net: dccp: initialize (addr,port) listening hashtable
authorPeter Oskolkov <posk@google.com>
Sun, 16 Dec 2018 23:42:48 +0000 (15:42 -0800)
committerDavid S. Miller <davem@davemloft.net>
Tue, 18 Dec 2018 07:11:48 +0000 (23:11 -0800)
Commit d9fbc7f6431f "net: tcp: prefer listeners bound to an address"
removes port-only listener lookups. This caused segfaults in DCCP
lookups because DCCP did not initialize the (addr,port) hashtable.

This patch adds said initialization.

The only non-trivial issue here is the size of the new hashtable.
It seemed reasonable to make it match the size of the port-only
hashtable (= INET_LHTABLE_SIZE) that was used previously. Other
parameters to inet_hashinfo2_init() match those used in TCP.

V2 changes: marked inet_hashinfo2_init as an exported symbol
so that DCCP compiles when configured as a module.

Tested: syzcaller issues fixed; the second patch in the patchset
        tests that DCCP lookups work correctly.

Fixes: d9fbc7f6431f "net: tcp: prefer listeners bound to an address"
Reported-by: syzcaller <syzkaller@googlegroups.com>
Signed-off-by: Peter Oskolkov <posk@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
net/dccp/proto.c
net/ipv4/inet_hashtables.c

index 658cd32bb7b37e740ec174481c067ef2ea67cb7e..be0b223aa862518c4a344a7b4e12f8a1db55c885 100644 (file)
@@ -1141,6 +1141,9 @@ static int __init dccp_init(void)
                goto out_fail;
        rc = -ENOBUFS;
        inet_hashinfo_init(&dccp_hashinfo);
+       inet_hashinfo2_init(&dccp_hashinfo, "dccp_listen_portaddr_hash",
+                           INET_LHTABLE_SIZE, 21,  /* one slot per 2 MB*/
+                           0, 64 * 1024);
        dccp_hashinfo.bind_bucket_cachep =
                kmem_cache_create("dccp_bind_bucket",
                                  sizeof(struct inet_bind_bucket), 0,
index cd03ab42705b457fab3084f6369509be3fbe7bff..2445614de6a762eb5b3f64e593b44e6bdabbdb98 100644 (file)
@@ -785,6 +785,7 @@ void __init inet_hashinfo2_init(struct inet_hashinfo *h, const char *name,
                h->lhash2[i].count = 0;
        }
 }
+EXPORT_SYMBOL_GPL(inet_hashinfo2_init);
 
 int inet_ehash_locks_alloc(struct inet_hashinfo *hashinfo)
 {