android_kernel_motorola_sm6375/net/ipv6
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Subash Abhinov Kasiviswanathan de256ffb4a netfilter: x_tables: Switch synchronization to RCU
When running concurrent iptables rules replacement with data, the per CPU
sequence count is checked after the assignment of the new information.
The sequence count is used to synchronize with the packet path without the
use of any explicit locking. If there are any packets in the packet path
using the table information, the sequence count is incremented to an odd
value and is incremented to an even after the packet process completion.

The new table value assignment is followed by a write memory barrier so
every CPU should see the latest value. If the packet path has started with
the old table information, the sequence counter will be odd and the
iptables replacement will wait till the sequence count is even prior to
freeing the old table info.

However, this assumes that the new table information assignment and the
memory barrier is actually executed prior to the counter check in the
replacement thread. If CPU decides to execute the assignment later as there
is no user of the table information prior to the sequence check, the packet
path in another CPU may use the old table information. The replacement
thread would then free the table information under it leading to a use
after free in the packet processing context-

Unable to handle kernel NULL pointer dereference at virtual
address 000000000000008e
pc : ip6t_do_table+0x5d0/0x89c
lr : ip6t_do_table+0x5b8/0x89c
ip6t_do_table+0x5d0/0x89c
ip6table_filter_hook+0x24/0x30
nf_hook_slow+0x84/0x120
ip6_input+0x74/0xe0
ip6_rcv_finish+0x7c/0x128
ipv6_rcv+0xac/0xe4
__netif_receive_skb+0x84/0x17c
process_backlog+0x15c/0x1b8
napi_poll+0x88/0x284
net_rx_action+0xbc/0x23c
__do_softirq+0x20c/0x48c

This could be fixed by forcing instruction order after the new table
information assignment or by switching to RCU for the synchronization.

Change-Id: I41ffb931b711cd2de9896d9ca7f13dda79e6709f
Signed-off-by: Subash Abhinov Kasiviswanathan <subashab@codeaurora.org>
2020-12-09 10:18:47 -08:00
..
ila
netfilter netfilter: x_tables: Switch synchronization to RCU 2020-12-09 10:18:47 -08:00
addrconf.c This is the 5.4.32 stable release 2020-04-13 13:11:19 +02:00
addrconf_core.c net: ipv6_stub: use ip6_dst_lookup_flow instead of ip6_dst_lookup 2019-12-18 16:08:42 +01:00
addrlabel.c
af_inet6.c This is the 5.4.5 stable release 2019-12-18 16:54:08 +01:00
ah6.c
anycast.c ipv6: fix memory leaks on IPV6_ADDRFORM path 2020-08-11 15:33:39 +02:00
calipso.c netlabel: cope with NULL catmap 2020-05-20 08:20:08 +02:00
datagram.c net: Indicate whether a socket is a transparent socket 2020-04-13 12:06:23 -07:00
esp6.c
esp6_offload.c esp6: get the right proto for transport mode in esp6_gso_encap 2020-06-03 08:21:35 +02:00
exthdrs.c
exthdrs_core.c
exthdrs_offload.c
fib6_notifier.c
fib6_rules.c
fou6.c
icmp.c ip: Fix SO_MARK in RST, ACK and ICMP packets 2020-07-22 09:32:50 +02:00
inet6_connection_sock.c net: add bool confirm_neigh parameter for dst_ops.update_pmtu 2020-01-04 19:18:58 +01:00
inet6_hashtables.c
ip6_checksum.c
ip6_fib.c net: don't return invalid table id error when we fall back to PF_UNSPEC 2020-06-03 08:20:41 +02:00
ip6_flowlabel.c
ip6_gre.c ip6_gre: fix null-ptr-deref in ip6gre_init_net() 2020-07-31 18:39:30 +02:00
ip6_icmp.c
ip6_input.c
ip6_offload.c
ip6_offload.h
ip6_output.c net: ipv6: add net argument to ip6_dst_lookup_flow 2019-12-18 16:08:40 +01:00
ip6_tunnel.c net, ip6_tunnel: fix namespaces move 2020-01-29 16:45:20 +01:00
ip6_udp_tunnel.c
ip6_vti.c vti6: Fix memory leak of skb if input policy check fails 2020-04-01 11:02:12 +02:00
ip6mr.c net: don't return invalid table id error when we fall back to PF_UNSPEC 2020-06-03 08:20:41 +02:00
ipcomp6.c
ipv6_sockglue.c ipv6: fix memory leaks on IPV6_ADDRFORM path 2020-08-11 15:33:39 +02:00
Kconfig
Makefile
mcast.c mld: fix memory leak in ipv6_mc_destroy_dev() 2020-06-30 15:36:43 -04:00
mcast_snoop.c
mip6.c
ndisc.c UPSTREAM: ipv6: ndisc: add support for 'PREF64' dns64 prefix identifier 2020-03-31 03:17:50 -07:00
netfilter.c
output_core.c
ping.c
proc.c
protocol.c
raw.c net: ipv6: add net argument to ip6_dst_lookup_flow 2019-12-18 16:08:40 +01:00
reassembly.c
route.c This is the 5.4.58 stable release 2020-08-11 18:37:58 +02:00
seg6.c
seg6_hmac.c
seg6_iptunnel.c
seg6_local.c ipv6: sr: remove SKB_GSO_IPXIP6 on End.D* actions 2020-01-29 16:45:20 +01:00
sit.c sit: do not confirm neighbor when do pmtu update 2020-01-04 19:19:04 +01:00
syncookies.c net: ipv6: add net argument to ip6_dst_lookup_flow 2019-12-18 16:08:40 +01:00
sysctl_net_ipv6.c
tcp_ipv6.c net: Indicate whether a socket is a transparent socket 2020-04-13 12:06:23 -07:00
tcpv6_offload.c
tunnel6.c
udp.c udp: Improve load balancing for SO_REUSEPORT. 2020-07-31 18:39:31 +02:00
udp_impl.h
udp_offload.c UPSTREAM: udp: Support UDP fraglist GRO/GSO. 2020-09-09 08:48:03 +00:00
udplite.c
xfrm6_input.c
xfrm6_output.c xfrm: Always set XFRM_TRANSFORMED in xfrm{4,6}_output_finish 2020-04-29 16:33:11 +02:00
xfrm6_policy.c net: add bool confirm_neigh parameter for dst_ops.update_pmtu 2020-01-04 19:18:58 +01:00
xfrm6_protocol.c
xfrm6_state.c
xfrm6_tunnel.c