1. 27 8月, 2015 1 次提交
  2. 18 8月, 2015 7 次提交
  3. 11 5月, 2015 1 次提交
  4. 12 6月, 2014 1 次提交
  5. 12 4月, 2014 1 次提交
    • D
      net: Fix use after free by removing length arg from sk_data_ready callbacks. · 676d2369
      David S. Miller 提交于
      Several spots in the kernel perform a sequence like:
      
      	skb_queue_tail(&sk->s_receive_queue, skb);
      	sk->sk_data_ready(sk, skb->len);
      
      But at the moment we place the SKB onto the socket receive queue it
      can be consumed and freed up.  So this skb->len access is potentially
      to freed up memory.
      
      Furthermore, the skb->len can be modified by the consumer so it is
      possible that the value isn't accurate.
      
      And finally, no actual implementation of this callback actually uses
      the length argument.  And since nobody actually cared about it's
      value, lots of call sites pass arbitrary values in such as '0' and
      even '1'.
      
      So just remove the length argument from the callback, that way there
      is no confusion whatsoever and all of these use-after-free cases get
      fixed as a side effect.
      
      Based upon a patch by Eric Dumazet and his suggestion to audit this
      issue tree-wide.
      Signed-off-by: NDavid S. Miller <davem@davemloft.net>
      676d2369
  6. 22 1月, 2014 1 次提交
  7. 16 12月, 2013 1 次提交
  8. 19 6月, 2013 1 次提交
  9. 15 6月, 2013 6 次提交
  10. 10 4月, 2013 1 次提交
    • D
      net: sctp: introduce uapi header for sctp · 1b866434
      Daniel Borkmann 提交于
      This patch introduces an UAPI header for the SCTP protocol,
      so that we can facilitate the maintenance and development of
      user land applications or libraries, in particular in terms
      of header synchronization.
      
      To not break compatibility, some fragments from lksctp-tools'
      netinet/sctp.h have been carefully included, while taking care
      that neither kernel nor user land breaks, so both compile fine
      with this change (for lksctp-tools I tested with the old
      netinet/sctp.h header and with a newly adapted one that includes
      the uapi sctp header). lksctp-tools smoke test run through
      successfully as well in both cases.
      Suggested-by: NNeil Horman <nhorman@tuxdriver.com>
      Cc: Neil Horman <nhorman@tuxdriver.com>
      Cc: Vlad Yasevich <vyasevich@gmail.com>
      Signed-off-by: NDaniel Borkmann <dborkman@redhat.com>
      Signed-off-by: NDavid S. Miller <davem@davemloft.net>
      1b866434
  11. 28 2月, 2013 1 次提交
    • S
      hlist: drop the node parameter from iterators · b67bfe0d
      Sasha Levin 提交于
      I'm not sure why, but the hlist for each entry iterators were conceived
      
              list_for_each_entry(pos, head, member)
      
      The hlist ones were greedy and wanted an extra parameter:
      
              hlist_for_each_entry(tpos, pos, head, member)
      
      Why did they need an extra pos parameter? I'm not quite sure. Not only
      they don't really need it, it also prevents the iterator from looking
      exactly like the list iterator, which is unfortunate.
      
      Besides the semantic patch, there was some manual work required:
      
       - Fix up the actual hlist iterators in linux/list.h
       - Fix up the declaration of other iterators based on the hlist ones.
       - A very small amount of places were using the 'node' parameter, this
       was modified to use 'obj->member' instead.
       - Coccinelle didn't handle the hlist_for_each_entry_safe iterator
       properly, so those had to be fixed up manually.
      
      The semantic patch which is mostly the work of Peter Senna Tschudin is here:
      
      @@
      iterator name hlist_for_each_entry, hlist_for_each_entry_continue, hlist_for_each_entry_from, hlist_for_each_entry_rcu, hlist_for_each_entry_rcu_bh, hlist_for_each_entry_continue_rcu_bh, for_each_busy_worker, ax25_uid_for_each, ax25_for_each, inet_bind_bucket_for_each, sctp_for_each_hentry, sk_for_each, sk_for_each_rcu, sk_for_each_from, sk_for_each_safe, sk_for_each_bound, hlist_for_each_entry_safe, hlist_for_each_entry_continue_rcu, nr_neigh_for_each, nr_neigh_for_each_safe, nr_node_for_each, nr_node_for_each_safe, for_each_gfn_indirect_valid_sp, for_each_gfn_sp, for_each_host;
      
      type T;
      expression a,c,d,e;
      identifier b;
      statement S;
      @@
      
      -T b;
          <+... when != b
      (
      hlist_for_each_entry(a,
      - b,
      c, d) S
      |
      hlist_for_each_entry_continue(a,
      - b,
      c) S
      |
      hlist_for_each_entry_from(a,
      - b,
      c) S
      |
      hlist_for_each_entry_rcu(a,
      - b,
      c, d) S
      |
      hlist_for_each_entry_rcu_bh(a,
      - b,
      c, d) S
      |
      hlist_for_each_entry_continue_rcu_bh(a,
      - b,
      c) S
      |
      for_each_busy_worker(a, c,
      - b,
      d) S
      |
      ax25_uid_for_each(a,
      - b,
      c) S
      |
      ax25_for_each(a,
      - b,
      c) S
      |
      inet_bind_bucket_for_each(a,
      - b,
      c) S
      |
      sctp_for_each_hentry(a,
      - b,
      c) S
      |
      sk_for_each(a,
      - b,
      c) S
      |
      sk_for_each_rcu(a,
      - b,
      c) S
      |
      sk_for_each_from
      -(a, b)
      +(a)
      S
      + sk_for_each_from(a) S
      |
      sk_for_each_safe(a,
      - b,
      c, d) S
      |
      sk_for_each_bound(a,
      - b,
      c) S
      |
      hlist_for_each_entry_safe(a,
      - b,
      c, d, e) S
      |
      hlist_for_each_entry_continue_rcu(a,
      - b,
      c) S
      |
      nr_neigh_for_each(a,
      - b,
      c) S
      |
      nr_neigh_for_each_safe(a,
      - b,
      c, d) S
      |
      nr_node_for_each(a,
      - b,
      c) S
      |
      nr_node_for_each_safe(a,
      - b,
      c, d) S
      |
      - for_each_gfn_sp(a, c, d, b) S
      + for_each_gfn_sp(a, c, d) S
      |
      - for_each_gfn_indirect_valid_sp(a, c, d, b) S
      + for_each_gfn_indirect_valid_sp(a, c, d) S
      |
      for_each_host(a,
      - b,
      c) S
      |
      for_each_host_safe(a,
      - b,
      c, d) S
      |
      for_each_mesh_entry(a,
      - b,
      c, d) S
      )
          ...+>
      
      [akpm@linux-foundation.org: drop bogus change from net/ipv4/raw.c]
      [akpm@linux-foundation.org: drop bogus hunk from net/ipv6/raw.c]
      [akpm@linux-foundation.org: checkpatch fixes]
      [akpm@linux-foundation.org: fix warnings]
      [akpm@linux-foudnation.org: redo intrusive kvm changes]
      Tested-by: NPeter Senna Tschudin <peter.senna@gmail.com>
      Acked-by: NPaul E. McKenney <paulmck@linux.vnet.ibm.com>
      Signed-off-by: NSasha Levin <sasha.levin@oracle.com>
      Cc: Wu Fengguang <fengguang.wu@intel.com>
      Cc: Marcelo Tosatti <mtosatti@redhat.com>
      Cc: Gleb Natapov <gleb@redhat.com>
      Signed-off-by: NAndrew Morton <akpm@linux-foundation.org>
      Signed-off-by: NLinus Torvalds <torvalds@linux-foundation.org>
      b67bfe0d
  12. 02 11月, 2012 1 次提交
  13. 13 8月, 2012 1 次提交
  14. 10 8月, 2012 2 次提交
  15. 09 8月, 2012 1 次提交
    • D
      dlm: fix deadlock between dlm_send and dlm_controld · 36b71a8b
      David Teigland 提交于
      A deadlock sometimes occurs between dlm_controld closing
      a lowcomms connection through configfs and dlm_send looking
      up the address for a new connection in configfs.
      
      dlm_controld does a configfs rmdir which calls
      dlm_lowcomms_close which waits for dlm_send to
      cancel work on the workqueues.
      
      The dlm_send workqueue thread has called
      tcp_connect_to_sock which calls dlm_nodeid_to_addr
      which does a configfs lookup and blocks on a lock
      held by dlm_controld in the rmdir path.
      
      The solution here is to save the node addresses within
      the lowcomms code so that the lowcomms workqueue does
      not need to step through configfs to get a node address.
      
      dlm_controld:
      wait_for_completion+0x1d/0x20
      __cancel_work_timer+0x1b3/0x1e0
      cancel_work_sync+0x10/0x20
      dlm_lowcomms_close+0x4c/0xb0 [dlm]
      drop_comm+0x22/0x60 [dlm]
      client_drop_item+0x26/0x50 [configfs]
      configfs_rmdir+0x180/0x230 [configfs]
      vfs_rmdir+0xbd/0xf0
      do_rmdir+0x103/0x120
      sys_rmdir+0x16/0x20
      
      dlm_send:
      mutex_lock+0x2b/0x50
      get_comm+0x34/0x140 [dlm]
      dlm_nodeid_to_addr+0x18/0xd0 [dlm]
      tcp_connect_to_sock+0xf4/0x2d0 [dlm]
      process_send_sockets+0x1d2/0x260 [dlm]
      worker_thread+0x170/0x2a0
      Signed-off-by: NDavid Teigland <teigland@redhat.com>
      36b71a8b
  16. 27 4月, 2012 1 次提交
  17. 21 3月, 2012 1 次提交
  18. 09 3月, 2012 1 次提交
  19. 23 11月, 2011 1 次提交
  20. 07 7月, 2011 1 次提交
  21. 31 3月, 2011 1 次提交
  22. 11 3月, 2011 1 次提交
  23. 12 2月, 2011 1 次提交
  24. 14 12月, 2010 1 次提交
  25. 13 11月, 2010 3 次提交
  26. 12 11月, 2010 1 次提交
    • D
      dlm: Handle application limited situations properly. · b36930dd
      David Miller 提交于
      In the normal regime where an application uses non-blocking I/O
      writes on a socket, they will handle -EAGAIN and use poll() to
      wait for send space.
      
      They don't actually sleep on the socket I/O write.
      
      But kernel level RPC layers that do socket I/O operations directly
      and key off of -EAGAIN on the write() to "try again later" don't
      use poll(), they instead have their own sleeping mechanism and
      rely upon ->sk_write_space() to trigger the wakeup.
      
      So they do effectively sleep on the write(), but this mechanism
      alone does not let the socket layers know what's going on.
      
      Therefore they must emulate what would have happened, otherwise
      TCP cannot possibly see that the connection is application window
      size limited.
      
      Handle this, therefore, like SUNRPC by setting SOCK_NOSPACE and
      bumping the ->sk_write_count as needed when we hit the send buffer
      limits.
      
      This should make TCP send buffer size auto-tuning and the
      ->sk_write_space() callback invocations actually happen.
      Signed-off-by: NDavid S. Miller <davem@davemloft.net>
      Signed-off-by: NDavid Teigland <teigland@redhat.com>
      b36930dd