[PATCH 1/1] AF_UNIX: Fix poll locking problem when reading from a stream socket

Subsystems: networking [general], networking [unix sockets], the rest

STALE5380d

3 messages, 3 authors, 2011-11-26 · open the first message on its own page

[PATCH 1/1] AF_UNIX: Fix poll locking problem when reading from a stream socket

From: Alexey Moiseytsev <hidden>
Date: 2011-11-21 23:36:25

poll() call may be locked by concurrent reading from the same stream
socket.

Signed-off-by: Alexey Moiseytsev <redacted>
---
 net/unix/af_unix.c |    4 ++++
 1 files changed, 4 insertions(+), 0 deletions(-)
diff --git a/net/unix/af_unix.c b/net/unix/af_unix.c
index 466fbcc..b595a3d 100644
--- a/net/unix/af_unix.c
+++ b/net/unix/af_unix.c
@@ -1957,6 +1957,7 @@ static int unix_stream_recvmsg(struct kiocb *iocb, struct socket *sock,
 			if ((UNIXCB(skb).pid  != siocb->scm->pid) ||
 			    (UNIXCB(skb).cred != siocb->scm->cred)) {
 				skb_queue_head(&sk->sk_receive_queue, skb);
+				sk->sk_data_ready(sk, skb->len);
 				break;
 			}
 		} else {
@@ -1974,6 +1975,7 @@ static int unix_stream_recvmsg(struct kiocb *iocb, struct socket *sock,
 		chunk = min_t(unsigned int, skb->len, size);
 		if (memcpy_toiovec(msg->msg_iov, skb->data, chunk)) {
 			skb_queue_head(&sk->sk_receive_queue, skb);
+			sk->sk_data_ready(sk, skb->len);
 			if (copied == 0)
 				copied = -EFAULT;
 			break;
@@ -1991,6 +1993,7 @@ static int unix_stream_recvmsg(struct kiocb *iocb, struct socket *sock,
 			/* put the skb back if we didn't use it up.. */
 			if (skb->len) {
 				skb_queue_head(&sk->sk_receive_queue, skb);
+				sk->sk_data_ready(sk, skb->len);
 				break;
 			}
 
@@ -2006,6 +2009,7 @@ static int unix_stream_recvmsg(struct kiocb *iocb, struct socket *sock,
 
 			/* put message back and return */
 			skb_queue_head(&sk->sk_receive_queue, skb);
+			sk->sk_data_ready(sk, skb->len);
 			break;
 		}
 	} while (size);
-- 
1.7.2.5

Re: [PATCH 1/1] AF_UNIX: Fix poll locking problem when reading from a stream socket

From: Eric Dumazet <hidden>
Date: 2011-11-22 05:23:09

Le mardi 22 novembre 2011 à 03:35 +0400, Alexey Moiseytsev a écrit :
quoted hunk
poll() call may be locked by concurrent reading from the same stream
socket.

Signed-off-by: Alexey Moiseytsev <redacted>
---
 net/unix/af_unix.c |    4 ++++
 1 files changed, 4 insertions(+), 0 deletions(-)
diff --git a/net/unix/af_unix.c b/net/unix/af_unix.c
index 466fbcc..b595a3d 100644
--- a/net/unix/af_unix.c
+++ b/net/unix/af_unix.c
@@ -1957,6 +1957,7 @@ static int unix_stream_recvmsg(struct kiocb *iocb, struct socket *sock,
 			if ((UNIXCB(skb).pid  != siocb->scm->pid) ||
 			    (UNIXCB(skb).cred != siocb->scm->cred)) {
 				skb_queue_head(&sk->sk_receive_queue, skb);
+				sk->sk_data_ready(sk, skb->len);
 				break;
 			}
 		} else {
@@ -1974,6 +1975,7 @@ static int unix_stream_recvmsg(struct kiocb *iocb, struct socket *sock,
 		chunk = min_t(unsigned int, skb->len, size);
 		if (memcpy_toiovec(msg->msg_iov, skb->data, chunk)) {
 			skb_queue_head(&sk->sk_receive_queue, skb);
+			sk->sk_data_ready(sk, skb->len);
 			if (copied == 0)
 				copied = -EFAULT;
 			break;
@@ -1991,6 +1993,7 @@ static int unix_stream_recvmsg(struct kiocb *iocb, struct socket *sock,
 			/* put the skb back if we didn't use it up.. */
 			if (skb->len) {
 				skb_queue_head(&sk->sk_receive_queue, skb);
+				sk->sk_data_ready(sk, skb->len);
 				break;
 			}
 
@@ -2006,6 +2009,7 @@ static int unix_stream_recvmsg(struct kiocb *iocb, struct socket *sock,
 
 			/* put message back and return */
 			skb_queue_head(&sk->sk_receive_queue, skb);
+			sk->sk_data_ready(sk, skb->len);
 			break;
 		}
 	} while (size);
Fine, the fix is technically correct since we own u->readlock mutex,
another thread cannot consume the just requeued skb. 

Small note : the words "locking" and "locked" are more used to describe
the action of taking a spinlock/mutex/rwlock or something, while the bug
you fixed is more about poll() system call being blocked/frozen forever.

Thanks !

Acked-by: Eric Dumazet <redacted>

Re: [PATCH 1/1] AF_UNIX: Fix poll locking problem when reading from a stream socket

From: David Miller <davem@davemloft.net>
Date: 2011-11-26 21:35:22

From: Eric Dumazet <redacted>
Date: Tue, 22 Nov 2011 06:23:01 +0100
Le mardi 22 novembre 2011 à 03:35 +0400, Alexey Moiseytsev a écrit :
quoted
poll() call may be locked by concurrent reading from the same stream
socket.

Signed-off-by: Alexey Moiseytsev <redacted>
 ..
Fine, the fix is technically correct since we own u->readlock mutex,
another thread cannot consume the just requeued skb. 

Small note : the words "locking" and "locked" are more used to describe
the action of taking a spinlock/mutex/rwlock or something, while the bug
you fixed is more about poll() system call being blocked/frozen forever.

Thanks !

Acked-by: Eric Dumazet <redacted>
Applied, with 'lock{ing,ed}' adjusted to 'block{ing,ed}'.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help