* [PATCH 1/4] sctp: fix association hangs due to off-by-one errors in sctp_tsnmap_grow()
@ 2013-02-21 16:44 Roberts, Lee A.
2013-02-21 17:18 ` Vlad Yasevich
0 siblings, 1 reply; 4+ messages in thread
From: Roberts, Lee A. @ 2013-02-21 16:44 UTC (permalink / raw)
To: linux-sctp, netdev; +Cc: linux-kernel
From: Lee A. Roberts <lee.roberts@hp.com>
Resolve SCTP association hangs observed during SCTP stress
testing. Observable symptoms include communications hangs
with data being held in the association lobby (ordering)
queue. Close examination of reassembly/ordering queues shows
duplicated packets.
In sctp_tsnmap_grow(), correct off-by-one errors when copying
and resizing the tsnmap. If max_tsn_seen is in the LSB of the
word, this bit can be lost, causing the corresponding packet
to be transmitted again and to be entered as a duplicate into
the SCTP reassembly/ordering queues.
Patch applies to linux-3.8 kernel.
Signed-off-by: Lee A. Roberts <lee.roberts@hp.com>
---
net/sctp/tsnmap.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
diff -uprN -X linux-3.8-vanilla/Documentation/dontdiff linux-3.8-vanilla/net/sctp/tsnmap.c linux-3.8-SCTP+1/net/sctp/tsnmap.c
--- linux-3.8-vanilla/net/sctp/tsnmap.c 2013-02-18 16:58:34.000000000 -0700
+++ linux-3.8-SCTP+1/net/sctp/tsnmap.c 2013-02-20 08:01:02.555223259 -0700
@@ -369,14 +369,15 @@ static int sctp_tsnmap_grow(struct sctp_
if (gap >= SCTP_TSN_MAP_SIZE)
return 0;
- inc = ALIGN((gap - map->len),BITS_PER_LONG) + SCTP_TSN_MAP_INCREMENT;
+ inc = ALIGN((gap - map->len + 1), BITS_PER_LONG)
+ + SCTP_TSN_MAP_INCREMENT;
len = min_t(u16, map->len + inc, SCTP_TSN_MAP_SIZE);
new = kzalloc(len>>3, GFP_ATOMIC);
if (!new)
return 0;
- bitmap_copy(new, map->tsn_map, map->max_tsn_seen - map->base_tsn);
+ bitmap_copy(new, map->tsn_map, map->max_tsn_seen - map->base_tsn + 1);
kfree(map->tsn_map);
map->tsn_map = new;
map->len = len;
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH 1/4] sctp: fix association hangs due to off-by-one errors in sctp_tsnmap_grow()
2013-02-21 16:44 [PATCH 1/4] sctp: fix association hangs due to off-by-one errors in sctp_tsnmap_grow() Roberts, Lee A.
@ 2013-02-21 17:18 ` Vlad Yasevich
2013-02-21 18:00 ` Roberts, Lee A.
2013-02-21 18:25 ` Roberts, Lee A.
0 siblings, 2 replies; 4+ messages in thread
From: Vlad Yasevich @ 2013-02-21 17:18 UTC (permalink / raw)
To: Roberts, Lee A.; +Cc: linux-sctp, netdev, linux-kernel
On 02/21/2013 11:44 AM, Roberts, Lee A. wrote:
> From: Lee A. Roberts <lee.roberts@hp.com>
>
> Resolve SCTP association hangs observed during SCTP stress
> testing. Observable symptoms include communications hangs
> with data being held in the association lobby (ordering)
> queue. Close examination of reassembly/ordering queues shows
> duplicated packets.
>
> In sctp_tsnmap_grow(), correct off-by-one errors when copying
> and resizing the tsnmap. If max_tsn_seen is in the LSB of the
> word, this bit can be lost, causing the corresponding packet
> to be transmitted again and to be entered as a duplicate into
> the SCTP reassembly/ordering queues.
>
> Patch applies to linux-3.8 kernel.
>
> Signed-off-by: Lee A. Roberts <lee.roberts@hp.com>
> ---
> net/sctp/tsnmap.c | 5 +++--
> 1 file changed, 3 insertions(+), 2 deletions(-)
>
> diff -uprN -X linux-3.8-vanilla/Documentation/dontdiff linux-3.8-vanilla/net/sctp/tsnmap.c linux-3.8-SCTP+1/net/sctp/tsnmap.c
> --- linux-3.8-vanilla/net/sctp/tsnmap.c 2013-02-18 16:58:34.000000000 -0700
> +++ linux-3.8-SCTP+1/net/sctp/tsnmap.c 2013-02-20 08:01:02.555223259 -0700
> @@ -369,14 +369,15 @@ static int sctp_tsnmap_grow(struct sctp_
> if (gap >= SCTP_TSN_MAP_SIZE)
No that I think about this a bit more, this should be gap + 1. If you
do that, you might as well call sctp_tsnmap_grow() with gap+1 as
argument and then can just use the 'gap' everywhere inside.
> return 0;
>
> - inc = ALIGN((gap - map->len),BITS_PER_LONG) + SCTP_TSN_MAP_INCREMENT;
> + inc = ALIGN((gap - map->len + 1), BITS_PER_LONG)
> + + SCTP_TSN_MAP_INCREMENT;
> len = min_t(u16, map->len + inc, SCTP_TSN_MAP_SIZE);
>
> new = kzalloc(len>>3, GFP_ATOMIC);
> if (!new)
> return 0;
>
> - bitmap_copy(new, map->tsn_map, map->max_tsn_seen - map->base_tsn);
> + bitmap_copy(new, map->tsn_map, map->max_tsn_seen - map->base_tsn + 1);
Can simplify that this by using map->cumulative_tsn_ack_point instead of
base_tsn.
-vlad
> kfree(map->tsn_map);
> map->tsn_map = new;
> map->len = len;
> --
> To unsubscribe from this list: send the line "unsubscribe linux-sctp" in
> the body of a message to majordomo@vger.kernel.org
> More majordomo info at http://vger.kernel.org/majordomo-info.html
>
^ permalink raw reply [flat|nested] 4+ messages in thread
* RE: [PATCH 1/4] sctp: fix association hangs due to off-by-one errors in sctp_tsnmap_grow()
2013-02-21 17:18 ` Vlad Yasevich
@ 2013-02-21 18:00 ` Roberts, Lee A.
2013-02-21 18:25 ` Roberts, Lee A.
1 sibling, 0 replies; 4+ messages in thread
From: Roberts, Lee A. @ 2013-02-21 18:00 UTC (permalink / raw)
To: Vlad Yasevich; +Cc: linux-sctp, netdev, linux-kernel
Vlad,
> -----Original Message-----
> From: Vlad Yasevich [mailto:vyasevich@gmail.com]
> Sent: Thursday, February 21, 2013 10:19 AM
> To: Roberts, Lee A.
> Cc: linux-sctp@vger.kernel.org; netdev@vger.kernel.org; linux-kernel@vger.kernel.org
> Subject: Re: [PATCH 1/4] sctp: fix association hangs due to off-by-one errors in sctp_tsnmap_grow()
>
> On 02/21/2013 11:44 AM, Roberts, Lee A. wrote:
> > From: Lee A. Roberts <lee.roberts@hp.com>
> >
> > Resolve SCTP association hangs observed during SCTP stress
> > testing. Observable symptoms include communications hangs
> > with data being held in the association lobby (ordering)
> > queue. Close examination of reassembly/ordering queues shows
> > duplicated packets.
> >
> > In sctp_tsnmap_grow(), correct off-by-one errors when copying
> > and resizing the tsnmap. If max_tsn_seen is in the LSB of the
> > word, this bit can be lost, causing the corresponding packet
> > to be transmitted again and to be entered as a duplicate into
> > the SCTP reassembly/ordering queues.
> >
> > Patch applies to linux-3.8 kernel.
> >
> > Signed-off-by: Lee A. Roberts <lee.roberts@hp.com>
> > ---
> > net/sctp/tsnmap.c | 5 +++--
> > 1 file changed, 3 insertions(+), 2 deletions(-)
> >
> > diff -uprN -X linux-3.8-vanilla/Documentation/dontdiff linux-3.8-vanilla/net/sctp/tsnmap.c linux-
> 3.8-SCTP+1/net/sctp/tsnmap.c
> > --- linux-3.8-vanilla/net/sctp/tsnmap.c 2013-02-18 16:58:34.000000000 -0700
> > +++ linux-3.8-SCTP+1/net/sctp/tsnmap.c 2013-02-20 08:01:02.555223259 -0700
> > @@ -369,14 +369,15 @@ static int sctp_tsnmap_grow(struct sctp_
> > if (gap >= SCTP_TSN_MAP_SIZE)
>
> No that I think about this a bit more, this should be gap + 1. If you
> do that, you might as well call sctp_tsnmap_grow() with gap+1 as
> argument and then can just use the 'gap' everywhere inside.
I think the calculation of "gap" in sctp_tsnmap_mark() should change:
- gap = tsn - map->base_tsn;
+ gap = tsn - map->cumulative_tsn_ack_point;
>
> > return 0;
> >
> > - inc = ALIGN((gap - map->len),BITS_PER_LONG) + SCTP_TSN_MAP_INCREMENT;
> > + inc = ALIGN((gap - map->len + 1), BITS_PER_LONG)
> > + + SCTP_TSN_MAP_INCREMENT;
> > len = min_t(u16, map->len + inc, SCTP_TSN_MAP_SIZE);
> >
> > new = kzalloc(len>>3, GFP_ATOMIC);
> > if (!new)
> > return 0;
> >
> > - bitmap_copy(new, map->tsn_map, map->max_tsn_seen - map->base_tsn);
> > + bitmap_copy(new, map->tsn_map, map->max_tsn_seen - map->base_tsn + 1);
>
> Can simplify that this by using map->cumulative_tsn_ack_point instead of
> base_tsn.
>
> -vlad
>
I changed the code to use "cumulative_tsn_ack_point" in an updated version
of the patch.
-- Lee
> > kfree(map->tsn_map);
> > map->tsn_map = new;
> > map->len = len;
> > --
> > To unsubscribe from this list: send the line "unsubscribe linux-sctp" in
> > the body of a message to majordomo@vger.kernel.org
> > More majordomo info at http://vger.kernel.org/majordomo-info.html
> >
^ permalink raw reply [flat|nested] 4+ messages in thread
* RE: [PATCH 1/4] sctp: fix association hangs due to off-by-one errors in sctp_tsnmap_grow()
2013-02-21 17:18 ` Vlad Yasevich
2013-02-21 18:00 ` Roberts, Lee A.
@ 2013-02-21 18:25 ` Roberts, Lee A.
1 sibling, 0 replies; 4+ messages in thread
From: Roberts, Lee A. @ 2013-02-21 18:25 UTC (permalink / raw)
To: Vlad Yasevich; +Cc: linux-sctp, netdev, linux-kernel
Vlad,
> -----Original Message-----
> From: Roberts, Lee A.
> Sent: Thursday, February 21, 2013 11:00 AM
> To: 'Vlad Yasevich'
> Cc: linux-sctp@vger.kernel.org; netdev@vger.kernel.org; linux-kernel@vger.kernel.org
> Subject: RE: [PATCH 1/4] sctp: fix association hangs due to off-by-one errors in sctp_tsnmap_grow()
>
> Vlad,
>
> > -----Original Message-----
> > From: Vlad Yasevich [mailto:vyasevich@gmail.com]
> > Sent: Thursday, February 21, 2013 10:19 AM
> > To: Roberts, Lee A.
> > Cc: linux-sctp@vger.kernel.org; netdev@vger.kernel.org; linux-kernel@vger.kernel.org
> > Subject: Re: [PATCH 1/4] sctp: fix association hangs due to off-by-one errors in sctp_tsnmap_grow()
> >
> > On 02/21/2013 11:44 AM, Roberts, Lee A. wrote:
> > > From: Lee A. Roberts <lee.roberts@hp.com>
> > >
> > > Resolve SCTP association hangs observed during SCTP stress
> > > testing. Observable symptoms include communications hangs
> > > with data being held in the association lobby (ordering)
> > > queue. Close examination of reassembly/ordering queues shows
> > > duplicated packets.
> > >
> > > In sctp_tsnmap_grow(), correct off-by-one errors when copying
> > > and resizing the tsnmap. If max_tsn_seen is in the LSB of the
> > > word, this bit can be lost, causing the corresponding packet
> > > to be transmitted again and to be entered as a duplicate into
> > > the SCTP reassembly/ordering queues.
> > >
> > > Patch applies to linux-3.8 kernel.
> > >
> > > Signed-off-by: Lee A. Roberts <lee.roberts@hp.com>
> > > ---
> > > net/sctp/tsnmap.c | 5 +++--
> > > 1 file changed, 3 insertions(+), 2 deletions(-)
> > >
> > > diff -uprN -X linux-3.8-vanilla/Documentation/dontdiff linux-3.8-vanilla/net/sctp/tsnmap.c linux-
> > 3.8-SCTP+1/net/sctp/tsnmap.c
> > > --- linux-3.8-vanilla/net/sctp/tsnmap.c 2013-02-18 16:58:34.000000000 -0700
> > > +++ linux-3.8-SCTP+1/net/sctp/tsnmap.c 2013-02-20 08:01:02.555223259 -0700
> > > @@ -369,14 +369,15 @@ static int sctp_tsnmap_grow(struct sctp_
> > > if (gap >= SCTP_TSN_MAP_SIZE)
> >
> > No that I think about this a bit more, this should be gap + 1. If you
> > do that, you might as well call sctp_tsnmap_grow() with gap+1 as
> > argument and then can just use the 'gap' everywhere inside.
>
> I think the calculation of "gap" in sctp_tsnmap_mark() should change:
>
> - gap = tsn - map->base_tsn;
> + gap = tsn - map->cumulative_tsn_ack_point;
>
Oops, this breaks the logic that follows. Using "gap + 1" in the call should work.
I sent an updated patch (v3).
- Lee
> >
> > > return 0;
> > >
> > > - inc = ALIGN((gap - map->len),BITS_PER_LONG) + SCTP_TSN_MAP_INCREMENT;
> > > + inc = ALIGN((gap - map->len + 1), BITS_PER_LONG)
> > > + + SCTP_TSN_MAP_INCREMENT;
> > > len = min_t(u16, map->len + inc, SCTP_TSN_MAP_SIZE);
> > >
> > > new = kzalloc(len>>3, GFP_ATOMIC);
> > > if (!new)
> > > return 0;
> > >
> > > - bitmap_copy(new, map->tsn_map, map->max_tsn_seen - map->base_tsn);
> > > + bitmap_copy(new, map->tsn_map, map->max_tsn_seen - map->base_tsn + 1);
> >
> > Can simplify that this by using map->cumulative_tsn_ack_point instead of
> > base_tsn.
> >
> > -vlad
> >
>
> I changed the code to use "cumulative_tsn_ack_point" in an updated version
> of the patch.
>
> -- Lee
>
> > > kfree(map->tsn_map);
> > > map->tsn_map = new;
> > > map->len = len;
> > > --
> > > To unsubscribe from this list: send the line "unsubscribe linux-sctp" in
> > > the body of a message to majordomo@vger.kernel.org
> > > More majordomo info at http://vger.kernel.org/majordomo-info.html
> > >
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2013-02-21 18:26 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2013-02-21 16:44 [PATCH 1/4] sctp: fix association hangs due to off-by-one errors in sctp_tsnmap_grow() Roberts, Lee A.
2013-02-21 17:18 ` Vlad Yasevich
2013-02-21 18:00 ` Roberts, Lee A.
2013-02-21 18:25 ` Roberts, Lee A.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®