From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-26.2 required=3.0 tests=BAYES_00,DKIMWL_WL_MED, DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,HEADER_FROM_DIFFERENT_DOMAINS, INCLUDES_CR_TRAILER,INCLUDES_PATCH,MAILING_LIST_MULTI,SPF_HELO_NONE,SPF_PASS, URIBL_BLOCKED,USER_AGENT_GIT,USER_IN_DEF_DKIM_WL autolearn=ham autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id C6618C433DB for ; Mon, 1 Feb 2021 16:05:55 +0000 (UTC) Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by mail.kernel.org (Postfix) with ESMTP id 9514264D7F for ; Mon, 1 Feb 2021 16:05:55 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S230159AbhBAQFi (ORCPT ); Mon, 1 Feb 2021 11:05:38 -0500 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:49326 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S229696AbhBAQF1 (ORCPT ); Mon, 1 Feb 2021 11:05:27 -0500 Received: from mail-wm1-x34a.google.com (mail-wm1-x34a.google.com [IPv6:2a00:1450:4864:20::34a]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id C2F20C061573 for ; Mon, 1 Feb 2021 08:04:46 -0800 (PST) Received: by mail-wm1-x34a.google.com with SMTP id y9so5014515wmi.8 for ; Mon, 01 Feb 2021 08:04:46 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=sender:date:message-id:mime-version:subject:from:to:cc; bh=k0C1xWSejIoCUIkR3Xdpp2QfnBoYRRN5HyYkZB6dBTA=; b=NepNoYaSqyIEMzp6Df1/nXS4fC6aPClhYVE07/UQ8P/TA/6hzQq8i4FI1xSSiIMehd JBC4glTTbdqOCO/siFNbS2TTeBHRfWbLk2zqwrl88bzHvv2xfjxmFD5zNrDfFHnnmliK LyYwHowk9nqaJAWtjk0M7k5kGcTTCrvW6oN/+mG/pJHIISh7b/el2cPEP75uvJo2Bmyh IJf28vVsat0mk2unsmH4O/0QG2kWQWtgIAHMrkmmcNmMhKvj+XKzNS3aZSVDOBSUVAeQ NQMBdGPGBnbBnc9Vqzrbrrhq2PBnRwkJfvi34kcKwjrNey1eftKXLGNGt6re4wvO40mD Q4vQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:sender:date:message-id:mime-version:subject:from :to:cc; bh=k0C1xWSejIoCUIkR3Xdpp2QfnBoYRRN5HyYkZB6dBTA=; b=YsB9OK7rdVGn2svGG3xhrMM1hiHZxiIIOp3XIAngm+lqA1LqE2Ayg282I8HJ9nReZq bc0FHVbBwA2ik/UbIjJIeEyrJgAt3ELOxBae+hIkb+CEDZa/Q61DGxbtgVi7wDQjzrP6 Fh7PKXIVpyrtewsLBGLI7ZOQPmSWiHQEAKgqwOL6lnBkf1uGjunMIVKsGw65aR6TUPIz 6GMtuqi3BkC0x8kcrX7TBOEQcvmUf4Z5kxgajNXgbEuPBqdIyY8nT3om6OCRE4JaUAoE D6xszrSc5Gt+L89Mc/DvhAEiiQsSJZygqcHqLxr2XIG0y2geZ5GZTr+pD5Ho6p+IPmlN 3hog== X-Gm-Message-State: AOAM532tEj2pnfrbpMBavDKsMesYzEcoIlgHblkJ0kxhNPt5qus98rtF nC3KV8IWMZMDPYNqQxASjJYDoQA2Aw== X-Google-Smtp-Source: ABdhPJyfdxQAQE01yNUQDQX5ATRJfd8Q1f/BzqudRhIhMaukawQGypsRjYGiYl0suwLJ8tqxRRVJ6lOy8g== Sender: "elver via sendgmr" X-Received: from elver.muc.corp.google.com ([2a00:79e0:15:13:f693:9fff:fef4:2449]) (user=elver job=sendgmr) by 2002:a7b:c76e:: with SMTP id x14mr2587288wmk.17.1612195485394; Mon, 01 Feb 2021 08:04:45 -0800 (PST) Date: Mon, 1 Feb 2021 17:04:20 +0100 Message-Id: <20210201160420.2826895-1-elver@google.com> Mime-Version: 1.0 X-Mailer: git-send-email 2.30.0.365.g02bc693789-goog Subject: [PATCH net-next] net: fix up truesize of cloned skb in skb_prepare_for_shift() From: Marco Elver To: elver@google.com Cc: linux-kernel@vger.kernel.org, kasan-dev@googlegroups.com, davem@davemloft.net, kuba@kernel.org, jonathan.lemon@gmail.com, willemb@google.com, linmiaohe@huawei.com, gnault@redhat.com, dseok.yi@samsung.com, kyk.segfault@gmail.com, viro@zeniv.linux.org.uk, netdev@vger.kernel.org, glider@google.com, syzbot+7b99aafdcc2eedea6178@syzkaller.appspotmail.com, Eric Dumazet Content-Type: text/plain; charset="UTF-8" Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Avoid the assumption that ksize(kmalloc(S)) == ksize(kmalloc(S)): when cloning an skb, save and restore truesize after pskb_expand_head(). This can occur if the allocator decides to service an allocation of the same size differently (e.g. use a different size class, or pass the allocation on to KFENCE). Because truesize is used for bookkeeping (such as sk_wmem_queued), a modified truesize of a cloned skb may result in corrupt bookkeeping and relevant warnings (such as in sk_stream_kill_queues()). Link: https://lkml.kernel.org/r/X9JR/J6dMMOy1obu@elver.google.com Reported-by: syzbot+7b99aafdcc2eedea6178@syzkaller.appspotmail.com Suggested-by: Eric Dumazet Signed-off-by: Marco Elver --- net/core/skbuff.c | 14 +++++++++++++- 1 file changed, 13 insertions(+), 1 deletion(-) diff --git a/net/core/skbuff.c b/net/core/skbuff.c index 2af12f7e170c..3787093239f5 100644 --- a/net/core/skbuff.c +++ b/net/core/skbuff.c @@ -3289,7 +3289,19 @@ EXPORT_SYMBOL(skb_split); */ static int skb_prepare_for_shift(struct sk_buff *skb) { - return skb_cloned(skb) && pskb_expand_head(skb, 0, 0, GFP_ATOMIC); + int ret = 0; + + if (skb_cloned(skb)) { + /* Save and restore truesize: pskb_expand_head() may reallocate + * memory where ksize(kmalloc(S)) != ksize(kmalloc(S)), but we + * cannot change truesize at this point. + */ + unsigned int save_truesize = skb->truesize; + + ret = pskb_expand_head(skb, 0, 0, GFP_ATOMIC); + skb->truesize = save_truesize; + } + return ret; } /** base-commit: 14e8e0f6008865d823a8184a276702a6c3cbef3d -- 2.30.0.365.g02bc693789-goog