From: Gao feng <gaofeng@cn.fujitsu.com>
To: Pablo Neira Ayuso <pablo@netfilter.org>
Cc: netdev@vger.kernel.org, netfilter-devel@vger.kernel.org
Subject: Re: [PATCH 01/13] netfilter: fix problem with proto register
Date: Tue, 26 Jun 2012 11:40:14 +0800 [thread overview]
Message-ID: <4FE92F1E.9020901@cn.fujitsu.com> (raw)
In-Reply-To: <20120625111253.GA4607@1984>
Hi Pablo:
于 2012年06月25日 19:12, Pablo Neira Ayuso 写道:
> On Thu, Jun 21, 2012 at 10:36:38PM +0800, Gao feng wrote:
>> before commit 2c352f444ccfa966a1aa4fd8e9ee29381c467448
>> (netfilter: nf_conntrack: prepare namespace support for
>> l4 protocol trackers), we register sysctl before register
>> protos, so if sysctl is registered faild, the protos will
>> not be registered.
>>
>> but now, we register protos first, and when register
>> sysctl failed, we can use protos too, it's different
>> from before.
>
> No, this has to be an all-or-nothing game. If one fails, everything
> else that you've registered has to be unregistered.
indeed,this is an all-or-nothing game right now,please look at the ipv4_net_init,
when we register nf_conntrack_l3proto_ipv4 failed,we will unregister the already
registered l4protoes, and in nf_conntrack_l4proto_unregister,we will call
nf_ct_l4proto_unregister_sysctl to free the sysctl table.
>
>> so change to register sysctl before register protos.
>>
>> Signed-off-by: Gao feng <gaofeng@cn.fujitsu.com>
>> ---
>> net/netfilter/nf_conntrack_proto.c | 36 +++++++++++++++++++++++-------------
>> 1 files changed, 23 insertions(+), 13 deletions(-)
>>
>> diff --git a/net/netfilter/nf_conntrack_proto.c b/net/netfilter/nf_conntrack_proto.c
>> index 1ea9194..9bd88aa 100644
>> --- a/net/netfilter/nf_conntrack_proto.c
>> +++ b/net/netfilter/nf_conntrack_proto.c
>> @@ -253,18 +253,23 @@ int nf_conntrack_l3proto_register(struct net *net,
>> {
>> int ret = 0;
>>
>> - if (net == &init_net)
>> - ret = nf_conntrack_l3proto_register_net(proto);
>> + if (proto->init_net) {
>> + ret = proto->init_net(net);
>> + if (ret < 0)
>> + return ret;
>> + }
>>
>> + ret = nf_ct_l3proto_register_sysctl(net, proto);
>> if (ret < 0)
>> return ret;
>
> This is still wrong.
>
> If nf_ct_l3proto_register_sysctl fails, we'll leak the memory that has
> been reserved by proto->init_net.
>
we have freed the memory in nf_ct_l[3,4]proto_register_sysctl when we
call nf_ct_register_sysctl failed, so there is no need to free this memory
in nf_conntrack_l[3,4]proto_register.
>> - if (proto->init_net) {
>> - ret = proto->init_net(net);
>> + if (net == &init_net) {
>> + ret = nf_conntrack_l3proto_register_net(proto);
>> if (ret < 0)
>> - return ret;
>> + nf_ct_l3proto_unregister_sysctl(net, proto);
>> }
>> - return nf_ct_l3proto_register_sysctl(net, proto);
>> +
>> + return ret;
>> }
>> EXPORT_SYMBOL_GPL(nf_conntrack_l3proto_register);
>>
>> @@ -454,19 +459,24 @@ int nf_conntrack_l4proto_register(struct net *net,
>> struct nf_conntrack_l4proto *l4proto)
>> {
>> int ret = 0;
>> - if (net == &init_net)
>> - ret = nf_conntrack_l4proto_register_net(l4proto);
>>
>> - if (ret < 0)
>> - return ret;
>> -
>> - if (l4proto->init_net)
>> + if (l4proto->init_net) {
>> ret = l4proto->init_net(net);
>> + if (ret < 0)
>> + return ret;
>> + }
>>
>> + ret = nf_ct_l4proto_register_sysctl(net, l4proto);
>> if (ret < 0)
>> return ret;
>>
>> - return nf_ct_l4proto_register_sysctl(net, l4proto);
>> + if (net == &init_net) {
>> + ret = nf_conntrack_l4proto_register_net(l4proto);
>> + if (ret < 0)
>> + nf_ct_l4proto_unregister_sysctl(net, l4proto);
>> + }
>> +
>> + return ret;
>> }
>> EXPORT_SYMBOL_GPL(nf_conntrack_l4proto_register);
>>
>> --
>> 1.7.7.6
>>
>> --
>> To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in
>> the body of a message to majordomo@vger.kernel.org
>> More majordomo info at http://vger.kernel.org/majordomo-info.html
> --
> To unsubscribe from this list: send the line "unsubscribe netdev" in
> the body of a message to majordomo@vger.kernel.org
> More majordomo info at http://vger.kernel.org/majordomo-info.html
>
next prev parent reply other threads:[~2012-06-26 3:40 UTC|newest]
Thread overview: 23+ messages / expand[flat|nested] mbox.gz Atom feed top
2012-06-21 14:36 [PATCH 01/13] netfilter: fix problem with proto register Gao feng
2012-06-21 14:36 ` [PATCH 02/13] netfilter: add parameter proto for l4proto.init_net Gao feng
2012-06-21 14:36 ` [PATCH 03/13] netfilter: add nf_ct_kfree_compat_sysctl_table to make codes clear Gao feng
2012-06-21 14:36 ` [PATCH 04/13] netfilter: regard users as refcount for l4proto's per-net data Gao feng
2012-06-25 11:20 ` Pablo Neira Ayuso
2012-06-26 3:58 ` Gao feng
2012-06-26 14:47 ` Pablo Neira Ayuso
2012-06-27 1:34 ` Gao feng
2012-06-27 9:05 ` Pablo Neira Ayuso
2012-06-21 14:36 ` [PATCH 05/13] netfilter: fix memory leak when register sysctl failed Gao feng
2012-06-21 14:36 ` [PATCH 06/13] netfilter: merge tcpv[4,6]_net_init into tcp_net_init Gao feng
2012-06-21 14:36 ` [PATCH 07/13] netfilter: merge udpv[4,6]_net_init into udp_net_init Gao feng
2012-06-21 14:36 ` [PATCH 08/13] netfilter: nf_conntrack_l4proto_udplite[4,6] cleanup Gao feng
2012-06-21 14:36 ` [PATCH 09/13] netfilter: merge sctpv[4,6]_net_init into sctp_net_init Gao feng
2012-06-21 14:36 ` [PATCH 10/13] netfilter: nf_conntrack_l4proto_generic cleanup Gao feng
2012-06-21 14:36 ` [PATCH 11/13] netfilter: nf_conntrack_l4proto_dccp[4,6] cleanup Gao feng
2012-06-21 14:36 ` [PATCH 12/13] netfilter: nf_conntrack_l4proto_icmp cleanup Gao feng
2012-06-21 14:36 ` [PATCH 13/13] netfilter: nf_conntrack_l4proto_icmpv6 cleanup Gao feng
2012-06-25 11:12 ` [PATCH 01/13] netfilter: fix problem with proto register Pablo Neira Ayuso
2012-06-26 3:40 ` Gao feng [this message]
2012-06-26 14:36 ` Pablo Neira Ayuso
2012-06-27 1:38 ` Gao feng
2012-06-27 8:53 ` Pablo Neira Ayuso
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4FE92F1E.9020901@cn.fujitsu.com \
--to=gaofeng@cn.fujitsu.com \
--cc=netdev@vger.kernel.org \
--cc=netfilter-devel@vger.kernel.org \
--cc=pablo@netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.