* [Patch net] tcp: reset sk_rx_dst in tcp_disconnect()
@ 2017-06-25 6:50 Cong Wang
2017-06-25 16:23 ` David Miller
2017-07-05 6:54 ` Jamie Bainbridge
0 siblings, 2 replies; 4+ messages in thread
From: Cong Wang @ 2017-06-25 6:50 UTC (permalink / raw)
To: netdev; +Cc: avagin, kaiwen.xu, Cong Wang
We have to reset the sk->sk_rx_dst when we disconnect a TCP
connection, because otherwise when we re-connect it this
dst reference is simply overridden in tcp_finish_connect().
This fixes a dst leak which leads to a loopback dev refcnt
leak. It is a long-standing bug, Kevin reported a very similar
(if not same) bug before. Thanks to Andrei for providing such
a reliable reproducer which greatly narrows down the problem.
Fixes: 41063e9dd119 ("ipv4: Early TCP socket demux.")
Reported-by: Andrei Vagin <avagin@gmail.com>
Reported-by: Kevin Xu <kaiwen.xu@hulu.com>
Signed-off-by: Cong Wang <xiyou.wangcong@gmail.com>
---
net/ipv4/tcp.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/net/ipv4/tcp.c b/net/ipv4/tcp.c
index b5ea036..40aca78 100644
--- a/net/ipv4/tcp.c
+++ b/net/ipv4/tcp.c
@@ -2330,6 +2330,8 @@ int tcp_disconnect(struct sock *sk, int flags)
tcp_init_send_head(sk);
memset(&tp->rx_opt, 0, sizeof(tp->rx_opt));
__sk_dst_reset(sk);
+ dst_release(sk->sk_rx_dst);
+ sk->sk_rx_dst = NULL;
tcp_saved_syn_free(tp);
/* Clean up fastopen related fields */
--
2.5.5
^ permalink raw reply related [flat|nested] 4+ messages in thread
* Re: [Patch net] tcp: reset sk_rx_dst in tcp_disconnect()
2017-06-25 6:50 [Patch net] tcp: reset sk_rx_dst in tcp_disconnect() Cong Wang
@ 2017-06-25 16:23 ` David Miller
2017-07-05 6:54 ` Jamie Bainbridge
1 sibling, 0 replies; 4+ messages in thread
From: David Miller @ 2017-06-25 16:23 UTC (permalink / raw)
To: xiyou.wangcong; +Cc: netdev, avagin, kaiwen.xu
From: Cong Wang <xiyou.wangcong@gmail.com>
Date: Sat, 24 Jun 2017 23:50:30 -0700
> We have to reset the sk->sk_rx_dst when we disconnect a TCP
> connection, because otherwise when we re-connect it this
> dst reference is simply overridden in tcp_finish_connect().
>
> This fixes a dst leak which leads to a loopback dev refcnt
> leak. It is a long-standing bug, Kevin reported a very similar
> (if not same) bug before. Thanks to Andrei for providing such
> a reliable reproducer which greatly narrows down the problem.
>
> Fixes: 41063e9dd119 ("ipv4: Early TCP socket demux.")
> Reported-by: Andrei Vagin <avagin@gmail.com>
> Reported-by: Kevin Xu <kaiwen.xu@hulu.com>
> Signed-off-by: Cong Wang <xiyou.wangcong@gmail.com>
Applied and queued up for -stable, thanks!
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [Patch net] tcp: reset sk_rx_dst in tcp_disconnect()
2017-06-25 6:50 [Patch net] tcp: reset sk_rx_dst in tcp_disconnect() Cong Wang
2017-06-25 16:23 ` David Miller
@ 2017-07-05 6:54 ` Jamie Bainbridge
2017-07-05 16:40 ` Cong Wang
1 sibling, 1 reply; 4+ messages in thread
From: Jamie Bainbridge @ 2017-07-05 6:54 UTC (permalink / raw)
To: Cong Wang; +Cc: netdev, avagin, kaiwen.xu
On 25 June 2017 at 16:50, Cong Wang <xiyou.wangcong@gmail.com> wrote:
> We have to reset the sk->sk_rx_dst when we disconnect a TCP
> connection, because otherwise when we re-connect it this
> dst reference is simply overridden in tcp_finish_connect().
>
> This fixes a dst leak which leads to a loopback dev refcnt
> leak. It is a long-standing bug, Kevin reported a very similar
> (if not same) bug before. Thanks to Andrei for providing such
> a reliable reproducer which greatly narrows down the problem.
>
> Fixes: 41063e9dd119 ("ipv4: Early TCP socket demux.")
> Reported-by: Andrei Vagin <avagin@gmail.com>
> Reported-by: Kevin Xu <kaiwen.xu@hulu.com>
> Signed-off-by: Cong Wang <xiyou.wangcong@gmail.com>
Are you able to supply the reproducer for this?
I did search for a previous thread about it but could not find.
Jamie
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [Patch net] tcp: reset sk_rx_dst in tcp_disconnect()
2017-07-05 6:54 ` Jamie Bainbridge
@ 2017-07-05 16:40 ` Cong Wang
0 siblings, 0 replies; 4+ messages in thread
From: Cong Wang @ 2017-07-05 16:40 UTC (permalink / raw)
To: Jamie Bainbridge; +Cc: Linux Kernel Network Developers, Andrey Wagin, Kaiwen Xu
On Tue, Jul 4, 2017 at 11:54 PM, Jamie Bainbridge
<jamie.bainbridge@gmail.com> wrote:
> On 25 June 2017 at 16:50, Cong Wang <xiyou.wangcong@gmail.com> wrote:
>> We have to reset the sk->sk_rx_dst when we disconnect a TCP
>> connection, because otherwise when we re-connect it this
>> dst reference is simply overridden in tcp_finish_connect().
>>
>> This fixes a dst leak which leads to a loopback dev refcnt
>> leak. It is a long-standing bug, Kevin reported a very similar
>> (if not same) bug before. Thanks to Andrei for providing such
>> a reliable reproducer which greatly narrows down the problem.
>>
>> Fixes: 41063e9dd119 ("ipv4: Early TCP socket demux.")
>> Reported-by: Andrei Vagin <avagin@gmail.com>
>> Reported-by: Kevin Xu <kaiwen.xu@hulu.com>
>> Signed-off-by: Cong Wang <xiyou.wangcong@gmail.com>
>
> Are you able to supply the reproducer for this?
>
> I did search for a previous thread about it but could not find.
Here it is:
http://marc.info/?l=linux-kernel&m=149825461307610&w=2
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2017-07-05 16:40 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2017-06-25 6:50 [Patch net] tcp: reset sk_rx_dst in tcp_disconnect() Cong Wang
2017-06-25 16:23 ` David Miller
2017-07-05 6:54 ` Jamie Bainbridge
2017-07-05 16:40 ` Cong Wang
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).