Received: by 10.213.65.68 with SMTP id h4csp2112626imn; Sun, 8 Apr 2018 20:02:23 -0700 (PDT) X-Google-Smtp-Source: AIpwx48+x+1v6VUxBLFBlFPf170OPQ15i6Zkh96p3oMsQgHzGjBwZwlMWJ+P16YnFFJqoJM11b0J X-Received: by 2002:a17:902:1025:: with SMTP id b34-v6mr19226329pla.324.1523242943732; Sun, 08 Apr 2018 20:02:23 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1523242943; cv=none; d=google.com; s=arc-20160816; b=DugHySwITnUCjSPr5Z8ZnxmPSyvxENXb3IvzSEgHpjRGvU8hP2Y4GynDoPfukTcqfu LXCPbFl0GP1xswg9YGk8AtsxcLZK+1gXn+sdob58FVZj9xYyntoDTTpNS30M/DDOTF4W gGkKhSP/bjBrhfkFbHeYucUmWeK+uzgSbQ41HBXxCQjTinxxvi3WnVdMP9eC1ZLWLiMn crGLZmq+uyUhcQxR7FYm1c9G5mwNjtD0LErunrQG1cJw9SfXwJTkn40Mx3l7RTx+q2OS VWqdc5kpIvvfST9TAKnwGDWejBtaKhPpO675Oyt1G7EH5E6xjhrvd2G5cb8eEbLQAwE3 7vNw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:mime-version:content-transfer-encoding :spamdiagnosticmetadata:spamdiagnosticoutput:content-language :accept-language:in-reply-to:references:message-id:date:thread-index :thread-topic:subject:cc:to:from:dkim-signature :arc-authentication-results; bh=mY6JM3pvf3oJYEPJYnAkS49q1yYsAfSvGIYMM12pfXo=; b=gL/iywd7zetZu0McJJWtMi735lMQ/Mg/zAJHc8EYeoMewCuxPllLrDbltzicm1SCyG Z7yjUZWkZwMcUrnw24tHsASROMFIZNNb3Tm1rOrAG4xnqToYiowh0IrCs30OfPjpb80q LTN9p6HV5B5vgo/D8uRmwCS9M/5SmJtGzApa+Nt+K1YeHM0GG1s5yt6tEn1nPUTD2Jcc cq5ZzYNkwE6MGvUes/Vtqz18oHkAUDNttBtobTUpzwDHD3dNG0G0Fu8aljUVWabrw/ok R350i8n5w7CghE/4rfSQLQE/unsYtBbBYtnwlVgx9uD93kC3A0pzQdb9v0wmXZ0TtpFc a7lA== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@microsoft.com header.s=selector1 header.b=K2bLKbqY; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=microsoft.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id o16si10399734pgc.832.2018.04.08.20.01.46; Sun, 08 Apr 2018 20:02:23 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@microsoft.com header.s=selector1 header.b=K2bLKbqY; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=microsoft.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1755292AbeDIAZx (ORCPT + 99 others); Sun, 8 Apr 2018 20:25:53 -0400 Received: from mail-bn3nam01on0139.outbound.protection.outlook.com ([104.47.33.139]:14848 "EHLO NAM01-BN3-obe.outbound.protection.outlook.com" rhost-flags-OK-OK-OK-FAIL) by vger.kernel.org with ESMTP id S1755165AbeDIAZm (ORCPT ); Sun, 8 Apr 2018 20:25:42 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=mY6JM3pvf3oJYEPJYnAkS49q1yYsAfSvGIYMM12pfXo=; b=K2bLKbqY06K9D3iyXJZ3NAREIohZUZTDZ/7U0N/uQj1M4shpQXD48Y02nvEN8oAL7xXBisDHz5D/qwXPdun0bUcDPGp3qng0QACEld0pkkK0x+JR2zawoQ8s5NmnUsBtGbMsvepl1qL5wiqgHExUciHC5iDRzAf4+5Z+SDjVVOg= Received: from DM5PR2101MB1032.namprd21.prod.outlook.com (52.132.128.13) by DM5PR2101MB1013.namprd21.prod.outlook.com (52.132.133.35) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.696.0; Mon, 9 Apr 2018 00:25:37 +0000 Received: from DM5PR2101MB1032.namprd21.prod.outlook.com ([fe80::8109:aef0:a777:7059]) by DM5PR2101MB1032.namprd21.prod.outlook.com ([fe80::8109:aef0:a777:7059%2]) with mapi id 15.20.0696.003; Mon, 9 Apr 2018 00:25:37 +0000 From: Sasha Levin To: "stable@vger.kernel.org" , "linux-kernel@vger.kernel.org" CC: John Fastabend , Daniel Borkmann , Sasha Levin Subject: [PATCH AUTOSEL for 4.14 130/161] bpf: sockmap, fix leaking maps with attached but not detached progs Thread-Topic: [PATCH AUTOSEL for 4.14 130/161] bpf: sockmap, fix leaking maps with attached but not detached progs Thread-Index: AQHTz5i6XVCjRUduTUSxwSCDJr87ag== Date: Mon, 9 Apr 2018 00:21:39 +0000 Message-ID: <20180409001936.162706-130-alexander.levin@microsoft.com> References: <20180409001936.162706-1-alexander.levin@microsoft.com> In-Reply-To: <20180409001936.162706-1-alexander.levin@microsoft.com> Accept-Language: en-US Content-Language: en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: x-originating-ip: [52.168.54.252] x-ms-publictraffictype: Email x-microsoft-exchange-diagnostics: 1;DM5PR2101MB1013;7:76dDk0EE8tP5PPu+EjS5BM7ZXr9c/AJlOZgM6iDou+7tBeWmip0plYMOuT0/ANMjabk9RqtP8i1Ld+J1MEkZXRJ+a3Bg5OBk+KyNt7i+OixX7/6ygqU2yYVYgwiK/nWSjSxbp7PGtmmJ7+u/GE6Q0we1vun8Jqf2dkpD4oFenrMcRyxxVX6HuAsFmpsPwMM6c12aBdfNdO6butWWdMWd3MLZguRrJ26hQraxr5y7FA7123LGK53bjLaP9DSEoENv;20:uaT3vnS6FJ3BrjSyHUDrL9oiBi/Q8IUWH1hZJEpBgCrw5qmUeig0BCAGp256BKuSEM/6Xcy02XWOuUwUbDxS6xC6jTP800hnoPoJ82QGUGHpacu9ulDv1ZI5M5vHOS5giyXMsF3P/8yA4S9KU+MJm5sU/9fQaD/I7gl3KWoQL0E= X-MS-Office365-Filtering-Correlation-Id: 91b37cb9-87ac-4520-a457-08d59db06ad1 x-ms-office365-filtering-ht: Tenant x-microsoft-antispam: UriScan:;BCL:0;PCL:0;RULEID:(7020095)(4652020)(4534165)(4627221)(201703031133081)(201702281549075)(5600026)(4604075)(3008032)(48565401081)(2017052603328)(7193020);SRVR:DM5PR2101MB1013; x-ms-traffictypediagnostic: DM5PR2101MB1013: authentication-results: spf=none (sender IP is ) smtp.mailfrom=Alexander.Levin@microsoft.com; x-microsoft-antispam-prvs: x-exchange-antispam-report-test: UriScan:(28532068793085)(89211679590171)(85827821059158); x-exchange-antispam-report-cfa-test: BCL:0;PCL:0;RULEID:(8211001083)(61425038)(6040522)(2401047)(8121501046)(5005006)(3231221)(944501327)(52105095)(3002001)(93006095)(93001095)(10201501046)(6055026)(61426038)(61427038)(6041310)(20161123560045)(20161123564045)(20161123558120)(20161123562045)(201703131423095)(201702281528075)(20161123555045)(201703061421075)(201703061406153)(6072148)(201708071742011);SRVR:DM5PR2101MB1013;BCL:0;PCL:0;RULEID:;SRVR:DM5PR2101MB1013; x-forefront-prvs: 0637FCE711 x-forefront-antispam-report: SFV:NSPM;SFS:(10019020)(346002)(366004)(376002)(396003)(39860400002)(39380400002)(189003)(199004)(3280700002)(2616005)(8936002)(7736002)(476003)(446003)(11346002)(53936002)(3660700001)(86362001)(86612001)(81156014)(2906002)(186003)(81166006)(105586002)(1076002)(8676002)(26005)(97736004)(25786009)(6512007)(3846002)(68736007)(72206003)(106356001)(5660300001)(6486002)(6116002)(14454004)(4326008)(305945005)(6436002)(2501003)(5890100001)(5250100002)(10290500003)(478600001)(2900100001)(59450400001)(22452003)(110136005)(39060400002)(316002)(99286004)(66066001)(10090500001)(107886003)(76176011)(102836004)(54906003)(6506007)(36756003)(486006)(22906009)(217873001);DIR:OUT;SFP:1102;SCL:1;SRVR:DM5PR2101MB1013;H:DM5PR2101MB1032.namprd21.prod.outlook.com;FPR:;SPF:None;LANG:en;PTR:InfoNoRecords;MX:1;A:1; received-spf: None (protection.outlook.com: microsoft.com does not designate permitted sender hosts) x-microsoft-antispam-message-info: PrX+k7lIisO5pnsXzIG92naOhB1770VIHGZCEqf5nJOgc5qPkFnF01XoxmI+Lx1oAGUjezBGMmVfhJ2oUBkPBB8mvU06b7ziNweDZr3Bm9+dcH3EGv4I61vDT3n/lRfAaXkUYZz1QPebR6bSIRr4dcpThoQK2wsgCchytFTTi7+6jJBk9ZpXL/zDU56gfmEnLr2Z0QdmoqVEqfhW5V5WvvMJ36gM8EzG8zQTQyICRkyRISMTD4QwowYtuWwp98l4VvvEO920C/NTdw6emQ0ejkAKnABSbKq1wPqcBRpmn7gYYsI3U1jSt1L3js9lszkpAvc5YYUwsLshn0qI2VvtfUFdaLshGDscTjuSI69PxnhWjlh7/P2L8sBsYYyMxgKjFblferYOH1g2/GQ0bnzzQb1mGmfosVNluDNLnwfVSoQ= spamdiagnosticoutput: 1:99 spamdiagnosticmetadata: NSPM Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 X-OriginatorOrg: microsoft.com X-MS-Exchange-CrossTenant-Network-Message-Id: 91b37cb9-87ac-4520-a457-08d59db06ad1 X-MS-Exchange-CrossTenant-originalarrivaltime: 09 Apr 2018 00:21:39.9092 (UTC) X-MS-Exchange-CrossTenant-fromentityheader: Hosted X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47 X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM5PR2101MB1013 Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org From: John Fastabend [ Upstream commit 3d9e952697de89b53227f06d4241f275eb99cfc4 ] When a program is attached to a map we increment the program refcnt to ensure that the program is not removed while it is potentially being referenced from sockmap side. However, if this same program also references the map (this is a reasonably common pattern in my programs) then the verifier will also increment the maps refcnt from the verifier. This is to ensure the map doesn't get garbage collected while the program has a reference to it. So we are left in a state where the map holds the refcnt on the program stopping it from being removed and releasing the map refcnt. And vice versa the program holds a refcnt on the map stopping it from releasing the refcnt on the prog. All this is fine as long as users detach the program while the map fd is still around. But, if the user omits this detach command we are left with a dangling map we can no longer release. To resolve this when the map fd is released decrement the program references and remove any reference from the map to the program. This fixes the issue with possibly dangling map and creates a user side API constraint. That is, the map fd must be held open for programs to be attached to a map. Fixes: 174a79ff9515 ("bpf: sockmap with sk redirect support") Signed-off-by: John Fastabend Signed-off-by: Daniel Borkmann Signed-off-by: Sasha Levin --- kernel/bpf/sockmap.c | 19 ++++++++++++++----- 1 file changed, 14 insertions(+), 5 deletions(-) diff --git a/kernel/bpf/sockmap.c b/kernel/bpf/sockmap.c index 1890be7ea9cd..53a4787c08d8 100644 --- a/kernel/bpf/sockmap.c +++ b/kernel/bpf/sockmap.c @@ -601,11 +601,6 @@ static void sock_map_free(struct bpf_map *map) } rcu_read_unlock(); =20 - if (stab->bpf_verdict) - bpf_prog_put(stab->bpf_verdict); - if (stab->bpf_parse) - bpf_prog_put(stab->bpf_parse); - sock_map_remove_complete(stab); } =20 @@ -877,6 +872,19 @@ static int sock_map_update_elem(struct bpf_map *map, return err; } =20 +static void sock_map_release(struct bpf_map *map, struct file *map_file) +{ + struct bpf_stab *stab =3D container_of(map, struct bpf_stab, map); + struct bpf_prog *orig; + + orig =3D xchg(&stab->bpf_parse, NULL); + if (orig) + bpf_prog_put(orig); + orig =3D xchg(&stab->bpf_verdict, NULL); + if (orig) + bpf_prog_put(orig); +} + const struct bpf_map_ops sock_map_ops =3D { .map_alloc =3D sock_map_alloc, .map_free =3D sock_map_free, @@ -884,6 +892,7 @@ const struct bpf_map_ops sock_map_ops =3D { .map_get_next_key =3D sock_map_get_next_key, .map_update_elem =3D sock_map_update_elem, .map_delete_elem =3D sock_map_delete_elem, + .map_release =3D sock_map_release, }; =20 BPF_CALL_4(bpf_sock_map_update, struct bpf_sock_ops_kern *, bpf_sock, --=20 2.15.1