Page MenuHomeFreeBSD

netlink: answer a request whose reply ran out of memory
Needs ReviewPublic

Authored by rcm on Fri, Oct 2, 2:45 PM.
Tags
None
Referenced Files
F174409668: D60249.id188396.diff
Sat, Oct 3, 12:11 AM
F174409378: D60249.diff
Sat, Oct 3, 12:08 AM
F174402765: D60249.id188445.diff
Fri, Oct 2, 11:01 PM
F174400096: D60249.id188423.diff
Fri, Oct 2, 10:32 PM
F174353733: D60249.diff
Fri, Oct 2, 3:35 PM
Subscribers

Details

Reviewers
glebius
melifaro
Summary

A writer that fails to allocate a buffer refuses every later message,
the ack and NLMSG_DONE included. nlmsg_end_dump() ignored that,
reported success and suppressed the ack. Either way the request got no
answer and its sender waited for ever. The requests of a whole send(2)
were lost the same way when the first buffer of the writer could not be
allocated.

Neither that buffer nor the ack is allocated with locks held, so let
both wait for memory. Send the ack with ENOMEM for every reply that
ran out of memory: that also ends a dump that nlmsg_end_dump() could
not.

Replies to Linux processes can still be lost when their translation
runs out of memory.

Fixes: 7e5bf68495cc ("netlink: add netlink support")
Fixes: f4d3aa749084 ("netlink: suppress sending NLMSG_ERROR if NLMSG_DONE is already sent")
MFC after: 1 week
Sponsored by: Rubicon Communications, LLC ("Netgate")

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Skipped
Unit
Tests Skipped

Event Timeline

rcm requested review of this revision.Fri, Oct 2, 2:45 PM
rcm retitled this revision from netlink: end a dump that ran out of memory to netlink: always answer a request whose reply ran out of memory.
rcm edited the summary of this revision. (Show Details)
rcm changed the visibility from "Public (No Login Required)" to "rcm (R. Christian McDonald)".
rcm changed the edit policy from "All Users" to "rcm (R. Christian McDonald)".

The first version made room for NLMSG_DONE by overwriting completed messages in the writer's buffer, which could discard replies to earlier requests from the same send() and still left non-dump requests without an ack. This version drops that: nlmsg_ack() now waits for memory and reports ENOMEM for any reply that ran out of it, so a failed dump ends with NLMSG_ERROR after its complete messages and every request gets an answer.

rcm retitled this revision from netlink: always answer a request whose reply ran out of memory to netlink: answer a request whose reply ran out of memory.
rcm edited the summary of this revision. (Show Details)
rcm changed the edit policy from "rcm (R. Christian McDonald)" to "All Users".
rcm changed the visibility from "All Users" to "Public (No Login Required)".Fri, Oct 2, 5:06 PM