Skip to content

Commit 2d3916f

Browse files
edumazetkuba-moo
authored andcommitted
ipv6: fix skb drops in igmp6_event_query() and igmp6_event_report()
While investigating on why a synchronize_net() has been added recently in ipv6_mc_down(), I found that igmp6_event_query() and igmp6_event_report() might drop skbs in some cases. Discussion about removing synchronize_net() from ipv6_mc_down() will happen in a different thread. Fixes: f185de2 ("mld: add new workqueues for process mld events") Signed-off-by: Eric Dumazet <edumazet@google.com> Cc: Taehee Yoo <ap420073@gmail.com> Cc: Cong Wang <xiyou.wangcong@gmail.com> Cc: David Ahern <dsahern@kernel.org> Link: https://lore.kernel.org/r/20220303173728.937869-1-eric.dumazet@gmail.com Signed-off-by: Jakub Kicinski <kuba@kernel.org>
1 parent e1bec7f commit 2d3916f

2 files changed

Lines changed: 14 additions & 22 deletions

File tree

include/net/ndisc.h

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -475,9 +475,9 @@ int igmp6_late_init(void);
475475
void igmp6_cleanup(void);
476476
void igmp6_late_cleanup(void);
477477

478-
int igmp6_event_query(struct sk_buff *skb);
478+
void igmp6_event_query(struct sk_buff *skb);
479479

480-
int igmp6_event_report(struct sk_buff *skb);
480+
void igmp6_event_report(struct sk_buff *skb);
481481

482482

483483
#ifdef CONFIG_SYSCTL

net/ipv6/mcast.c

Lines changed: 12 additions & 20 deletions
Original file line numberDiff line numberDiff line change
@@ -1371,27 +1371,23 @@ static void mld_process_v2(struct inet6_dev *idev, struct mld2_query *mld,
13711371
}
13721372

13731373
/* called with rcu_read_lock() */
1374-
int igmp6_event_query(struct sk_buff *skb)
1374+
void igmp6_event_query(struct sk_buff *skb)
13751375
{
13761376
struct inet6_dev *idev = __in6_dev_get(skb->dev);
13771377

1378-
if (!idev)
1379-
return -EINVAL;
1380-
1381-
if (idev->dead) {
1382-
kfree_skb(skb);
1383-
return -ENODEV;
1384-
}
1378+
if (!idev || idev->dead)
1379+
goto out;
13851380

13861381
spin_lock_bh(&idev->mc_query_lock);
13871382
if (skb_queue_len(&idev->mc_query_queue) < MLD_MAX_SKBS) {
13881383
__skb_queue_tail(&idev->mc_query_queue, skb);
13891384
if (!mod_delayed_work(mld_wq, &idev->mc_query_work, 0))
13901385
in6_dev_hold(idev);
1386+
skb = NULL;
13911387
}
13921388
spin_unlock_bh(&idev->mc_query_lock);
1393-
1394-
return 0;
1389+
out:
1390+
kfree_skb(skb);
13951391
}
13961392

13971393
static void __mld_query_work(struct sk_buff *skb)
@@ -1542,27 +1538,23 @@ static void mld_query_work(struct work_struct *work)
15421538
}
15431539

15441540
/* called with rcu_read_lock() */
1545-
int igmp6_event_report(struct sk_buff *skb)
1541+
void igmp6_event_report(struct sk_buff *skb)
15461542
{
15471543
struct inet6_dev *idev = __in6_dev_get(skb->dev);
15481544

1549-
if (!idev)
1550-
return -EINVAL;
1551-
1552-
if (idev->dead) {
1553-
kfree_skb(skb);
1554-
return -ENODEV;
1555-
}
1545+
if (!idev || idev->dead)
1546+
goto out;
15561547

15571548
spin_lock_bh(&idev->mc_report_lock);
15581549
if (skb_queue_len(&idev->mc_report_queue) < MLD_MAX_SKBS) {
15591550
__skb_queue_tail(&idev->mc_report_queue, skb);
15601551
if (!mod_delayed_work(mld_wq, &idev->mc_report_work, 0))
15611552
in6_dev_hold(idev);
1553+
skb = NULL;
15621554
}
15631555
spin_unlock_bh(&idev->mc_report_lock);
1564-
1565-
return 0;
1556+
out:
1557+
kfree_skb(skb);
15661558
}
15671559

15681560
static void __mld_report_work(struct sk_buff *skb)

0 commit comments

Comments
 (0)