Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1258341
| From | Jason Baron <jbaron@akamai.com> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | Re: [RFC] unix: fix use-after-free in unix_dgram_poll() |
| Date | 2015-10-28 19:00 +0100 |
| Message-ID | <qoDaW-5OU-29@gated-at.bofh.it> (permalink) |
| References | (7 earlier) <qjGVQ-1zi-3@gated-at.bofh.it> <ql3nk-ga-19@gated-at.bofh.it> <qlkev-82E-43@gated-at.bofh.it> <qlNJw-Ca-15@gated-at.bofh.it> <qoC5c-55v-21@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
On 10/28/2015 12:46 PM, Rainer Weikusat wrote: > Rainer Weikusat <rw@doppelsaurus.mobileactivedefense.com> writes: >> Jason Baron <jbaron@akamai.com> writes: > > [...] > >>> 2) >>> >>> For the case of epoll() in edge triggered mode we need to ensure that >>> when we return -EAGAIN from unix_dgram_sendmsg() when unix_recvq_full() >>> is true, we need to add a unix_peer_wake_connect() call to guarantee a >>> wakeup. Otherwise, we are going to potentially hang there. >> >> I consider this necessary. > > (As already discussed privately) just doing this would open up another > way for sockets to be enqueued on the peer_wait queue of the peer > forever despite no one wants to be notified of write space > availability. Here's another RFC patch addressing the issues so far plus > this one by breaking the connection to the peer socket from the wake up > relaying function. This has the nice additional property that the > dgram_poll code becomes somewhat simpler as the "dequeued where we > didn't enqueue" situation can no longer occur and the not-so-nice > additional property that the connect and disconnect functions need to > take the peer_wait.lock spinlock explicitly so that this lock is used to > ensure that no two threads modifiy the private pointer of the client > wait_queue_t. Hmmm...I thought these were already all guarded by unix_state_lock(sk). In any case, rest of the patch overall looks good to me. Thanks, -Jason -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Re: [PATCH v2 1/3] unix: fix use-after-free in unix_dgram_poll() Rainer Weikusat <rweikusat@mobileactivedefense.com> - 2015-10-18 23:10 +0200
Re: [PATCH v2 1/3] unix: fix use-after-free in unix_dgram_poll() Jason Baron <jbaron@akamai.com> - 2015-10-19 17:10 +0200
Re: [PATCH v2 1/3] unix: fix use-after-free in unix_dgram_poll() Rainer Weikusat <rweikusat@mobileactivedefense.com> - 2015-10-21 00:40 +0200
Re: [PATCH v2 1/3] unix: fix use-after-free in unix_dgram_poll() Rainer Weikusat <rweikusat@mobileactivedefense.com> - 2015-10-21 19:40 +0200
[RFC] unix: fix use-after-free in unix_dgram_poll() Rainer Weikusat <rweikusat@mobileactivedefense.com> - 2015-10-28 17:50 +0100
Re: [RFC] unix: fix use-after-free in unix_dgram_poll() Jason Baron <jbaron@akamai.com> - 2015-10-28 19:00 +0100
Re: [RFC] unix: fix use-after-free in unix_dgram_poll() Rainer Weikusat <rweikusat@mobileactivedefense.com> - 2015-10-29 15:30 +0100
Re: [RFC] unix: fix use-after-free in unix_dgram_poll()/ 4.2.5 Rainer Weikusat <rweikusat@mobileactivedefense.com> - 2015-10-30 22:00 +0100
csiph-web