From patchwork Tue Apr 11 20:42:11 2023 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Matthieu Baerts X-Patchwork-Id: 82186 Return-Path: Delivered-To: ouuuleilei@gmail.com Received: by 2002:a59:b0ea:0:b0:3b6:4342:cba0 with SMTP id b10csp2845248vqo; Tue, 11 Apr 2023 13:47:08 -0700 (PDT) X-Google-Smtp-Source: AKy350Z/3BVUOqxvxjdMLz5/qkU9zOnOGZJeVFdN5bL19CQ9yIq7pdp9IGjjHY1GB+gHNy6LD+B6 X-Received: by 2002:a17:906:9255:b0:929:e5a8:63f7 with SMTP id c21-20020a170906925500b00929e5a863f7mr507853ejx.28.1681246028617; Tue, 11 Apr 2023 13:47:08 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1681246028; cv=none; d=google.com; s=arc-20160816; b=sE4/cVmzpIaR0s2IZxFlQDwAbkxhDl+IIk17o21qJWnR7VJCJogL6MS5yzXV3hB8/y BtRDaPL+x7a/ABn4evmjruX5Uc1Qgflwx70dlIbBQ4U5BsHfh76v6phqady64H7Fd2Cb hVx+JeI2qQWpGhMqb/5h5C6TsIGNgDiKwfZICdSCFDrpkQlFwDIuWUxhdBYsk9L82Qlt Gzq42oU1P50+wrCmk8T+NNXWf51wyvWZVPZlnJxgQH2RpqP+K76yzkDb4QTTKV0532Th C0b5uWJQS1x5T51RMqOgJjPOIBEC9JVL97boVZbBekAO71C/9FbUUtkedrnwZ+kJteQz DaYw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:cc:to:in-reply-to:references:message-id :content-transfer-encoding:mime-version:subject:date:from :dkim-signature; bh=iJSkDzvHDv+IldvOKYCUeGWLBa1YxITsKTNgz5UKiD4=; b=auXMtqsYJ3O4nOLa3jOQzdtFATZkvtwFRZBKmdKShkGYxCrE23kKwvaOSDPtOGn2lN TuMDTZezbDz4d4nYzPGBMfM2pSjRr2r6Zx04swWkk/iyo77WBqyVv6UuqFVqeEgNF5nj 2gTYYPPYfNsK/cAFAWY71qKLPxWXOfL6wINTYyOxe/3Saw2KWg9nKhas42ovioMb6Swy 8Iq0yzeLHFwSLs28q+H3U2Nm6tudetQPN1VOqPhqVb1rouptGc58gposO8Tnj3HhwTw0 uqQu1dqG0U/ypriBtjJaiWXww2PxKwZgCCq1IL/DHicO0ee0afwZTgEUSMMAvqcHhQkR JKVQ== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@tessares.net header.s=google header.b=0yNawdYC; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=tessares.net Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id 19-20020a170906311300b0093deb7c6bfcsi11507744ejx.795.2023.04.11.13.46.38; Tue, 11 Apr 2023 13:47:08 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; dkim=pass header.i=@tessares.net header.s=google header.b=0yNawdYC; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=tessares.net Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S230046AbjDKUmx (ORCPT + 99 others); Tue, 11 Apr 2023 16:42:53 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:47582 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S229696AbjDKUmh (ORCPT ); Tue, 11 Apr 2023 16:42:37 -0400 Received: from mail-wm1-x330.google.com (mail-wm1-x330.google.com [IPv6:2a00:1450:4864:20::330]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id D4DAA449A for ; Tue, 11 Apr 2023 13:42:28 -0700 (PDT) Received: by mail-wm1-x330.google.com with SMTP id he13so10310064wmb.2 for ; Tue, 11 Apr 2023 13:42:28 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=tessares.net; s=google; t=1681245746; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:from:to:cc:subject:date:message-id :reply-to; bh=iJSkDzvHDv+IldvOKYCUeGWLBa1YxITsKTNgz5UKiD4=; b=0yNawdYCXfHfH1a2o5KD4daFIw5hxojs6Vivsduai6u32Icbn0QMEKlF5qVaEZydDS ZTi9tokkuRtihm1pcqaeBvUBvBhvYDEm/l2HgI7DYHn5HZyqah9ur1KYEiAJrVRHsdat qRpEIWdvc3CC2VJ/LyrPBmaKibCPdsCFRYIz7fxF1COXjWcgpaSbP/+1pUZpcdtmCfsI j6Q2FG2UXt77b61OSneGev8C9QKvzefw+IAMTDuoTWa431wBo/XBJuh4VkkpXAd+hjFn +nZAPNILDcvS/6x24zbu+Hc+1/r3wQ78p5c+9llT4dXddUY9oAOq0WtF+cdbZfagIt4v wheg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; t=1681245746; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=iJSkDzvHDv+IldvOKYCUeGWLBa1YxITsKTNgz5UKiD4=; b=wdTkNOizOqFpe7eo3nmweXB1Wqr4Ip+hcLBlK6/BxxtmNRONjNAQxLjiIdZSkA0Mg/ G12fCow8y0vy+qhfklVVKmm+MT1fOks0aOOWIRFmq75ZXHO88muqVQTpnPL6gDnGiT48 ecDsKCDg31RNjqiJnXfZegbYsef4UMokSOKXK1zfyYFln0b9r6M9BHBNNJU+FibrfcTI P1CoyqgNxfozZ/2KSckzdTwPxn4jGx7P66Z/tW7FhrSRTcvNx7TNXZSbsjw/KmOSQEDj ELePmTffYjf56Z7eU+Ha4gZB52H5TncaytR4uXD4WFhbsSOxl8/wFtEBdLdFAFNCvXb5 v2mA== X-Gm-Message-State: AAQBX9cD7nhDUj4ZdX+27fMf9TE8igyZbDfPbrg4r9GGHOWSnQTwOkN1 nwsZwu4Yk4CAKNd2ciLn9JwFuw== X-Received: by 2002:a05:600c:1e25:b0:3ed:24f7:2b48 with SMTP id ay37-20020a05600c1e2500b003ed24f72b48mr279773wmb.8.1681245746479; Tue, 11 Apr 2023 13:42:26 -0700 (PDT) Received: from vdi08.nix.tessares.net (static.219.156.76.144.clients.your-server.de. [144.76.156.219]) by smtp.gmail.com with ESMTPSA id p23-20020a1c7417000000b003f0824e8c92sm86887wmc.7.2023.04.11.13.42.25 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 11 Apr 2023 13:42:26 -0700 (PDT) From: Matthieu Baerts Date: Tue, 11 Apr 2023 22:42:11 +0200 Subject: [PATCH net 3/4] mptcp: fix NULL pointer dereference on fastopen early fallback MIME-Version: 1.0 Message-Id: <20230411-upstream-net-20230411-mptcp-fixes-v1-3-ca540f3ef986@tessares.net> References: <20230411-upstream-net-20230411-mptcp-fixes-v1-0-ca540f3ef986@tessares.net> In-Reply-To: <20230411-upstream-net-20230411-mptcp-fixes-v1-0-ca540f3ef986@tessares.net> To: mptcp@lists.linux.dev, "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Davide Caratti , Dmytro Shytyi , Shuah Khan , Mat Martineau , Geliang Tang Cc: netdev@vger.kernel.org, linux-kernel@vger.kernel.org, linux-kselftest@vger.kernel.org, Matthieu Baerts , stable@vger.kernel.org X-Mailer: b4 0.12.2 X-Developer-Signature: v=1; a=openpgp-sha256; l=1313; i=matthieu.baerts@tessares.net; h=from:subject:message-id; bh=M0lbg2vrKXi+X9w75ix6Wwp/oOxfY96lIrVHUJdPEwE=; b=owEBbQKS/ZANAwAIAfa3gk9CaaBzAcsmYgBkNcYuUYRtIKl0zwJ/mKGDzxR9gRBkAHRRLlrq4 oIYSLoVXneJAjMEAAEIAB0WIQToy4X3aHcFem4n93r2t4JPQmmgcwUCZDXGLgAKCRD2t4JPQmmg c2/hEACJPabxn8n8GOLIdaDIhZa3hSUPMXr+LVjq3jLWwu2tFeLrppZQpoNO50UqV5Lui8cDLjw JH1Y6vIxKp1Bptqd194v+luCJ3HvCC+oshWSCDjfRD1nHSNE41BMe52hiFk+a1RBfiUhxwA6MLb QMy/EDQMJYJyJrJnGsH3tOBHN8oQFXlfqj1Oe++zYK3joDZFIgJRJq1UNUIfsrBA/LQsb28KPe3 UhSL/xflT3pdVZzzAG1R0jhLAIjOf/MpD82d3rmQLaz1AAB/1sCqSQRgjQFEPKjYPHXLrjO4Ud0 ks7j9FOefboDIUG1zEe6xOJuGPHUV9vHDL1DTXkSHLKzgrBOryPELBNfMauvzlEcAUr5HJJsXEL l0IWbret5sg+uWszLZth+6nv8XU5MOkmA1HRaQcbFdg6Ni+KVe7XFuroxMeU9vd+y9H6OqlnEep zWi12vS5L+5zvmPZlfkIBwOBH3y13xIqa68AL/3SasDxeG5sncUZLI2tSFu6l2Hgxsh7yj6Kg2z vc55pl0aIjoRU9Lv0a1e79/y309ZUK6iHwaUtj6wHNgrI58IP/3PjXvVyIaUvwcTnUJ8osQp+AW 07Qdpdn1CQhNnhhAPQeTCfShcCvBISudqowh+fQBf7tInGC0v7sACxSfqxyD6U6V2+au0tFkE3w KHw2vyIrQNnmdBg== X-Developer-Key: i=matthieu.baerts@tessares.net; a=openpgp; fpr=E8CB85F76877057A6E27F77AF6B7824F4269A073 X-Spam-Status: No, score=-2.1 required=5.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,RCVD_IN_DNSWL_NONE, SPF_HELO_NONE,SPF_PASS autolearn=unavailable autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org X-getmail-retrieved-from-mailbox: =?utf-8?q?INBOX?= X-GMAIL-THRID: =?utf-8?q?1762914235509277721?= X-GMAIL-MSGID: =?utf-8?q?1762914235509277721?= From: Paolo Abeni In case of early fallback to TCP, subflow_syn_recv_sock() deletes the subflow context before returning the newly allocated sock to the caller. The fastopen path does not cope with the above unconditionally dereferencing the subflow context. Fixes: 36b122baf6a8 ("mptcp: add subflow_v(4,6)_send_synack()") Cc: stable@vger.kernel.org Signed-off-by: Paolo Abeni Reviewed-by: Matthieu Baerts Signed-off-by: Matthieu Baerts --- net/mptcp/fastopen.c | 11 +++++++++-- 1 file changed, 9 insertions(+), 2 deletions(-) diff --git a/net/mptcp/fastopen.c b/net/mptcp/fastopen.c index d237d142171c..bceaab8dd8e4 100644 --- a/net/mptcp/fastopen.c +++ b/net/mptcp/fastopen.c @@ -9,11 +9,18 @@ void mptcp_fastopen_subflow_synack_set_params(struct mptcp_subflow_context *subflow, struct request_sock *req) { - struct sock *ssk = subflow->tcp_sock; - struct sock *sk = subflow->conn; + struct sock *sk, *ssk; struct sk_buff *skb; struct tcp_sock *tp; + /* on early fallback the subflow context is deleted by + * subflow_syn_recv_sock() + */ + if (!subflow) + return; + + ssk = subflow->tcp_sock; + sk = subflow->conn; tp = tcp_sk(ssk); subflow->is_mptfo = 1;