From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-5.5 required=3.0 tests=DKIM_SIGNED,DKIM_VALID, HEADER_FROM_DIFFERENT_DOMAINS,MAILING_LIST_MULTI,SIGNED_OFF_BY,SPF_PASS, USER_AGENT_MUTT autolearn=unavailable autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 4A1E4C282CE for ; Wed, 24 Apr 2019 21:06:44 +0000 (UTC) Received: from vger.kernel.org (vger.kernel.org [209.132.180.67]) by mail.kernel.org (Postfix) with ESMTP id 179BF20684 for ; Wed, 24 Apr 2019 21:06:44 +0000 (UTC) Authentication-Results: mail.kernel.org; dkim=pass (2048-bit key) header.d=fomichev-me.20150623.gappssmtp.com header.i=@fomichev-me.20150623.gappssmtp.com header.b="xMTxssWp" Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1732812AbfDXVGm (ORCPT ); Wed, 24 Apr 2019 17:06:42 -0400 Received: from mail-pf1-f196.google.com ([209.85.210.196]:35231 "EHLO mail-pf1-f196.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1731973AbfDXVGm (ORCPT ); Wed, 24 Apr 2019 17:06:42 -0400 Received: by mail-pf1-f196.google.com with SMTP id t21so9964205pfh.2 for ; Wed, 24 Apr 2019 14:06:42 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=fomichev-me.20150623.gappssmtp.com; s=20150623; h=date:from:to:cc:subject:message-id:references:mime-version :content-disposition:in-reply-to:user-agent; bh=rVtIgBZvZRJTUlOGEg63mCfmhpvDXAdZVWU4eQWweUg=; b=xMTxssWpW9Ky+Ln67ePsiafEdHX1LZCqxtvkYKDgiVoymLwdSTx/bXfTk9IW0xeRPi rPW1fZSWu4Xg4qYXpm3wgPLEBq5C2fYh6YsZHrFP080KEmStkE1CjukYxbzp645LNGC9 wLFm7DNyuP9ZYqrtHU8vzIIDpPJn3CzHvI3Z5letdtm63LMBxFeJEhoSczsK6JhzWW76 5o5mVpW5n4rr5FsOqP3kokqB4SoMBPAd8ZdftGZJkkIC27iJPWhzPgBF/7wfOvgV4YJN HjXtvDSlogkyBC6DtheDbWavNKs8D7L6I4KpqeKueX1orByymmd0tItOfrV6aQUAGDEl E0+A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:date:from:to:cc:subject:message-id:references :mime-version:content-disposition:in-reply-to:user-agent; bh=rVtIgBZvZRJTUlOGEg63mCfmhpvDXAdZVWU4eQWweUg=; b=bIBOIWpbH6Me8L8wOLSd8yBA+AHLbrtcT4dWgI7VaoKiiUk1YNvs6ZlbzftB/C18h3 FOQTBSWrjEFIHaK86cNIIgoTJ08qt7nILpngTVMhJLr7CiSmJvQ89YIeZO9tTd7dSGth Vs/Jaq6yTyvOxfYXcpHOxACyB01ua+6DDi3IVg5Nj6QekTSF/Q25O6zG3kAuwulDoqqD EQSGbvxqsgRWu7R9x1Z7SAMwV9cE1cZVumGKYppmxsgN1BEPd03SuYaCBSow1mSg2zN/ ZWbVi7lHp1QIb0EFQrZ7f+e80hOm76vk6qEQw1ZAw1lliA20/ueZr2CZTqVho7atV5KD xx4g== X-Gm-Message-State: APjAAAUgskr1wrr4jmA8fIiviL3uCxDBO2hAAOn/Ts1J9D/iBL47uqVL Et/SNzSDwSyOypD9Q35gstQZGw== X-Google-Smtp-Source: APXvYqxc8cyCUydoUiJc6sxd7PSyhfF/xShxaZv2WjkgUU4nXcBWQJo5q/9Fvt4pNgRDJRpO6nTcXw== X-Received: by 2002:a62:474a:: with SMTP id u71mr34818291pfa.87.1556140001182; Wed, 24 Apr 2019 14:06:41 -0700 (PDT) Received: from localhost ([2601:646:8f00:18d9:d0fa:7a4b:764f:de48]) by smtp.gmail.com with ESMTPSA id j12sm24469407pgg.79.2019.04.24.14.06.40 (version=TLS1_2 cipher=ECDHE-RSA-CHACHA20-POLY1305 bits=256/256); Wed, 24 Apr 2019 14:06:40 -0700 (PDT) Date: Wed, 24 Apr 2019 14:06:39 -0700 From: Stanislav Fomichev To: Jann Horn Cc: Stanislav Fomichev , Network Development , bpf@vger.kernel.org, "David S. Miller" , Alexei Starovoitov , Daniel Borkmann , jakub.kicinski@netronome.com, quentin.monnet@netronome.com Subject: Re: [PATCH bpf-next v2 1/2] bpf: support BPF_PROG_QUERY for BPF_FLOW_DISSECTOR attach_type Message-ID: <20190424210639.GD1247@mini-arch> References: <20190424160951.45865-1-sdf@google.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: User-Agent: Mutt/1.11.3 (2019-02-01) Sender: netdev-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: netdev@vger.kernel.org On 04/24, Jann Horn wrote: > On Wed, Apr 24, 2019 at 6:09 PM Stanislav Fomichev wrote: > > target_fd is target namespace. If there is a flow dissector BPF program > > attached to that namespace, its (single) id is returned. > > > > v2: > > * don't sleep in rcu critical section (Jakub Kicinski) > > * check input prog_cnt (exit early) > > > > Signed-off-by: Stanislav Fomichev > [...] > > +int skb_flow_dissector_prog_query(const union bpf_attr *attr, > > + union bpf_attr __user *uattr) > > +{ > [...] > > + net = get_net_ns_by_fd(attr->query.target_fd); > > + if (IS_ERR(net)) > > + return PTR_ERR(net); > > At this point, you're holding a refcounted reference to `net`. It > looks like that reference is never dropped? Ah, indeed, put_net is missing, thanks! > > + > > + rcu_read_lock(); > > + attached = rcu_dereference(net->flow_dissector_prog); > > + if (attached) { > > + prog_cnt = 1; > > + prog_id = attached->aux->id; > > + } > > + rcu_read_unlock(); > > + > > + if (copy_to_user(&uattr->query.attach_flags, &flags, sizeof(flags))) > > + return -EFAULT; > [...] > > +}