Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1278310

Re: use-after-free in sock_wake_async

From Eric Dumazet <eric.dumazet@gmail.com>
Newsgroups linux.kernel
Subject Re: use-after-free in sock_wake_async
Date 2015-11-26 17:00 +0100
Message-ID <qz77I-7ak-9@gated-at.bofh.it> (permalink)
References (16 earlier) <qyQqf-3L8-31@gated-at.bofh.it> <qyQTg-3Vd-3@gated-at.bofh.it> <qyR2W-3ZJ-9@gated-at.bofh.it> <qyRcC-43u-7@gated-at.bofh.it> <qz4We-5MB-3@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On Thu, 2015-11-26 at 14:32 +0100, Hannes Frederic Sowa wrote:
> Hannes Frederic Sowa <hannes@stressinduktion.org> writes:
> 
> 
> > I have seen filesystems already doing so in .destroy_inode, that's why I
> > am asking. The allocation happens the same way as we do with sock_alloc,
> > e.g. shmem. I actually thought that struct inode already provides an
> > rcu_head for exactly that reason.
> 
> E.g.:

> +static void sock_destroy_inode(struct inode *inode)
> +{
> +	call_rcu(&inode->i_rcu, sock_cache_free_rcu);
> +}

I guess you missed few years back why we had to implement
SLAB_DESTROY_BY_RCU for TCP sockets to not destroy performance.

By adding RCU grace period before reuse of this inode (about 640 bytes
today), you are asking the CPU to evict from its cache precious content,
and slow down some workloads, adding lot of ram pressure, as the cpu
allocating a TCP socket will have to populate its cache for a cold
inode.

The reason we put in a small object the RCU protected fields should be
pretty clear.

Do not copy code that people wrote in other layers without understanding
the performance implications.

Thanks.


--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

use-after-free in sock_wake_async Dmitry Vyukov <dvyukov@google.com> - 2015-11-24 15:20 +0100
  Re: use-after-free in sock_wake_async Eric Dumazet <edumazet@google.com> - 2015-11-24 16:30 +0100
    Re: use-after-free in sock_wake_async Eric Dumazet <eric.dumazet@gmail.com> - 2015-11-24 16:40 +0100
    Re: use-after-free in sock_wake_async Jason Baron <jbaron@akamai.com> - 2015-11-24 22:40 +0100
      Re: use-after-free in sock_wake_async Benjamin LaHaise <bcrl@kvack.org> - 2015-11-24 22:50 +0100
        Re: use-after-free in sock_wake_async Eric Dumazet <edumazet@google.com> - 2015-11-24 23:10 +0100
          Re: use-after-free in sock_wake_async Eric Dumazet <edumazet@google.com> - 2015-11-24 23:20 +0100
      Re: use-after-free in sock_wake_async Al Viro <viro@ZenIV.linux.org.uk> - 2015-11-24 22:50 +0100
    Re: use-after-free in sock_wake_async Rainer Weikusat <rweikusat@mobileactivedefense.com> - 2015-11-25 00:40 +0100
      Re: use-after-free in sock_wake_async Eric Dumazet <edumazet@google.com> - 2015-11-25 00:50 +0100
        Re: use-after-free in sock_wake_async Rainer Weikusat <rweikusat@mobileactivedefense.com> - 2015-11-25 02:20 +0100
        Re: use-after-free in sock_wake_async Eric Dumazet <edumazet@google.com> - 2015-11-25 02:20 +0100
          Re: use-after-free in sock_wake_async Eric Dumazet <eric.dumazet@gmail.com> - 2015-11-25 03:30 +0100
            Re: use-after-free in sock_wake_async Eric Dumazet <eric.dumazet@gmail.com> - 2015-11-25 06:50 +0100
              Re: use-after-free in sock_wake_async Eric Dumazet <eric.dumazet@gmail.com> - 2015-11-25 15:20 +0100
          Re: use-after-free in sock_wake_async Rainer Weikusat <rweikusat@mobileactivedefense.com> - 2015-11-25 17:50 +0100
            Re: use-after-free in sock_wake_async Eric Dumazet <eric.dumazet@gmail.com> - 2015-11-25 18:20 +0100
              Re: use-after-free in sock_wake_async Rainer Weikusat <rweikusat@mobileactivedefense.com> - 2015-11-25 18:40 +0100
                Re: use-after-free in sock_wake_async Eric Dumazet <eric.dumazet@gmail.com> - 2015-11-25 19:00 +0100
                Re: use-after-free in sock_wake_async Rainer Weikusat <rweikusat@mobileactivedefense.com> - 2015-11-25 19:30 +0100
                Re: use-after-free in sock_wake_async Eric Dumazet <eric.dumazet@gmail.com> - 2015-11-25 19:40 +0100
                Re: use-after-free in sock_wake_async Rainer Weikusat <rweikusat@mobileactivedefense.com> - 2015-11-25 20:40 +0100
                Re: use-after-free in sock_wake_async Eric Dumazet <eric.dumazet@gmail.com> - 2015-11-25 21:00 +0100
                Re: use-after-free in sock_wake_async Eric Dumazet <eric.dumazet@gmail.com> - 2015-11-25 21:30 +0100
                Re: use-after-free in sock_wake_async Rainer Weikusat <rweikusat@mobileactivedefense.com> - 2015-11-25 22:00 +0100
                Re: use-after-free in sock_wake_async Eric Dumazet <eric.dumazet@gmail.com> - 2015-11-25 23:10 +0100
                Re: use-after-free in sock_wake_async Hannes Frederic Sowa <hannes@stressinduktion.org> - 2015-11-25 23:40 +0100
                Re: use-after-free in sock_wake_async Eric Dumazet <eric.dumazet@gmail.com> - 2015-11-25 23:50 +0100
                Re: use-after-free in sock_wake_async Hannes Frederic Sowa <hannes@stressinduktion.org> - 2015-11-26 00:00 +0100
                Re: use-after-free in sock_wake_async Hannes Frederic Sowa <hannes@stressinduktion.org> - 2015-11-26 14:40 +0100
                Re: use-after-free in sock_wake_async Hannes Frederic Sowa <hannes@stressinduktion.org> - 2015-11-26 15:40 +0100
                Re: use-after-free in sock_wake_async Eric Dumazet <eric.dumazet@gmail.com> - 2015-11-26 17:00 +0100
                Re: use-after-free in sock_wake_async Eric Dumazet <eric.dumazet@gmail.com> - 2015-11-26 18:10 +0100
                Re: use-after-free in sock_wake_async Hannes Frederic Sowa <hannes@stressinduktion.org> - 2015-11-26 18:20 +0100
                Re: use-after-free in sock_wake_async Hannes Frederic Sowa <hannes@stressinduktion.org> - 2015-11-26 18:10 +0100
                Re: use-after-free in sock_wake_async Eric Dumazet <eric.dumazet@gmail.com> - 2015-11-26 18:30 +0100
        Re: use-after-free in sock_wake_async Rainer Weikusat <rweikusat@mobileactivedefense.com> - 2015-11-25 02:20 +0100

csiph-web