Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1267285

Re: [PATCH] unix: avoid use-after-free in ep_remove_wait_queue

From Rainer Weikusat <rweikusat@mobileactivedefense.com>
Newsgroups linux.kernel
Subject Re: [PATCH] unix: avoid use-after-free in ep_remove_wait_queue
Date 2015-11-11 17:20 +0100
Message-ID <qtGhQ-55w-9@gated-at.bofh.it> (permalink)
References (5 earlier) <qrQEG-5PE-15@gated-at.bofh.it> <qrQY1-6bv-3@gated-at.bofh.it> <qsVVE-7IC-11@gated-at.bofh.it> <qtp7j-2b1-1@gated-at.bofh.it> <qtCHg-2HY-5@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


Hannes Frederic Sowa <hannes@stressinduktion.org> writes:
> On Tue, Nov 10, 2015, at 22:55, Rainer Weikusat wrote:
>> An AF_UNIX datagram socket being the client in an n:1 association with
>> some server socket is only allowed to send messages to the server if the
>> receive queue of this socket contains at most sk_max_ack_backlog
>> datagrams.

[...]

> This whole patch seems pretty complicated to me.
>
> Can't we just remove the unix_recvq_full checks alltogether and unify
> unix_dgram_poll with unix_poll?
>
> If we want to be cautious we could simply make unix_max_dgram_qlen limit
> the number of skbs which are in flight from a sending socket. The skb
> destructor can then decrement this. This seems much simpler.
>
> Would this work?

In the way this is intended to work, cf

http://marc.info/?t=115627606000002&r=1&w=2

only if the limit would also apply to sockets which didn't sent anything
so far. Which means it'll end up in the exact same situation as before:
Sending something using a certain socket may not be possible because of
data sent by other sockets, so either, code trying to send using this
sockets ends up busy-waiting for "space again available" despite it's
trying to use select/ poll/ epolll/ $whatnot to get notified of this
condition and sleep until then or this notification needs to be
propagated to sleeping threads which didn't get to send anything yet.
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

Re: Use-after-free in ep_remove_wait_queue Dmitry Vyukov <dvyukov@google.com> - 2015-11-06 14:10 +0100
  Re: Use-after-free in ep_remove_wait_queue Jason Baron <jbaron@akamai.com> - 2015-11-06 16:00 +0100
    Re: Use-after-free in ep_remove_wait_queue Rainer Weikusat <rweikusat@mobileactivedefense.com> - 2015-11-06 16:20 +0100
      [PATCH] unix: avoid use-after-free in ep_remove_wait_queue Rainer Weikusat <rweikusat@mobileactivedefense.com> - 2015-11-09 15:50 +0100
        Re: [PATCH] unix: avoid use-after-free in ep_remove_wait_queue David Miller <davem@davemloft.net> - 2015-11-09 19:30 +0100
          Re: [PATCH] unix: avoid use-after-free in ep_remove_wait_queue Rainer Weikusat <rweikusat@mobileactivedefense.com> - 2015-11-10 18:20 +0100
        Re: [PATCH] unix: avoid use-after-free in ep_remove_wait_queue Jason Baron <jbaron@akamai.com> - 2015-11-09 23:50 +0100
          Re: [PATCH] unix: avoid use-after-free in ep_remove_wait_queue Rainer Weikusat <rweikusat@mobileactivedefense.com> - 2015-11-10 18:40 +0100
        Re: [PATCH] unix: avoid use-after-free in ep_remove_wait_queue Rainer Weikusat <rweikusat@mobileactivedefense.com> - 2015-11-10 23:00 +0100
          Re: [PATCH] unix: avoid use-after-free in ep_remove_wait_queue Hannes Frederic Sowa <hannes@stressinduktion.org> - 2015-11-11 13:30 +0100
            Re: [PATCH] unix: avoid use-after-free in ep_remove_wait_queue Rainer Weikusat <rweikusat@mobileactivedefense.com> - 2015-11-11 17:20 +0100
              Re: [PATCH] unix: avoid use-after-free in ep_remove_wait_queue Hannes Frederic Sowa <hannes@stressinduktion.org> - 2015-11-11 20:00 +0100
                Re: [PATCH] unix: avoid use-after-free in ep_remove_wait_queue Rainer Weikusat <rweikusat@mobileactivedefense.com> - 2015-11-13 20:10 +0100
          Re: [PATCH] unix: avoid use-after-free in ep_remove_wait_queue Jason Baron <jbaron@akamai.com> - 2015-11-11 18:40 +0100
            Re: [PATCH] unix: avoid use-after-free in ep_remove_wait_queue Rainer Weikusat <rweikusat@mobileactivedefense.com> - 2015-11-12 20:20 +0100
          Re: [PATCH] unix: avoid use-after-free in ep_remove_wait_queue Rainer Weikusat <rweikusat@mobileactivedefense.com> - 2015-11-13 20:00 +0100
            Re: [PATCH] unix: avoid use-after-free in ep_remove_wait_queue Jason Baron <jbaron@akamai.com> - 2015-11-13 23:20 +0100
              Re: [PATCH] unix: avoid use-after-free in ep_remove_wait_queue Rainer Weikusat <rweikusat@mobileactivedefense.com> - 2015-11-15 19:40 +0100

csiph-web