Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1589612
| From | Dmitry Vyukov <dvyukov@google.com> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | Re: net/rds: use-after-free in inet_create |
| Date | 2017-02-28 17:40 +0100 |
| Message-ID | <tfSYG-70r-9@gated-at.bofh.it> (permalink) |
| References | <tfRpU-5QG-39@gated-at.bofh.it> <tfS2B-6kf-11@gated-at.bofh.it> <tfSlY-6te-23@gated-at.bofh.it> <tfSFj-6Rj-1@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
On Tue, Feb 28, 2017 at 5:15 PM, Sowmini Varadhan <sowmini.varadhan@oracle.com> wrote: > On (02/28/17 16:49), Dmitry Vyukov wrote: >> >> Grepping "socket" there, it was doing lots of things with sockets. Are >> we looking for some particular socket type? If there are few programs >> that create sockets of that type, then we can narrow down the set: > > Yes, we are looking for PF_RDS/AF_RDS - this should be > #define AF_RDS 21 /* RDS sockets */ > > I see PF_KCM there (value 41) but no instances of 0x15.. how did > the rds_connect_worker thread get kicked off at all? > > the way this is supposed to work is > 1. someone modprobes rds-tcp > 2. app tries to do rds_sendmsg to some ip address in a netns - this triggers the > creation of an rds_connection, and subsequent kernel socket TCP connection > threads (i.e., rds_connect_worker) for that netns > 3. if you unload rds-tcp, the module_unload should do all the cleanup > needed via rds_tcp_conn_paths_destroy. This is done > Its not clear to me that the test is doing any of this... > > is this reproducible? let me check if there is some race window where > we can restart a connection attempt when rds_tcp_kill_sock assumes > that the connect worker has been quiesced.. Not reproducible so far. rds is compiled into kernel (no modules): CONFIG_RDS=y CONFIG_RDS_TCP=y Also fuzzer actively creates and destroys namespaces. Yes, I don't see socket(0x15) in the log. Probably it was truncated.
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
net/rds: use-after-free in inet_create Dmitry Vyukov <dvyukov@google.com> - 2017-02-28 16:00 +0100
Re: net/rds: use-after-free in inet_create Sowmini Varadhan <sowmini.varadhan@oracle.com> - 2017-02-28 16:40 +0100
Re: net/rds: use-after-free in inet_create Dmitry Vyukov <dvyukov@google.com> - 2017-02-28 17:00 +0100
Re: net/rds: use-after-free in inet_create Sowmini Varadhan <sowmini.varadhan@oracle.com> - 2017-02-28 17:20 +0100
Re: net/rds: use-after-free in inet_create Dmitry Vyukov <dvyukov@google.com> - 2017-02-28 17:40 +0100
Re: net/rds: use-after-free in inet_create Sowmini Varadhan <sowmini.varadhan@oracle.com> - 2017-02-28 17:50 +0100
Re: net/rds: use-after-free in inet_create Dmitry Vyukov <dvyukov@google.com> - 2017-02-28 18:00 +0100
Re: net/rds: use-after-free in inet_create Sowmini Varadhan <sowmini.varadhan@oracle.com> - 2017-02-28 18:40 +0100
Re: net/rds: use-after-free in inet_create Sowmini Varadhan <sowmini.varadhan@oracle.com> - 2017-02-28 19:00 +0100
Re: net/rds: use-after-free in inet_create Dmitry Vyukov <dvyukov@google.com> - 2017-02-28 20:10 +0100
Re: net/rds: use-after-free in inet_create Sowmini Varadhan <sowmini.varadhan@oracle.com> - 2017-03-01 01:10 +0100
Re: net/rds: use-after-free in inet_create Dmitry Vyukov <dvyukov@google.com> - 2017-03-01 11:00 +0100
csiph-web