Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1452685
| Path | csiph.com!aioe.org!gothmog.csi.it!bofh.it!news.nic.it!robomod |
|---|---|
| From | ebiederm@xmission.com (Eric W. Biederman) |
| Newsgroups | linux.kernel |
| Subject | Re: [PATCH RESEND nf] netfilter: avoid a race between nf_register_hook() and cleanup_net() |
| Date | Sat, 30 Jul 2016 15:40:01 +0200 |
| Message-ID | <s0CEF-38l-5@gated-at.bofh.it> (permalink) |
| References | <s0iFY-6Z7-9@gated-at.bofh.it> <s0iFY-6Z7-7@gated-at.bofh.it> |
| X-Original-To | Michal Kubecek <mkubecek@suse.cz> |
| User-Agent | Gnus/5.13 (Gnus v5.13) Emacs/24.5 (gnu/linux) |
| MIME-Version | 1.0 |
| Content-Type | text/plain |
| X-Xm-Spf | eid=1bTUSS-0005Nz-OR;;;mid=<87shurb6ne.fsf@x220.int.ebiederm.org>;;;hst=in01.mta.xmission.com;;;ip=67.3.204.119;;;frm=ebiederm@xmission.com;;;spf=neutral |
| X-Xm-Aid | U2FsdGVkX18xKBd9H0n3ifLmsEQjS8J7h2G0+i58JVM= |
| X-Sa-Exim-Connect-IP | 67.3.204.119 |
| X-Sa-Exim-Mail-From | ebiederm@xmission.com |
| X-Spam-Report | * -1.0 ALL_TRUSTED Passed through trusted hosts only via SMTP * 0.7 XMSubLong Long Subject * 0.0 TVD_RCVD_IP Message was received from an IP address * 0.0 T_TM2_M_HEADER_IN_MSG BODY: No description available. * 0.8 BAYES_50 BODY: Bayes spam probability is 40 to 60% * [score: 0.5000] * -0.0 DCC_CHECK_NEGATIVE Not listed in DCC * [sa07 1397; Body=1 Fuz1=1 Fuz2=1] * 0.0 T_TooManySym_01 4+ unique symbols in subject * 0.0 T_TooManySym_02 5+ unique symbols in subject |
| X-Spam-Dcc | XMission; sa07 1397; Body=1 Fuz1=1 Fuz2=1 |
| X-Spam-Combo | ;Michal Kubecek <mkubecek@suse.cz> |
| X-Spam-Timing | total 549 ms - load_scoreonly_sql: 0.04 (0.0%), signal_user_changed: 4.6 (0.8%), b_tie_ro: 3.3 (0.6%), parse: 1.12 (0.2%), extract_message_metadata: 20 (3.6%), get_uri_detail_list: 3.5 (0.6%), tests_pri_-1000: 7 (1.3%), tests_pri_-950: 1.23 (0.2%), tests_pri_-900: 1.03 (0.2%), tests_pri_-400: 27 (4.9%), check_bayes: 26 (4.7%), b_tokenize: 8 (1.4%), b_tok_get_all: 9 (1.6%), b_comp_prob: 3.2 (0.6%), b_tok_touch_all: 3.6 (0.7%), b_finish: 0.92 (0.2%), tests_pri_0: 479 (87.3%), check_dkim_signature: 0.52 (0.1%), check_dkim_adsp: 22 (3.9%), tests_pri_500: 4.7 (0.9%), rewrite_mail: 0.00 (0.0%) |
| X-Spam-Flag | No |
| X-Sa-Exim-Version | 4.2.1 (built Thu, 05 May 2016 13:38:54 -0600) |
| X-Sa-Exim-Scanned | Yes (on in01.mta.xmission.com) |
| Sender | robomod@news.nic.it |
| List-ID | <linux-kernel.vger.kernel.org> |
| X-Mailing-List | linux-kernel@vger.kernel.org |
| Approved | robomod@news.nic.it |
| Lines | 98 |
| Organization | linux.* mail to news gateway |
| X-Original-Cc | Pablo Neira Ayuso <pablo@netfilter.org>, Patrick McHardy <kaber@trash.net>, Jozsef Kadlecsik <kadlec@blackhole.kfki.hu>, netfilter-devel@vger.kernel.org, coreteam@netfilter.org, netdev@vger.kernel.org, linux-kernel@vger.kernel.org |
| X-Original-Date | Sat, 30 Jul 2016 08:24:37 -0500 |
| X-Original-Message-ID | <87shurb6ne.fsf@x220.int.ebiederm.org> |
| X-Original-References | <20160729150033.E0250A0BD9@unicorn.suse.cz> <20160729161904.4F00BA0BD9@unicorn.suse.cz> |
| X-Original-Sender | linux-kernel-owner@vger.kernel.org |
| Xref | csiph.com linux.kernel:1452685 |
Show key headers only | View raw
Michal Kubecek <mkubecek@suse.cz> writes:
> There is a race condition between nf_{,un}register_hook() and
> cleanup_net() which can either trigger WARN check or cause a memory
> leak. The scenario is like this (2a and 2b are alternatives):
>
> 1. cleanup_net() removes one or more struct net from net_namespace_list
> 2a. nf_register_hook() adds per-netns hooks to all netns (but not those
> removed in step 1) and adds the hook to global nf_hook_list
> 2b. nf_unregister_hook() deletes per-netns hooks from all netns (but not
> those removed in step 1) and removes the hook from nf_hook_list
> 3. cleanup_net() calls pernet subsystem exit functions for netns being
> removed; one of them is netfilter_net_exit() which (among others)
> calls nf_unregister_net_hook() to unregister per-netns hooks for all
> hooks in nf_hook_list.
>
> In case (a), per-netns hooks are never added as the namespace was
> already invisible to for_each_net() in step 2a but an attempt to remove
> them in step 3 (the hook is already in nf_hook_list) triggers a WARN
> check in nf_unregister_net_hook() (no real harm done, however). In case
> (b), the per-netns hook is removed neither in step 2b (netns is already
> invisible to for_each_net()) nor in step 3 (the hook is already removed
> from nf_hook_list), causing a memory leak.
>
> Prevent the race by protecting the for_each_net() loop in
> nf_{,un}register_hook() (also) by net_mutex. There is already a
> precendens for this in rtnl_link_unregister() which addresses similar
> race.
So this analysis of a problem appears to be spot on.
Reviewed-by: "Eric W. Biederman" <ebiederm@xmission.com>
I really really want there to be a better way to do this, but it is
really not ok for a hook to continue it's life past
nf_unregister_net_hook as after that point the code may be removed
from the kernel (sigh).
Although keeping with the precedent and minimizing net_mutex
we could remove the WARN and keep nf_register_hook as it is.
But that sounds entirely too clever for a fix that will
probably be backported.
But that sounds entirely too clever for a fix that likely needs to be
backported.
Eric
> Fixes: 085db2c04557 ("netfilter: Per network namespace netfilter hooks.")
> Signed-off-by: Michal Kubecek <mkubecek@suse.cz>
> ---
> net/netfilter/core.c | 7 +++++++
> 1 file changed, 7 insertions(+)
>
> diff --git a/net/netfilter/core.c b/net/netfilter/core.c
> index f39276d1c2d7..860978c9f82e 100644
> --- a/net/netfilter/core.c
> +++ b/net/netfilter/core.c
> @@ -193,6 +193,8 @@ int nf_register_hook(struct nf_hook_ops *reg)
> struct net *net, *last;
> int ret;
>
> + /* prevent race with cleanup_net() */
> + mutex_lock(&net_mutex);
> rtnl_lock();
> for_each_net(net) {
> ret = nf_register_net_hook(net, reg);
> @@ -201,6 +203,7 @@ int nf_register_hook(struct nf_hook_ops *reg)
> }
> list_add_tail(®->list, &nf_hook_list);
> rtnl_unlock();
> + mutex_unlock(&net_mutex);
>
> return 0;
> rollback:
> @@ -211,6 +214,7 @@ rollback:
> nf_unregister_net_hook(net, reg);
> }
> rtnl_unlock();
> + mutex_unlock(&net_mutex);
> return ret;
> }
> EXPORT_SYMBOL(nf_register_hook);
> @@ -219,11 +223,14 @@ void nf_unregister_hook(struct nf_hook_ops *reg)
> {
> struct net *net;
>
> + /* prevent race with cleanup_net() */
> + mutex_lock(&net_mutex);
> rtnl_lock();
> list_del(®->list);
> for_each_net(net)
> nf_unregister_net_hook(net, reg);
> rtnl_unlock();
> + mutex_unlock(&net_mutex);
> }
> EXPORT_SYMBOL(nf_unregister_hook);
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
[PATCH RESEND nf] netfilter: avoid a race between nf_register_hook() and cleanup_net() Michal Kubecek <mkubecek@suse.cz> - 2016-07-29 18:20 +0200
Re: [PATCH RESEND nf] netfilter: avoid a race between nf_register_hook() and cleanup_net() ebiederm@xmission.com (Eric W. Biederman) - 2016-07-30 15:40 +0200
Re: [PATCH RESEND nf] netfilter: avoid a race between nf_register_hook() and cleanup_net() Pablo Neira Ayuso <pablo@netfilter.org> - 2016-08-01 14:50 +0200
csiph-web