Skip to content

Commit 197c949

Browse files
Eric Dumazetdavem330
Eric Dumazet
authored andcommitted
udp: properly support MSG_PEEK with truncated buffers
Backport of this upstream commit into stable kernels : 89c22d8 ("net: Fix skb csum races when peeking") exposed a bug in udp stack vs MSG_PEEK support, when user provides a buffer smaller than skb payload. In this case, skb_copy_and_csum_datagram_iovec(skb, sizeof(struct udphdr), msg->msg_iov); returns -EFAULT. This bug does not happen in upstream kernels since Al Viro did a great job to replace this into : skb_copy_and_csum_datagram_msg(skb, sizeof(struct udphdr), msg); This variant is safe vs short buffers. For the time being, instead reverting Herbert Xu patch and add back skb->ip_summed invalid changes, simply store the result of udp_lib_checksum_complete() so that we avoid computing the checksum a second time, and avoid the problematic skb_copy_and_csum_datagram_iovec() call. This patch can be applied on recent kernels as it avoids a double checksumming, then backported to stable kernels as a bug fix. Signed-off-by: Eric Dumazet <edumazet@google.com> Acked-by: Herbert Xu <herbert@gondor.apana.org.au> Signed-off-by: David S. Miller <davem@davemloft.net>
1 parent 815bc58 commit 197c949

File tree

2 files changed

+8
-4
lines changed

2 files changed

+8
-4
lines changed

Diff for: net/ipv4/udp.c

+4-2
Original file line numberDiff line numberDiff line change
@@ -1271,6 +1271,7 @@ int udp_recvmsg(struct sock *sk, struct msghdr *msg, size_t len, int noblock,
12711271
int peeked, off = 0;
12721272
int err;
12731273
int is_udplite = IS_UDPLITE(sk);
1274+
bool checksum_valid = false;
12741275
bool slow;
12751276

12761277
if (flags & MSG_ERRQUEUE)
@@ -1296,11 +1297,12 @@ int udp_recvmsg(struct sock *sk, struct msghdr *msg, size_t len, int noblock,
12961297
*/
12971298

12981299
if (copied < ulen || UDP_SKB_CB(skb)->partial_cov) {
1299-
if (udp_lib_checksum_complete(skb))
1300+
checksum_valid = !udp_lib_checksum_complete(skb);
1301+
if (!checksum_valid)
13001302
goto csum_copy_err;
13011303
}
13021304

1303-
if (skb_csum_unnecessary(skb))
1305+
if (checksum_valid || skb_csum_unnecessary(skb))
13041306
err = skb_copy_datagram_msg(skb, sizeof(struct udphdr),
13051307
msg, copied);
13061308
else {

Diff for: net/ipv6/udp.c

+4-2
Original file line numberDiff line numberDiff line change
@@ -402,6 +402,7 @@ int udpv6_recvmsg(struct sock *sk, struct msghdr *msg, size_t len,
402402
int peeked, off = 0;
403403
int err;
404404
int is_udplite = IS_UDPLITE(sk);
405+
bool checksum_valid = false;
405406
int is_udp4;
406407
bool slow;
407408

@@ -433,11 +434,12 @@ int udpv6_recvmsg(struct sock *sk, struct msghdr *msg, size_t len,
433434
*/
434435

435436
if (copied < ulen || UDP_SKB_CB(skb)->partial_cov) {
436-
if (udp_lib_checksum_complete(skb))
437+
checksum_valid = !udp_lib_checksum_complete(skb);
438+
if (!checksum_valid)
437439
goto csum_copy_err;
438440
}
439441

440-
if (skb_csum_unnecessary(skb))
442+
if (checksum_valid || skb_csum_unnecessary(skb))
441443
err = skb_copy_datagram_msg(skb, sizeof(struct udphdr),
442444
msg, copied);
443445
else {

0 commit comments

Comments
 (0)