From fdf453c0a97841cf238191eef63382b650ffe07f Mon Sep 17 00:00:00 2001 From: Harald Welte Date: Sat, 14 Jul 2012 12:15:19 +0200 Subject: SGSN: Code to help debug / fix sgsn crash in cb_data_ind() A crash was obsserved in cb_data_ind() when mm is dereferenced. This patch adds some safeguards that try to prevent the library handle back-pointer to the pdp_ctx to be NULL, and print a stack backtrace in case we are free() ing the sgsn-side pdp_ctx while there's still a library handle attached. --- openbsc/src/gprs/sgsn_libgtp.c | 12 +++++++++++- 1 file changed, 11 insertions(+), 1 deletion(-) (limited to 'openbsc/src/gprs/sgsn_libgtp.c') diff --git a/openbsc/src/gprs/sgsn_libgtp.c b/openbsc/src/gprs/sgsn_libgtp.c index a19af366e..7c17f9d41 100644 --- a/openbsc/src/gprs/sgsn_libgtp.c +++ b/openbsc/src/gprs/sgsn_libgtp.c @@ -317,6 +317,10 @@ static int delete_pdp_conf(struct pdp_t *pdp, void *cbp, int cause) /* Confirm deactivation of PDP context to MS */ rc = gsm48_tx_gsm_deact_pdp_acc(pctx); + /* unlink the now non-existing library handle from the pdp + * context */ + pctx->lib = NULL; + sgsn_pdp_ctx_free(pctx); return rc; @@ -422,10 +426,16 @@ static int cb_data_ind(struct pdp_t *lib, void *packet, unsigned int len) pdp = lib->priv; if (!pdp) { - DEBUGP(DGPRS, "GTP DATA IND from GGSN for unknown PDP\n"); + LOGP(DGPRS, LOGL_NOTICE, + "GTP DATA IND from GGSN for unknown PDP\n"); return -EIO; } mm = pdp->mm; + if (!mm) { + LOGP(DGPRS, LOGL_ERROR, + "PDP context (imsi=%s) without MM context!\n", mm->imsi); + return -EIO; + } msg = msgb_alloc_headroom(len+256, 128, "GTP->SNDCP"); ud = msgb_put(msg, len); -- cgit v1.2.3