Skip to content

Commit

Permalink
mptcp: prevent tcp diag from closing listener subflows
Browse files Browse the repository at this point in the history
The MPTCP protocol does not expect that any other entity could change
the first subflow status when such socket is listening.
Unfortunately the TCP diag interface allows aborting any TCP socket,
including MPTCP listeners subflows. As reported by syzbot, that trigger
a WARN() and could lead to later bigger trouble.

The MPTCP protocol needs to do some MPTCP-level cleanup actions to
properly shutdown the listener. To keep the fix simple, prevent
entirely the diag interface from stopping such listeners.

We could refine the diag callback in a later, larger patch targeting
net-next.

Fixes: 57fc0f1 ("mptcp: ensure listener is unhashed before updating the sk status")
Closes: https://lore.kernel.org/netdev/[email protected]/
Reported-by: [email protected]
Signed-off-by: Paolo Abeni <[email protected]>
  • Loading branch information
Paolo Abeni authored and intel-lab-lkp committed Dec 15, 2023
1 parent 41512e5 commit d06ad5c
Showing 1 changed file with 13 additions and 0 deletions.
13 changes: 13 additions & 0 deletions net/mptcp/subflow.c
Original file line number Diff line number Diff line change
Expand Up @@ -1981,6 +1981,17 @@ static void tcp_release_cb_override(struct sock *ssk)
tcp_release_cb(ssk);
}

static int tcp_abort_override(struct sock *ssk, int err)
{
/* closing a listener subflow requires a great deal of care.
* keep it simple and just prevent such operation
*/
if (inet_sk_state_load(ssk) == TCP_LISTEN)
return -EINVAL;

return tcp_abort(ssk, err);
}

static struct tcp_ulp_ops subflow_ulp_ops __read_mostly = {
.name = "mptcp",
.owner = THIS_MODULE,
Expand Down Expand Up @@ -2025,6 +2036,7 @@ void __init mptcp_subflow_init(void)

tcp_prot_override = tcp_prot;
tcp_prot_override.release_cb = tcp_release_cb_override;
tcp_prot_override.diag_destroy = tcp_abort_override;

#if IS_ENABLED(CONFIG_MPTCP_IPV6)
/* In struct mptcp_subflow_request_sock, we assume the TCP request sock
Expand Down Expand Up @@ -2060,6 +2072,7 @@ void __init mptcp_subflow_init(void)

tcpv6_prot_override = tcpv6_prot;
tcpv6_prot_override.release_cb = tcp_release_cb_override;
tcpv6_prot_override.diag_destroy = tcp_abort_override;
#endif

mptcp_diag_subflow_init(&subflow_ulp_ops);
Expand Down

0 comments on commit d06ad5c

Please sign in to comment.