From: Jason Xing <kerneljasonxing@gmail.com>
To: davem@davemloft.net, edumazet@google.com, kuba@kernel.org,
pabeni@redhat.com, dsahern@kernel.org, kuniyu@amazon.com
Cc: netdev@vger.kernel.org, kerneljasonxing@gmail.com,
Jason Xing <kernelxing@tencent.com>
Subject: [PATCH net-next v4 4/5] tcp: directly drop skb in cookie check for ipv6
Date: Tue, 13 Feb 2024 21:42:04 +0800 [thread overview]
Message-ID: <20240213134205.8705-5-kerneljasonxing@gmail.com> (raw)
In-Reply-To: <20240213134205.8705-1-kerneljasonxing@gmail.com>
From: Jason Xing <kernelxing@tencent.com>
Like previous patch does, only moving skb drop logical code to
cookie_v6_check() for later refinement.
Signed-off-by: Jason Xing <kernelxing@tencent.com>
---
net/ipv6/syncookies.c | 4 ++++
net/ipv6/tcp_ipv6.c | 7 +++++--
2 files changed, 9 insertions(+), 2 deletions(-)
diff --git a/net/ipv6/syncookies.c b/net/ipv6/syncookies.c
index 6b9c69278819..ea0d9954a29f 100644
--- a/net/ipv6/syncookies.c
+++ b/net/ipv6/syncookies.c
@@ -177,6 +177,7 @@ struct sock *cookie_v6_check(struct sock *sk, struct sk_buff *skb)
struct sock *ret = sk;
__u8 rcv_wscale;
int full_space;
+ SKB_DR(reason);
if (!READ_ONCE(net->ipv4.sysctl_tcp_syncookies) ||
!th->ack || th->rst)
@@ -256,10 +257,13 @@ struct sock *cookie_v6_check(struct sock *sk, struct sk_buff *skb)
ireq->ecn_ok &= cookie_ecn_ok(net, dst);
ret = tcp_get_cookie_sock(sk, skb, req, dst);
+ if (!ret)
+ goto out_drop;
out:
return ret;
out_free:
reqsk_free(req);
out_drop:
+ kfree_skb_reason(skb, reason);
return NULL;
}
diff --git a/net/ipv6/tcp_ipv6.c b/net/ipv6/tcp_ipv6.c
index 57b25b1fc9d9..27639ffcae2f 100644
--- a/net/ipv6/tcp_ipv6.c
+++ b/net/ipv6/tcp_ipv6.c
@@ -1653,8 +1653,11 @@ int tcp_v6_do_rcv(struct sock *sk, struct sk_buff *skb)
if (sk->sk_state == TCP_LISTEN) {
struct sock *nsk = tcp_v6_cookie_check(sk, skb);
- if (!nsk)
- goto discard;
+ if (!nsk) {
+ if (opt_skb)
+ __kfree_skb(opt_skb);
+ return 0;
+ }
if (nsk != sk) {
if (tcp_child_process(sk, nsk, skb))
--
2.37.3
next prev parent reply other threads:[~2024-02-13 13:42 UTC|newest]
Thread overview: 12+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-02-13 13:42 [PATCH net-next v4 0/5] introduce drop reasons for cookie check Jason Xing
2024-02-13 13:42 ` [PATCH net-next v4 1/5] tcp: add dropreasons definitions and prepare " Jason Xing
2024-02-13 15:23 ` Eric Dumazet
2024-02-13 17:16 ` Jason Xing
2024-02-13 13:42 ` [PATCH net-next v4 2/5] tcp: directly drop skb in cookie check for ipv4 Jason Xing
2024-02-13 13:42 ` [PATCH net-next v4 3/5] tcp: use drop reasons " Jason Xing
2024-02-13 15:56 ` David Ahern
2024-02-13 17:01 ` Jason Xing
2024-02-13 13:42 ` Jason Xing [this message]
2024-02-13 15:30 ` [PATCH net-next v4 4/5] tcp: directly drop skb in cookie check for ipv6 Eric Dumazet
2024-02-13 17:09 ` Jason Xing
2024-02-13 13:42 ` [PATCH net-next v4 5/5] tcp: use drop reasons " Jason Xing
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20240213134205.8705-5-kerneljasonxing@gmail.com \
--to=kerneljasonxing@gmail.com \
--cc=davem@davemloft.net \
--cc=dsahern@kernel.org \
--cc=edumazet@google.com \
--cc=kernelxing@tencent.com \
--cc=kuba@kernel.org \
--cc=kuniyu@amazon.com \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.