All of lore.kernel.org
 help / color / mirror / Atom feed
From: Jason Xing <kerneljasonxing@gmail.com>
To: davem@davemloft.net, edumazet@google.com, kuba@kernel.org,
	pabeni@redhat.com, dsahern@kernel.org, kuniyu@amazon.com
Cc: netdev@vger.kernel.org, kerneljasonxing@gmail.com,
	Jason Xing <kernelxing@tencent.com>
Subject: [PATCH net-next v5 04/11] tcp: directly drop skb in cookie check for ipv6
Date: Thu, 15 Feb 2024 09:20:20 +0800	[thread overview]
Message-ID: <20240215012027.11467-5-kerneljasonxing@gmail.com> (raw)
In-Reply-To: <20240215012027.11467-1-kerneljasonxing@gmail.com>

From: Jason Xing <kernelxing@tencent.com>

Like previous patch does, only moving skb drop logical code to
cookie_v6_check() for later refinement.

Signed-off-by: Jason Xing <kernelxing@tencent.com>
--
v5
Link: https://lore.kernel.org/netdev/CANn89iKz7=1q7e8KY57Dn3ED7O=RCOfLxoHQKO4eNXnZa1OPWg@mail.gmail.com/
1. avoid duplication of these opt_skb tests/actions (Eric)
---
 net/ipv6/syncookies.c |  4 ++++
 net/ipv6/tcp_ipv6.c   | 11 ++++-------
 2 files changed, 8 insertions(+), 7 deletions(-)

diff --git a/net/ipv6/syncookies.c b/net/ipv6/syncookies.c
index 6b9c69278819..ea0d9954a29f 100644
--- a/net/ipv6/syncookies.c
+++ b/net/ipv6/syncookies.c
@@ -177,6 +177,7 @@ struct sock *cookie_v6_check(struct sock *sk, struct sk_buff *skb)
 	struct sock *ret = sk;
 	__u8 rcv_wscale;
 	int full_space;
+	SKB_DR(reason);
 
 	if (!READ_ONCE(net->ipv4.sysctl_tcp_syncookies) ||
 	    !th->ack || th->rst)
@@ -256,10 +257,13 @@ struct sock *cookie_v6_check(struct sock *sk, struct sk_buff *skb)
 	ireq->ecn_ok &= cookie_ecn_ok(net, dst);
 
 	ret = tcp_get_cookie_sock(sk, skb, req, dst);
+	if (!ret)
+		goto out_drop;
 out:
 	return ret;
 out_free:
 	reqsk_free(req);
 out_drop:
+	kfree_skb_reason(skb, reason);
 	return NULL;
 }
diff --git a/net/ipv6/tcp_ipv6.c b/net/ipv6/tcp_ipv6.c
index 57b25b1fc9d9..1ca4f11c3d6f 100644
--- a/net/ipv6/tcp_ipv6.c
+++ b/net/ipv6/tcp_ipv6.c
@@ -1653,16 +1653,13 @@ int tcp_v6_do_rcv(struct sock *sk, struct sk_buff *skb)
 	if (sk->sk_state == TCP_LISTEN) {
 		struct sock *nsk = tcp_v6_cookie_check(sk, skb);
 
-		if (!nsk)
-			goto discard;
-
-		if (nsk != sk) {
+		if (nsk && nsk != sk) {
 			if (tcp_child_process(sk, nsk, skb))
 				goto reset;
-			if (opt_skb)
-				__kfree_skb(opt_skb);
-			return 0;
 		}
+		if (opt_skb)
+			__kfree_skb(opt_skb);
+		return 0;
 	} else
 		sock_rps_save_rxhash(sk, skb);
 
-- 
2.37.3


  parent reply	other threads:[~2024-02-15  1:20 UTC|newest]

Thread overview: 21+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2024-02-15  1:20 [PATCH net-next v5 00/11] introduce drop reasons for tcp receive path Jason Xing
2024-02-15  1:20 ` [PATCH net-next v5 01/11] tcp: add a dropreason definitions and prepare for cookie check Jason Xing
2024-02-15  1:20 ` [PATCH net-next v5 02/11] tcp: directly drop skb in cookie check for ipv4 Jason Xing
2024-02-15  1:20 ` [PATCH net-next v5 03/11] tcp: use drop reasons " Jason Xing
2024-02-15 21:09   ` Kuniyuki Iwashima
2024-02-16  1:28     ` Jason Xing
2024-02-16  3:03       ` Kuniyuki Iwashima
2024-02-16  3:50         ` Jason Xing
2024-02-16  4:11           ` Kuniyuki Iwashima
2024-02-16  4:41             ` Jason Xing
2024-02-15  1:20 ` Jason Xing [this message]
2024-02-15 11:08   ` [PATCH net-next v5 04/11] tcp: directly drop skb in cookie check for ipv6 Jason Xing
2024-02-15  1:20 ` [PATCH net-next v5 05/11] tcp: use drop reasons " Jason Xing
2024-02-15  1:20 ` [PATCH net-next v5 06/11] tcp: introduce dropreasons in receive path Jason Xing
2024-02-15  1:20 ` [PATCH net-next v5 07/11] tcp: add more specific possible drop reasons in tcp_rcv_synsent_state_process() Jason Xing
2024-02-15  1:20 ` [PATCH net-next v5 08/11] tcp: add dropreasons in tcp_rcv_state_process() Jason Xing
2024-02-15  1:20 ` [PATCH net-next v5 09/11] tcp: make the dropreason really work when calling tcp_rcv_state_process() Jason Xing
2024-02-15  1:20 ` [PATCH net-next v5 10/11] tcp: make dropreason in tcp_child_process() work Jason Xing
2024-02-15  1:20 ` [PATCH net-next v5 11/11] tcp: get rid of NOT_SPECIFIED reason in tcp_v4/6_do_rcv Jason Xing
2024-02-15 10:12 ` [PATCH net-next v5 00/11] introduce drop reasons for tcp receive path Paolo Abeni
2024-02-15 11:10   ` Jason Xing

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20240215012027.11467-5-kerneljasonxing@gmail.com \
    --to=kerneljasonxing@gmail.com \
    --cc=davem@davemloft.net \
    --cc=dsahern@kernel.org \
    --cc=edumazet@google.com \
    --cc=kernelxing@tencent.com \
    --cc=kuba@kernel.org \
    --cc=kuniyu@amazon.com \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.