Thread (2 messages) flat view 2 messages, 2 authors, 2017-08-22

Re: [PATCH net-next] virtio-net: invoke zerocopy callback on xmit path if no tx napi

From: Eric Dumazet <hidden>
Date: 2017-08-22 18:28:28
Also in: netdev

On Tue, 2017-08-22 at 11:01 -0700, David Miller wrote:
From: "Michael S. Tsirkin" <mst@redhat.com>
Date: Tue, 22 Aug 2017 20:55:56 +0300
quoted
Which reminds me that skb_linearize in net core seems to be
fundamentally racy - I suspect that if skb is cloned, and someone is
trying to use the shared frags while another thread calls skb_linearize,
we get some use after free bugs which likely mostly go undetected
because the corrupted packets mostly go on wire and get dropped
by checksum code.
Indeed, it does assume that the skb from which the clone was made
never has it's geometry changed.

I don't think even the TCP retransmit queue has this guarantee.
TCP retransmit makes sure to avoid that.

if (skb_unclone(skb, GFP_ATOMIC))
     return -ENOMEM;

( Before cloning again skb )
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help