From: James Chapman <jchapman@katalix.com> Date: 2007-09-18 20:19:48
Herbert Xu wrote:
[PPP] L2TP: Fix skb handling in pppol2tp_xmit
This patch makes pppol2tp_xmit call skb_cow_head so that we don't modify
cloned skb data. It also gets rid of skb2 we only need to preserve the
original skb for congestion notification, which is only applicable for
ppp_async and ppp_sync.
The other semantic change made here is the removal of socket accounting
for data tranmitted out of pppol2tp_xmit. The original code leaked any
existing socket skb accounting. We could fix this by dropping the
original skb owner. However, this is undesirable as the packet has not
physically left the host yet.
In fact, all other tunnels in the kernel do not account skb's passing
through to their own socket. In partciular, ESP over UDP does not do
so and it is the closest tunnel type to PPPoL2TP. So this patch simply
removes the socket accounting in pppol2tp_xmit. The accounting still
applies to control packets of course.
I've also added a reminder that the outgoing checksum here doesn't work.
I suppose existing deployments don't actually enable checksums.
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
This one causes my test system to lock up. I'll investigate. Please
don't apply this patch for now.
--
James Chapman
Katalix Systems Ltd
http://www.katalix.com
Catalysts for your Embedded Linux software development
From: Herbert Xu <herbert@gondor.apana.org.au> Date: 2007-09-19 01:26:22
On Tue, Sep 18, 2007 at 09:19:33PM +0100, James Chapman wrote:
This one causes my test system to lock up. I'll investigate. Please
don't apply this patch for now.
Sorry, I added a double-free on the skb after ip_queue_xmit.
Please try this one instead.
[PPP] L2TP: Fix skb handling in pppol2tp_xmit
This patch makes pppol2tp_xmit call skb_cow_head so that we don't modify
cloned skb data. It also gets rid of skb2 we only need to preserve the
original skb for congestion notification, which is only applicable for
ppp_async and ppp_sync.
The other semantic change made here is the removal of socket accounting
for data tranmitted out of pppol2tp_xmit. The original code leaked any
existing socket skb accounting. We could fix this by dropping the
original skb owner. However, this is undesirable as the packet has not
physically left the host yet.
In fact, all other tunnels in the kernel do not account skb's passing
through to their own socket. In partciular, ESP over UDP does not do
so and it is the closest tunnel type to PPPoL2TP. So this patch simply
removes the socket accounting in pppol2tp_xmit. The accounting still
applies to control packets of course.
I've also added a reminder that the outgoing checksum here doesn't work.
I suppose existing deployments don't actually enable checksums.
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Thanks,
--
Visit Openswan at http://www.openswan.org/
Email: Herbert Xu ~{PmV>HI~} [off-list ref]
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt
--
@@ -989,41 +988,30 @@ static int pppol2tp_xmit(struct ppp_channel *chan, struct sk_buff *skb)*/headroom=NET_SKB_PAD+sizeof(structiphdr)+sizeof(structudphdr)+hdr_len+sizeof(ppph);-if(skb_headroom(skb)<headroom){-skb2=skb_realloc_headroom(skb,headroom);-if(skb2==NULL)-gotoabort;-}else-skb2=skb;--/* Check that the socket has room */-if(atomic_read(&sk_tun->sk_wmem_alloc)<sk_tun->sk_sndbuf)-skb_set_owner_w(skb2,sk_tun);-else-gotodiscard;+if(skb_cow_head(skb,headroom))+gotoabort;/* Setup PPP header */-skb_push(skb2,sizeof(ppph));-skb2->data[0]=ppph[0];-skb2->data[1]=ppph[1];+__skb_push(skb,sizeof(ppph));+skb->data[0]=ppph[0];+skb->data[1]=ppph[1];/* Setup L2TP header */-skb_push(skb2,hdr_len);-pppol2tp_build_l2tp_header(session,skb2->data);+pppol2tp_build_l2tp_header(session,__skb_push(skb,hdr_len));/* Setup UDP header */inet=inet_sk(sk_tun);-skb_push(skb2,sizeof(structudphdr));-skb_reset_transport_header(skb2);-uh=(structudphdr*)skb2->data;+__skb_push(skb,sizeof(*uh));+skb_reset_transport_header(skb);+uh=udp_hdr(skb);uh->source=inet->sport;uh->dest=inet->dport;uh->len=htons(sizeof(structudphdr)+hdr_len+sizeof(ppph)+data_len);uh->check=0;-/* Calculate UDP checksum if configured to do so */+/* *BROKEN* Calculate UDP checksum if configured to do so */if(sk_tun->sk_no_check!=UDP_CSUM_NOXMIT)-csum=udp_csum_outgoing(sk_tun,skb2);+csum=udp_csum_outgoing(sk_tun,skb);/* Debug */if(session->send_seq)
@@ -1049,18 +1037,18 @@ static int pppol2tp_xmit(struct ppp_channel *chan, struct sk_buff *skb)printk("\n");}-memset(&(IPCB(skb2)->opt),0,sizeof(IPCB(skb2)->opt));-IPCB(skb2)->flags&=~(IPSKB_XFRM_TUNNEL_SIZE|IPSKB_XFRM_TRANSFORMED|-IPSKB_REROUTED);-nf_reset(skb2);+memset(&(IPCB(skb)->opt),0,sizeof(IPCB(skb)->opt));+IPCB(skb)->flags&=~(IPSKB_XFRM_TUNNEL_SIZE|IPSKB_XFRM_TRANSFORMED|+IPSKB_REROUTED);+nf_reset(skb);/* Get routing info from the tunnel socket */-dst_release(skb2->dst);-skb2->dst=sk_dst_get(sk_tun);+dst_release(skb->dst);+skb->dst=sk_dst_get(sk_tun);/* Queue the packet to IP for output */-len=skb2->len;-rc=ip_queue_xmit(skb2,1);+len=skb->len;+rc=ip_queue_xmit(skb,1);/* Update stats */if(rc>=0){
@@ -1073,17 +1061,12 @@ static int pppol2tp_xmit(struct ppp_channel *chan, struct sk_buff *skb)session->stats.tx_errors++;}-/* Free the original skb */-kfree_skb(skb);-return1;-discard:-/* Free the new skb. Caller will free original skb. */-if(skb2!=skb)-kfree_skb(skb2);abort:-return0;+/* Free the original skb */+kfree_skb(skb);+return1;}/*****************************************************************************
From: Herbert Xu <herbert@gondor.apana.org.au> Date: 2007-09-19 01:30:37
On Tue, Sep 18, 2007 at 01:32:40PM -0700, David Miller wrote:
I'll make sure not to push this until we figure out what's
wrong, thanks for checking James.
I think it was because of a double-free that I created after
transmitting the packet. In fact I had the same bug in PPPOE
too.
[PPP] pppoe: Fix double-free on skb after transmit failure
When I got rid of the second packet in __pppoe_xmit I created
a double-free on the skb because of the goto abort on failure.
This patch removes that.
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Cheers,
--
Visit Openswan at http://www.openswan.org/
Email: Herbert Xu ~{PmV>HI~} [off-list ref]
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt
--
From: James Chapman <jchapman@katalix.com> Date: 2007-09-19 08:44:05
Herbert Xu wrote:
On Tue, Sep 18, 2007 at 09:19:33PM +0100, James Chapman wrote:
quoted
This one causes my test system to lock up. I'll investigate. Please
don't apply this patch for now.
Sorry, I added a double-free on the skb after ip_queue_xmit.
Please try this one instead.
>
- /* Free the original skb */
- kfree_skb(skb);
-
return 1;
-discard:
- /* Free the new skb. Caller will free original skb. */
- if (skb2 != skb)
- kfree_skb(skb2);
abort:
- return 0;
+ /* Free the original skb */
+ kfree_skb(skb);
+ return 1;
}
Shouldn't this return 0 in the error case and without the kfree_skb()?
This lets ppp requeue the skb.
--
James Chapman
Katalix Systems Ltd
http://www.katalix.com
Catalysts for your Embedded Linux software development
From: Herbert Xu <hidden> Date: 2007-09-19 08:52:08
On Wed, Sep 19, 2007 at 09:43:49AM +0100, James Chapman wrote:
quoted
-discard:
- /* Free the new skb. Caller will free original skb. */
- if (skb2 != skb)
- kfree_skb(skb2);
abort:
- return 0;
+ /* Free the original skb */
+ kfree_skb(skb);
+ return 1;
}
Shouldn't this return 0 in the error case and without the kfree_skb()?
This lets ppp requeue the skb.
No. As I described in the changelog, the return value of 0
is only meaningful for ppp_async and ppp_sync. Returning 0
means that you're congested, not that there has been a
temporary error and the packet should be retried.
Retransmission should be left to the higher protocols.
Cheers,
--
Visit Openswan at http://www.openswan.org/
Email: Herbert Xu ~{PmV>HI~} [off-list ref]
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt
[PPP] pppoe: Fix double-free on skb after transmit failure
When I got rid of the second packet in __pppoe_xmit I created
a double-free on the skb because of the goto abort on failure.
This patch removes that.
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
[PPP] L2TP: Fix skb handling in pppol2tp_xmit
This patch makes pppol2tp_xmit call skb_cow_head so that we don't modify
cloned skb data. It also gets rid of skb2 we only need to preserve the
original skb for congestion notification, which is only applicable for
ppp_async and ppp_sync.
The other semantic change made here is the removal of socket accounting
for data tranmitted out of pppol2tp_xmit. The original code leaked any
existing socket skb accounting. We could fix this by dropping the
original skb owner. However, this is undesirable as the packet has not
physically left the host yet.
In fact, all other tunnels in the kernel do not account skb's passing
through to their own socket. In partciular, ESP over UDP does not do
so and it is the closest tunnel type to PPPoL2TP. So this patch simply
removes the socket accounting in pppol2tp_xmit. The accounting still
applies to control packets of course.
I've also added a reminder that the outgoing checksum here doesn't work.
I suppose existing deployments don't actually enable checksums.
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
I've replaced the older patch with the leak with this one,
thanks Herbert.
[PPP] pppoe: Fix double-free on skb after transmit failure
When I got rid of the second packet in __pppoe_xmit I created
a double-free on the skb because of the goto abort on failure.
This patch removes that.
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Applied.
Please excuse in case this was already clear, but since this regression
made it into Linus' tree it should be fixed there before 2.6.23.
cu
Adrian
--
"Is there not promise of rain?" Ling Tan asked suddenly out
of the darkness. There had been need of rain for many days.
"Only a promise," Lao Er said.
Pearl S. Buck - Dragon Seed
[PPP] pppoe: Fix double-free on skb after transmit failure
When I got rid of the second packet in __pppoe_xmit I created
a double-free on the skb because of the goto abort on failure.
This patch removes that.
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Applied.
Please excuse in case this was already clear, but since this regression
made it into Linus' tree it should be fixed there before 2.6.23.
I will make sure this happens.
I'm just waiting for Alexey to test the SFQ crash fix and
then I'll send everything queued.