PATCH 1/1] AX.25: Close socket connection on session completion

Subsystems: networking [general], the rest

7 messages, 4 authors, 2016-07-04 · open the first message on its own page

PATCH 1/1] AX.25: Close socket connection on session completion

From: Basil Gunn <hidden>
Date: 2016-06-16 16:47:59

A socket connection made in ax.25 is not closed when session is
completed.  The heartbeat timer is stopped prematurely and this is
where the socket gets closed. Allow heatbeat timer to run to close
socket. Symptom occurs in kernels >= 4.2.0

Originally sent 6/15/2016. Resend with distribution list matching
scripts/maintainer.pl output.

Signed-off-by: Basil Gunn <redacted>
---
diff --git a/net/ax25/af_ax25.c b/net/ax25/af_ax25.c
index fbd0acf..2fdebab 100644
--- a/net/ax25/af_ax25.c
+++ b/net/ax25/af_ax25.c
@@ -976,7 +976,8 @@ static int ax25_release(struct socket *sock)
 			release_sock(sk);
 			ax25_disconnect(ax25, 0);
 			lock_sock(sk);
-			ax25_destroy_socket(ax25);
+			if (!sock_flag(ax25->sk, SOCK_DESTROY))
+				ax25_destroy_socket(ax25);
 			break;

 		case AX25_STATE_3:
diff --git a/net/ax25/ax25_ds_timer.c b/net/ax25/ax25_ds_timer.c
index 951cd57..5237dff 100644
--- a/net/ax25/ax25_ds_timer.c
+++ b/net/ax25/ax25_ds_timer.c
@@ -102,6 +102,7 @@ void ax25_ds_heartbeat_expiry(ax25_cb *ax25)
 	switch (ax25->state) {

 	case AX25_STATE_0:
+	case AX25_STATE_2:
 		/* Magic here: If we listen() and a new link dies before it
 		   is accepted() it isn't 'dead' so doesn't get removed. */
 		if (!sk || sock_flag(sk, SOCK_DESTROY) ||
@@ -111,6 +112,7 @@ void ax25_ds_heartbeat_expiry(ax25_cb *ax25)
 				sock_hold(sk);
 				ax25_destroy_socket(ax25);
 				bh_unlock_sock(sk);
+				/* Ungrab socket and destroy it */
 				sock_put(sk);
 			} else
 				ax25_destroy_socket(ax25);
@@ -213,7 +215,8 @@ void ax25_ds_t1_timeout(ax25_cb *ax25)
 	case AX25_STATE_2:
 		if (ax25->n2count == ax25->n2) {
 			ax25_send_control(ax25, AX25_DISC, AX25_POLLON, AX25_COMMAND);
-			ax25_disconnect(ax25, ETIMEDOUT);
+			if (!sock_flag(ax25->sk, SOCK_DESTROY))
+				ax25_disconnect(ax25, ETIMEDOUT);
 			return;
 		} else {
 			ax25->n2count++;
diff --git a/net/ax25/ax25_std_timer.c b/net/ax25/ax25_std_timer.c
index 004467c9..2c0d6ef 100644
--- a/net/ax25/ax25_std_timer.c
+++ b/net/ax25/ax25_std_timer.c
@@ -38,6 +38,7 @@ void ax25_std_heartbeat_expiry(ax25_cb *ax25)

 	switch (ax25->state) {
 	case AX25_STATE_0:
+	case AX25_STATE_2:
 		/* Magic here: If we listen() and a new link dies before it
 		   is accepted() it isn't 'dead' so doesn't get removed. */
 		if (!sk || sock_flag(sk, SOCK_DESTROY) ||
@@ -47,6 +48,7 @@ void ax25_std_heartbeat_expiry(ax25_cb *ax25)
 				sock_hold(sk);
 				ax25_destroy_socket(ax25);
 				bh_unlock_sock(sk);
+				/* Ungrab socket and destroy it */
 				sock_put(sk);
 			} else
 				ax25_destroy_socket(ax25);
@@ -144,7 +146,8 @@ void ax25_std_t1timer_expiry(ax25_cb *ax25)
 	case AX25_STATE_2:
 		if (ax25->n2count == ax25->n2) {
 			ax25_send_control(ax25, AX25_DISC, AX25_POLLON, AX25_COMMAND);
-			ax25_disconnect(ax25, ETIMEDOUT);
+			if (!sock_flag(ax25->sk, SOCK_DESTROY))
+				ax25_disconnect(ax25, ETIMEDOUT);
 			return;
 		} else {
 			ax25->n2count++;
diff --git a/net/ax25/ax25_subr.c b/net/ax25/ax25_subr.c
index 3b78e84..655a7d4 100644
--- a/net/ax25/ax25_subr.c
+++ b/net/ax25/ax25_subr.c
@@ -264,7 +264,8 @@ void ax25_disconnect(ax25_cb *ax25, int reason)
 {
 	ax25_clear_queues(ax25);

-	ax25_stop_heartbeat(ax25);
+	if (!sock_flag(ax25->sk, SOCK_DESTROY))
+		ax25_stop_heartbeat(ax25);
 	ax25_stop_t1timer(ax25);
 	ax25_stop_t2timer(ax25);
 	ax25_stop_t3timer(ax25);

Re: PATCH 1/1] AX.25: Close socket connection on session completion

From: David Miller <davem@davemloft.net>
Date: 2016-06-17 18:33:21

From: Basil Gunn <redacted>
Date: Thu, 16 Jun 2016 09:42:30 -0700
A socket connection made in ax.25 is not closed when session is
completed.  The heartbeat timer is stopped prematurely and this is
where the socket gets closed. Allow heatbeat timer to run to close
socket. Symptom occurs in kernels >= 4.2.0

Originally sent 6/15/2016. Resend with distribution list matching
scripts/maintainer.pl output.

Signed-off-by: Basil Gunn <redacted>
What changed in 4.2.x that broke this?

Re: PATCH 1/1] AX.25: Close socket connection on session completion

From: David Ranch <hidden>
Date: 2016-06-19 01:04:08

Hello David,

I don't have a specific commit # for you at the moment but there have been a few serious regressions since 4.1.x.  When new code gets commited, are there any systems to run regession tests on?  I'd be willing to build up a pair of VMs that can be run with scripts to verify say basic sanity for kissattach, ax.25, netrom, rose, etc.

Btw, once I get back, I hope to pursue some additional negative case fixes:  (pulling a usb-to-serial adapter when used with kiss-attach will panic the kernel, ifconfig rose0 down will take the kernel to 100%, and a data corruption issue for large transfers (2MB+).

Thanks for your help!

--David
KI6ZHD
--David

On June 17, 2016 12:33:19 PM CST, David Miller [off-list ref] wrote:
From: Basil Gunn <redacted>
Date: Thu, 16 Jun 2016 09:42:30 -0700
quoted
A socket connection made in ax.25 is not closed when session is
completed.  The heartbeat timer is stopped prematurely and this is
where the socket gets closed. Allow heatbeat timer to run to close
socket. Symptom occurs in kernels >= 4.2.0

Originally sent 6/15/2016. Resend with distribution list matching
scripts/maintainer.pl output.

Signed-off-by: Basil Gunn <redacted>
What changed in 4.2.x that broke this?
--
To unsubscribe from this list: send the line "unsubscribe linux-hams"
in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html

Re: PATCH 1/1] AX.25: Close socket connection on session completion

From: David Miller <davem@davemloft.net>
Date: 2016-06-19 03:55:47

From: Basil Gunn <redacted>
Date: Thu, 16 Jun 2016 09:42:30 -0700
A socket connection made in ax.25 is not closed when session is
completed.  The heartbeat timer is stopped prematurely and this is
where the socket gets closed. Allow heatbeat timer to run to close
socket. Symptom occurs in kernels >= 4.2.0

Originally sent 6/15/2016. Resend with distribution list matching
scripts/maintainer.pl output.

Signed-off-by: Basil Gunn <redacted>
Applied.

Re: PATCH 1/1] AX.25: Close socket connection on session completion

From: Thomas Osterried <hidden>
Date: 2016-06-19 07:59:37

quoted
socket. Symptom occurs in kernels >= 4.2.0
[..] 
What changed in 4.2.x that broke this?
3.x'er kernel had also this problem; but there it happens rarely.

vy 73,
	- Thomas  dl9sau

Re: PATCH 1/1] AX.25: Close socket connection on session completion

From: David Ranch <hidden>
Date: 2016-07-04 22:48:53

Hello David,

Unless I'm doing something wrong, it seems this patch has only been 
applied to the newest
kernel:

    Git/linux-stable$ git tag -l --contains 
4a7d99ea1b27734558feb6833f180cd38a159940
    v4.7-rc6

How can we get this critical fix applied to the other stable kernel 
versions?  I would really hate
to depend on all the various Distro packagers to miss on picking this up 
as this is a critical
toxicity fix.


Reference: http://www.spinics.net/lists/linux-hams/msg03628.html

--David




On 06/18/2016 08:55 PM, David Miller wrote:
From: Basil Gunn <redacted>
Date: Thu, 16 Jun 2016 09:42:30 -0700
quoted
A socket connection made in ax.25 is not closed when session is
completed.  The heartbeat timer is stopped prematurely and this is
where the socket gets closed. Allow heatbeat timer to run to close
socket. Symptom occurs in kernels >= 4.2.0

Originally sent 6/15/2016. Resend with distribution list matching
scripts/maintainer.pl output.

Signed-off-by: Basil Gunn <redacted>
Applied.
--
To unsubscribe from this list: send the line "unsubscribe linux-hams" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html

Re: PATCH 1/1] AX.25: Close socket connection on session completion

From: David Miller <davem@davemloft.net>
Date: 2016-07-04 23:31:42

From: David Ranch <redacted>
Date: Mon, 4 Jul 2016 15:48:40 -0700
How can we get this critical fix applied to the other stable kernel
versions?
Networking patches are submitted to -stable when people ask me to
do so.  So simply ask for this when you submit your patch.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help