From: Kuniyuki Iwashima <kuniyu@amazon.com>
To: <kerneljasonxing@gmail.com>
Cc: <davem@davemloft.net>, <dsahern@kernel.org>,
<edumazet@google.com>, <kernelxing@tencent.com>,
<kuba@kernel.org>, <kuniyu@amazon.com>, <netdev@vger.kernel.org>,
<pabeni@redhat.com>
Subject: [PATCH net-next v5 03/11] tcp: use drop reasons in cookie check for ipv4
Date: Thu, 15 Feb 2024 13:09:22 -0800 [thread overview]
Message-ID: <20240215210922.19969-1-kuniyu@amazon.com> (raw)
In-Reply-To: <20240215012027.11467-4-kerneljasonxing@gmail.com>
From: Jason Xing <kerneljasonxing@gmail.com>
Date: Thu, 15 Feb 2024 09:20:19 +0800
> From: Jason Xing <kernelxing@tencent.com>
>
> Now it's time to use the prepared definitions to refine this part.
> Four reasons used might enough for now, I think.
>
> Signed-off-by: Jason Xing <kernelxing@tencent.com>
> --
> v5:
> Link: https://lore.kernel.org/netdev/CANn89i+iELpsoea6+C-08m6+=JkneEEM=nAj-28eNtcOCkwQjw@mail.gmail.com/
> Link: https://lore.kernel.org/netdev/632c6fd4-e060-4b8e-a80e-5d545a6c6b6c@kernel.org/
> 1. Use SKB_DROP_REASON_IP_OUTNOROUTES instead of introducing a new one (Eric, David)
> 2. Reuse SKB_DROP_REASON_NOMEM to handle failure of request socket allocation (Eric)
> 3. Reuse NO_SOCKET instead of introducing COOKIE_NOCHILD
> ---
> net/ipv4/syncookies.c | 18 +++++++++++++-----
> 1 file changed, 13 insertions(+), 5 deletions(-)
>
> diff --git a/net/ipv4/syncookies.c b/net/ipv4/syncookies.c
> index 38f331da6677..aeb61c880fbd 100644
> --- a/net/ipv4/syncookies.c
> +++ b/net/ipv4/syncookies.c
> @@ -421,8 +421,10 @@ struct sock *cookie_v4_check(struct sock *sk, struct sk_buff *skb)
> if (IS_ERR(req))
> goto out;
> }
> - if (!req)
> + if (!req) {
> + SKB_DR_SET(reason, NOMEM);
NOMEM is not appropriate when mptcp_subflow_init_cookie_req() fails.
> goto out_drop;
> + }
>
> ireq = inet_rsk(req);
>
> @@ -434,8 +436,10 @@ struct sock *cookie_v4_check(struct sock *sk, struct sk_buff *skb)
> */
> RCU_INIT_POINTER(ireq->ireq_opt, tcp_v4_save_options(net, skb));
>
> - if (security_inet_conn_request(sk, skb, req))
> + if (security_inet_conn_request(sk, skb, req)) {
> + SKB_DR_SET(reason, SECURITY_HOOK);
> goto out_free;
> + }
>
> tcp_ao_syncookie(sk, skb, req, AF_INET);
>
> @@ -452,8 +456,10 @@ struct sock *cookie_v4_check(struct sock *sk, struct sk_buff *skb)
> ireq->ir_loc_addr, th->source, th->dest, sk->sk_uid);
> security_req_classify_flow(req, flowi4_to_flowi_common(&fl4));
> rt = ip_route_output_key(net, &fl4);
> - if (IS_ERR(rt))
> + if (IS_ERR(rt)) {
> + SKB_DR_SET(reason, IP_OUTNOROUTES);
> goto out_free;
> + }
>
> /* Try to redo what tcp_v4_send_synack did. */
> req->rsk_window_clamp = tp->window_clamp ? :dst_metric(&rt->dst, RTAX_WINDOW);
> @@ -476,10 +482,12 @@ struct sock *cookie_v4_check(struct sock *sk, struct sk_buff *skb)
> /* ip_queue_xmit() depends on our flow being setup
> * Normal sockets get it right from inet_csk_route_child_sock()
> */
> - if (ret)
> + if (ret) {
> inet_sk(ret)->cork.fl.u.ip4 = fl4;
> - else
> + } else {
> + SKB_DR_SET(reason, NO_SOCKET);
This also seems wrong to me.
e.g. syn_recv_sock() could fail with sk_acceptq_is_full(sk),
then the listener is actually found.
> goto out_drop;
> + }
> out:
> return ret;
> out_free:
> --
> 2.37.3
>
next prev parent reply other threads:[~2024-02-15 21:09 UTC|newest]
Thread overview: 21+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-02-15 1:20 [PATCH net-next v5 00/11] introduce drop reasons for tcp receive path Jason Xing
2024-02-15 1:20 ` [PATCH net-next v5 01/11] tcp: add a dropreason definitions and prepare for cookie check Jason Xing
2024-02-15 1:20 ` [PATCH net-next v5 02/11] tcp: directly drop skb in cookie check for ipv4 Jason Xing
2024-02-15 1:20 ` [PATCH net-next v5 03/11] tcp: use drop reasons " Jason Xing
2024-02-15 21:09 ` Kuniyuki Iwashima [this message]
2024-02-16 1:28 ` Jason Xing
2024-02-16 3:03 ` Kuniyuki Iwashima
2024-02-16 3:50 ` Jason Xing
2024-02-16 4:11 ` Kuniyuki Iwashima
2024-02-16 4:41 ` Jason Xing
2024-02-15 1:20 ` [PATCH net-next v5 04/11] tcp: directly drop skb in cookie check for ipv6 Jason Xing
2024-02-15 11:08 ` Jason Xing
2024-02-15 1:20 ` [PATCH net-next v5 05/11] tcp: use drop reasons " Jason Xing
2024-02-15 1:20 ` [PATCH net-next v5 06/11] tcp: introduce dropreasons in receive path Jason Xing
2024-02-15 1:20 ` [PATCH net-next v5 07/11] tcp: add more specific possible drop reasons in tcp_rcv_synsent_state_process() Jason Xing
2024-02-15 1:20 ` [PATCH net-next v5 08/11] tcp: add dropreasons in tcp_rcv_state_process() Jason Xing
2024-02-15 1:20 ` [PATCH net-next v5 09/11] tcp: make the dropreason really work when calling tcp_rcv_state_process() Jason Xing
2024-02-15 1:20 ` [PATCH net-next v5 10/11] tcp: make dropreason in tcp_child_process() work Jason Xing
2024-02-15 1:20 ` [PATCH net-next v5 11/11] tcp: get rid of NOT_SPECIFIED reason in tcp_v4/6_do_rcv Jason Xing
2024-02-15 10:12 ` [PATCH net-next v5 00/11] introduce drop reasons for tcp receive path Paolo Abeni
2024-02-15 11:10 ` Jason Xing
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20240215210922.19969-1-kuniyu@amazon.com \
--to=kuniyu@amazon.com \
--cc=davem@davemloft.net \
--cc=dsahern@kernel.org \
--cc=edumazet@google.com \
--cc=kerneljasonxing@gmail.com \
--cc=kernelxing@tencent.com \
--cc=kuba@kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.