提交 2a0c451a 编写于 作者: T Thomas Graf 提交者: David S. Miller

ipv6: Prevent access to uninitialized fib_table_hash via /proc/net/ipv6_route

/proc/net/ipv6_route reflects the contents of fib_table_hash. The proc
handler is installed in ip6_route_net_init() whereas fib_table_hash is
allocated in fib6_net_init() _after_ the proc handler has been installed.

This opens up a short time frame to access fib_table_hash with its pants
down.

fib6_init() as a whole can't be moved to an earlier position as it also
registers the rtnetlink message handlers which should be registered at
the end. Therefore split it into fib6_init() which is run early and
fib6_init_late() to register the rtnetlink message handlers.
Signed-off-by: NThomas Graf <tgraf@suug.ch>
Reviewed-by: NNeil Horman <nhorman@tuxdriver.com>
Signed-off-by: NDavid S. Miller <davem@davemloft.net>
上级 0f6efff9
...@@ -271,6 +271,8 @@ extern void fib6_run_gc(unsigned long expires, ...@@ -271,6 +271,8 @@ extern void fib6_run_gc(unsigned long expires,
extern void fib6_gc_cleanup(void); extern void fib6_gc_cleanup(void);
extern int fib6_init(void); extern int fib6_init(void);
extern int fib6_init_late(void);
extern void fib6_cleanup_late(void);
#ifdef CONFIG_IPV6_MULTIPLE_TABLES #ifdef CONFIG_IPV6_MULTIPLE_TABLES
extern int fib6_rules_init(void); extern int fib6_rules_init(void);
......
...@@ -1692,21 +1692,25 @@ int __init fib6_init(void) ...@@ -1692,21 +1692,25 @@ int __init fib6_init(void)
ret = register_pernet_subsys(&fib6_net_ops); ret = register_pernet_subsys(&fib6_net_ops);
if (ret) if (ret)
goto out_kmem_cache_create; goto out_kmem_cache_create;
ret = __rtnl_register(PF_INET6, RTM_GETROUTE, NULL, inet6_dump_fib,
NULL);
if (ret)
goto out_unregister_subsys;
out: out:
return ret; return ret;
out_unregister_subsys:
unregister_pernet_subsys(&fib6_net_ops);
out_kmem_cache_create: out_kmem_cache_create:
kmem_cache_destroy(fib6_node_kmem); kmem_cache_destroy(fib6_node_kmem);
goto out; goto out;
} }
int __init fib6_init_late(void)
{
return __rtnl_register(PF_INET6, RTM_GETROUTE, NULL, inet6_dump_fib,
NULL);
}
void fib6_cleanup_late(void)
{
rtnl_unregister(PF_INET6, RTM_GETROUTE);
}
void fib6_gc_cleanup(void) void fib6_gc_cleanup(void)
{ {
unregister_pernet_subsys(&fib6_net_ops); unregister_pernet_subsys(&fib6_net_ops);
......
...@@ -3018,10 +3018,14 @@ int __init ip6_route_init(void) ...@@ -3018,10 +3018,14 @@ int __init ip6_route_init(void)
if (ret) if (ret)
goto out_kmem_cache; goto out_kmem_cache;
ret = register_pernet_subsys(&ip6_route_net_ops); ret = fib6_init();
if (ret) if (ret)
goto out_dst_entries; goto out_dst_entries;
ret = register_pernet_subsys(&ip6_route_net_ops);
if (ret)
goto out_fib6_init;
ip6_dst_blackhole_ops.kmem_cachep = ip6_dst_ops_template.kmem_cachep; ip6_dst_blackhole_ops.kmem_cachep = ip6_dst_ops_template.kmem_cachep;
/* Registering of the loopback is done before this portion of code, /* Registering of the loopback is done before this portion of code,
...@@ -3035,13 +3039,13 @@ int __init ip6_route_init(void) ...@@ -3035,13 +3039,13 @@ int __init ip6_route_init(void)
init_net.ipv6.ip6_blk_hole_entry->dst.dev = init_net.loopback_dev; init_net.ipv6.ip6_blk_hole_entry->dst.dev = init_net.loopback_dev;
init_net.ipv6.ip6_blk_hole_entry->rt6i_idev = in6_dev_get(init_net.loopback_dev); init_net.ipv6.ip6_blk_hole_entry->rt6i_idev = in6_dev_get(init_net.loopback_dev);
#endif #endif
ret = fib6_init(); ret = fib6_init_late();
if (ret) if (ret)
goto out_register_subsys; goto out_register_subsys;
ret = xfrm6_init(); ret = xfrm6_init();
if (ret) if (ret)
goto out_fib6_init; goto out_fib6_init_late;
ret = fib6_rules_init(); ret = fib6_rules_init();
if (ret) if (ret)
...@@ -3064,10 +3068,12 @@ int __init ip6_route_init(void) ...@@ -3064,10 +3068,12 @@ int __init ip6_route_init(void)
fib6_rules_cleanup(); fib6_rules_cleanup();
xfrm6_init: xfrm6_init:
xfrm6_fini(); xfrm6_fini();
out_fib6_init: out_fib6_init_late:
fib6_gc_cleanup(); fib6_cleanup_late();
out_register_subsys: out_register_subsys:
unregister_pernet_subsys(&ip6_route_net_ops); unregister_pernet_subsys(&ip6_route_net_ops);
out_fib6_init:
fib6_gc_cleanup();
out_dst_entries: out_dst_entries:
dst_entries_destroy(&ip6_dst_blackhole_ops); dst_entries_destroy(&ip6_dst_blackhole_ops);
out_kmem_cache: out_kmem_cache:
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册