From: Florian Westphal <fw@strlen.de>
To: netfilter-devel@vger.kernel.org
Cc: Houcheng Lin <houcheng@gmail.com>, Florian Westphal <fw@strlen.de>
Subject: [PATCH 3/3] netfilter: nf_log: release skbuff on nlmsg put failure
Date: Thu, 23 Oct 2014 10:36:08 +0200 [thread overview]
Message-ID: <1414053368-29037-4-git-send-email-fw@strlen.de> (raw)
In-Reply-To: <1414053368-29037-1-git-send-email-fw@strlen.de>
From: Houcheng Lin <houcheng@gmail.com>
The kernel should reserve enough room in the skb so that the DONE
message can always be appended. However, in case of e.g. new attribute
erronously not being size-accounted for, __nfulnl_send() will still
try to put next nlmsg into this full skbuf, causing the skb to be stuck
forever and blocking delivery of further messages.
Fix issue by releasing skb immediately after nlmsg_put error and
WARN() so we can track down the cause of such size mismatch.
[ fw@strlen.de: add tailroom/len info to WARN ]
Signed-off-by: Houcheng Lin <houcheng@gmail.com>
Signed-off-by: Florian Westphal <fw@strlen.de>
---
net/netfilter/nfnetlink_log.c | 17 ++++++++---------
1 file changed, 8 insertions(+), 9 deletions(-)
diff --git a/net/netfilter/nfnetlink_log.c b/net/netfilter/nfnetlink_log.c
index 2d02eac3..5f1be5b 100644
--- a/net/netfilter/nfnetlink_log.c
+++ b/net/netfilter/nfnetlink_log.c
@@ -346,26 +346,25 @@ nfulnl_alloc_skb(struct net *net, u32 peer_portid, unsigned int inst_size,
return skb;
}
-static int
+static void
__nfulnl_send(struct nfulnl_instance *inst)
{
- int status = -1;
-
if (inst->qlen > 1) {
struct nlmsghdr *nlh = nlmsg_put(inst->skb, 0, 0,
NLMSG_DONE,
sizeof(struct nfgenmsg),
0);
- if (!nlh)
+ if (WARN_ONCE(!nlh, "bad nlskb size: %u, tailroom %d\n",
+ inst->skb->len, skb_tailroom(inst->skb))) {
+ kfree_skb(inst->skb);
goto out;
+ }
}
- status = nfnetlink_unicast(inst->skb, inst->net, inst->peer_portid,
- MSG_DONTWAIT);
-
+ nfnetlink_unicast(inst->skb, inst->net, inst->peer_portid,
+ MSG_DONTWAIT);
+out:
inst->qlen = 0;
inst->skb = NULL;
-out:
- return status;
}
static void
--
2.0.4
next prev parent reply other threads:[~2014-10-23 8:36 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-10-23 8:36 [PATCH 0/3] netfilter: nf_log: nlmsg size fixes Florian Westphal
2014-10-23 8:36 ` [PATCH 1/3] netfilter: nf_log: account for size of NLMSG_DONE attribute Florian Westphal
2014-10-24 12:30 ` Pablo Neira Ayuso
2014-10-24 12:39 ` Pablo Neira Ayuso
2014-10-23 8:36 ` [PATCH 2/3] netfilter: nfnetlink_log: fix maximum packet length logged to userspace Florian Westphal
2014-10-24 12:33 ` Pablo Neira Ayuso
2014-10-23 8:36 ` Florian Westphal [this message]
2014-10-24 12:35 ` [PATCH 3/3] netfilter: nf_log: release skbuff on nlmsg put failure Pablo Neira Ayuso
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1414053368-29037-4-git-send-email-fw@strlen.de \
--to=fw@strlen.de \
--cc=houcheng@gmail.com \
--cc=netfilter-devel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).