From: Kuniyuki Iwashima <kuniyu@amazon.com>
To: "David S. Miller" <davem@davemloft.net>,
Eric Dumazet <edumazet@google.com>,
Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
David Ahern <dsahern@kernel.org>,
Hideaki YOSHIFUJI <yoshfuji@linux-ipv6.org>
Cc: Kuniyuki Iwashima <kuniyu@amazon.com>,
Kuniyuki Iwashima <kuni1840@gmail.com>, <netdev@vger.kernel.org>,
<syzkaller-bugs@googlegroups.com>, <linux-kernel@vger.kernel.org>
Subject: [PATCH v4 net 0/5] tcp/udp: Fix memory leaks and data races around IPV6_ADDRFORM.
Date: Tue, 4 Oct 2022 10:17:57 -0700 [thread overview]
Message-ID: <20221004171802.40968-1-kuniyu@amazon.com> (raw)
This series fixes some memory leaks and data races caused in the
same scenario where one thread converts an IPv6 socket into IPv4
with IPV6_ADDRFORM and another accesses the socket concurrently.
Note patch 1 and 5 conflict with these commits in net-next, respectively.
* 24426654ed3a ("bpf: net: Avoid sk_setsockopt() taking sk lock when called from bpf")
* 34704ef024ae ("bpf: net: Change do_tcp_getsockopt() to take the sockptr_t argument")
Changes:
v4:
* Patch 3:
* Change UDPv6 Lite's sk->sk_prot->init() and sk->destruct() as well.
* Move udplite_sk_init() from udplite.h to udplite.c.
v3 (Resend): https://lore.kernel.org/netdev/20221003154425.49458-1-kuniyu@amazon.com/
* CC blamed commits' EHOSTUNREACH authors to make patchwork happy
v3: https://lore.kernel.org/netdev/20220929012542.55424-1-kuniyu@amazon.com/
* Patch 2:
* Add comment for np->rxopt.all = 0
* Add inet6_cleanup_sock()
* Patch 3:
* Call inet6_cleanup_sock() instead of inet6_destroy_sock()
v2: https://lore.kernel.org/netdev/20220928002741.64237-1-kuniyu@amazon.com/
* Patch 3:
* Move inet6_destroy_sock() from sk_prot->destroy()
to sk->sk_destruct() and fix CONFIG_IPV6=m build failure
* Patch 5:
* Add WRITE_ONCE()s in tcp_v6_connect()
* Add Reported-by tags and KCSAN log in changelog
v1: https://lore.kernel.org/netdev/20220927161209.32939-1-kuniyu@amazon.com/
Kuniyuki Iwashima (5):
tcp/udp: Fix memory leak in ipv6_renew_options().
udp: Call inet6_destroy_sock() in setsockopt(IPV6_ADDRFORM).
tcp/udp: Call inet6_destroy_sock() in IPv6 sk->sk_destruct().
ipv6: Fix data races around sk->sk_prot.
tcp: Fix data races around icsk->icsk_af_ops.
include/net/ipv6.h | 2 ++
include/net/udp.h | 2 +-
include/net/udplite.h | 8 --------
net/core/sock.c | 6 ++++--
net/ipv4/af_inet.c | 23 ++++++++++++++++-------
net/ipv4/tcp.c | 10 ++++++----
net/ipv4/udp.c | 9 ++++++---
net/ipv4/udplite.c | 8 ++++++++
net/ipv6/af_inet6.c | 15 ++++++++++++++-
net/ipv6/ipv6_sockglue.c | 34 +++++++++++++++++++---------------
net/ipv6/tcp_ipv6.c | 6 ++++--
net/ipv6/udp.c | 15 ++++++++++++++-
net/ipv6/udp_impl.h | 1 +
net/ipv6/udplite.c | 9 ++++++++-
14 files changed, 103 insertions(+), 45 deletions(-)
--
2.30.2
next reply other threads:[~2022-10-04 17:39 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2022-10-04 17:17 Kuniyuki Iwashima [this message]
2022-10-04 17:17 ` [PATCH v4 net 1/5] tcp/udp: Fix memory leak in ipv6_renew_options() Kuniyuki Iwashima
2022-10-04 17:17 ` [PATCH v4 net 2/5] udp: Call inet6_destroy_sock() in setsockopt(IPV6_ADDRFORM) Kuniyuki Iwashima
2022-10-04 17:18 ` [PATCH v4 net 3/5] tcp/udp: Call inet6_destroy_sock() in IPv6 sk->sk_destruct() Kuniyuki Iwashima
2022-10-06 9:19 ` Paolo Abeni
2022-10-06 17:10 ` Kuniyuki Iwashima
2022-10-04 17:18 ` [PATCH v4 net 4/5] ipv6: Fix data races around sk->sk_prot Kuniyuki Iwashima
2022-10-04 17:18 ` [PATCH v4 net 5/5] tcp: Fix data races around icsk->icsk_af_ops Kuniyuki Iwashima
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20221004171802.40968-1-kuniyu@amazon.com \
--to=kuniyu@amazon.com \
--cc=davem@davemloft.net \
--cc=dsahern@kernel.org \
--cc=edumazet@google.com \
--cc=kuba@kernel.org \
--cc=kuni1840@gmail.com \
--cc=linux-kernel@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=syzkaller-bugs@googlegroups.com \
--cc=yoshfuji@linux-ipv6.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Powered by JetHome