Commit 27ab2568 authored by Herbert Xu's avatar Herbert Xu Committed by David S. Miller

[UDP]: Avoid repeated counting of checksum errors due to peeking

Currently it is possible for two processes to peek on the same socket
and end up incrementing the error counter twice for the same packet.

This patch fixes it by making skb_kill_datagram return whether it
succeeded in unlinking the packet and only incrementing the counter
if it did.
Signed-off-by: default avatarHerbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: default avatarDavid S. Miller <davem@davemloft.net>
parent c8fecf22
...@@ -1549,7 +1549,7 @@ extern int skb_copy_and_csum_datagram_iovec(struct sk_buff *skb, ...@@ -1549,7 +1549,7 @@ extern int skb_copy_and_csum_datagram_iovec(struct sk_buff *skb,
int hlen, int hlen,
struct iovec *iov); struct iovec *iov);
extern void skb_free_datagram(struct sock *sk, struct sk_buff *skb); extern void skb_free_datagram(struct sock *sk, struct sk_buff *skb);
extern void skb_kill_datagram(struct sock *sk, struct sk_buff *skb, extern int skb_kill_datagram(struct sock *sk, struct sk_buff *skb,
unsigned int flags); unsigned int flags);
extern __wsum skb_checksum(const struct sk_buff *skb, int offset, extern __wsum skb_checksum(const struct sk_buff *skb, int offset,
int len, __wsum csum); int len, __wsum csum);
......
...@@ -217,20 +217,27 @@ void skb_free_datagram(struct sock *sk, struct sk_buff *skb) ...@@ -217,20 +217,27 @@ void skb_free_datagram(struct sock *sk, struct sk_buff *skb)
* This function currently only disables BH when acquiring the * This function currently only disables BH when acquiring the
* sk_receive_queue lock. Therefore it must not be used in a * sk_receive_queue lock. Therefore it must not be used in a
* context where that lock is acquired in an IRQ context. * context where that lock is acquired in an IRQ context.
*
* It returns 0 if the packet was removed by us.
*/ */
void skb_kill_datagram(struct sock *sk, struct sk_buff *skb, unsigned int flags) int skb_kill_datagram(struct sock *sk, struct sk_buff *skb, unsigned int flags)
{ {
int err = 0;
if (flags & MSG_PEEK) { if (flags & MSG_PEEK) {
err = -ENOENT;
spin_lock_bh(&sk->sk_receive_queue.lock); spin_lock_bh(&sk->sk_receive_queue.lock);
if (skb == skb_peek(&sk->sk_receive_queue)) { if (skb == skb_peek(&sk->sk_receive_queue)) {
__skb_unlink(skb, &sk->sk_receive_queue); __skb_unlink(skb, &sk->sk_receive_queue);
atomic_dec(&skb->users); atomic_dec(&skb->users);
err = 0;
} }
spin_unlock_bh(&sk->sk_receive_queue.lock); spin_unlock_bh(&sk->sk_receive_queue.lock);
} }
kfree_skb(skb); kfree_skb(skb);
return err;
} }
EXPORT_SYMBOL(skb_kill_datagram); EXPORT_SYMBOL(skb_kill_datagram);
......
...@@ -899,9 +899,8 @@ out: ...@@ -899,9 +899,8 @@ out:
return err; return err;
csum_copy_err: csum_copy_err:
UDP_INC_STATS_USER(UDP_MIB_INERRORS, is_udplite); if (!skb_kill_datagram(sk, skb, flags))
UDP_INC_STATS_USER(UDP_MIB_INERRORS, is_udplite);
skb_kill_datagram(sk, skb, flags);
if (noblock) if (noblock)
return -EAGAIN; return -EAGAIN;
......
...@@ -207,8 +207,8 @@ out: ...@@ -207,8 +207,8 @@ out:
return err; return err;
csum_copy_err: csum_copy_err:
UDP6_INC_STATS_USER(UDP_MIB_INERRORS, is_udplite); if (!skb_kill_datagram(sk, skb, flags))
skb_kill_datagram(sk, skb, flags); UDP6_INC_STATS_USER(UDP_MIB_INERRORS, is_udplite);
if (flags & MSG_DONTWAIT) if (flags & MSG_DONTWAIT)
return -EAGAIN; return -EAGAIN;
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment