From nobody Fri Jan 3 05:31:28 2025 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C710356B81; Sat, 19 Oct 2024 10:29:13 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1729333754; cv=none; b=TDgN9ehDWJfOug/UQjA8U0JPmA4Hfcy4GKwJfR/5Y/1G8lqBLSMPWRHERW79VduoS4I/Vbu4RODNog0awAgS8jKJUrRKLbiekQop5emaOy8DfobpcmVlWwtKdwSL9fG05qfjVi/kui8TXxreQ4mGM9U9hCeKwmL7fHWCIPD6R5o= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1729333754; c=relaxed/simple; bh=VpqFXISswc8exQVEP8luyYLRhtlSzgWomoKX4ar6WoU=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=WgNyWUbGr/Pc4klIKZ6Mgn8GnIHH4o8hPmjQ5ACATm+kVLWNaHLUmM2YQbrZ0Nx5OQ5B82amr6wEfC0xDqQ6o9I4IKhqenveL8uIXSW2lxk+v3WXtwt+lDSTR+Fd8HdI1doV/RXWkwa8m52fgTFsBb5psiGev1GdgHfy8IkWh7E= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=ovh6Lazu; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="ovh6Lazu" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 74DF0C4CED0; Sat, 19 Oct 2024 10:29:11 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1729333753; bh=VpqFXISswc8exQVEP8luyYLRhtlSzgWomoKX4ar6WoU=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=ovh6Lazu60JYAgmyPwfFmF5eCJn7IwcTLnvmNsRKSbJ3M2lMi3jdLwT8+/IP5CKKV rfh8UN4e5PmrRTvC2BMEAPu0g1lSnJ1DOHVKYA9Dfx7jxGnDjOvsdR278x9Ybj6h5+ ttWMciNvOrOXC/3j8TmDDiQuAgWVhHcHTeuGsnB5TwK0zOe66kxaiZyUnFRNZIiU/D EaEKZoJfbeT11pjK7iqjIh+5odk49SehQak30yV8y9w74KX1t3DTBPWf+Uagg5nqOR opq8jTFbxAmxF+NjwrHmOi8zMx4TB436oxsBOkaMXICewiPxikweKcO4uyD2BPjn78 dqh3oNQAOl8/Q== From: "Matthieu Baerts (NGI0)" To: mptcp@lists.linux.dev, stable@vger.kernel.org, gregkh@linuxfoundation.org Cc: Geliang Tang , sashal@kernel.org, Paolo Abeni , Mat Martineau , "David S . Miller" , Matthieu Baerts Subject: [PATCH 5.10.y 1/3] mptcp: track and update contiguous data status Date: Sat, 19 Oct 2024 12:29:07 +0200 Message-ID: <20241019102905.3383483-6-matttbe@kernel.org> X-Mailer: git-send-email 2.45.2 In-Reply-To: <20241019102905.3383483-5-matttbe@kernel.org> References: <20241019102905.3383483-5-matttbe@kernel.org> Precedence: bulk X-Mailing-List: mptcp@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=3622; i=matttbe@kernel.org; h=from:subject; bh=cJMz9CWTxnjL18zdD09XUIClsjXXzQuv24tkpzLXHU0=; b=owEBbQKS/ZANAwAIAfa3gk9CaaBzAcsmYgBnE4nxMaHon3IvNEswAXCDyNUjkXFlqX3rGmULZ kXc6kgDtYqJAjMEAAEIAB0WIQToy4X3aHcFem4n93r2t4JPQmmgcwUCZxOJ8QAKCRD2t4JPQmmg cw/mEACjdEVjTtBkB5FcGWduudkB6G6xJSMvCRnGE88QVPajUhWDzKJc5vaCjrVUDrXcFtozFz8 zJVE7NfnwPD+6m+3T6KG1PEIcjylW9BKLWBJLshDRjr5TZLRBjRj7tW6H1sapEEzf3tB0sWxKMn +rR1l4ZBjxVGIDGvD4rY9kpwaac187JXtLtmqwEMF7eGxKmV1Eq2nm2xY35scT1PVE/PbC5NXzl 0bKr4uaIJ8tCyxkHYcAR+edvCl3IpNIILg7mK5lkLSECDls2qAgzZF5B20KfUvquwBFukgfHft8 UDUPbHixMEJboNMy4bYJCSPJFXbbG0LJu5mmel/An3kMPO2JIuu7H7AfnMAx39YfizkbtU3Xg1Z xTi3a8SFFnI+re3IDUSzFNNh83hbD5s4jv1ER1grLE98gHDsVgyh5S62BqN03Lu6xYZXaU45Vuj tfGxofdaIW+eFANIP/vw0z+UFw+XoxSIDPlz3/xBUUmzlqvj74AHNl+vHTIN2af1dCfnjM8QlPN qzAvp4lD4DJ8FxXM+P5fyH/jfuGcqNhiXZiYdZ52eJRsJCScXlyV1IJsGCxDiLhlmH28pFN+Cuq SlpQN/rxGAduMmfSOtUK0AVCP4lDKVVyeKwZqzP7I5eUtUUZ3/ZsEyQjfAyOZK6xWK6e+ZpCE7z vqHBzEGuFTgRmaQ== X-Developer-Key: i=matttbe@kernel.org; a=openpgp; fpr=E8CB85F76877057A6E27F77AF6B7824F4269A073 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Geliang Tang commit 0530020a7c8f2204e784f0dbdc882bbd961fdbde upstream. This patch adds a new member allow_infinite_fallback in mptcp_sock, which is initialized to 'true' when the connection begins and is set to 'false' on any retransmit or successful MP_JOIN. Only do infinite mapping fallback if there is a single subflow AND there have been no retransmissions AND there have never been any MP_JOINs. Suggested-by: Paolo Abeni Signed-off-by: Geliang Tang Signed-off-by: Mat Martineau Signed-off-by: David S. Miller Stable-dep-of: e32d262c89e2 ("mptcp: handle consistently DSS corruption") [ Conflicts in protocol.c, because commit 3e5014909b56 ("mptcp: cleanup MPJ subflow list handling") is not in this version. This commit is linked to a new feature, changing the context around. The new line can still be added at the same place. Conflicts in protocol.h, because commit 4f6e14bd19d6 ("mptcp: support TCP_CORK and TCP_NODELAY") is not in this version. This commit is linked to a new feature, changing the context around. The new line can still be added at the same place. Conflicts in subflow.c, because commit 0348c690ed37 ("mptcp: add the fallback check") is not in this version. This commit is linked to a new feature, changing the context around. The new line can still be added at the same place. Extra conflicts in v5.10, because the context has been changed. ] Signed-off-by: Matthieu Baerts (NGI0) --- net/mptcp/protocol.c | 6 +++++- net/mptcp/protocol.h | 1 + net/mptcp/subflow.c | 1 + 3 files changed, 7 insertions(+), 1 deletion(-) diff --git a/net/mptcp/protocol.c b/net/mptcp/protocol.c index 590e2c9bb67e..24a21ff0cb8a 100644 --- a/net/mptcp/protocol.c +++ b/net/mptcp/protocol.c @@ -1810,9 +1810,11 @@ static void mptcp_worker(struct work_struct *work) if (!mptcp_ext_cache_refill(msk)) break; } - if (copied) + if (copied) { tcp_push(ssk, msg.msg_flags, mss_now, tcp_sk(ssk)->nonagle, size_goal); + WRITE_ONCE(msk->allow_infinite_fallback, false); + } =20 dfrag->data_seq =3D orig_write_seq; dfrag->offset =3D orig_offset; @@ -1845,6 +1847,7 @@ static int __mptcp_init_sock(struct sock *sk) =20 msk->first =3D NULL; inet_csk(sk)->icsk_sync_mss =3D mptcp_sync_mss; + WRITE_ONCE(msk->allow_infinite_fallback, true); =20 mptcp_pm_data_init(msk); =20 @@ -2543,6 +2546,7 @@ bool mptcp_finish_join(struct sock *sk) if (parent_sock && !sk->sk_socket) mptcp_sock_graft(sk, parent_sock); subflow->map_seq =3D READ_ONCE(msk->ack_seq); + WRITE_ONCE(msk->allow_infinite_fallback, false); return true; } =20 diff --git a/net/mptcp/protocol.h b/net/mptcp/protocol.h index 44944e8f73c5..2330140d6b1c 100644 --- a/net/mptcp/protocol.h +++ b/net/mptcp/protocol.h @@ -213,6 +213,7 @@ struct mptcp_sock { bool rcv_data_fin; bool snd_data_fin_enable; bool use_64bit_ack; /* Set when we received a 64-bit DSN */ + bool allow_infinite_fallback; spinlock_t join_list_lock; struct work_struct work; struct sk_buff *ooo_last_skb; diff --git a/net/mptcp/subflow.c b/net/mptcp/subflow.c index 843c61ebd421..0c020ca463f4 100644 --- a/net/mptcp/subflow.c +++ b/net/mptcp/subflow.c @@ -1179,6 +1179,7 @@ int __mptcp_subflow_connect(struct sock *sk, const st= ruct mptcp_addr_info *loc, list_add_tail(&subflow->node, &msk->join_list); spin_unlock_bh(&msk->join_list_lock); =20 + WRITE_ONCE(msk->allow_infinite_fallback, false); return err; =20 failed: --=20 2.45.2 From nobody Fri Jan 3 05:31:28 2025 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id F2B6956B81; Sat, 19 Oct 2024 10:29:15 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1729333756; cv=none; b=FpCdi+BeHbszNrqkylUv5Mvf3nyHBGIRr4wFRFlYk0FZaIn1fcnBCyyApgknvb0O/5v9EtJNKxipmThEvHs6mqdencp3ZQ3aPKcPR2eByy2rULozVhVTgmc7YhmLwQ/QiYYDCkV/t6/EYOacSUBhjybzJe68O7AYIaqrlkkTbjI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1729333756; c=relaxed/simple; bh=BFI0jyosPmOnHqY0LnMSWCjphPbM+TMeHEB94JgUkuQ=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=F8pC3Ht8Xo1hwqEAXgw5BHjVZB0EStIyaoD3oSvOHSIdngbJ/pUs6R1x3aBZAXlayy1pSNff8FXWdPgpyzCWDR96fZefH5Jj2QEd50N9amJqC6p30m9xZnRROZ4C1/FElPc5HMXtYOMOuTBkbioIwMPi8AzUFTrtLBh6dIK1fVo= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=qpHZqyc6; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="qpHZqyc6" Received: by smtp.kernel.org (Postfix) with ESMTPSA id E5DB2C4CECF; Sat, 19 Oct 2024 10:29:13 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1729333755; bh=BFI0jyosPmOnHqY0LnMSWCjphPbM+TMeHEB94JgUkuQ=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=qpHZqyc6b8rIlmMq6l60oALf/2YYcovxDxyVLB4GaA5ZL5D+Zjv6HuydKovuozlGQ ia7qnLKKpoTIVv+vVovVo4FIj6NXynHX3z8I32XLBM/J0hlWEJxmSyvO+ggP/bphs5 FSddmQ5OwgGTom1Sj/PB3RhgyKdHvSoIhiI0L8qC6Ht6zDHcZuEFnb4a3RvFJtsArN o3YxA2TAsy06nMeUR8AST/5gAmRDQsRjNeKIgKO3phisvXWl0ofC7+YF+t3y1cHpJn Zj70gFlw4FJAP8cjvp6VJ0FmqCcmDnCf6JOwNmmpx0gkrXjqDxLTeT661YUoMTVHZo Z6HQuBOV49toQ== From: "Matthieu Baerts (NGI0)" To: mptcp@lists.linux.dev, stable@vger.kernel.org, gregkh@linuxfoundation.org Cc: Paolo Abeni , sashal@kernel.org, Matthieu Baerts , Jakub Kicinski Subject: [PATCH 5.10.y 2/3] mptcp: handle consistently DSS corruption Date: Sat, 19 Oct 2024 12:29:08 +0200 Message-ID: <20241019102905.3383483-7-matttbe@kernel.org> X-Mailer: git-send-email 2.45.2 In-Reply-To: <20241019102905.3383483-5-matttbe@kernel.org> References: <20241019102905.3383483-5-matttbe@kernel.org> Precedence: bulk X-Mailing-List: mptcp@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=4615; i=matttbe@kernel.org; h=from:subject; bh=mgszj9fxlSPmfVrM9CCcEDleRtBoxxHe8lu9QEVHeps=; b=owEBbQKS/ZANAwAIAfa3gk9CaaBzAcsmYgBnE4nxGiuWpdXslByoOacFsm24MBBj0PPi3G2rZ U9dwT9qKriJAjMEAAEIAB0WIQToy4X3aHcFem4n93r2t4JPQmmgcwUCZxOJ8QAKCRD2t4JPQmmg c4XpEAC0wSodm833As+NY6pNPR6NE/9mTOP+sE9YIrdSQ07eiiZ1c4NJT/6ezifQr/UX1d+J28y ONQU0iL74tPl9N7+qWMzdj0NuvCUMUCOa0gN/hd/nVNB7zLGWZWgOUm/Hzr4Lc8Q+JYwjIe+dnn ZB+PdApK20GAvgHvlGqPm7vA1MEviWUzxUpy+6elgmRO4Dz3LOTED4hUHW+7akTcMxzE0Z2zXSt h/BsOUsUxhehRwmmggo5nnenGGa2slaEgKU9cFkXzdjGbc1LQ0Zlk0qbJlEfVLXw3sn/vwV8Cil /CV+gZiN4imeFwlJDMVsNHqSd+aACxtBxyHyeyCcTQfTujfLfd+6rWkBiKruZ3p1OZ3Jm+wF+La CekiKgs0tfUGhDXv1HhJWixoiURidwQyWSlT/KLeF3CU7otJsLXOk63716hvK8u7FdDWUUPImnH DRu2Eq3lVHcaBEnbraiuJSJtH/q/hUbNYPng58qUXexXi24Pd0pco9Fmh9nkWDybg1r7yKrz2r+ 0ZI14eIRaJBjvUppwNmHf4OLway2Lf87txAv3XsNrDIXAupjwf+c35iUf3dnCKaAFC2H0n0Zkz1 m6zXrt4bsPlPQ9WE6WIfSPnbsA96RpVcbQxHtKiEv4MWn1dcHRWu8fxlJXATH9w8Buxq4c4Wvzz MM+RNZSAK3oN2gA== X-Developer-Key: i=matttbe@kernel.org; a=openpgp; fpr=E8CB85F76877057A6E27F77AF6B7824F4269A073 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Paolo Abeni commit e32d262c89e2b22cb0640223f953b548617ed8a6 upstream. Bugged peer implementation can send corrupted DSS options, consistently hitting a few warning in the data path. Use DEBUG_NET assertions, to avoid the splat on some builds and handle consistently the error, dumping related MIBs and performing fallback and/or reset according to the subflow type. Fixes: 6771bfd9ee24 ("mptcp: update mptcp ack sequence from work queue") Cc: stable@vger.kernel.org Signed-off-by: Paolo Abeni Reviewed-by: Matthieu Baerts (NGI0) Signed-off-by: Matthieu Baerts (NGI0) Link: https://patch.msgid.link/20241008-net-mptcp-fallback-fixes-v1-1-c6fb8= e93e551@kernel.org Signed-off-by: Jakub Kicinski [ Conflicts in mib.[ch], because commit 104125b82e5c ("mptcp: add mib for infinite map sending") is linked to a new feature, not available in this version. Resolving the conflicts is easy, simply adding the new lines declaring the new "DSS corruptions" MIB entries. Also removed in protocol.c and subflow.c all DEBUG_NET_WARN_ON_ONCE because they are not defined in this version: enough with the MIB counters that have been added in this commit. ] Signed-off-by: Matthieu Baerts (NGI0) --- net/mptcp/mib.c | 2 ++ net/mptcp/mib.h | 2 ++ net/mptcp/protocol.c | 20 +++++++++++++++++--- net/mptcp/subflow.c | 2 +- 4 files changed, 22 insertions(+), 4 deletions(-) diff --git a/net/mptcp/mib.c b/net/mptcp/mib.c index f4034e000f3e..44d083958d8e 100644 --- a/net/mptcp/mib.c +++ b/net/mptcp/mib.c @@ -23,6 +23,8 @@ static const struct snmp_mib mptcp_snmp_list[] =3D { SNMP_MIB_ITEM("MPJoinAckRx", MPTCP_MIB_JOINACKRX), SNMP_MIB_ITEM("MPJoinAckHMacFailure", MPTCP_MIB_JOINACKMAC), SNMP_MIB_ITEM("DSSNotMatching", MPTCP_MIB_DSSNOMATCH), + SNMP_MIB_ITEM("DSSCorruptionFallback", MPTCP_MIB_DSSCORRUPTIONFALLBACK), + SNMP_MIB_ITEM("DSSCorruptionReset", MPTCP_MIB_DSSCORRUPTIONRESET), SNMP_MIB_ITEM("InfiniteMapRx", MPTCP_MIB_INFINITEMAPRX), SNMP_MIB_ITEM("OFOQueueTail", MPTCP_MIB_OFOQUEUETAIL), SNMP_MIB_ITEM("OFOQueue", MPTCP_MIB_OFOQUEUE), diff --git a/net/mptcp/mib.h b/net/mptcp/mib.h index a9f43ff00b3c..0e17e1cebdbc 100644 --- a/net/mptcp/mib.h +++ b/net/mptcp/mib.h @@ -16,6 +16,8 @@ enum linux_mptcp_mib_field { MPTCP_MIB_JOINACKRX, /* Received an ACK + MP_JOIN */ MPTCP_MIB_JOINACKMAC, /* HMAC was wrong on ACK + MP_JOIN */ MPTCP_MIB_DSSNOMATCH, /* Received a new mapping that did not match the p= revious one */ + MPTCP_MIB_DSSCORRUPTIONFALLBACK,/* DSS corruption detected, fallback */ + MPTCP_MIB_DSSCORRUPTIONRESET, /* DSS corruption detected, MPJ subflow res= et */ MPTCP_MIB_INFINITEMAPRX, /* Received an infinite mapping */ MPTCP_MIB_OFOQUEUETAIL, /* Segments inserted into OoO queue tail */ MPTCP_MIB_OFOQUEUE, /* Segments inserted into OoO queue */ diff --git a/net/mptcp/protocol.c b/net/mptcp/protocol.c index 24a21ff0cb8a..8558309a2d3f 100644 --- a/net/mptcp/protocol.c +++ b/net/mptcp/protocol.c @@ -457,6 +457,18 @@ static void mptcp_check_data_fin(struct sock *sk) } } =20 +static void mptcp_dss_corruption(struct mptcp_sock *msk, struct sock *ssk) +{ + if (READ_ONCE(msk->allow_infinite_fallback)) { + MPTCP_INC_STATS(sock_net(ssk), + MPTCP_MIB_DSSCORRUPTIONFALLBACK); + mptcp_do_fallback(ssk); + } else { + MPTCP_INC_STATS(sock_net(ssk), MPTCP_MIB_DSSCORRUPTIONRESET); + mptcp_subflow_reset(ssk); + } +} + static bool __mptcp_move_skbs_from_subflow(struct mptcp_sock *msk, struct sock *ssk, unsigned int *bytes) @@ -519,10 +531,12 @@ static bool __mptcp_move_skbs_from_subflow(struct mpt= cp_sock *msk, moved +=3D len; seq +=3D len; =20 - if (WARN_ON_ONCE(map_remaining < len)) - break; + if (unlikely(map_remaining < len)) + mptcp_dss_corruption(msk, ssk); } else { - WARN_ON_ONCE(!fin); + if (unlikely(!fin)) + mptcp_dss_corruption(msk, ssk); + sk_eat_skb(ssk, skb); done =3D true; } diff --git a/net/mptcp/subflow.c b/net/mptcp/subflow.c index 0c020ca463f4..c3434069fb0a 100644 --- a/net/mptcp/subflow.c +++ b/net/mptcp/subflow.c @@ -702,7 +702,7 @@ static bool skb_is_fully_mapped(struct sock *ssk, struc= t sk_buff *skb) unsigned int skb_consumed; =20 skb_consumed =3D tcp_sk(ssk)->copied_seq - TCP_SKB_CB(skb)->seq; - if (WARN_ON_ONCE(skb_consumed >=3D skb->len)) + if (unlikely(skb_consumed >=3D skb->len)) return true; =20 return skb->len - skb_consumed <=3D subflow->map_data_len - --=20 2.45.2 From nobody Fri Jan 3 05:31:28 2025 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0AC4556B81; Sat, 19 Oct 2024 10:29:18 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1729333758; cv=none; b=Zg6xj7Qoevd1jIZFRIj6uy2/azcqhUPd+4W0LVKdhKhK7NjG849kPqJezNCkzBMt1L7UNHdydinQoTWmdL4iA/TQPkdE5cdzJqQz84veWj8IK5mruTduxc6rK8bJ6eUpAzZbS4sJyUinR2/rhicLk5BW5YsI7mo09ANha3XNIss= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1729333758; c=relaxed/simple; bh=K5YBnONewniJvt0wp3E4MXTUXkSnW9pxnlKxUvgNGuE=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=I62ekEyMSIkJVA3LYMj46b8MaWm1IbRBGczpNoPs9544jJriFDt0exUazwcq0pMo21+UHD05TAV845kcyJoU2BuQ0jP78FHleHP0fDmxE6eUH8ZaPRROjgwt0ciPbzViGUi9BMpzTEI3CrBQQVu/8iH6l2CaG1jyEpQ6U8ZNGTI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=rdqADpZt; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="rdqADpZt" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 07DEFC4CEC5; Sat, 19 Oct 2024 10:29:15 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1729333757; bh=K5YBnONewniJvt0wp3E4MXTUXkSnW9pxnlKxUvgNGuE=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=rdqADpZt9SCTdAksSDRDj+DnO2uDZ9HCw6pecfSPwvaIp6IWyyd1sRjsEJK+ng1ir dQBLJrFM4CkXceBFsn1/RLZpTUpSpHI5fHryl4M57p2oN3G5HYqCwYhnWNrD0Tb1ZG piSjFpjcXL9AGX0cVVZJ4exoMfvX+geXZUPamo7KpBzfSTKrle0ckqvjoAbGubHPNE jEcg5qaEkvchny76RRM2rtVf7YcvKVRy1pRb3vIiRKOb4xV2fDh+MRje7s5lZ/RQFk 5ViY9oTdRxr1jZ9dJv8zCUUvgjX4+YXLzm4Yik5622yitpEWn4EvoHpCzN5nPAy/Q6 uLK0X6Iu0ZEyw== From: "Matthieu Baerts (NGI0)" To: mptcp@lists.linux.dev, stable@vger.kernel.org, gregkh@linuxfoundation.org Cc: Paolo Abeni , sashal@kernel.org, syzbot+d1bff73460e33101f0e7@syzkaller.appspotmail.com, Matthieu Baerts , Jakub Kicinski Subject: [PATCH 5.10.y 3/3] tcp: fix mptcp DSS corruption due to large pmtu xmit Date: Sat, 19 Oct 2024 12:29:09 +0200 Message-ID: <20241019102905.3383483-8-matttbe@kernel.org> X-Mailer: git-send-email 2.45.2 In-Reply-To: <20241019102905.3383483-5-matttbe@kernel.org> References: <20241019102905.3383483-5-matttbe@kernel.org> Precedence: bulk X-Mailing-List: mptcp@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=7338; i=matttbe@kernel.org; h=from:subject; bh=ojETHMOMRvRrt27eZAhBiLeAAWqHvBX3+PNF4zvFgv4=; b=owEBbQKS/ZANAwAIAfa3gk9CaaBzAcsmYgBnE4nxV3Wulu1CFGAxP59/ItPweWFrC0j0gBLom apHaspmdD2JAjMEAAEIAB0WIQToy4X3aHcFem4n93r2t4JPQmmgcwUCZxOJ8QAKCRD2t4JPQmmg c73bEAC0v+iXHAlBee3U9Za3eOTyiO8dDycVCcNj8DCl4Ro2OkJoVRyqSE5lOUTWN24mfuYepZK 4FQ3lggRKIo9ZKvw5NJBWfZ5L9bTpwp/5iQsHzj2m1Dx+aB+jiNu37rItclDOL03wc6Y3VMNHHX oPbMHa7iLLhDW2I3pZi6Xyb4RflYR19ijeZTwfLtVjzaIo6yXkKxK7Ih+uXqBFU+R7eEi0uh7EN 1s4sWZhMdEVY9pBmTM/9g95+tZtiHJpb2iP1HLdrqMpy9FDvb8FpQYMMkSFkvhuEnwX5YWBTV3k oCf/VSfOiGrYsv7nnDt2Xv+w/6tTv7evtqy2dglM4lafeWidXkhj8hUEA2AV7tsIS8M5d51LuNz C1JyFpw+TzdMGEabUQAcj28iciskKjbMB6YsfSW1+jgIPlaV7ZV6uzQ9uu+Du0VarRi0pW8Lssj +uskt6gNPXb0IyWr+7gzbm8BL/cA3j8UY7/LBnvCB2O4jtOYzsh8pr+9wVtZEHh2tflCBJRXY8h iDddiGUSwvtXvHgUA8zL8StYiPhOzx8cwZxHfs6WQ/T7Hwgn0N2QDi/0BxP1fRc9t/3ix+hGZIy cFoBP713dosF6UlT9CJjHKmSZNPoiWsRGGtJ+XYVUptloITtCfHOjCdV08GqZ+wb8izvk4D9CFj osQ5MWtaua/4Fig== X-Developer-Key: i=matttbe@kernel.org; a=openpgp; fpr=E8CB85F76877057A6E27F77AF6B7824F4269A073 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Paolo Abeni commit 4dabcdf581217e60690467a37c956a5b8dbc6bd9 upstream. Syzkaller was able to trigger a DSS corruption: TCP: request_sock_subflow_v4: Possible SYN flooding on port [::]:20002. S= ending cookies. ------------[ cut here ]------------ WARNING: CPU: 0 PID: 5227 at net/mptcp/protocol.c:695 __mptcp_move_skbs_f= rom_subflow+0x20a9/0x21f0 net/mptcp/protocol.c:695 Modules linked in: CPU: 0 UID: 0 PID: 5227 Comm: syz-executor350 Not tainted 6.11.0-syzkalle= r-08829-gaf9c191ac2a0 #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS G= oogle 08/06/2024 RIP: 0010:__mptcp_move_skbs_from_subflow+0x20a9/0x21f0 net/mptcp/protocol= .c:695 Code: 0f b6 dc 31 ff 89 de e8 b5 dd ea f5 89 d8 48 81 c4 50 01 00 00 5b 4= 1 5c 41 5d 41 5e 41 5f 5d c3 cc cc cc cc e8 98 da ea f5 90 <0f> 0b 90 e9 47= ff ff ff e8 8a da ea f5 90 0f 0b 90 e9 99 e0 ff ff RSP: 0018:ffffc90000006db8 EFLAGS: 00010246 RAX: ffffffff8ba9df18 RBX: 00000000000055f0 RCX: ffff888030023c00 RDX: 0000000000000100 RSI: 00000000000081e5 RDI: 00000000000055f0 RBP: 1ffff110062bf1ae R08: ffffffff8ba9cf12 R09: 1ffff110062bf1b8 R10: dffffc0000000000 R11: ffffed10062bf1b9 R12: 0000000000000000 R13: dffffc0000000000 R14: 00000000700cec61 R15: 00000000000081e5 FS: 000055556679c380(0000) GS:ffff8880b8600000(0000) knlGS:0000000000000= 000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000000020287000 CR3: 0000000077892000 CR4: 00000000003506f0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 Call Trace: move_skbs_to_msk net/mptcp/protocol.c:811 [inline] mptcp_data_ready+0x29c/0xa90 net/mptcp/protocol.c:854 subflow_data_ready+0x34a/0x920 net/mptcp/subflow.c:1490 tcp_data_queue+0x20fd/0x76c0 net/ipv4/tcp_input.c:5283 tcp_rcv_established+0xfba/0x2020 net/ipv4/tcp_input.c:6237 tcp_v4_do_rcv+0x96d/0xc70 net/ipv4/tcp_ipv4.c:1915 tcp_v4_rcv+0x2dc0/0x37f0 net/ipv4/tcp_ipv4.c:2350 ip_protocol_deliver_rcu+0x22e/0x440 net/ipv4/ip_input.c:205 ip_local_deliver_finish+0x341/0x5f0 net/ipv4/ip_input.c:233 NF_HOOK+0x3a4/0x450 include/linux/netfilter.h:314 NF_HOOK+0x3a4/0x450 include/linux/netfilter.h:314 __netif_receive_skb_one_core net/core/dev.c:5662 [inline] __netif_receive_skb+0x2bf/0x650 net/core/dev.c:5775 process_backlog+0x662/0x15b0 net/core/dev.c:6107 __napi_poll+0xcb/0x490 net/core/dev.c:6771 napi_poll net/core/dev.c:6840 [inline] net_rx_action+0x89b/0x1240 net/core/dev.c:6962 handle_softirqs+0x2c5/0x980 kernel/softirq.c:554 do_softirq+0x11b/0x1e0 kernel/softirq.c:455 __local_bh_enable_ip+0x1bb/0x200 kernel/softirq.c:382 local_bh_enable include/linux/bottom_half.h:33 [inline] rcu_read_unlock_bh include/linux/rcupdate.h:919 [inline] __dev_queue_xmit+0x1764/0x3e80 net/core/dev.c:4451 dev_queue_xmit include/linux/netdevice.h:3094 [inline] neigh_hh_output include/net/neighbour.h:526 [inline] neigh_output include/net/neighbour.h:540 [inline] ip_finish_output2+0xd41/0x1390 net/ipv4/ip_output.c:236 ip_local_out net/ipv4/ip_output.c:130 [inline] __ip_queue_xmit+0x118c/0x1b80 net/ipv4/ip_output.c:536 __tcp_transmit_skb+0x2544/0x3b30 net/ipv4/tcp_output.c:1466 tcp_transmit_skb net/ipv4/tcp_output.c:1484 [inline] tcp_mtu_probe net/ipv4/tcp_output.c:2547 [inline] tcp_write_xmit+0x641d/0x6bf0 net/ipv4/tcp_output.c:2752 __tcp_push_pending_frames+0x9b/0x360 net/ipv4/tcp_output.c:3015 tcp_push_pending_frames include/net/tcp.h:2107 [inline] tcp_data_snd_check net/ipv4/tcp_input.c:5714 [inline] tcp_rcv_established+0x1026/0x2020 net/ipv4/tcp_input.c:6239 tcp_v4_do_rcv+0x96d/0xc70 net/ipv4/tcp_ipv4.c:1915 sk_backlog_rcv include/net/sock.h:1113 [inline] __release_sock+0x214/0x350 net/core/sock.c:3072 release_sock+0x61/0x1f0 net/core/sock.c:3626 mptcp_push_release net/mptcp/protocol.c:1486 [inline] __mptcp_push_pending+0x6b5/0x9f0 net/mptcp/protocol.c:1625 mptcp_sendmsg+0x10bb/0x1b10 net/mptcp/protocol.c:1903 sock_sendmsg_nosec net/socket.c:730 [inline] __sock_sendmsg+0x1a6/0x270 net/socket.c:745 ____sys_sendmsg+0x52a/0x7e0 net/socket.c:2603 ___sys_sendmsg net/socket.c:2657 [inline] __sys_sendmsg+0x2aa/0x390 net/socket.c:2686 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7fb06e9317f9 Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f= 7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff= ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48 RSP: 002b:00007ffe2cfd4f98 EFLAGS: 00000246 ORIG_RAX: 000000000000002e RAX: ffffffffffffffda RBX: 00007fb06e97f468 RCX: 00007fb06e9317f9 RDX: 0000000000000000 RSI: 0000000020000080 RDI: 0000000000000005 RBP: 00007fb06e97f446 R08: 0000555500000000 R09: 0000555500000000 R10: 0000555500000000 R11: 0000000000000246 R12: 00007fb06e97f406 R13: 0000000000000001 R14: 00007ffe2cfd4fe0 R15: 0000000000000003 Additionally syzkaller provided a nice reproducer. The repro enables pmtu on the loopback device, leading to tcp_mtu_probe() generating very large probe packets. tcp_can_coalesce_send_queue_head() currently does not check for mptcp-level invariants, and allowed the creation of cross-DSS probes, leading to the mentioned corruption. Address the issue teaching tcp_can_coalesce_send_queue_head() about mptcp using the tcp_skb_can_collapse(), also reducing the code duplication. Fixes: 85712484110d ("tcp: coalesce/collapse must respect MPTCP extensions") Cc: stable@vger.kernel.org Reported-by: syzbot+d1bff73460e33101f0e7@syzkaller.appspotmail.com Closes: https://github.com/multipath-tcp/mptcp_net-next/issues/513 Signed-off-by: Paolo Abeni Acked-by: Matthieu Baerts (NGI0) Signed-off-by: Matthieu Baerts (NGI0) Link: https://patch.msgid.link/20241008-net-mptcp-fallback-fixes-v1-2-c6fb8= e93e551@kernel.org Signed-off-by: Jakub Kicinski [ Conflict in tcp_output.c, because commit 65249feb6b3d ("net: add support for skbs with unreadable frags"), and commit 9b65b17db723 ("net: avoid double accounting for pure zerocopy skbs") are not in this version. These commits are linked to new features and introduce new conditions which cause the conflicts. Resolving this is easy: we can ignore the missing new condition, and use tcp_skb_can_collapse() like in the original patch. ] Signed-off-by: Matthieu Baerts (NGI0) --- net/ipv4/tcp_output.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/net/ipv4/tcp_output.c b/net/ipv4/tcp_output.c index 68f1633c477a..165be30e42c0 100644 --- a/net/ipv4/tcp_output.c +++ b/net/ipv4/tcp_output.c @@ -2305,7 +2305,7 @@ static bool tcp_can_coalesce_send_queue_head(struct s= ock *sk, int len) if (len <=3D skb->len) break; =20 - if (unlikely(TCP_SKB_CB(skb)->eor) || tcp_has_tx_tstamp(skb)) + if (tcp_has_tx_tstamp(skb) || !tcp_skb_can_collapse(skb, next)) return false; =20 len -=3D skb->len; --=20 2.45.2