Skip to content

Commit

Permalink
Phonet: remove dangling pipe if an endpoint is closed early
Browse files Browse the repository at this point in the history
Closing a pipe endpoint is not normally allowed by the Phonet pipe,
other than as a side after-effect of removing the pipe between two
endpoints. But there is no way to prevent Linux userspace processes
from being killed or suffering from bugs, so this can still happen.
We might as well forcefully close Phonet pipe endpoints then.

The cellular modem supports only a few existing pipes at a time. So we
really should not leak them. This change instructs the modem to destroy
the pipe if either of the pipe's endpoint (Linux socket) is closed too
early.

Signed-off-by: Rémi Denis-Courmont <remi.denis-courmont@nokia.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
  • Loading branch information
Rémi Denis-Courmont authored and David S. Miller committed Sep 16, 2010
1 parent 7fedd7e commit 6482f55
Show file tree
Hide file tree
Showing 2 changed files with 31 additions and 1 deletion.
5 changes: 5 additions & 0 deletions include/net/phonet/pep.h
Original file line number Diff line number Diff line change
Expand Up @@ -77,6 +77,11 @@ static inline struct pnpipehdr *pnp_hdr(struct sk_buff *skb)
#define MAX_PNPIPE_HEADER (MAX_PHONET_HEADER + 4)

enum {
PNS_PIPE_CREATE_REQ = 0x00,
PNS_PIPE_CREATE_RESP,
PNS_PIPE_REMOVE_REQ,
PNS_PIPE_REMOVE_RESP,

PNS_PIPE_DATA = 0x20,
PNS_PIPE_ALIGNED_DATA,

Expand Down
27 changes: 26 additions & 1 deletion net/phonet/pep.c
Original file line number Diff line number Diff line change
Expand Up @@ -620,6 +620,28 @@ static int pep_do_rcv(struct sock *sk, struct sk_buff *skb)
return err;
}

static int pipe_do_remove(struct sock *sk)
{
struct pep_sock *pn = pep_sk(sk);
struct pnpipehdr *ph;
struct sk_buff *skb;

skb = alloc_skb(MAX_PNPIPE_HEADER, GFP_KERNEL);
if (!skb)
return -ENOMEM;

skb_reserve(skb, MAX_PNPIPE_HEADER);
__skb_push(skb, sizeof(*ph));
skb_reset_transport_header(skb);
ph = pnp_hdr(skb);
ph->utid = 0;
ph->message_id = PNS_PIPE_REMOVE_REQ;
ph->pipe_handle = pn->pipe_handle;
ph->data[0] = PAD;

return pn_skb_send(sk, skb, &pipe_srv);
}

/* associated socket ceases to exist */
static void pep_sock_close(struct sock *sk, long timeout)
{
Expand All @@ -638,7 +660,10 @@ static void pep_sock_close(struct sock *sk, long timeout)
sk_for_each_safe(sknode, p, n, &pn->ackq)
sk_del_node_init(sknode);
sk->sk_state = TCP_CLOSE;
}
} else if ((1 << sk->sk_state) & (TCPF_SYN_RECV|TCPF_ESTABLISHED))
/* Forcefully remove dangling Phonet pipe */
pipe_do_remove(sk);

ifindex = pn->ifindex;
pn->ifindex = 0;
release_sock(sk);
Expand Down

0 comments on commit 6482f55

Please sign in to comment.