Skip to content
This repository was archived by the owner on Oct 31, 2024. It is now read-only.

Commit cdf4bbb

Browse files
dhowellsgregkh
authored andcommittedOct 10, 2024
rxrpc: Fix a race between socket set up and I/O thread creation
commit bc21246 upstream. In rxrpc_open_socket(), it sets up the socket and then sets up the I/O thread that will handle it. This is a problem, however, as there's a gap between the two phases in which a packet may come into rxrpc_encap_rcv() from the UDP packet but we oops when trying to wake the not-yet created I/O thread. As a quick fix, just make rxrpc_encap_rcv() discard the packet if there's no I/O thread yet. A better, but more intrusive fix would perhaps be to rearrange things such that the socket creation is done by the I/O thread. Fixes: a275da6 ("rxrpc: Create a per-local endpoint receive queue and I/O thread") Signed-off-by: David Howells <dhowells@redhat.com> cc: yuxuanzhe@outlook.com cc: Marc Dionne <marc.dionne@auristor.com> cc: Simon Horman <horms@kernel.org> cc: linux-afs@lists.infradead.org Reviewed-by: Eric Dumazet <edumazet@google.com> Link: https://patch.msgid.link/20241001132702.3122709-2-dhowells@redhat.com Signed-off-by: Jakub Kicinski <kuba@kernel.org> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
1 parent b538fef commit cdf4bbb

File tree

3 files changed

+10
-4
lines changed

3 files changed

+10
-4
lines changed
 

‎net/rxrpc/ar-internal.h

+1-1
Original file line numberDiff line numberDiff line change
@@ -1066,7 +1066,7 @@ bool rxrpc_direct_abort(struct sk_buff *skb, enum rxrpc_abort_reason why,
10661066
int rxrpc_io_thread(void *data);
10671067
static inline void rxrpc_wake_up_io_thread(struct rxrpc_local *local)
10681068
{
1069-
wake_up_process(local->io_thread);
1069+
wake_up_process(READ_ONCE(local->io_thread));
10701070
}
10711071

10721072
static inline bool rxrpc_protocol_error(struct sk_buff *skb, enum rxrpc_abort_reason why)

‎net/rxrpc/io_thread.c

+8-2
Original file line numberDiff line numberDiff line change
@@ -27,11 +27,17 @@ int rxrpc_encap_rcv(struct sock *udp_sk, struct sk_buff *skb)
2727
{
2828
struct sk_buff_head *rx_queue;
2929
struct rxrpc_local *local = rcu_dereference_sk_user_data(udp_sk);
30+
struct task_struct *io_thread;
3031

3132
if (unlikely(!local)) {
3233
kfree_skb(skb);
3334
return 0;
3435
}
36+
io_thread = READ_ONCE(local->io_thread);
37+
if (!io_thread) {
38+
kfree_skb(skb);
39+
return 0;
40+
}
3541
if (skb->tstamp == 0)
3642
skb->tstamp = ktime_get_real();
3743

@@ -47,7 +53,7 @@ int rxrpc_encap_rcv(struct sock *udp_sk, struct sk_buff *skb)
4753
#endif
4854

4955
skb_queue_tail(rx_queue, skb);
50-
rxrpc_wake_up_io_thread(local);
56+
wake_up_process(io_thread);
5157
return 0;
5258
}
5359

@@ -554,7 +560,7 @@ int rxrpc_io_thread(void *data)
554560
__set_current_state(TASK_RUNNING);
555561
rxrpc_see_local(local, rxrpc_local_stop);
556562
rxrpc_destroy_local(local);
557-
local->io_thread = NULL;
563+
WRITE_ONCE(local->io_thread, NULL);
558564
rxrpc_see_local(local, rxrpc_local_stopped);
559565
return 0;
560566
}

‎net/rxrpc/local_object.c

+1-1
Original file line numberDiff line numberDiff line change
@@ -232,7 +232,7 @@ static int rxrpc_open_socket(struct rxrpc_local *local, struct net *net)
232232
}
233233

234234
wait_for_completion(&local->io_thread_ready);
235-
local->io_thread = io_thread;
235+
WRITE_ONCE(local->io_thread, io_thread);
236236
_leave(" = 0");
237237
return 0;
238238

0 commit comments

Comments
 (0)
This repository has been archived.