Commit 80d84ef3 authored by Tom Parkin's avatar Tom Parkin Committed by David S. Miller

l2tp: prevent l2tp_tunnel_delete racing with userspace close

If a tunnel socket is created by userspace, l2tp hooks the socket destructor
in order to clean up resources if userspace closes the socket or crashes.  It
also caches a pointer to the struct sock for use in the data path and in the
netlink interface.

While it is safe to use the cached sock pointer in the data path, where the
skb references keep the socket alive, it is not safe to use it elsewhere as
such access introduces a race with userspace closing the socket.  In
particular, l2tp_tunnel_delete is prone to oopsing if a multithreaded
userspace application closes a socket at the same time as sending a netlink
delete command for the tunnel.

This patch fixes this oops by forcing l2tp_tunnel_delete to explicitly look up
a tunnel socket held by userspace using sockfd_lookup().
Signed-off-by: default avatarTom Parkin <tparkin@katalix.com>
Signed-off-by: default avatarJames Chapman <jchapman@katalix.com>
Signed-off-by: default avatarDavid S. Miller <davem@davemloft.net>
parent fc16e884
...@@ -168,6 +168,51 @@ l2tp_session_id_hash_2(struct l2tp_net *pn, u32 session_id) ...@@ -168,6 +168,51 @@ l2tp_session_id_hash_2(struct l2tp_net *pn, u32 session_id)
} }
/* Lookup the tunnel socket, possibly involving the fs code if the socket is
* owned by userspace. A struct sock returned from this function must be
* released using l2tp_tunnel_sock_put once you're done with it.
*/
struct sock *l2tp_tunnel_sock_lookup(struct l2tp_tunnel *tunnel)
{
int err = 0;
struct socket *sock = NULL;
struct sock *sk = NULL;
if (!tunnel)
goto out;
if (tunnel->fd >= 0) {
/* Socket is owned by userspace, who might be in the process
* of closing it. Look the socket up using the fd to ensure
* consistency.
*/
sock = sockfd_lookup(tunnel->fd, &err);
if (sock)
sk = sock->sk;
} else {
/* Socket is owned by kernelspace */
sk = tunnel->sock;
}
out:
return sk;
}
EXPORT_SYMBOL_GPL(l2tp_tunnel_sock_lookup);
/* Drop a reference to a tunnel socket obtained via. l2tp_tunnel_sock_put */
void l2tp_tunnel_sock_put(struct sock *sk)
{
struct l2tp_tunnel *tunnel = l2tp_sock_to_tunnel(sk);
if (tunnel) {
if (tunnel->fd >= 0) {
/* Socket is owned by userspace */
sockfd_put(sk->sk_socket);
}
sock_put(sk);
}
}
EXPORT_SYMBOL_GPL(l2tp_tunnel_sock_put);
/* Lookup a session by id in the global session list /* Lookup a session by id in the global session list
*/ */
static struct l2tp_session *l2tp_session_find_2(struct net *net, u32 session_id) static struct l2tp_session *l2tp_session_find_2(struct net *net, u32 session_id)
...@@ -1607,6 +1652,7 @@ int l2tp_tunnel_create(struct net *net, int fd, int version, u32 tunnel_id, u32 ...@@ -1607,6 +1652,7 @@ int l2tp_tunnel_create(struct net *net, int fd, int version, u32 tunnel_id, u32
tunnel->old_sk_destruct = sk->sk_destruct; tunnel->old_sk_destruct = sk->sk_destruct;
sk->sk_destruct = &l2tp_tunnel_destruct; sk->sk_destruct = &l2tp_tunnel_destruct;
tunnel->sock = sk; tunnel->sock = sk;
tunnel->fd = fd;
lockdep_set_class_and_name(&sk->sk_lock.slock, &l2tp_socket_class, "l2tp_sock"); lockdep_set_class_and_name(&sk->sk_lock.slock, &l2tp_socket_class, "l2tp_sock");
sk->sk_allocation = GFP_ATOMIC; sk->sk_allocation = GFP_ATOMIC;
...@@ -1642,14 +1688,21 @@ EXPORT_SYMBOL_GPL(l2tp_tunnel_create); ...@@ -1642,14 +1688,21 @@ EXPORT_SYMBOL_GPL(l2tp_tunnel_create);
*/ */
int l2tp_tunnel_delete(struct l2tp_tunnel *tunnel) int l2tp_tunnel_delete(struct l2tp_tunnel *tunnel)
{ {
int err = 0; int err = -EBADF;
struct socket *sock = tunnel->sock ? tunnel->sock->sk_socket : NULL; struct socket *sock = NULL;
struct sock *sk = NULL;
sk = l2tp_tunnel_sock_lookup(tunnel);
if (!sk)
goto out;
sock = sk->sk_socket;
BUG_ON(!sock);
/* Force the tunnel socket to close. This will eventually /* Force the tunnel socket to close. This will eventually
* cause the tunnel to be deleted via the normal socket close * cause the tunnel to be deleted via the normal socket close
* mechanisms when userspace closes the tunnel socket. * mechanisms when userspace closes the tunnel socket.
*/ */
if (sock != NULL) {
err = inet_shutdown(sock, 2); err = inet_shutdown(sock, 2);
/* If the tunnel's socket was created by the kernel, /* If the tunnel's socket was created by the kernel,
...@@ -1658,8 +1711,9 @@ int l2tp_tunnel_delete(struct l2tp_tunnel *tunnel) ...@@ -1658,8 +1711,9 @@ int l2tp_tunnel_delete(struct l2tp_tunnel *tunnel)
*/ */
if (sock->file == NULL) if (sock->file == NULL)
err = inet_release(sock); err = inet_release(sock);
}
l2tp_tunnel_sock_put(sk);
out:
return err; return err;
} }
EXPORT_SYMBOL_GPL(l2tp_tunnel_delete); EXPORT_SYMBOL_GPL(l2tp_tunnel_delete);
......
...@@ -188,7 +188,8 @@ struct l2tp_tunnel { ...@@ -188,7 +188,8 @@ struct l2tp_tunnel {
int (*recv_payload_hook)(struct sk_buff *skb); int (*recv_payload_hook)(struct sk_buff *skb);
void (*old_sk_destruct)(struct sock *); void (*old_sk_destruct)(struct sock *);
struct sock *sock; /* Parent socket */ struct sock *sock; /* Parent socket */
int fd; int fd; /* Parent fd, if tunnel socket
* was created by userspace */
uint8_t priv[0]; /* private data */ uint8_t priv[0]; /* private data */
}; };
...@@ -228,6 +229,8 @@ static inline struct l2tp_tunnel *l2tp_sock_to_tunnel(struct sock *sk) ...@@ -228,6 +229,8 @@ static inline struct l2tp_tunnel *l2tp_sock_to_tunnel(struct sock *sk)
return tunnel; return tunnel;
} }
extern struct sock *l2tp_tunnel_sock_lookup(struct l2tp_tunnel *tunnel);
extern void l2tp_tunnel_sock_put(struct sock *sk);
extern struct l2tp_session *l2tp_session_find(struct net *net, struct l2tp_tunnel *tunnel, u32 session_id); extern struct l2tp_session *l2tp_session_find(struct net *net, struct l2tp_tunnel *tunnel, u32 session_id);
extern struct l2tp_session *l2tp_session_find_nth(struct l2tp_tunnel *tunnel, int nth); extern struct l2tp_session *l2tp_session_find_nth(struct l2tp_tunnel *tunnel, int nth);
extern struct l2tp_session *l2tp_session_find_by_ifname(struct net *net, char *ifname); extern struct l2tp_session *l2tp_session_find_by_ifname(struct net *net, char *ifname);
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment