From: John Fastabend <john.fastabend@gmail.com> Date: 2021-07-06 16:31:57
While investigating a memleak in sockmap I found these two issues. Patch
1 found doing code review, I wasn't able to get KASAN to trigger a
memleak here, but should be necessary. Patch 2 fixes proc stats so when
we use sockstats for debugging we get correct values.
The fix for observered memleak will come after these, but requires some
more discussion and potentially patch revert so I'll try to get the set
here going now.
John Fastabend (2):
bpf, sockmap: fix potential memory leak on unlikely error case
bpf, sockmap: sk_prot needs inuse_idx set for proc stats
net/core/skmsg.c | 10 ++++++----
net/core/sock_map.c | 11 ++++++++++-
2 files changed, 16 insertions(+), 5 deletions(-)
--
2.25.1
From: John Fastabend <john.fastabend@gmail.com> Date: 2021-07-06 16:32:03
Proc socket stats use sk_prot->inuse_idx value to record inuse sock stats.
We currently do not set this correctly from sockmap side. The result is
reading sock stats '/proc/net/sockstat' gives incorrect values. The
socket counter is incremented correctly, but because we don't set the
counter correctly when we replace sk_prot we may omit the decrement.
Fixes: 604326b41a6fb ("bpf, sockmap: convert to generic sk_msg interface")
Signed-off-by: John Fastabend <john.fastabend@gmail.com>
---
net/core/sock_map.c | 11 ++++++++++-
1 file changed, 10 insertions(+), 1 deletion(-)
From: John Fastabend <john.fastabend@gmail.com> Date: 2021-07-06 16:32:03
If skb_linearize is needed and fails we could leak a msg on the error
handling. To fix ensure we kfree the msg block before returning error.
Found during code review.
Fixes: 4363023d2668e ("bpf, sockmap: Avoid failures from skb_to_sgvec when skb has frag_list")
Signed-off-by: John Fastabend <john.fastabend@gmail.com>
---
net/core/skmsg.c | 10 ++++++----
1 file changed, 6 insertions(+), 4 deletions(-)
@@ -508,10 +508,8 @@ static int sk_psock_skb_ingress_enqueue(struct sk_buff *skb,if(skb_linearize(skb))return-EAGAIN;num_sge=skb_to_sgvec(skb,msg->sg.data,0,skb->len);-if(unlikely(num_sge<0)){-kfree(msg);+if(unlikely(num_sge<0))returnnum_sge;-}copied=skb->len;msg->sg.start=0;
@@ -530,6 +528,7 @@ static int sk_psock_skb_ingress(struct sk_psock *psock, struct sk_buff *skb){structsock*sk=psock->sk;structsk_msg*msg;+interr;/* If we are receiving on the same sock skb->sk is already assigned,*skipmemoryaccountingandownertransitionseeingitalreadyset
@@ -548,7 +547,10 @@ static int sk_psock_skb_ingress(struct sk_psock *psock, struct sk_buff *skb)*intouserbuffers.*/skb_set_owner_r(skb,sk);-returnsk_psock_skb_ingress_enqueue(skb,psock,sk,msg);+err=sk_psock_skb_ingress_enqueue(skb,psock,sk,msg);+if(err<0)+kfree(msg);+returnerr;}/* Puts an skb on the ingress queue of the socket already assigned to the
From: Cong Wang <hidden> Date: 2021-07-08 19:38:54
On Tue, Jul 6, 2021 at 9:31 AM John Fastabend [off-list ref] wrote:
If skb_linearize is needed and fails we could leak a msg on the error
handling. To fix ensure we kfree the msg block before returning error.
Found during code review.
sk_psock_skb_ingress_self() also needs the same fix, right?
Other than this, it looks good to me.
Thanks.
From: Cong Wang <hidden> Date: 2021-07-08 19:42:43
On Tue, Jul 6, 2021 at 9:31 AM John Fastabend [off-list ref] wrote:
quoted hunk
Proc socket stats use sk_prot->inuse_idx value to record inuse sock stats.
We currently do not set this correctly from sockmap side. The result is
reading sock stats '/proc/net/sockstat' gives incorrect values. The
socket counter is incremented correctly, but because we don't set the
counter correctly when we replace sk_prot we may omit the decrement.
Fixes: 604326b41a6fb ("bpf, sockmap: convert to generic sk_msg interface")
Signed-off-by: John Fastabend <john.fastabend@gmail.com>
---
net/core/sock_map.c | 11 ++++++++++-
1 file changed, 10 insertions(+), 1 deletion(-)
From: John Fastabend <john.fastabend@gmail.com> Date: 2021-07-08 20:39:18
Cong Wang wrote:
On Tue, Jul 6, 2021 at 9:31 AM John Fastabend [off-list ref] wrote:
quoted
If skb_linearize is needed and fails we could leak a msg on the error
handling. To fix ensure we kfree the msg block before returning error.
Found during code review.
sk_psock_skb_ingress_self() also needs the same fix, right?
Yep.
Other than this, it looks good to me.
I'll do another spin to get the other one as well. Mind as well
fix both cases at once.
From: Jakub Sitnicki <jakub@cloudflare.com> Date: 2021-07-12 07:32:39
On Tue, Jul 06, 2021 at 06:31 PM CEST, John Fastabend wrote:
quoted hunk
Proc socket stats use sk_prot->inuse_idx value to record inuse sock stats.
We currently do not set this correctly from sockmap side. The result is
reading sock stats '/proc/net/sockstat' gives incorrect values. The
socket counter is incremented correctly, but because we don't set the
counter correctly when we replace sk_prot we may omit the decrement.
Fixes: 604326b41a6fb ("bpf, sockmap: convert to generic sk_msg interface")
Signed-off-by: John Fastabend <john.fastabend@gmail.com>
---
net/core/sock_map.c | 11 ++++++++++-
1 file changed, 10 insertions(+), 1 deletion(-)
We could initialize inuse_idx just once in {tcp,udp}_bpf_rebuild_protos,
if we changed {tcp,udp}_bpf_v4_build_proto to be a late_initcall, so
that it runs after inet_init when {tcp,udp}_prot and udp_prot are
already registered and have inuse_idx assigned.
From: John Fastabend <john.fastabend@gmail.com> Date: 2021-07-12 17:18:04
Jakub Sitnicki wrote:
On Tue, Jul 06, 2021 at 06:31 PM CEST, John Fastabend wrote:
quoted
Proc socket stats use sk_prot->inuse_idx value to record inuse sock stats.
We currently do not set this correctly from sockmap side. The result is
reading sock stats '/proc/net/sockstat' gives incorrect values. The
socket counter is incremented correctly, but because we don't set the
counter correctly when we replace sk_prot we may omit the decrement.
Fixes: 604326b41a6fb ("bpf, sockmap: convert to generic sk_msg interface")
Signed-off-by: John Fastabend <john.fastabend@gmail.com>
---
net/core/sock_map.c | 11 ++++++++++-
1 file changed, 10 insertions(+), 1 deletion(-)
We could initialize inuse_idx just once in {tcp,udp}_bpf_rebuild_protos,
if we changed {tcp,udp}_bpf_v4_build_proto to be a late_initcall, so
that it runs after inet_init when {tcp,udp}_prot and udp_prot are
already registered and have inuse_idx assigned.
OK does seem slightly nicer. Then I guess the diff is just,