GPF when doing jail -r, possibly an use-after-free

Mikolaj Golub trociny at
Thu Jul 5 19:54:03 UTC 2012

On Thu, 05 Jul 2012 12:18:20 -0700 Xin Li wrote:

 XL> Hi, Mikolaj,

 XL> On 07/04/12 00:00, Mikolaj Golub wrote:
 >> Is this observed after destroying epair? There is an issue with
 >> epair: on destroy, when epair_clone_destroy() calls
 >> ether_ifdetach() for its second half it does not switch to its vnet
 >> and if_detach_internal() can't find the interface and just returns.
 >> As a result V_ifnet list is left with dead reference.

 XL> Yes.

 >>  Here is an updated patch against CURRENT:

 XL> Your
 XL> patch did fixed the problem, thanks!  Are you going to commit it
 XL> against -HEAD and then MFC after a while?

I would like Bjoern review it before me committing, or at least tell he does
not mind, if he does not have time to review -)

Mikolaj Golub

More information about the freebsd-virtualization mailing list