From: Wei Liu <wei.liu2@citrix.com>
To: <xen-devel@lists.xen.org>, <netdev@vger.kernel.org>
Cc: <davem@davemloft.net>, <ian.campbell@citrix.com>,
<wdauchy@gmail.com>, <konrad.wilk@oracle.com>,
Wei Liu <wei.liu2@citrix.com>,
David Vrabel <david.vrabel@citrix.com>
Subject: [PATCH 4/4] xen-netback: don't disconnect frontend when seeing oversize packet
Date: Wed, 17 Apr 2013 18:42:03 +0100 [thread overview]
Message-ID: <1366220523-14579-5-git-send-email-wei.liu2@citrix.com> (raw)
In-Reply-To: <1366220523-14579-1-git-send-email-wei.liu2@citrix.com>
Some frontend drivers are sending packets > 64 KiB in length. This length
overflows the length field in the first slot making the following slots have
an invalid length.
Turn this error back into a non-fatal error by dropping the packet. To avoid
having the following slots having fatal errors, consume all slots in the
packet.
This does not reopen the security hole in XSA-39 as if the packet as an
invalid number of slots it will still hit fatal error case.
Signed-off-by: David Vrabel <david.vrabel@citrix.com>
Signed-off-by: Wei Liu <wei.liu2@citrix.com>
Acked-by: Ian Campbell <ian.campbell@citrix.com>
---
drivers/net/xen-netback/netback.c | 22 ++++++++++++++++------
1 file changed, 16 insertions(+), 6 deletions(-)
diff --git a/drivers/net/xen-netback/netback.c b/drivers/net/xen-netback/netback.c
index 86d533a..8b25124 100644
--- a/drivers/net/xen-netback/netback.c
+++ b/drivers/net/xen-netback/netback.c
@@ -981,12 +981,22 @@ static int netbk_count_requests(struct xenvif *vif,
memcpy(txp, RING_GET_REQUEST(&vif->tx, cons + slots),
sizeof(*txp));
- if (txp->size > first->size) {
- netdev_err(vif->dev,
- "Invalid tx request, slot size %u > remaining size %u\n",
- txp->size, first->size);
- netbk_fatal_tx_err(vif);
- return -EIO;
+
+ /* If the guest submitted a frame >= 64 KiB then
+ * first->size overflowed and following slots will
+ * appear to be larger than the frame.
+ *
+ * This cannot be fatal error as there are buggy
+ * frontends that do this.
+ *
+ * Consume all slots and drop the packet.
+ */
+ if (!drop_err && txp->size > first->size) {
+ if (net_ratelimit())
+ netdev_dbg(vif->dev,
+ "Invalid tx request, slot size %u > remaining size %u\n",
+ txp->size, first->size);
+ drop_err = -EIO;
}
first->size -= txp->size;
--
1.7.10.4
next prev parent reply other threads:[~2013-04-17 17:42 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2013-04-17 17:41 [PATCH V6] Bundle fixes for Xen netfront / netback Wei Liu
2013-04-17 17:42 ` [PATCH 1/4] xen-netfront: frags -> slots in log message Wei Liu
2013-04-17 17:42 ` [PATCH 2/4] xen-netfront: reduce gso_max_size to account for max TCP header Wei Liu
2013-04-17 17:42 ` [PATCH 3/4] xen-netback: coalesce slots in TX path and fix regressions Wei Liu
2013-04-17 17:42 ` Wei Liu [this message]
2013-04-17 18:09 ` [PATCH V6] Bundle fixes for Xen netfront / netback David Miller
2013-04-17 18:17 ` Wei Liu
2013-04-17 19:31 ` [Xen-devel] " Konrad Rzeszutek Wilk
2013-04-17 19:43 ` Wei Liu
2013-04-17 21:21 ` David Miller
2013-04-18 1:20 ` Wei Liu
2013-04-18 7:02 ` Ian Campbell
2013-04-17 21:20 ` David Miller
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1366220523-14579-5-git-send-email-wei.liu2@citrix.com \
--to=wei.liu2@citrix.com \
--cc=davem@davemloft.net \
--cc=david.vrabel@citrix.com \
--cc=ian.campbell@citrix.com \
--cc=konrad.wilk@oracle.com \
--cc=netdev@vger.kernel.org \
--cc=wdauchy@gmail.com \
--cc=xen-devel@lists.xen.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).