netdev.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
From: Wei Liu <wei.liu2@citrix.com>
To: <netdev@vger.kernel.org>, <xen-devel@lists.xen.org>
Cc: <annie.li@oracle.com>, <konrad.wilk@oracle.com>,
	<jbeulich@suse.com>, <ian.campbell@citrix.com>,
	<wdauchy@gmail.com>, <david.vrabel@citrix.com>,
	Wei Liu <wei.liu2@citrix.com>
Subject: [PATCH V4 7/7] xen-netback: don't disconnect frontend when seeing oversize packet
Date: Fri, 12 Apr 2013 15:24:06 +0100	[thread overview]
Message-ID: <1365776646-10796-8-git-send-email-wei.liu2@citrix.com> (raw)
In-Reply-To: <1365776646-10796-1-git-send-email-wei.liu2@citrix.com>

Some frontend drivers are sending packets > 64 KiB in length. This length
overflows the length field in the first slot making the following slots have
an invalid length.

Turn this error back into a non-fatal error by dropping the packet. To avoid
having the following slots having fatal errors, consume all slots in the
packet.

This does not reopen the security hole in XSA-39 as if the packet as an
invalid number of slots it will still hit fatal error case.

Signed-off-by: David Vrabel <david.vrabel@citrix.com>
Signed-off-by: Wei Liu <wei.liu2@citrix.com>
---
 drivers/net/xen-netback/netback.c |   22 ++++++++++++++++------
 1 file changed, 16 insertions(+), 6 deletions(-)

diff --git a/drivers/net/xen-netback/netback.c b/drivers/net/xen-netback/netback.c
index 00ae841..e21c15e 100644
--- a/drivers/net/xen-netback/netback.c
+++ b/drivers/net/xen-netback/netback.c
@@ -993,12 +993,22 @@ static int netbk_count_requests(struct xenvif *vif,
 
 		memcpy(txp, RING_GET_REQUEST(&vif->tx, cons + slots),
 		       sizeof(*txp));
-		if (txp->size > first->size) {
-			netdev_err(vif->dev,
-				   "Invalid tx request, slot size %u > remaining size %u\n",
-				   txp->size, first->size);
-			netbk_fatal_tx_err(vif);
-			return -EIO;
+
+		/* If the guest submitted a frame >= 64 KiB then
+		 * first->size overflowed and following slots will
+		 * appear to be larger than the frame.
+		 *
+		 * This cannot be fatal error as there are buggy
+		 * frontends that do this.
+		 *
+		 * Consume all slots and drop the packet.
+		 */
+		if (!drop_err && txp->size > first->size) {
+			if (net_ratelimit())
+				netdev_dbg(vif->dev,
+					   "Invalid tx request, slot size %u > remaining size %u\n",
+					   txp->size, first->size);
+			drop_err = -EIO;
 		}
 
 		first->size -= txp->size;
-- 
1.7.10.4

  parent reply	other threads:[~2013-04-12 14:24 UTC|newest]

Thread overview: 23+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2013-04-12 14:23 [PATCH V4 0/7] Bundle fixes for Xen netfront / netback Wei Liu
2013-04-12 14:24 ` [PATCH V4 1/7] xen-netfront: remove unused variable `extra' Wei Liu
2013-04-12 14:24 ` [PATCH V4 2/7] xen-netfront: frags -> slots in xennet_get_responses Wei Liu
2013-04-12 14:24 ` [PATCH V4 3/7] xen-netback: remove skb in xen_netbk_alloc_page Wei Liu
2013-04-12 14:24 ` [PATCH V4 4/7] xen-netfront: frags -> slots in log message Wei Liu
2013-04-12 14:41   ` Ian Campbell
2013-04-12 14:24 ` [PATCH V4 5/7] xen-netfront: reduce gso_max_size to account for max TCP header Wei Liu
2013-04-12 14:44   ` Ian Campbell
2013-04-12 15:07     ` Jan Beulich
2013-04-12 14:24 ` [PATCH V4 6/7] xen-netback: coalesce slots in TX path and fix regressions Wei Liu
2013-04-12 15:35   ` Ian Campbell
2013-04-14 16:15     ` Wei Liu
2013-04-12 14:24 ` Wei Liu [this message]
2013-04-12 15:38   ` [PATCH V4 7/7] xen-netback: don't disconnect frontend when seeing oversize packet Ian Campbell
2013-04-12 17:17   ` William Dauchy
2013-04-15  9:03     ` Ian Campbell
2013-04-15 14:53       ` Wei Liu
2013-04-15 15:22         ` Wei Liu
2013-04-15 15:24         ` Ian Campbell
2013-04-15 15:30           ` Wei Liu
2013-04-15 15:35             ` Ian Campbell
2013-04-15 15:39               ` Wei Liu
2013-04-15 17:36             ` David Miller

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1365776646-10796-8-git-send-email-wei.liu2@citrix.com \
    --to=wei.liu2@citrix.com \
    --cc=annie.li@oracle.com \
    --cc=david.vrabel@citrix.com \
    --cc=ian.campbell@citrix.com \
    --cc=jbeulich@suse.com \
    --cc=konrad.wilk@oracle.com \
    --cc=netdev@vger.kernel.org \
    --cc=wdauchy@gmail.com \
    --cc=xen-devel@lists.xen.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).