0010-tap-free-skb-if-flags-error.patch 1.7 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758
  1. From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
  2. From: Wei Xu <[email protected]>
  3. Date: Fri, 1 Dec 2017 05:10:38 -0500
  4. Subject: [PATCH] tap: free skb if flags error
  5. MIME-Version: 1.0
  6. Content-Type: text/plain; charset=UTF-8
  7. Content-Transfer-Encoding: 8bit
  8. tap_recvmsg() supports accepting skb by msg_control after
  9. commit 3b4ba04acca8 ("tap: support receiving skb from msg_control"),
  10. the skb if presented should be freed within the function, otherwise
  11. it would be leaked.
  12. Signed-off-by: Wei Xu <[email protected]>
  13. Reported-by: Matthew Rosato <[email protected]>
  14. Signed-off-by: Fabian Grünbichler <[email protected]>
  15. ---
  16. drivers/net/tap.c | 14 ++++++++++----
  17. 1 file changed, 10 insertions(+), 4 deletions(-)
  18. diff --git a/drivers/net/tap.c b/drivers/net/tap.c
  19. index 3570c7576993..4e04b6094f3c 100644
  20. --- a/drivers/net/tap.c
  21. +++ b/drivers/net/tap.c
  22. @@ -829,8 +829,11 @@ static ssize_t tap_do_read(struct tap_queue *q,
  23. DEFINE_WAIT(wait);
  24. ssize_t ret = 0;
  25. - if (!iov_iter_count(to))
  26. + if (!iov_iter_count(to)) {
  27. + if (skb)
  28. + kfree_skb(skb);
  29. return 0;
  30. + }
  31. if (skb)
  32. goto put;
  33. @@ -1155,11 +1158,14 @@ static int tap_recvmsg(struct socket *sock, struct msghdr *m,
  34. size_t total_len, int flags)
  35. {
  36. struct tap_queue *q = container_of(sock, struct tap_queue, sock);
  37. + struct sk_buff *skb = m->msg_control;
  38. int ret;
  39. - if (flags & ~(MSG_DONTWAIT|MSG_TRUNC))
  40. + if (flags & ~(MSG_DONTWAIT|MSG_TRUNC)) {
  41. + if (skb)
  42. + kfree_skb(skb);
  43. return -EINVAL;
  44. - ret = tap_do_read(q, &m->msg_iter, flags & MSG_DONTWAIT,
  45. - m->msg_control);
  46. + }
  47. + ret = tap_do_read(q, &m->msg_iter, flags & MSG_DONTWAIT, skb);
  48. if (ret > total_len) {
  49. m->msg_flags |= MSG_TRUNC;
  50. ret = flags & MSG_TRUNC ? ret : total_len;
  51. --
  52. 2.14.2