2019-05-27 09:55:01 +03:00
// SPDX-License-Identifier: GPL-2.0-or-later
2006-11-27 22:10:57 +03:00
/*
* UDPLITE An implementation of the UDP - Lite protocol ( RFC 3828 ) .
*
* Authors : Gerrit Renker < gerrit @ erg . abdn . ac . uk >
*
* Changes :
* Fixes :
*/
2012-03-12 11:03:32 +04:00
# define pr_fmt(fmt) "UDPLite: " fmt
2011-07-15 19:47:34 +04:00
# include <linux/export.h>
2018-04-10 22:31:50 +03:00
# include <linux/proc_fs.h>
2006-11-27 22:10:57 +03:00
# include "udp_impl.h"
2009-10-07 04:37:59 +04:00
struct udp_table udplite_table __read_mostly ;
2008-10-29 11:41:45 +03:00
EXPORT_SYMBOL ( udplite_table ) ;
2006-11-27 22:10:57 +03:00
tcp/udp: Call inet6_destroy_sock() in IPv6 sk->sk_destruct().
Originally, inet6_sk(sk)->XXX were changed under lock_sock(), so we were
able to clean them up by calling inet6_destroy_sock() during the IPv6 ->
IPv4 conversion by IPV6_ADDRFORM. However, commit 03485f2adcde ("udpv6:
Add lockless sendmsg() support") added a lockless memory allocation path,
which could cause a memory leak:
setsockopt(IPV6_ADDRFORM) sendmsg()
+-----------------------+ +-------+
- do_ipv6_setsockopt(sk, ...) - udpv6_sendmsg(sk, ...)
- sockopt_lock_sock(sk) ^._ called via udpv6_prot
- lock_sock(sk) before WRITE_ONCE()
- WRITE_ONCE(sk->sk_prot, &tcp_prot)
- inet6_destroy_sock() - if (!corkreq)
- sockopt_release_sock(sk) - ip6_make_skb(sk, ...)
- release_sock(sk) ^._ lockless fast path for
the non-corking case
- __ip6_append_data(sk, ...)
- ipv6_local_rxpmtu(sk, ...)
- xchg(&np->rxpmtu, skb)
^._ rxpmtu is never freed.
- goto out_no_dst;
- lock_sock(sk)
For now, rxpmtu is only the case, but not to miss the future change
and a similar bug fixed in commit e27326009a3d ("net: ping6: Fix
memleak in ipv6_renew_options()."), let's set a new function to IPv6
sk->sk_destruct() and call inet6_cleanup_sock() there. Since the
conversion does not change sk->sk_destruct(), we can guarantee that
we can clean up IPv6 resources finally.
We can now remove all inet6_destroy_sock() calls from IPv6 protocol
specific ->destroy() functions, but such changes are invasive to
backport. So they can be posted as a follow-up later for net-next.
Fixes: 03485f2adcde ("udpv6: Add lockless sendmsg() support")
Signed-off-by: Kuniyuki Iwashima <kuniyu@amazon.com>
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
2022-10-06 21:53:47 +03:00
/* Designate sk as UDP-Lite socket */
static int udplite_sk_init ( struct sock * sk )
{
udp_init_sock ( sk ) ;
udp_sk ( sk ) - > pcflag = UDPLITE_BIT ;
2023-06-14 22:47:04 +03:00
pr_warn_once ( " UDP-Lite is deprecated and scheduled to be removed in 2025, "
" please contact the netdev mailing list \n " ) ;
tcp/udp: Call inet6_destroy_sock() in IPv6 sk->sk_destruct().
Originally, inet6_sk(sk)->XXX were changed under lock_sock(), so we were
able to clean them up by calling inet6_destroy_sock() during the IPv6 ->
IPv4 conversion by IPV6_ADDRFORM. However, commit 03485f2adcde ("udpv6:
Add lockless sendmsg() support") added a lockless memory allocation path,
which could cause a memory leak:
setsockopt(IPV6_ADDRFORM) sendmsg()
+-----------------------+ +-------+
- do_ipv6_setsockopt(sk, ...) - udpv6_sendmsg(sk, ...)
- sockopt_lock_sock(sk) ^._ called via udpv6_prot
- lock_sock(sk) before WRITE_ONCE()
- WRITE_ONCE(sk->sk_prot, &tcp_prot)
- inet6_destroy_sock() - if (!corkreq)
- sockopt_release_sock(sk) - ip6_make_skb(sk, ...)
- release_sock(sk) ^._ lockless fast path for
the non-corking case
- __ip6_append_data(sk, ...)
- ipv6_local_rxpmtu(sk, ...)
- xchg(&np->rxpmtu, skb)
^._ rxpmtu is never freed.
- goto out_no_dst;
- lock_sock(sk)
For now, rxpmtu is only the case, but not to miss the future change
and a similar bug fixed in commit e27326009a3d ("net: ping6: Fix
memleak in ipv6_renew_options()."), let's set a new function to IPv6
sk->sk_destruct() and call inet6_cleanup_sock() there. Since the
conversion does not change sk->sk_destruct(), we can guarantee that
we can clean up IPv6 resources finally.
We can now remove all inet6_destroy_sock() calls from IPv6 protocol
specific ->destroy() functions, but such changes are invasive to
backport. So they can be posted as a follow-up later for net-next.
Fixes: 03485f2adcde ("udpv6: Add lockless sendmsg() support")
Signed-off-by: Kuniyuki Iwashima <kuniyu@amazon.com>
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
2022-10-06 21:53:47 +03:00
return 0 ;
}
2006-12-01 04:22:29 +03:00
static int udplite_rcv ( struct sk_buff * skb )
2006-11-27 22:10:57 +03:00
{
2008-10-29 11:41:45 +03:00
return __udp4_lib_rcv ( skb , & udplite_table , IPPROTO_UDPLITE ) ;
2006-11-27 22:10:57 +03:00
}
2018-11-08 14:19:21 +03:00
static int udplite_err ( struct sk_buff * skb , u32 info )
2006-11-27 22:10:57 +03:00
{
2018-11-08 14:19:21 +03:00
return __udp4_lib_err ( skb , info , & udplite_table ) ;
2006-11-27 22:10:57 +03:00
}
2009-09-14 16:21:47 +04:00
static const struct net_protocol udplite_protocol = {
2006-11-27 22:10:57 +03:00
. handler = udplite_rcv ,
. err_handler = udplite_err ,
. no_policy = 1 ,
} ;
struct proto udplite_prot = {
. name = " UDP-Lite " ,
. owner = THIS_MODULE ,
. close = udp_lib_close ,
. connect = ip4_datagram_connect ,
. disconnect = udp_disconnect ,
. ioctl = udp_ioctl ,
. init = udplite_sk_init ,
. destroy = udp_destroy_sock ,
. setsockopt = udp_setsockopt ,
. getsockopt = udp_getsockopt ,
. sendmsg = udp_sendmsg ,
. recvmsg = udp_recvmsg ,
. hash = udp_lib_hash ,
. unhash = udp_lib_unhash ,
2019-01-16 19:17:44 +03:00
. rehash = udp_v4_rehash ,
2008-03-23 02:51:21 +03:00
. get_port = udp_v4_get_port ,
2022-06-09 09:34:08 +03:00
2016-11-15 18:37:53 +03:00
. memory_allocated = & udp_memory_allocated ,
2022-06-09 09:34:08 +03:00
. per_cpu_fw_alloc = & udp_memory_per_cpu_fw_alloc ,
2016-11-15 18:37:53 +03:00
. sysctl_mem = sysctl_udp_mem ,
2023-05-23 19:33:05 +03:00
. sysctl_wmem_offset = offsetof ( struct net , ipv4 . sysctl_udp_wmem_min ) ,
. sysctl_rmem_offset = offsetof ( struct net , ipv4 . sysctl_udp_rmem_min ) ,
2006-11-27 22:10:57 +03:00
. obj_size = sizeof ( struct udp_sock ) ,
2008-10-29 11:41:45 +03:00
. h . udp_table = & udplite_table ,
2006-11-27 22:10:57 +03:00
} ;
2010-07-10 01:22:10 +04:00
EXPORT_SYMBOL ( udplite_prot ) ;
2006-11-27 22:10:57 +03:00
static struct inet_protosw udplite4_protosw = {
. type = SOCK_DGRAM ,
. protocol = IPPROTO_UDPLITE ,
. prot = & udplite_prot ,
. ops = & inet_dgram_ops ,
. flags = INET_PROTOSW_PERMANENT ,
} ;
# ifdef CONFIG_PROC_FS
static struct udp_seq_afinfo udplite4_seq_afinfo = {
. family = AF_INET ,
2008-10-29 11:41:45 +03:00
. udp_table = & udplite_table ,
2006-11-27 22:10:57 +03:00
} ;
2008-03-25 00:56:34 +03:00
2010-01-17 06:35:32 +03:00
static int __net_init udplite4_proc_init_net ( struct net * net )
2008-03-25 00:56:57 +03:00
{
2018-04-10 20:42:55 +03:00
if ( ! proc_create_net_data ( " udplite " , 0444 , net - > proc_net , & udp_seq_ops ,
sizeof ( struct udp_iter_state ) , & udplite4_seq_afinfo ) )
2018-04-10 22:31:50 +03:00
return - ENOMEM ;
return 0 ;
2008-03-25 00:56:57 +03:00
}
2010-01-17 06:35:32 +03:00
static void __net_exit udplite4_proc_exit_net ( struct net * net )
2008-03-25 00:56:57 +03:00
{
2018-04-10 22:31:50 +03:00
remove_proc_entry ( " udplite " , net - > proc_net ) ;
2008-03-25 00:56:57 +03:00
}
static struct pernet_operations udplite4_net_ops = {
. init = udplite4_proc_init_net ,
. exit = udplite4_proc_exit_net ,
} ;
2008-03-25 00:56:34 +03:00
static __init int udplite4_proc_init ( void )
{
2008-03-25 00:56:57 +03:00
return register_pernet_subsys ( & udplite4_net_ops ) ;
2008-03-25 00:56:34 +03:00
}
# else
static inline int udplite4_proc_init ( void )
{
return 0 ;
}
2006-11-27 22:10:57 +03:00
# endif
void __init udplite4_register ( void )
{
2009-10-07 04:37:59 +04:00
udp_table_init ( & udplite_table , " UDP-Lite " ) ;
2006-11-27 22:10:57 +03:00
if ( proto_register ( & udplite_prot , 1 ) )
goto out_register_err ;
if ( inet_add_protocol ( & udplite_protocol , IPPROTO_UDPLITE ) < 0 )
goto out_unregister_proto ;
inet_register_protosw ( & udplite4_protosw ) ;
2008-03-25 00:56:34 +03:00
if ( udplite4_proc_init ( ) )
2012-03-11 22:36:11 +04:00
pr_err ( " %s: Cannot register /proc! \n " , __func__ ) ;
2006-11-27 22:10:57 +03:00
return ;
out_unregister_proto :
proto_unregister ( & udplite_prot ) ;
out_register_err :
2012-03-11 22:36:11 +04:00
pr_crit ( " %s: Cannot add UDP-Lite protocol \n " , __func__ ) ;
2006-11-27 22:10:57 +03:00
}