Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1735060 > unrolled thread

Re: Re: [PATCH] net/packet: fix race condition between fanout_add and __unregister_prot_hook

Started byWillem de Bruijn <willemdebruijn.kernel@gmail.com>
First post2017-09-19 18:20 +0200
Last post2017-09-19 18:20 +0200
Articles 2 — 1 participant

Back to article view | Back to linux.kernel

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  Re: Re: [PATCH] net/packet: fix race condition between fanout_add and __unregister_prot_hook Willem de Bruijn <willemdebruijn.kernel@gmail.com> - 2017-09-19 18:20 +0200
    Re: Re: [PATCH] net/packet: fix race condition between fanout_add and __unregister_prot_hook Willem de Bruijn <willemdebruijn.kernel@gmail.com> - 2017-09-19 18:20 +0200

#1735060 — Re: Re: [PATCH] net/packet: fix race condition between fanout_add and __unregister_prot_hook

FromWillem de Bruijn <willemdebruijn.kernel@gmail.com>
Date2017-09-19 18:20 +0200
SubjectRe: Re: [PATCH] net/packet: fix race condition between fanout_add and __unregister_prot_hook
Message-ID<urtpD-7FJ-3@gated-at.bofh.it>
On Tue, Sep 19, 2017 at 3:21 AM, Nixiaoming <nixiaoming@huawei.com> wrote:
> On Fri, Sep 15, 2017 at 10:46 AM, Willem de Bruijn
>
> <willemdebruijn.kernel@gmail.com> wrote:
>
>>
>
>> In case of failure we also need to unlink and free match. I
>
>> sent the following:
>
>>
>
>> http://patchwork.ozlabs.org/patch/813945/
>
>
>
> +       spin_lock(&po->bind_lock);
>
> +       if (po->running &&
>
> +           match->type == type &&
>
>            match->prot_hook.type == po->prot_hook.type &&
>
>            match->prot_hook.dev == po->prot_hook.dev) {
>
>                 err = -ENOSPC;
>
> @@ -1761,6 +1760,13 @@  static int fanout_add(struct sock *sk, u16 id, u16
> type_flags)
>
>                           err = 0;
>
>                 }
>
>        }
>
> +       spin_unlock(&po->bind_lock);
>
> +
>
> +       if (err && !refcount_read(&match->sk_ref)) {
>
> +                list_del(&match->list);
>
> +                kfree(match);
>
> +       }
>
>
>
>
>
> In the function fanout_add add spin_lock to protect po-> running and po->
> fanout,
>
> then whether it should be in the function fanout_release also add spin_lock
> protection ?

po->bind_lock is held when registering and unregistering the
protocol hook. fanout_release does access po->running or
prot_hook.

It is called from packet_release, which does hold the bind_lock
when unregistering the protocol hook.

[toc] | [next] | [standalone]


#1735061

FromWillem de Bruijn <willemdebruijn.kernel@gmail.com>
Date2017-09-19 18:20 +0200
Message-ID<urtpD-7FJ-11@gated-at.bofh.it>
In reply to#1735060
On Tue, Sep 19, 2017 at 12:09 PM, Willem de Bruijn
<willemdebruijn.kernel@gmail.com> wrote:
> On Tue, Sep 19, 2017 at 3:21 AM, Nixiaoming <nixiaoming@huawei.com> wrote:
>> On Fri, Sep 15, 2017 at 10:46 AM, Willem de Bruijn
>>
>> <willemdebruijn.kernel@gmail.com> wrote:
>>
>>>
>>
>>> In case of failure we also need to unlink and free match. I
>>
>>> sent the following:
>>
>>>
>>
>>> http://patchwork.ozlabs.org/patch/813945/
>>
>>
>>
>> +       spin_lock(&po->bind_lock);
>>
>> +       if (po->running &&
>>
>> +           match->type == type &&
>>
>>            match->prot_hook.type == po->prot_hook.type &&
>>
>>            match->prot_hook.dev == po->prot_hook.dev) {
>>
>>                 err = -ENOSPC;
>>
>> @@ -1761,6 +1760,13 @@  static int fanout_add(struct sock *sk, u16 id, u16
>> type_flags)
>>
>>                           err = 0;
>>
>>                 }
>>
>>        }
>>
>> +       spin_unlock(&po->bind_lock);
>>
>> +
>>
>> +       if (err && !refcount_read(&match->sk_ref)) {
>>
>> +                list_del(&match->list);
>>
>> +                kfree(match);
>>
>> +       }
>>
>>
>>
>>
>>
>> In the function fanout_add add spin_lock to protect po-> running and po->
>> fanout,
>>
>> then whether it should be in the function fanout_release also add spin_lock
>> protection ?
>
> po->bind_lock is held when registering and unregistering the
> protocol hook. fanout_release does access po->running or
> prot_hook.

whoops. does *not* access.

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web