Skip to content

Commit 36f41f8

Browse files
Eric Dumazetdavem330
Eric Dumazet
authored andcommitted
af_key: do not use GFP_KERNEL in atomic contexts
pfkey_broadcast() might be called from non process contexts, we can not use GFP_KERNEL in these cases [1]. This patch partially reverts commit ba51b6b ("net: Fix RCU splat in af_key"), only keeping the GFP_ATOMIC forcing under rcu_read_lock() section. [1] : syzkaller reported : in_atomic(): 1, irqs_disabled(): 0, pid: 2932, name: syzkaller183439 3 locks held by syzkaller183439/2932: #0: (&net->xfrm.xfrm_cfg_mutex){+.+.+.}, at: [<ffffffff83b43888>] pfkey_sendmsg+0x4c8/0x9f0 net/key/af_key.c:3649 #1: (&pfk->dump_lock){+.+.+.}, at: [<ffffffff83b467f6>] pfkey_do_dump+0x76/0x3f0 net/key/af_key.c:293 #2: (&(&net->xfrm.xfrm_policy_lock)->rlock){+...+.}, at: [<ffffffff83957632>] spin_lock_bh include/linux/spinlock.h:304 [inline] #2: (&(&net->xfrm.xfrm_policy_lock)->rlock){+...+.}, at: [<ffffffff83957632>] xfrm_policy_walk+0x192/0xa30 net/xfrm/xfrm_policy.c:1028 CPU: 0 PID: 2932 Comm: syzkaller183439 Not tainted 4.13.0-rc4+ #24 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011 Call Trace: __dump_stack lib/dump_stack.c:16 [inline] dump_stack+0x194/0x257 lib/dump_stack.c:52 ___might_sleep+0x2b2/0x470 kernel/sched/core.c:5994 __might_sleep+0x95/0x190 kernel/sched/core.c:5947 slab_pre_alloc_hook mm/slab.h:416 [inline] slab_alloc mm/slab.c:3383 [inline] kmem_cache_alloc+0x24b/0x6e0 mm/slab.c:3559 skb_clone+0x1a0/0x400 net/core/skbuff.c:1037 pfkey_broadcast_one+0x4b2/0x6f0 net/key/af_key.c:207 pfkey_broadcast+0x4ba/0x770 net/key/af_key.c:281 dump_sp+0x3d6/0x500 net/key/af_key.c:2685 xfrm_policy_walk+0x2f1/0xa30 net/xfrm/xfrm_policy.c:1042 pfkey_dump_sp+0x42/0x50 net/key/af_key.c:2695 pfkey_do_dump+0xaa/0x3f0 net/key/af_key.c:299 pfkey_spddump+0x1a0/0x210 net/key/af_key.c:2722 pfkey_process+0x606/0x710 net/key/af_key.c:2814 pfkey_sendmsg+0x4d6/0x9f0 net/key/af_key.c:3650 sock_sendmsg_nosec net/socket.c:633 [inline] sock_sendmsg+0xca/0x110 net/socket.c:643 ___sys_sendmsg+0x755/0x890 net/socket.c:2035 __sys_sendmsg+0xe5/0x210 net/socket.c:2069 SYSC_sendmsg net/socket.c:2080 [inline] SyS_sendmsg+0x2d/0x50 net/socket.c:2076 entry_SYSCALL_64_fastpath+0x1f/0xbe RIP: 0033:0x445d79 RSP: 002b:00007f32447c1dc8 EFLAGS: 00000202 ORIG_RAX: 000000000000002e RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 0000000000445d79 RDX: 0000000000000000 RSI: 000000002023dfc8 RDI: 0000000000000008 RBP: 0000000000000086 R08: 00007f32447c2700 R09: 00007f32447c2700 R10: 00007f32447c2700 R11: 0000000000000202 R12: 0000000000000000 R13: 00007ffe33edec4f R14: 00007f32447c29c0 R15: 0000000000000000 Fixes: ba51b6b ("net: Fix RCU splat in af_key") Signed-off-by: Eric Dumazet <[email protected]> Reported-by: Dmitry Vyukov <[email protected]> Cc: David Ahern <[email protected]> Acked-by: David Ahern <[email protected]> Signed-off-by: David S. Miller <[email protected]>
1 parent 539a06b commit 36f41f8

File tree

1 file changed

+26
-22
lines changed

1 file changed

+26
-22
lines changed

net/key/af_key.c

Lines changed: 26 additions & 22 deletions
Original file line numberDiff line numberDiff line change
@@ -228,7 +228,7 @@ static int pfkey_broadcast_one(struct sk_buff *skb, struct sk_buff **skb2,
228228
#define BROADCAST_ONE 1
229229
#define BROADCAST_REGISTERED 2
230230
#define BROADCAST_PROMISC_ONLY 4
231-
static int pfkey_broadcast(struct sk_buff *skb,
231+
static int pfkey_broadcast(struct sk_buff *skb, gfp_t allocation,
232232
int broadcast_flags, struct sock *one_sk,
233233
struct net *net)
234234
{
@@ -278,7 +278,7 @@ static int pfkey_broadcast(struct sk_buff *skb,
278278
rcu_read_unlock();
279279

280280
if (one_sk != NULL)
281-
err = pfkey_broadcast_one(skb, &skb2, GFP_KERNEL, one_sk);
281+
err = pfkey_broadcast_one(skb, &skb2, allocation, one_sk);
282282

283283
kfree_skb(skb2);
284284
kfree_skb(skb);
@@ -311,7 +311,7 @@ static int pfkey_do_dump(struct pfkey_sock *pfk)
311311
hdr = (struct sadb_msg *) pfk->dump.skb->data;
312312
hdr->sadb_msg_seq = 0;
313313
hdr->sadb_msg_errno = rc;
314-
pfkey_broadcast(pfk->dump.skb, BROADCAST_ONE,
314+
pfkey_broadcast(pfk->dump.skb, GFP_ATOMIC, BROADCAST_ONE,
315315
&pfk->sk, sock_net(&pfk->sk));
316316
pfk->dump.skb = NULL;
317317
}
@@ -355,7 +355,7 @@ static int pfkey_error(const struct sadb_msg *orig, int err, struct sock *sk)
355355
hdr->sadb_msg_len = (sizeof(struct sadb_msg) /
356356
sizeof(uint64_t));
357357

358-
pfkey_broadcast(skb, BROADCAST_ONE, sk, sock_net(sk));
358+
pfkey_broadcast(skb, GFP_KERNEL, BROADCAST_ONE, sk, sock_net(sk));
359359

360360
return 0;
361361
}
@@ -1389,7 +1389,7 @@ static int pfkey_getspi(struct sock *sk, struct sk_buff *skb, const struct sadb_
13891389

13901390
xfrm_state_put(x);
13911391

1392-
pfkey_broadcast(resp_skb, BROADCAST_ONE, sk, net);
1392+
pfkey_broadcast(resp_skb, GFP_KERNEL, BROADCAST_ONE, sk, net);
13931393

13941394
return 0;
13951395
}
@@ -1476,7 +1476,7 @@ static int key_notify_sa(struct xfrm_state *x, const struct km_event *c)
14761476
hdr->sadb_msg_seq = c->seq;
14771477
hdr->sadb_msg_pid = c->portid;
14781478

1479-
pfkey_broadcast(skb, BROADCAST_ALL, NULL, xs_net(x));
1479+
pfkey_broadcast(skb, GFP_ATOMIC, BROADCAST_ALL, NULL, xs_net(x));
14801480

14811481
return 0;
14821482
}
@@ -1589,7 +1589,7 @@ static int pfkey_get(struct sock *sk, struct sk_buff *skb, const struct sadb_msg
15891589
out_hdr->sadb_msg_reserved = 0;
15901590
out_hdr->sadb_msg_seq = hdr->sadb_msg_seq;
15911591
out_hdr->sadb_msg_pid = hdr->sadb_msg_pid;
1592-
pfkey_broadcast(out_skb, BROADCAST_ONE, sk, sock_net(sk));
1592+
pfkey_broadcast(out_skb, GFP_ATOMIC, BROADCAST_ONE, sk, sock_net(sk));
15931593

15941594
return 0;
15951595
}
@@ -1694,8 +1694,8 @@ static int pfkey_register(struct sock *sk, struct sk_buff *skb, const struct sad
16941694
return -ENOBUFS;
16951695
}
16961696

1697-
pfkey_broadcast(supp_skb, BROADCAST_REGISTERED, sk, sock_net(sk));
1698-
1697+
pfkey_broadcast(supp_skb, GFP_KERNEL, BROADCAST_REGISTERED, sk,
1698+
sock_net(sk));
16991699
return 0;
17001700
}
17011701

@@ -1712,7 +1712,8 @@ static int unicast_flush_resp(struct sock *sk, const struct sadb_msg *ihdr)
17121712
hdr->sadb_msg_errno = (uint8_t) 0;
17131713
hdr->sadb_msg_len = (sizeof(struct sadb_msg) / sizeof(uint64_t));
17141714

1715-
return pfkey_broadcast(skb, BROADCAST_ONE, sk, sock_net(sk));
1715+
return pfkey_broadcast(skb, GFP_ATOMIC, BROADCAST_ONE, sk,
1716+
sock_net(sk));
17161717
}
17171718

17181719
static int key_notify_sa_flush(const struct km_event *c)
@@ -1733,7 +1734,7 @@ static int key_notify_sa_flush(const struct km_event *c)
17331734
hdr->sadb_msg_len = (sizeof(struct sadb_msg) / sizeof(uint64_t));
17341735
hdr->sadb_msg_reserved = 0;
17351736

1736-
pfkey_broadcast(skb, BROADCAST_ALL, NULL, c->net);
1737+
pfkey_broadcast(skb, GFP_ATOMIC, BROADCAST_ALL, NULL, c->net);
17371738

17381739
return 0;
17391740
}
@@ -1790,7 +1791,7 @@ static int dump_sa(struct xfrm_state *x, int count, void *ptr)
17901791
out_hdr->sadb_msg_pid = pfk->dump.msg_portid;
17911792

17921793
if (pfk->dump.skb)
1793-
pfkey_broadcast(pfk->dump.skb, BROADCAST_ONE,
1794+
pfkey_broadcast(pfk->dump.skb, GFP_ATOMIC, BROADCAST_ONE,
17941795
&pfk->sk, sock_net(&pfk->sk));
17951796
pfk->dump.skb = out_skb;
17961797

@@ -1878,7 +1879,7 @@ static int pfkey_promisc(struct sock *sk, struct sk_buff *skb, const struct sadb
18781879
new_hdr->sadb_msg_errno = 0;
18791880
}
18801881

1881-
pfkey_broadcast(skb, BROADCAST_ALL, NULL, sock_net(sk));
1882+
pfkey_broadcast(skb, GFP_KERNEL, BROADCAST_ALL, NULL, sock_net(sk));
18821883
return 0;
18831884
}
18841885

@@ -2206,7 +2207,7 @@ static int key_notify_policy(struct xfrm_policy *xp, int dir, const struct km_ev
22062207
out_hdr->sadb_msg_errno = 0;
22072208
out_hdr->sadb_msg_seq = c->seq;
22082209
out_hdr->sadb_msg_pid = c->portid;
2209-
pfkey_broadcast(out_skb, BROADCAST_ALL, NULL, xp_net(xp));
2210+
pfkey_broadcast(out_skb, GFP_ATOMIC, BROADCAST_ALL, NULL, xp_net(xp));
22102211
return 0;
22112212

22122213
}
@@ -2426,7 +2427,7 @@ static int key_pol_get_resp(struct sock *sk, struct xfrm_policy *xp, const struc
24262427
out_hdr->sadb_msg_errno = 0;
24272428
out_hdr->sadb_msg_seq = hdr->sadb_msg_seq;
24282429
out_hdr->sadb_msg_pid = hdr->sadb_msg_pid;
2429-
pfkey_broadcast(out_skb, BROADCAST_ONE, sk, xp_net(xp));
2430+
pfkey_broadcast(out_skb, GFP_ATOMIC, BROADCAST_ONE, sk, xp_net(xp));
24302431
err = 0;
24312432

24322433
out:
@@ -2682,7 +2683,7 @@ static int dump_sp(struct xfrm_policy *xp, int dir, int count, void *ptr)
26822683
out_hdr->sadb_msg_pid = pfk->dump.msg_portid;
26832684

26842685
if (pfk->dump.skb)
2685-
pfkey_broadcast(pfk->dump.skb, BROADCAST_ONE,
2686+
pfkey_broadcast(pfk->dump.skb, GFP_ATOMIC, BROADCAST_ONE,
26862687
&pfk->sk, sock_net(&pfk->sk));
26872688
pfk->dump.skb = out_skb;
26882689

@@ -2739,7 +2740,7 @@ static int key_notify_policy_flush(const struct km_event *c)
27392740
hdr->sadb_msg_satype = SADB_SATYPE_UNSPEC;
27402741
hdr->sadb_msg_len = (sizeof(struct sadb_msg) / sizeof(uint64_t));
27412742
hdr->sadb_msg_reserved = 0;
2742-
pfkey_broadcast(skb_out, BROADCAST_ALL, NULL, c->net);
2743+
pfkey_broadcast(skb_out, GFP_ATOMIC, BROADCAST_ALL, NULL, c->net);
27432744
return 0;
27442745

27452746
}
@@ -2803,7 +2804,7 @@ static int pfkey_process(struct sock *sk, struct sk_buff *skb, const struct sadb
28032804
void *ext_hdrs[SADB_EXT_MAX];
28042805
int err;
28052806

2806-
pfkey_broadcast(skb_clone(skb, GFP_KERNEL),
2807+
pfkey_broadcast(skb_clone(skb, GFP_KERNEL), GFP_KERNEL,
28072808
BROADCAST_PROMISC_ONLY, NULL, sock_net(sk));
28082809

28092810
memset(ext_hdrs, 0, sizeof(ext_hdrs));
@@ -3024,7 +3025,8 @@ static int key_notify_sa_expire(struct xfrm_state *x, const struct km_event *c)
30243025
out_hdr->sadb_msg_seq = 0;
30253026
out_hdr->sadb_msg_pid = 0;
30263027

3027-
pfkey_broadcast(out_skb, BROADCAST_REGISTERED, NULL, xs_net(x));
3028+
pfkey_broadcast(out_skb, GFP_ATOMIC, BROADCAST_REGISTERED, NULL,
3029+
xs_net(x));
30283030
return 0;
30293031
}
30303032

@@ -3212,7 +3214,8 @@ static int pfkey_send_acquire(struct xfrm_state *x, struct xfrm_tmpl *t, struct
32123214
xfrm_ctx->ctx_len);
32133215
}
32143216

3215-
return pfkey_broadcast(skb, BROADCAST_REGISTERED, NULL, xs_net(x));
3217+
return pfkey_broadcast(skb, GFP_ATOMIC, BROADCAST_REGISTERED, NULL,
3218+
xs_net(x));
32163219
}
32173220

32183221
static struct xfrm_policy *pfkey_compile_policy(struct sock *sk, int opt,
@@ -3408,7 +3411,8 @@ static int pfkey_send_new_mapping(struct xfrm_state *x, xfrm_address_t *ipaddr,
34083411
n_port->sadb_x_nat_t_port_port = sport;
34093412
n_port->sadb_x_nat_t_port_reserved = 0;
34103413

3411-
return pfkey_broadcast(skb, BROADCAST_REGISTERED, NULL, xs_net(x));
3414+
return pfkey_broadcast(skb, GFP_ATOMIC, BROADCAST_REGISTERED, NULL,
3415+
xs_net(x));
34123416
}
34133417

34143418
#ifdef CONFIG_NET_KEY_MIGRATE
@@ -3599,7 +3603,7 @@ static int pfkey_send_migrate(const struct xfrm_selector *sel, u8 dir, u8 type,
35993603
}
36003604

36013605
/* broadcast migrate message to sockets */
3602-
pfkey_broadcast(skb, BROADCAST_ALL, NULL, &init_net);
3606+
pfkey_broadcast(skb, GFP_ATOMIC, BROADCAST_ALL, NULL, &init_net);
36033607

36043608
return 0;
36053609

0 commit comments

Comments
 (0)