Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1639606

[PATCH 4.4 49/60] tcp: do not underestimate skb->truesize in tcp_trim_head()

From Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Newsgroups linux.kernel
Subject [PATCH 4.4 49/60] tcp: do not underestimate skb->truesize in tcp_trim_head()
Date 2017-05-11 16:40 +0200
Message-ID <tFXq3-7wN-35@gated-at.bofh.it> (permalink)
References <tFXgl-7ta-3@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


4.4-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Eric Dumazet <edumazet@google.com>


[ Upstream commit 7162fb242cb8322beb558828fd26b33c3e9fc805 ]

Andrey found a way to trigger the WARN_ON_ONCE(delta < len) in
skb_try_coalesce() using syzkaller and a filter attached to a TCP
socket over loopback interface.

I believe one issue with looped skbs is that tcp_trim_head() can end up
producing skb with under estimated truesize.

It hardly matters for normal conditions, since packets sent over
loopback are never truncated.

Bytes trimmed from skb->head should not change skb truesize, since
skb->head is not reallocated.

Signed-off-by: Eric Dumazet <edumazet@google.com>
Reported-by: Andrey Konovalov <andreyknvl@google.com>
Tested-by: Andrey Konovalov <andreyknvl@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 net/ipv4/tcp_output.c |   19 ++++++++++++-------
 1 file changed, 12 insertions(+), 7 deletions(-)

--- a/net/ipv4/tcp_output.c
+++ b/net/ipv4/tcp_output.c
@@ -1221,7 +1221,7 @@ int tcp_fragment(struct sock *sk, struct
  * eventually). The difference is that pulled data not copied, but
  * immediately discarded.
  */
-static void __pskb_trim_head(struct sk_buff *skb, int len)
+static int __pskb_trim_head(struct sk_buff *skb, int len)
 {
 	struct skb_shared_info *shinfo;
 	int i, k, eat;
@@ -1231,7 +1231,7 @@ static void __pskb_trim_head(struct sk_b
 		__skb_pull(skb, eat);
 		len -= eat;
 		if (!len)
-			return;
+			return 0;
 	}
 	eat = len;
 	k = 0;
@@ -1257,23 +1257,28 @@ static void __pskb_trim_head(struct sk_b
 	skb_reset_tail_pointer(skb);
 	skb->data_len -= len;
 	skb->len = skb->data_len;
+	return len;
 }
 
 /* Remove acked data from a packet in the transmit queue. */
 int tcp_trim_head(struct sock *sk, struct sk_buff *skb, u32 len)
 {
+	u32 delta_truesize;
+
 	if (skb_unclone(skb, GFP_ATOMIC))
 		return -ENOMEM;
 
-	__pskb_trim_head(skb, len);
+	delta_truesize = __pskb_trim_head(skb, len);
 
 	TCP_SKB_CB(skb)->seq += len;
 	skb->ip_summed = CHECKSUM_PARTIAL;
 
-	skb->truesize	     -= len;
-	sk->sk_wmem_queued   -= len;
-	sk_mem_uncharge(sk, len);
-	sock_set_flag(sk, SOCK_QUEUE_SHRUNK);
+	if (delta_truesize) {
+		skb->truesize	   -= delta_truesize;
+		sk->sk_wmem_queued -= delta_truesize;
+		sk_mem_uncharge(sk, delta_truesize);
+		sock_set_flag(sk, SOCK_QUEUE_SHRUNK);
+	}
 
 	/* Any change of skb->len requires recalculation of tso factor. */
 	if (tcp_skb_pcount(skb) > 1)

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

[PATCH 4.4 00/60] 4.4.68-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-11 16:40 +0200
  [PATCH 4.4 10/60] power: supply: bq24190_charger: Handle fault before status on interrupt Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-11 16:40 +0200
  [PATCH 4.4 05/60] power: supply: bq24190_charger: Fix irq trigger to IRQF_TRIGGER_FALLING Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-11 16:40 +0200
  [PATCH 4.4 49/60] tcp: do not underestimate skb->truesize in tcp_trim_head() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-11 16:40 +0200
  [PATCH 4.4 11/60] leds: ktd2692: avoid harmless maybe-uninitialized warning Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-11 16:40 +0200
  [PATCH 4.4 45/60] brcmfmac: Make skb header writable before use Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-11 16:40 +0200
  [PATCH 4.4 25/60] usb: host: ohci-exynos: Decrese node refcount on exynos_ehci_get_phy() error paths Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-11 16:40 +0200
  [PATCH 4.4 41/60] scsi: mac_scsi: Fix MAC_SCSI=m option when SCSI=m Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-11 16:40 +0200
  [PATCH 4.4 38/60] USB: serial: sierra: fix bogus alternate-setting assumption Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-11 16:40 +0200
    Re: [PATCH 4.4 38/60] USB: serial: sierra: fix bogus  alternate-setting assumption Ben Hutchings <ben.hutchings@codethink.co.uk> - 2017-05-12 13:30 +0200
      Re: [PATCH 4.4 38/60] USB: serial: sierra: fix bogus  alternate-setting assumption Johan Hovold <johan@kernel.org> - 2017-05-12 14:20 +0200
        Re: [PATCH 4.4 38/60] USB: serial: sierra: fix bogus  alternate-setting assumption Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-12 15:20 +0200
  [PATCH 4.4 40/60] serial: 8250_omap: Fix probe and remove for PM runtime Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-11 16:40 +0200
  [PATCH 4.4 02/60] ARM: 8452/3: PJ4: make coprocessor access sequences buildable in Thumb2 mode Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-11 16:40 +0200
  [PATCH 4.4 19/60] kprobes/x86: Fix kernel panic when certain exception-handling addresses are probed Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-11 16:40 +0200
  [PATCH 4.4 44/60] brcmfmac: Ensure pointer correctly set if skb data location changes Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-11 16:40 +0200
  [PATCH 4.4 47/60] staging: emxx_udc: remove incorrect __init annotations Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-11 16:40 +0200
  [PATCH 4.4 18/60] clk: Make x86/ conditional on CONFIG_COMMON_CLK Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-11 16:40 +0200
  [PATCH 4.4 13/60] mwifiex: debugfs: Fix (sometimes) off-by-1 SSID print Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-11 16:40 +0200
  [PATCH 4.4 55/60] ipv6: initialize route null entry in addrconf_init() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-11 16:40 +0200
  [PATCH 4.4 08/60] power: supply: bq24190_charger: Call power_supply_changed() for relevant component Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-11 16:40 +0200
  [PATCH 4.4 50/60] bpf, arm64: fix jit branch offset related to ldimm64 Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-11 16:40 +0200
  [PATCH 4.4 15/60] mwifiex: Avoid skipping WEP key deletion for AP Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-11 16:50 +0200
  [PATCH 4.4 01/60] 9p: fix a potential acl leak Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-11 16:50 +0200
  [PATCH 4.4 14/60] mwifiex: remove redundant dma padding in AMSDU Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-11 16:50 +0200
  Re: [PATCH 4.4 00/60] 4.4.68-stable review Guenter Roeck <linux@roeck-us.net> - 2017-05-11 23:10 +0200
    Re: [PATCH 4.4 00/60] 4.4.68-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-12 18:00 +0200
  Re: [PATCH 4.4 00/60] 4.4.68-stable review Shuah Khan <shuahkh@osg.samsung.com> - 2017-05-12 17:30 +0200
  Re: [PATCH 4.4 00/60] 4.4.68-stable review Guenter Roeck <linux@roeck-us.net> - 2017-05-12 21:50 +0200

csiph-web