 ingress handle ffff: > # tc filter add dev eth1 parent ffff: u32 match u32 0 0 action xt \ > -j ECN --ecn-tcp-remove > > It could also crash kernel when using target CLUSTERIP or TPROXY. > > By now there's no proper value for par.entryinfo in ipt_init_target, > but it can not be set with NULL. This patch is to void all these > panics by setting it with an ipt_entry obj with all members = 0. > > Note that this issue has been there since the very beginning. > > Signed-off-by: Xin Long <lucien....@gmail.com> Applied and queued up for -stable, thanks.