2011-10-25 19:26:31 -07:00
|
|
|
|
2014-09-15 19:37:25 -07:00
|
|
|
|
2011-10-25 19:26:31 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-07-21 10:43:54 +02:00
|
|
|
|
2011-10-25 19:26:31 -07:00
|
|
|
|
2015-08-26 11:31:48 -07:00
|
|
|
|
2011-10-25 19:26:31 -07:00
|
|
|
|
2013-10-03 18:16:47 -07:00
|
|
|
|
2017-11-10 12:09:43 -08:00
|
|
|
|
2017-11-10 12:09:41 -08:00
|
|
|
|
2011-10-25 19:26:31 -07:00
|
|
|
|
2012-08-23 12:40:54 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2011-10-25 19:26:31 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-10-22 10:42:46 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2011-10-25 19:26:31 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-10-22 10:42:46 -07:00
|
|
|
|
2014-02-14 15:10:46 -08:00
|
|
|
|
2011-10-25 19:26:31 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-10-04 00:14:23 -07:00
|
|
|
|
2012-08-23 12:40:54 -07:00
|
|
|
|
2013-04-15 13:23:03 -07:00
|
|
|
|
2011-10-25 19:26:31 -07:00
|
|
|
|
2012-02-22 19:58:59 -08:00
|
|
|
|
2016-02-26 10:45:39 +01:00
|
|
|
|
|
|
|
|
|
2011-10-25 19:26:31 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-10-04 00:14:23 -07:00
|
|
|
|
2011-10-25 19:26:31 -07:00
|
|
|
|
|
|
|
|
|
2012-08-23 12:40:54 -07:00
|
|
|
|
2011-10-25 19:26:31 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-02-22 19:58:59 -08:00
|
|
|
|
|
|
|
|
|
2015-03-11 23:06:44 -05:00
|
|
|
|
2013-12-13 15:22:18 +01:00
|
|
|
|
|
|
|
|
|
2016-02-26 10:45:39 +01:00
|
|
|
|
|
|
|
|
|
2017-11-10 12:09:42 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2011-10-25 19:26:31 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-09-15 19:20:31 -07:00
|
|
|
|
|
|
|
|
|
2015-08-26 11:31:48 -07:00
|
|
|
|
|
|
|
|
|
openvswitch: fix skb_panic due to the incorrect actions attrlen
For sw_flow_actions, the actions_len only represents the kernel part's
size, and when we dump the actions to the userspace, we will do the
convertions, so it's true size may become bigger than the actions_len.
But unfortunately, for OVS_PACKET_ATTR_ACTIONS, we use the actions_len
to alloc the skbuff, so the user_skb's size may become insufficient and
oops will happen like this:
skbuff: skb_over_panic: text:ffffffff8148fabf len:1749 put:157 head:
ffff881300f39000 data:ffff881300f39000 tail:0x6d5 end:0x6c0 dev:<NULL>
------------[ cut here ]------------
kernel BUG at net/core/skbuff.c:129!
[...]
Call Trace:
<IRQ>
[<ffffffff8148be82>] skb_put+0x43/0x44
[<ffffffff8148fabf>] skb_zerocopy+0x6c/0x1f4
[<ffffffffa0290d36>] queue_userspace_packet+0x3a3/0x448 [openvswitch]
[<ffffffffa0292023>] ovs_dp_upcall+0x30/0x5c [openvswitch]
[<ffffffffa028d435>] output_userspace+0x132/0x158 [openvswitch]
[<ffffffffa01e6890>] ? ip6_rcv_finish+0x74/0x77 [ipv6]
[<ffffffffa028e277>] do_execute_actions+0xcc1/0xdc8 [openvswitch]
[<ffffffffa028e3f2>] ovs_execute_actions+0x74/0x106 [openvswitch]
[<ffffffffa0292130>] ovs_dp_process_packet+0xe1/0xfd [openvswitch]
[<ffffffffa0292b77>] ? key_extract+0x63c/0x8d5 [openvswitch]
[<ffffffffa029848b>] ovs_vport_receive+0xa1/0xc3 [openvswitch]
[...]
Also we can find that the actions_len is much little than the orig_len:
crash> struct sw_flow_actions 0xffff8812f539d000
struct sw_flow_actions {
rcu = {
next = 0xffff8812f5398800,
func = 0xffffe3b00035db32
},
orig_len = 1384,
actions_len = 592,
actions = 0xffff8812f539d01c
}
So as a quick fix, use the orig_len instead of the actions_len to alloc
the user_skb.
Last, this oops happened on our system running a relative old kernel, but
the same risk still exists on the mainline, since we use the wrong
actions_len from the beginning.
Fixes: ccea74457bbd ("openvswitch: include datapath actions with sampled-packet upcall to userspace")
Cc: Neil McKee <neil.mckee@inmon.com>
Signed-off-by: Liping Zhang <zlpnobody@gmail.com>
Acked-by: Pravin B Shelar <pshelar@ovn.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
2017-08-16 13:30:07 +08:00
|
|
|
|
2017-07-03 21:46:43 +10:00
|
|
|
|
2011-10-25 19:26:31 -07:00
|
|
|
|
|
|
|
|
|
2014-09-15 19:20:31 -07:00
|
|
|
|
2015-08-26 11:31:48 -07:00
|
|
|
|
openvswitch: fix skb_panic due to the incorrect actions attrlen
For sw_flow_actions, the actions_len only represents the kernel part's
size, and when we dump the actions to the userspace, we will do the
convertions, so it's true size may become bigger than the actions_len.
But unfortunately, for OVS_PACKET_ATTR_ACTIONS, we use the actions_len
to alloc the skbuff, so the user_skb's size may become insufficient and
oops will happen like this:
skbuff: skb_over_panic: text:ffffffff8148fabf len:1749 put:157 head:
ffff881300f39000 data:ffff881300f39000 tail:0x6d5 end:0x6c0 dev:<NULL>
------------[ cut here ]------------
kernel BUG at net/core/skbuff.c:129!
[...]
Call Trace:
<IRQ>
[<ffffffff8148be82>] skb_put+0x43/0x44
[<ffffffff8148fabf>] skb_zerocopy+0x6c/0x1f4
[<ffffffffa0290d36>] queue_userspace_packet+0x3a3/0x448 [openvswitch]
[<ffffffffa0292023>] ovs_dp_upcall+0x30/0x5c [openvswitch]
[<ffffffffa028d435>] output_userspace+0x132/0x158 [openvswitch]
[<ffffffffa01e6890>] ? ip6_rcv_finish+0x74/0x77 [ipv6]
[<ffffffffa028e277>] do_execute_actions+0xcc1/0xdc8 [openvswitch]
[<ffffffffa028e3f2>] ovs_execute_actions+0x74/0x106 [openvswitch]
[<ffffffffa0292130>] ovs_dp_process_packet+0xe1/0xfd [openvswitch]
[<ffffffffa0292b77>] ? key_extract+0x63c/0x8d5 [openvswitch]
[<ffffffffa029848b>] ovs_vport_receive+0xa1/0xc3 [openvswitch]
[...]
Also we can find that the actions_len is much little than the orig_len:
crash> struct sw_flow_actions 0xffff8812f539d000
struct sw_flow_actions {
rcu = {
next = 0xffff8812f5398800,
func = 0xffffe3b00035db32
},
orig_len = 1384,
actions_len = 592,
actions = 0xffff8812f539d01c
}
So as a quick fix, use the orig_len instead of the actions_len to alloc
the user_skb.
Last, this oops happened on our system running a relative old kernel, but
the same risk still exists on the mainline, since we use the wrong
actions_len from the beginning.
Fixes: ccea74457bbd ("openvswitch: include datapath actions with sampled-packet upcall to userspace")
Cc: Neil McKee <neil.mckee@inmon.com>
Signed-off-by: Liping Zhang <zlpnobody@gmail.com>
Acked-by: Pravin B Shelar <pshelar@ovn.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
2017-08-16 13:30:07 +08:00
|
|
|
|
2016-06-10 11:49:33 -07:00
|
|
|
|
2011-10-25 19:26:31 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-02-15 17:29:22 -08:00
|
|
|
|
2011-10-25 19:26:31 -07:00
|
|
|
|
2014-11-06 06:57:27 -08:00
|
|
|
|
|
|
|
|
|
2011-10-25 19:26:31 -07:00
|
|
|
|
2014-11-06 06:51:24 -08:00
|
|
|
|
2015-08-26 11:31:48 -07:00
|
|
|
|
2011-10-25 19:26:31 -07:00
|
|
|
|
|
|
|
|
|
2015-08-30 18:09:38 -07:00
|
|
|
|
2011-10-25 19:26:31 -07:00
|
|
|
|
2015-05-26 20:59:43 -07:00
|
|
|
|
|
|
|
|
|
2012-09-07 20:12:54 +00:00
|
|
|
|
2014-11-06 06:57:27 -08:00
|
|
|
|
2015-08-26 11:31:48 -07:00
|
|
|
|
2011-10-25 19:26:31 -07:00
|
|
|
|
|
|
|
|
|
2013-04-15 13:23:03 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-08-26 11:31:52 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-04-15 13:23:03 -07:00
|
|
|
|
|
|
|
|
|
netns: make struct pernet_operations::id unsigned int
Make struct pernet_operations::id unsigned.
There are 2 reasons to do so:
1)
This field is really an index into an zero based array and
thus is unsigned entity. Using negative value is out-of-bound
access by definition.
2)
On x86_64 unsigned 32-bit data which are mixed with pointers
via array indexing or offsets added or subtracted to pointers
are preffered to signed 32-bit data.
"int" being used as an array index needs to be sign-extended
to 64-bit before being used.
void f(long *p, int i)
{
g(p[i]);
}
roughly translates to
movsx rsi, esi
mov rdi, [rsi+...]
call g
MOVSX is 3 byte instruction which isn't necessary if the variable is
unsigned because x86_64 is zero extending by default.
Now, there is net_generic() function which, you guessed it right, uses
"int" as an array index:
static inline void *net_generic(const struct net *net, int id)
{
...
ptr = ng->ptr[id - 1];
...
}
And this function is used a lot, so those sign extensions add up.
Patch snipes ~1730 bytes on allyesconfig kernel (without all junk
messing with code generation):
add/remove: 0/0 grow/shrink: 70/598 up/down: 396/-2126 (-1730)
Unfortunately some functions actually grow bigger.
This is a semmingly random artefact of code generation with register
allocator being used differently. gcc decides that some variable
needs to live in new r8+ registers and every access now requires REX
prefix. Or it is shifted into r12, so [r12+0] addressing mode has to be
used which is longer than [r8]
However, overall balance is in negative direction:
add/remove: 0/0 grow/shrink: 70/598 up/down: 396/-2126 (-1730)
function old new delta
nfsd4_lock 3886 3959 +73
tipc_link_build_proto_msg 1096 1140 +44
mac80211_hwsim_new_radio 2776 2808 +32
tipc_mon_rcv 1032 1058 +26
svcauth_gss_legacy_init 1413 1429 +16
tipc_bcbase_select_primary 379 392 +13
nfsd4_exchange_id 1247 1260 +13
nfsd4_setclientid_confirm 782 793 +11
...
put_client_renew_locked 494 480 -14
ip_set_sockfn_get 730 716 -14
geneve_sock_add 829 813 -16
nfsd4_sequence_done 721 703 -18
nlmclnt_lookup_host 708 686 -22
nfsd4_lockt 1085 1063 -22
nfs_get_client 1077 1050 -27
tcf_bpf_init 1106 1076 -30
nfsd4_encode_fattr 5997 5930 -67
Total: Before=154856051, After=154854321, chg -0.00%
Signed-off-by: Alexey Dobriyan <adobriyan@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2016-11-17 04:58:21 +03:00
|
|
|
|
2013-04-15 13:23:03 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-07-30 02:31:08 +02:00
|
|
|
|
2013-04-15 13:23:03 -07:00
|
|
|
|
|
|
|
|
|
2013-12-03 10:58:53 -08:00
|
|
|
|
|
|
|
|
|
2013-04-15 13:23:03 -07:00
|
|
|
|
2014-11-06 06:58:52 -08:00
|
|
|
|
2012-02-22 19:58:59 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-04-15 13:23:03 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-11-10 12:09:41 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2011-10-25 19:26:31 -07:00
|
|
|
|
2013-11-19 15:19:38 +01:00
|
|
|
|
2011-10-25 19:26:31 -07:00
|
|
|
|
2014-09-15 19:28:44 -07:00
|
|
|
|
2011-10-25 19:26:31 -07:00
|
|
|
|
|
|
|
|
|
2016-06-10 11:49:33 -07:00
|
|
|
|
|
|
|
|
|
2011-10-25 19:26:31 -07:00
|
|
|
|
2014-09-15 19:37:25 -07:00
|
|
|
|
2017-11-02 17:04:37 -02:00
|
|
|
|
|
|
|
|
|
2011-10-25 19:26:31 -07:00
|
|
|
|
2014-09-15 19:15:28 -07:00
|
|
|
|
2014-11-06 06:58:52 -08:00
|
|
|
|
2014-09-15 19:37:25 -07:00
|
|
|
|
2013-04-15 13:23:03 -07:00
|
|
|
|
2013-08-07 20:01:00 -07:00
|
|
|
|
2014-09-15 19:37:25 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-08-26 11:31:45 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-11-06 07:03:05 -08:00
|
|
|
|
2014-02-03 17:06:46 -08:00
|
|
|
|
2014-11-06 07:03:05 -08:00
|
|
|
|
|
|
|
|
|
2014-02-03 17:06:46 -08:00
|
|
|
|
2011-10-25 19:26:31 -07:00
|
|
|
|