Skip to content

Commit dfbafc9

Browse files
qsndavem330
authored andcommitted
tcp: fix recv with flags MSG_WAITALL | MSG_PEEK
Currently, tcp_recvmsg enters a busy loop in sk_wait_data if called with flags = MSG_WAITALL | MSG_PEEK. sk_wait_data waits for sk_receive_queue not empty, but in this case, the receive queue is not empty, but does not contain any skb that we can use. Add a "last skb seen on receive queue" argument to sk_wait_data, so that it sleeps until the receive queue has new skbs. Link: https://bugzilla.kernel.org/show_bug.cgi?id=99461 Link: https://sourceware.org/bugzilla/show_bug.cgi?id=18493 Link: https://bugzilla.redhat.com/show_bug.cgi?id=1205258 Reported-by: Enrico Scholz <rh-bugzilla@ensc.de> Reported-by: Dan Searle <dan@censornet.com> Signed-off-by: Sabrina Dubroca <sd@queasysnail.net> Acked-by: Eric Dumazet <edumazet@google.com> Signed-off-by: David S. Miller <davem@davemloft.net>
1 parent 3d3af88 commit dfbafc9

File tree

5 files changed

+14
-10
lines changed

5 files changed

+14
-10
lines changed

include/net/sock.h

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -902,7 +902,7 @@ void sk_stream_kill_queues(struct sock *sk);
902902
void sk_set_memalloc(struct sock *sk);
903903
void sk_clear_memalloc(struct sock *sk);
904904

905-
int sk_wait_data(struct sock *sk, long *timeo);
905+
int sk_wait_data(struct sock *sk, long *timeo, const struct sk_buff *skb);
906906

907907
struct request_sock_ops;
908908
struct timewait_sock_ops;

net/core/sock.c

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1967,20 +1967,21 @@ static void __release_sock(struct sock *sk)
19671967
* sk_wait_data - wait for data to arrive at sk_receive_queue
19681968
* @sk: sock to wait on
19691969
* @timeo: for how long
1970+
* @skb: last skb seen on sk_receive_queue
19701971
*
19711972
* Now socket state including sk->sk_err is changed only under lock,
19721973
* hence we may omit checks after joining wait queue.
19731974
* We check receive queue before schedule() only as optimization;
19741975
* it is very likely that release_sock() added new data.
19751976
*/
1976-
int sk_wait_data(struct sock *sk, long *timeo)
1977+
int sk_wait_data(struct sock *sk, long *timeo, const struct sk_buff *skb)
19771978
{
19781979
int rc;
19791980
DEFINE_WAIT(wait);
19801981

19811982
prepare_to_wait(sk_sleep(sk), &wait, TASK_INTERRUPTIBLE);
19821983
set_bit(SOCK_ASYNC_WAITDATA, &sk->sk_socket->flags);
1983-
rc = sk_wait_event(sk, timeo, !skb_queue_empty(&sk->sk_receive_queue));
1984+
rc = sk_wait_event(sk, timeo, skb_peek_tail(&sk->sk_receive_queue) != skb);
19841985
clear_bit(SOCK_ASYNC_WAITDATA, &sk->sk_socket->flags);
19851986
finish_wait(sk_sleep(sk), &wait);
19861987
return rc;

net/dccp/proto.c

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -886,7 +886,7 @@ int dccp_recvmsg(struct sock *sk, struct msghdr *msg, size_t len, int nonblock,
886886
break;
887887
}
888888

889-
sk_wait_data(sk, &timeo);
889+
sk_wait_data(sk, &timeo, NULL);
890890
continue;
891891
found_ok_skb:
892892
if (len > skb->len)

net/ipv4/tcp.c

Lines changed: 7 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -780,7 +780,7 @@ ssize_t tcp_splice_read(struct socket *sock, loff_t *ppos,
780780
ret = -EAGAIN;
781781
break;
782782
}
783-
sk_wait_data(sk, &timeo);
783+
sk_wait_data(sk, &timeo, NULL);
784784
if (signal_pending(current)) {
785785
ret = sock_intr_errno(timeo);
786786
break;
@@ -1575,7 +1575,7 @@ int tcp_recvmsg(struct sock *sk, struct msghdr *msg, size_t len, int nonblock,
15751575
int target; /* Read at least this many bytes */
15761576
long timeo;
15771577
struct task_struct *user_recv = NULL;
1578-
struct sk_buff *skb;
1578+
struct sk_buff *skb, *last;
15791579
u32 urg_hole = 0;
15801580

15811581
if (unlikely(flags & MSG_ERRQUEUE))
@@ -1635,7 +1635,9 @@ int tcp_recvmsg(struct sock *sk, struct msghdr *msg, size_t len, int nonblock,
16351635

16361636
/* Next get a buffer. */
16371637

1638+
last = skb_peek_tail(&sk->sk_receive_queue);
16381639
skb_queue_walk(&sk->sk_receive_queue, skb) {
1640+
last = skb;
16391641
/* Now that we have two receive queues this
16401642
* shouldn't happen.
16411643
*/
@@ -1754,8 +1756,9 @@ int tcp_recvmsg(struct sock *sk, struct msghdr *msg, size_t len, int nonblock,
17541756
/* Do not sleep, just process backlog. */
17551757
release_sock(sk);
17561758
lock_sock(sk);
1757-
} else
1758-
sk_wait_data(sk, &timeo);
1759+
} else {
1760+
sk_wait_data(sk, &timeo, last);
1761+
}
17591762

17601763
if (user_recv) {
17611764
int chunk;

net/llc/af_llc.c

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -613,7 +613,7 @@ static int llc_wait_data(struct sock *sk, long timeo)
613613
if (signal_pending(current))
614614
break;
615615
rc = 0;
616-
if (sk_wait_data(sk, &timeo))
616+
if (sk_wait_data(sk, &timeo, NULL))
617617
break;
618618
}
619619
return rc;
@@ -802,7 +802,7 @@ static int llc_ui_recvmsg(struct socket *sock, struct msghdr *msg, size_t len,
802802
release_sock(sk);
803803
lock_sock(sk);
804804
} else
805-
sk_wait_data(sk, &timeo);
805+
sk_wait_data(sk, &timeo, NULL);
806806

807807
if ((flags & MSG_PEEK) && peek_seq != llc->copied_seq) {
808808
net_dbg_ratelimited("LLC(%s:%d): Application bug, race in MSG_PEEK\n",

0 commit comments

Comments
 (0)