[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-Id: <20230728153537.1865379-1-pctammela@mojatatu.com>
Date: Fri, 28 Jul 2023 12:35:32 -0300
From: Pedro Tammela <pctammela@...atatu.com>
To: netdev@...r.kernel.org
Cc: davem@...emloft.net,
edumazet@...gle.com,
kuba@...nel.org,
pabeni@...hat.com,
jhs@...atatu.com,
xiyou.wangcong@...il.com,
jiri@...nulli.us,
Pedro Tammela <pctammela@...atatu.com>
Subject: [PATCH net-next v2 0/5] net/sched: improve class lifetime handling
Valis says[0]:
============
Three classifiers (cls_fw, cls_u32 and cls_route) always copy
tcf_result struct into the new instance of the filter on update.
This causes a problem when updating a filter bound to a class,
as tcf_unbind_filter() is always called on the old instance in the
success path, decreasing filter_cnt of the still referenced class
and allowing it to be deleted, leading to a use-after-free.
============
Turns out these could have been spotted easily with proper warnings.
Improve the current class lifetime with wrappers that check for
overflow/underflow.
While at it add an extack for when a class in use is deleted.
[0] https://lore.kernel.org/all/20230721174856.3045-1-sec@valis.email/
v1 -> v2:
- Add ack tag from Jamal
- Move definitions to sch_generic.h as suggested by Cong
Pedro Tammela (5):
net/sched: wrap open coded Qdics class filter counter
net/sched: sch_drr: warn about class in use while deleting
net/sched: sch_hfsc: warn about class in use while deleting
net/sched: sch_htb: warn about class in use while deleting
net/sched: sch_qfq: warn about class in use while deleting
include/net/sch_generic.h | 26 ++++++++++++++++++++++++++
net/sched/sch_drr.c | 11 ++++++-----
net/sched/sch_hfsc.c | 10 ++++++----
net/sched/sch_htb.c | 10 +++++-----
net/sched/sch_qfq.c | 12 ++++++------
5 files changed, 49 insertions(+), 20 deletions(-)
--
2.39.2
Powered by blists - more mailing lists