mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Ben Hutchings <ben@decadent.org.uk>
To: linux-kernel@vger.kernel.org, stable@vger.kernel.org
Cc: torvalds@linux-foundation.org, akpm@linux-foundation.org,
	alan@lxorguk.ukuu.org.uk, Neil Horman <nhorman@tuxdriver.com>,
	Eric Dumazet <eric.dumazet@gmail.com>,
	David Miller <davem@davemloft.net>,
	Eric Dumazet <edumazet@google.com>
Subject: [ 65/70] drop_monitor: Make updating data->skb smp safe
Date: Tue, 07 Aug 2012 04:29:00 +0100	[thread overview]
Message-ID: <20120807032805.522973792@decadent.org.uk> (raw)
In-Reply-To: <20120807032755.803571133@decadent.org.uk>

3.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Neil Horman <nhorman@tuxdriver.com>

commit 3885ca785a3618593226687ced84f3f336dc3860 upstream.

Eric Dumazet pointed out to me that the drop_monitor protocol has some holes in
its smp protections.  Specifically, its possible to replace data->skb while its
being written.  This patch corrects that by making data->skb an rcu protected
variable.  That will prevent it from being overwritten while a tracepoint is
modifying it.

Signed-off-by: Neil Horman <nhorman@tuxdriver.com>
Reported-by: Eric Dumazet <eric.dumazet@gmail.com>
CC: David Miller <davem@davemloft.net>
Acked-by: Eric Dumazet <edumazet@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 net/core/drop_monitor.c |   70 ++++++++++++++++++++++++++++++++++++-----------
 1 file changed, 54 insertions(+), 16 deletions(-)

diff --git a/net/core/drop_monitor.c b/net/core/drop_monitor.c
index a221a5b..7592943 100644
--- a/net/core/drop_monitor.c
+++ b/net/core/drop_monitor.c
@@ -46,7 +46,7 @@ static DEFINE_MUTEX(trace_state_mutex);
 
 struct per_cpu_dm_data {
 	struct work_struct dm_alert_work;
-	struct sk_buff *skb;
+	struct sk_buff __rcu *skb;
 	atomic_t dm_hit_count;
 	struct timer_list send_timer;
 };
@@ -73,35 +73,58 @@ static int dm_hit_limit = 64;
 static int dm_delay = 1;
 static unsigned long dm_hw_check_delta = 2*HZ;
 static LIST_HEAD(hw_stats_list);
+static int initialized = 0;
 
 static void reset_per_cpu_data(struct per_cpu_dm_data *data)
 {
 	size_t al;
 	struct net_dm_alert_msg *msg;
 	struct nlattr *nla;
+	struct sk_buff *skb;
+	struct sk_buff *oskb = rcu_dereference_protected(data->skb, 1);
 
 	al = sizeof(struct net_dm_alert_msg);
 	al += dm_hit_limit * sizeof(struct net_dm_drop_point);
 	al += sizeof(struct nlattr);
 
-	data->skb = genlmsg_new(al, GFP_KERNEL);
-	genlmsg_put(data->skb, 0, 0, &net_drop_monitor_family,
-			0, NET_DM_CMD_ALERT);
-	nla = nla_reserve(data->skb, NLA_UNSPEC, sizeof(struct net_dm_alert_msg));
-	msg = nla_data(nla);
-	memset(msg, 0, al);
-	atomic_set(&data->dm_hit_count, dm_hit_limit);
+	skb = genlmsg_new(al, GFP_KERNEL);
+
+	if (skb) {
+		genlmsg_put(skb, 0, 0, &net_drop_monitor_family,
+				0, NET_DM_CMD_ALERT);
+		nla = nla_reserve(skb, NLA_UNSPEC,
+				  sizeof(struct net_dm_alert_msg));
+		msg = nla_data(nla);
+		memset(msg, 0, al);
+	} else if (initialized)
+		schedule_work_on(smp_processor_id(), &data->dm_alert_work);
+
+	/*
+	 * Don't need to lock this, since we are guaranteed to only
+	 * run this on a single cpu at a time.
+	 * Note also that we only update data->skb if the old and new skb
+	 * pointers don't match.  This ensures that we don't continually call
+	 * synchornize_rcu if we repeatedly fail to alloc a new netlink message.
+	 */
+	if (skb != oskb) {
+		rcu_assign_pointer(data->skb, skb);
+
+		synchronize_rcu();
+
+		atomic_set(&data->dm_hit_count, dm_hit_limit);
+	}
+
 }
 
 static void send_dm_alert(struct work_struct *unused)
 {
 	struct sk_buff *skb;
-	struct per_cpu_dm_data *data = &__get_cpu_var(dm_cpu_data);
+	struct per_cpu_dm_data *data = &get_cpu_var(dm_cpu_data);
 
 	/*
 	 * Grab the skb we're about to send
 	 */
-	skb = data->skb;
+	skb = rcu_dereference_protected(data->skb, 1);
 
 	/*
 	 * Replace it with a new one
@@ -111,8 +134,10 @@ static void send_dm_alert(struct work_struct *unused)
 	/*
 	 * Ship it!
 	 */
-	genlmsg_multicast(skb, 0, NET_DM_GRP_ALERT, GFP_KERNEL);
+	if (skb)
+		genlmsg_multicast(skb, 0, NET_DM_GRP_ALERT, GFP_KERNEL);
 
+	put_cpu_var(dm_cpu_data);
 }
 
 /*
@@ -123,9 +148,11 @@ static void send_dm_alert(struct work_struct *unused)
  */
 static void sched_send_work(unsigned long unused)
 {
-	struct per_cpu_dm_data *data =  &__get_cpu_var(dm_cpu_data);
+	struct per_cpu_dm_data *data =  &get_cpu_var(dm_cpu_data);
+
+	schedule_work_on(smp_processor_id(), &data->dm_alert_work);
 
-	schedule_work(&data->dm_alert_work);
+	put_cpu_var(dm_cpu_data);
 }
 
 static void trace_drop_common(struct sk_buff *skb, void *location)
@@ -134,9 +161,16 @@ static void trace_drop_common(struct sk_buff *skb, void *location)
 	struct nlmsghdr *nlh;
 	struct nlattr *nla;
 	int i;
-	struct per_cpu_dm_data *data = &__get_cpu_var(dm_cpu_data);
+	struct sk_buff *dskb;
+	struct per_cpu_dm_data *data = &get_cpu_var(dm_cpu_data);
 
 
+	rcu_read_lock();
+	dskb = rcu_dereference(data->skb);
+
+	if (!dskb)
+		goto out;
+
 	if (!atomic_add_unless(&data->dm_hit_count, -1, 0)) {
 		/*
 		 * we're already at zero, discard this hit
@@ -144,7 +178,7 @@ static void trace_drop_common(struct sk_buff *skb, void *location)
 		goto out;
 	}
 
-	nlh = (struct nlmsghdr *)data->skb->data;
+	nlh = (struct nlmsghdr *)dskb->data;
 	nla = genlmsg_data(nlmsg_data(nlh));
 	msg = nla_data(nla);
 	for (i = 0; i < msg->entries; i++) {
@@ -158,7 +192,7 @@ static void trace_drop_common(struct sk_buff *skb, void *location)
 	/*
 	 * We need to create a new entry
 	 */
-	__nla_reserve_nohdr(data->skb, sizeof(struct net_dm_drop_point));
+	__nla_reserve_nohdr(dskb, sizeof(struct net_dm_drop_point));
 	nla->nla_len += NLA_ALIGN(sizeof(struct net_dm_drop_point));
 	memcpy(msg->points[msg->entries].pc, &location, sizeof(void *));
 	msg->points[msg->entries].count = 1;
@@ -170,6 +204,8 @@ static void trace_drop_common(struct sk_buff *skb, void *location)
 	}
 
 out:
+	rcu_read_unlock();
+	put_cpu_var(dm_cpu_data);
 	return;
 }
 
@@ -375,6 +411,8 @@ static int __init init_net_drop_monitor(void)
 		data->send_timer.function = sched_send_work;
 	}
 
+	initialized = 1;
+
 	goto out;
 
 out_unreg:



  parent reply	other threads:[~2012-08-07  3:48 UTC|newest]

Thread overview: 75+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2012-08-07  3:27 [ 00/70] 3.2.27-stable review Ben Hutchings
2012-08-07  3:27 ` [ 01/70] sched: Fix race in task_group() Ben Hutchings
2012-08-07  3:27 ` [ 02/70] floppy: Cleanup disk->queue before caling put_disk() if add_disk() was never called Ben Hutchings
2012-08-07 22:49   ` Herton Ronaldo Krzesinski
2012-08-08  0:40     ` Ben Hutchings
2012-08-08 13:02       ` Herton Ronaldo Krzesinski
2012-08-07  3:27 ` [ 03/70] xen: mark local pages as FOREIGN in the m2p_override Ben Hutchings
2012-08-07  3:27 ` [ 04/70] [media] lirc_sir: make device registration work Ben Hutchings
2012-08-07  3:28 ` [ 05/70] stable: update references to older 2.6 versions for 3.x Ben Hutchings
2012-08-07  3:28 ` [ 06/70] ALSA: hda - add dock support for Thinkpad X230 Tablet Ben Hutchings
2012-08-07  3:28 ` [ 07/70] cfg80211: fix interface combinations check for ADHOC(IBSS) Ben Hutchings
2012-08-07  3:28 ` [ 08/70] m68k: Correct the Atari ALLOWINT definition Ben Hutchings
2012-08-07  3:28 ` [ 09/70] [media] ene_ir: Fix driver initialisation Ben Hutchings
2012-08-07  3:28 ` [ 10/70] nfsd4: our filesystems are normally case sensitive Ben Hutchings
2012-08-07  3:28 ` [ 11/70] random: Use arch_get_random_int instead of cycle counter if avail Ben Hutchings
2012-08-07  3:28 ` [ 12/70] random: Use arch-specific RNG to initialize the entropy store Ben Hutchings
2012-08-07  3:28 ` [ 13/70] random: Adjust the number of loops when initializing Ben Hutchings
2012-08-07  3:28 ` [ 14/70] random: make add_interrupt_randomness() do something sane Ben Hutchings
2012-08-07  3:28 ` [ 15/70] random: use lockless techniques in the interrupt path Ben Hutchings
2012-08-07  3:28 ` [ 16/70] random: create add_device_randomness() interface Ben Hutchings
2012-08-07  3:28 ` [ 17/70] usb: feed USB device information to the /dev/random driver Ben Hutchings
2012-08-07  3:28 ` [ 18/70] net: feed /dev/random with the MAC address when registering a device Ben Hutchings
2012-08-07  3:28 ` [ 19/70] random: use the arch-specific rng in xfer_secondary_pool Ben Hutchings
2012-08-07  3:28 ` [ 20/70] random: add new get_random_bytes_arch() function Ben Hutchings
2012-08-07  3:28 ` [ 21/70] rtc: wm831x: Feed the write counter into device_add_randomness() Ben Hutchings
2012-08-07  3:28 ` [ 22/70] mfd: wm831x: Feed the device UUID " Ben Hutchings
2012-08-07  3:28 ` [ 23/70] ASoC: wm8994: Ensure there are enough BCLKs for four channels Ben Hutchings
2012-08-07  3:28 ` [ 24/70] futex: Test for pi_mutex on fault in futex_wait_requeue_pi() Ben Hutchings
2012-08-07  3:28 ` [ 25/70] futex: Fix bug in WARN_ON for NULL q.pi_state Ben Hutchings
2012-08-07  3:28 ` [ 26/70] futex: Forbid uaddr == uaddr2 in futex_wait_requeue_pi() Ben Hutchings
2012-08-07  3:28 ` [ 27/70] video/smscufx: fix line counting in fb_write Ben Hutchings
2012-08-07  3:28 ` [ 28/70] Input: synaptics - handle out of bounds values from the hardware Ben Hutchings
2012-08-07  3:28 ` [ 29/70] ALSA: hda - Fix invalid D3 of headphone DAC on VT202x codecs Ben Hutchings
2012-08-07  3:28 ` [ 30/70] ALSA: mpu401: Fix missing initialization of irq field Ben Hutchings
2012-08-07  3:28 ` [ 31/70] x86, nops: Missing break resulting in incorrect selection on Intel Ben Hutchings
2012-08-07  3:28 ` [ 32/70] s390/mm: downgrade page table after fork of a 31 bit process Ben Hutchings
2012-08-07  3:28 ` [ 33/70] [IA64] Redefine ATOMIC_INIT and ATOMIC64_INIT to drop the casts Ben Hutchings
2012-08-07  3:28 ` [ 34/70] dm thin: reduce endio_hook pool size Ben Hutchings
2012-08-07  3:28 ` [ 35/70] dm thin: fix memory leak in process_prepared_mapping error paths Ben Hutchings
2012-08-07  3:28 ` [ 36/70] random: mix in architectural randomness in extract_buf() Ben Hutchings
2012-08-07  3:28 ` [ 37/70] asus-wmi: use ASUS_WMI_METHODID_DSTS2 as default DSTS ID Ben Hutchings
2012-08-07  3:28 ` [ 38/70] virtio-blk: Use block layer provided spinlock Ben Hutchings
2012-08-07  3:28 ` [ 39/70] s390/mm: fix fault handling for page table walk case Ben Hutchings
2012-08-07  3:28 ` [ 40/70] nfs: skip commit in releasepage if were freeing memory for fs-related reasons Ben Hutchings
2012-08-07  3:28 ` [ 41/70] md/raid1: dont abort a resync on the first badblock Ben Hutchings
2012-08-07  3:28 ` [ 42/70] pcdp: use early_ioremap/early_iounmap to access pcdp table Ben Hutchings
2012-08-07  3:28 ` [ 43/70] lib/vsprintf.c: kptr_restrict: fix pK-error in SysRq show-all-timers(Q) Ben Hutchings
2012-08-07  3:28 ` [ 44/70] nilfs2: fix deadlock issue between chcp and thaw ioctls Ben Hutchings
2012-08-07  3:28 ` [ 45/70] SUNRPC: return negative value in case rpcbind client creation error Ben Hutchings
2012-08-07  3:28 ` [ 46/70] ARM: 7466/1: disable interrupt before spinning endlessly Ben Hutchings
2012-08-07  3:28 ` [ 47/70] ARM: 7467/1: mutex: use generic xchg-based implementation for ARMv6+ Ben Hutchings
2012-08-07  3:28 ` [ 48/70] ARM: 7476/1: vfp: only clear vfp state for current cpu in vfp_pm_suspend Ben Hutchings
2012-08-07  3:28 ` [ 49/70] ARM: 7477/1: vfp: Always save VFP state in vfp_pm_suspend on UP Ben Hutchings
2012-08-07  3:28 ` [ 50/70] ARM: 7478/1: errata: extend workaround for erratum #720789 Ben Hutchings
2012-08-07  3:28 ` [ 51/70] ARM: Fix undefined instruction exception handling Ben Hutchings
2012-08-07  3:28 ` [ 52/70] USB: echi-dbgp: increase the controller wait time to come out of halt Ben Hutchings
2012-08-07  3:28 ` [ 53/70] ASoC: wm8962: Allow VMID time to fully ramp Ben Hutchings
2012-08-07  3:28 ` [ 54/70] mm/page_alloc.c: remove pageblock_default_order() Ben Hutchings
2012-08-07  3:28 ` [ 55/70] mm: setup pageblock_order before its used by sparsemem Ben Hutchings
2012-08-07  3:28 ` [ 56/70] mm: mmu_notifier: fix freed page still mapped in secondary MMU Ben Hutchings
2012-08-07  3:28 ` [ 57/70] mm: hugetlbfs: close race during teardown of hugetlbfs shared page tables Ben Hutchings
2012-08-07  3:28 ` [ 58/70] ALSA: snd-usb: fix clock source validity index Ben Hutchings
2012-08-07  3:28 ` [ 59/70] ALSA: hda - Support dock on Lenovo Thinkpad T530 with ALC269VC Ben Hutchings
2012-08-07  3:28 ` [ 60/70] ore: Fix out-of-bounds access in _ios_obj() Ben Hutchings
2012-08-07  3:28 ` [ 61/70] m68k: Make sys_atomic_cmpxchg_32 work on classic m68k Ben Hutchings
2012-08-07  3:28 ` [ 62/70] drm/i915: prefer wide & slow to fast & narrow in DP configs Ben Hutchings
2012-08-07  3:28 ` [ 63/70] rt2x00: Add support for BUFFALO WLI-UC-GNM2 to rt2800usb Ben Hutchings
2012-08-07  3:28 ` [ 64/70] drop_monitor: fix sleeping in invalid context warning Ben Hutchings
2012-08-07  3:29 ` Ben Hutchings [this message]
2012-08-07  3:29 ` [ 66/70] drop_monitor: prevent init path from scheduling on the wrong cpu Ben Hutchings
2012-08-07  3:29 ` [ 67/70] drop_monitor: dont sleep in atomic context Ben Hutchings
2012-08-07  3:29 ` [ 68/70] pch_uart: Fix missing break for 16 byte fifo Ben Hutchings
2012-08-07  3:29 ` [ 69/70] pch_uart: Fix rx error interrupt setting issue Ben Hutchings
2012-08-07  3:29 ` [ 70/70] pch_uart: Fix parity " Ben Hutchings
2012-08-07  3:49 ` [ 00/70] 3.2.27-stable review Ben Hutchings

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20120807032805.522973792@decadent.org.uk \
    --to=ben@decadent.org.uk \
    --cc=akpm@linux-foundation.org \
    --cc=alan@lxorguk.ukuu.org.uk \
    --cc=davem@davemloft.net \
    --cc=edumazet@google.com \
    --cc=eric.dumazet@gmail.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=nhorman@tuxdriver.com \
    --cc=stable@vger.kernel.org \
    --cc=torvalds@linux-foundation.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®