Page MenuHomeFreeBSD

sbappendcontrol() needs to avoid clearing M_NOTREADY on data mbufs.
ClosedPublic

Authored by markj on Apr 7 2020, 9:53 PM.
Tags
None
Referenced Files
F170723073: D24333.id70321.diff
Sun, Sep 6, 5:37 AM
F170699637: D24333.id70416.diff
Sun, Sep 6, 2:25 AM
Unknown Object (File)
Sat, Sep 5, 1:53 AM
Unknown Object (File)
Fri, Sep 4, 2:02 AM
Unknown Object (File)
Mon, Aug 31, 11:55 PM
Unknown Object (File)
Sun, Aug 30, 9:25 AM
Unknown Object (File)
Sat, Aug 29, 8:14 AM
Unknown Object (File)
Sat, Aug 29, 6:18 AM
Subscribers

Details

Summary

If LOCAL_CREDS is set on a unix socket and we use sendfile, sendfile
will call uipc_send(PRUS_NOTREADY), which prepends a control message to
M_NOTREADY mbufs. uipc_send() then calls sbappendcontrol() instead of
sbappend(), and sbappendcontrol() was clearing M_NOTREADY, leading to
nasty results.

Test Plan

Ran a simple test case that previously triggers this bug and causes a kernel
panic due to an mbuf double free.

Diff Detail

Lint
Lint Passed
Unit
No Test Coverage
Build Status
Buildable 30349
Build 28116: arc lint + arc unit

Event Timeline

markj added a reviewer: glebius.
This revision was not accepted when it landed; it landed in state Needs Review.Apr 10 2020, 8:42 PM
This revision was automatically updated to reflect the committed changes.