2005-04-17 06:20:36 +08:00
|
|
|
/*
|
|
|
|
* INET An implementation of the TCP/IP protocol suite for the LINUX
|
|
|
|
* operating system. INET is implemented using the BSD Socket
|
|
|
|
* interface as the means of communication with the user level.
|
|
|
|
*
|
|
|
|
* Implementation of the Transmission Control Protocol(TCP).
|
|
|
|
*
|
|
|
|
* IPv4 specific functions
|
|
|
|
*
|
|
|
|
*
|
|
|
|
* code split from:
|
|
|
|
* linux/ipv4/tcp.c
|
|
|
|
* linux/ipv4/tcp_input.c
|
|
|
|
* linux/ipv4/tcp_output.c
|
|
|
|
*
|
|
|
|
* See tcp.c for author information
|
|
|
|
*
|
|
|
|
* This program is free software; you can redistribute it and/or
|
|
|
|
* modify it under the terms of the GNU General Public License
|
|
|
|
* as published by the Free Software Foundation; either version
|
|
|
|
* 2 of the License, or (at your option) any later version.
|
|
|
|
*/
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Changes:
|
|
|
|
* David S. Miller : New socket lookup architecture.
|
|
|
|
* This code is dedicated to John Dyson.
|
|
|
|
* David S. Miller : Change semantics of established hash,
|
|
|
|
* half is devoted to TIME_WAIT sockets
|
|
|
|
* and the rest go in the other half.
|
|
|
|
* Andi Kleen : Add support for syncookies and fixed
|
|
|
|
* some bugs: ip options weren't passed to
|
|
|
|
* the TCP layer, missed a check for an
|
|
|
|
* ACK bit.
|
|
|
|
* Andi Kleen : Implemented fast path mtu discovery.
|
|
|
|
* Fixed many serious bugs in the
|
2005-06-19 13:47:21 +08:00
|
|
|
* request_sock handling and moved
|
2005-04-17 06:20:36 +08:00
|
|
|
* most of it into the af independent code.
|
|
|
|
* Added tail drop and some other bugfixes.
|
2005-11-11 09:13:47 +08:00
|
|
|
* Added new listen semantics.
|
2005-04-17 06:20:36 +08:00
|
|
|
* Mike McLagan : Routing by source
|
|
|
|
* Juan Jose Ciarlante: ip_dynaddr bits
|
|
|
|
* Andi Kleen: various fixes.
|
|
|
|
* Vitaly E. Lavrov : Transparent proxy revived after year
|
|
|
|
* coma.
|
|
|
|
* Andi Kleen : Fix new listen.
|
|
|
|
* Andi Kleen : Fix accept error reporting.
|
|
|
|
* YOSHIFUJI Hideaki @USAGI and: Support IPV6_V6ONLY socket option, which
|
|
|
|
* Alexey Kuznetsov allow both IPv4 and IPv6 sockets to bind
|
|
|
|
* a single port at the same time.
|
|
|
|
*/
|
|
|
|
|
|
|
|
|
2008-12-30 15:04:08 +08:00
|
|
|
#include <linux/bottom_half.h>
|
2005-04-17 06:20:36 +08:00
|
|
|
#include <linux/types.h>
|
|
|
|
#include <linux/fcntl.h>
|
|
|
|
#include <linux/module.h>
|
|
|
|
#include <linux/random.h>
|
|
|
|
#include <linux/cache.h>
|
|
|
|
#include <linux/jhash.h>
|
|
|
|
#include <linux/init.h>
|
|
|
|
#include <linux/times.h>
|
|
|
|
|
2007-09-12 18:01:34 +08:00
|
|
|
#include <net/net_namespace.h>
|
2005-04-17 06:20:36 +08:00
|
|
|
#include <net/icmp.h>
|
2005-08-10 10:59:20 +08:00
|
|
|
#include <net/inet_hashtables.h>
|
2005-04-17 06:20:36 +08:00
|
|
|
#include <net/tcp.h>
|
2005-08-16 13:18:02 +08:00
|
|
|
#include <net/transp_v6.h>
|
2005-04-17 06:20:36 +08:00
|
|
|
#include <net/ipv6.h>
|
|
|
|
#include <net/inet_common.h>
|
2005-12-14 15:25:19 +08:00
|
|
|
#include <net/timewait_sock.h>
|
2005-04-17 06:20:36 +08:00
|
|
|
#include <net/xfrm.h>
|
2006-05-24 09:05:53 +08:00
|
|
|
#include <net/netdma.h>
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
#include <linux/inet.h>
|
|
|
|
#include <linux/ipv6.h>
|
|
|
|
#include <linux/stddef.h>
|
|
|
|
#include <linux/proc_fs.h>
|
|
|
|
#include <linux/seq_file.h>
|
|
|
|
|
2006-11-15 11:07:45 +08:00
|
|
|
#include <linux/crypto.h>
|
|
|
|
#include <linux/scatterlist.h>
|
|
|
|
|
2006-09-23 05:15:41 +08:00
|
|
|
int sysctl_tcp_tw_reuse __read_mostly;
|
|
|
|
int sysctl_tcp_low_latency __read_mostly;
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
|
2006-11-15 11:07:45 +08:00
|
|
|
#ifdef CONFIG_TCP_MD5SIG
|
2006-11-17 20:57:30 +08:00
|
|
|
static struct tcp_md5sig_key *tcp_v4_md5_do_lookup(struct sock *sk,
|
|
|
|
__be32 addr);
|
2008-07-19 15:01:42 +08:00
|
|
|
static int tcp_v4_md5_hash_hdr(char *md5_hash, struct tcp_md5sig_key *key,
|
|
|
|
__be32 daddr, __be32 saddr, struct tcphdr *th);
|
2008-04-18 11:45:16 +08:00
|
|
|
#else
|
|
|
|
static inline
|
|
|
|
struct tcp_md5sig_key *tcp_v4_md5_do_lookup(struct sock *sk, __be32 addr)
|
|
|
|
{
|
|
|
|
return NULL;
|
|
|
|
}
|
2006-11-15 11:07:45 +08:00
|
|
|
#endif
|
|
|
|
|
2008-11-20 16:40:07 +08:00
|
|
|
struct inet_hashinfo tcp_hashinfo;
|
2005-04-17 06:20:36 +08:00
|
|
|
|
2006-11-11 06:06:49 +08:00
|
|
|
static inline __u32 tcp_v4_init_sequence(struct sk_buff *skb)
|
2005-04-17 06:20:36 +08:00
|
|
|
{
|
2007-04-21 13:47:35 +08:00
|
|
|
return secure_tcp_sequence_number(ip_hdr(skb)->daddr,
|
|
|
|
ip_hdr(skb)->saddr,
|
2007-04-11 12:04:22 +08:00
|
|
|
tcp_hdr(skb)->dest,
|
|
|
|
tcp_hdr(skb)->source);
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
|
|
|
|
2005-12-14 15:25:19 +08:00
|
|
|
int tcp_twsk_unique(struct sock *sk, struct sock *sktw, void *twp)
|
|
|
|
{
|
|
|
|
const struct tcp_timewait_sock *tcptw = tcp_twsk(sktw);
|
|
|
|
struct tcp_sock *tp = tcp_sk(sk);
|
|
|
|
|
|
|
|
/* With PAWS, it is safe from the viewpoint
|
|
|
|
of data integrity. Even without PAWS it is safe provided sequence
|
|
|
|
spaces do not overlap i.e. at data rates <= 80Mbit/sec.
|
|
|
|
|
|
|
|
Actually, the idea is close to VJ's one, only timestamp cache is
|
|
|
|
held not per host, but per port pair and TW bucket is used as state
|
|
|
|
holder.
|
|
|
|
|
|
|
|
If TW bucket has been already destroyed we fall back to VJ's scheme
|
|
|
|
and use initial timestamp retrieved from peer table.
|
|
|
|
*/
|
|
|
|
if (tcptw->tw_ts_recent_stamp &&
|
|
|
|
(twp == NULL || (sysctl_tcp_tw_reuse &&
|
2007-03-05 08:12:44 +08:00
|
|
|
get_seconds() - tcptw->tw_ts_recent_stamp > 1))) {
|
2005-12-14 15:25:19 +08:00
|
|
|
tp->write_seq = tcptw->tw_snd_nxt + 65535 + 2;
|
|
|
|
if (tp->write_seq == 0)
|
|
|
|
tp->write_seq = 1;
|
|
|
|
tp->rx_opt.ts_recent = tcptw->tw_ts_recent;
|
|
|
|
tp->rx_opt.ts_recent_stamp = tcptw->tw_ts_recent_stamp;
|
|
|
|
sock_hold(sktw);
|
|
|
|
return 1;
|
|
|
|
}
|
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
EXPORT_SYMBOL_GPL(tcp_twsk_unique);
|
|
|
|
|
2005-04-17 06:20:36 +08:00
|
|
|
/* This will initiate an outgoing connection. */
|
|
|
|
int tcp_v4_connect(struct sock *sk, struct sockaddr *uaddr, int addr_len)
|
|
|
|
{
|
|
|
|
struct inet_sock *inet = inet_sk(sk);
|
|
|
|
struct tcp_sock *tp = tcp_sk(sk);
|
|
|
|
struct sockaddr_in *usin = (struct sockaddr_in *)uaddr;
|
|
|
|
struct rtable *rt;
|
2006-09-27 12:27:15 +08:00
|
|
|
__be32 daddr, nexthop;
|
2005-04-17 06:20:36 +08:00
|
|
|
int tmp;
|
|
|
|
int err;
|
|
|
|
|
|
|
|
if (addr_len < sizeof(struct sockaddr_in))
|
|
|
|
return -EINVAL;
|
|
|
|
|
|
|
|
if (usin->sin_family != AF_INET)
|
|
|
|
return -EAFNOSUPPORT;
|
|
|
|
|
|
|
|
nexthop = daddr = usin->sin_addr.s_addr;
|
|
|
|
if (inet->opt && inet->opt->srr) {
|
|
|
|
if (!daddr)
|
|
|
|
return -EINVAL;
|
|
|
|
nexthop = inet->opt->faddr;
|
|
|
|
}
|
|
|
|
|
2009-10-15 14:30:45 +08:00
|
|
|
tmp = ip_route_connect(&rt, nexthop, inet->inet_saddr,
|
2005-04-17 06:20:36 +08:00
|
|
|
RT_CONN_FLAGS(sk), sk->sk_bound_dev_if,
|
|
|
|
IPPROTO_TCP,
|
2009-10-15 14:30:45 +08:00
|
|
|
inet->inet_sport, usin->sin_port, sk, 1);
|
2007-06-01 13:49:28 +08:00
|
|
|
if (tmp < 0) {
|
|
|
|
if (tmp == -ENETUNREACH)
|
2008-07-17 11:20:11 +08:00
|
|
|
IP_INC_STATS_BH(sock_net(sk), IPSTATS_MIB_OUTNOROUTES);
|
2005-04-17 06:20:36 +08:00
|
|
|
return tmp;
|
2007-06-01 13:49:28 +08:00
|
|
|
}
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
if (rt->rt_flags & (RTCF_MULTICAST | RTCF_BROADCAST)) {
|
|
|
|
ip_rt_put(rt);
|
|
|
|
return -ENETUNREACH;
|
|
|
|
}
|
|
|
|
|
|
|
|
if (!inet->opt || !inet->opt->srr)
|
|
|
|
daddr = rt->rt_dst;
|
|
|
|
|
2009-10-15 14:30:45 +08:00
|
|
|
if (!inet->inet_saddr)
|
|
|
|
inet->inet_saddr = rt->rt_src;
|
|
|
|
inet->inet_rcv_saddr = inet->inet_saddr;
|
2005-04-17 06:20:36 +08:00
|
|
|
|
2009-10-15 14:30:45 +08:00
|
|
|
if (tp->rx_opt.ts_recent_stamp && inet->inet_daddr != daddr) {
|
2005-04-17 06:20:36 +08:00
|
|
|
/* Reset inherited state */
|
|
|
|
tp->rx_opt.ts_recent = 0;
|
|
|
|
tp->rx_opt.ts_recent_stamp = 0;
|
|
|
|
tp->write_seq = 0;
|
|
|
|
}
|
|
|
|
|
2005-08-10 11:44:40 +08:00
|
|
|
if (tcp_death_row.sysctl_tw_recycle &&
|
2005-04-17 06:20:36 +08:00
|
|
|
!tp->rx_opt.ts_recent_stamp && rt->rt_dst == daddr) {
|
|
|
|
struct inet_peer *peer = rt_get_peer(rt);
|
2006-11-17 20:57:30 +08:00
|
|
|
/*
|
|
|
|
* VJ's idea. We save last timestamp seen from
|
|
|
|
* the destination in peer table, when entering state
|
|
|
|
* TIME-WAIT * and initialize rx_opt.ts_recent from it,
|
|
|
|
* when trying new connection.
|
2005-04-17 06:20:36 +08:00
|
|
|
*/
|
2006-11-17 20:57:30 +08:00
|
|
|
if (peer != NULL &&
|
2009-11-12 17:33:09 +08:00
|
|
|
(u32)get_seconds() - peer->tcp_ts_stamp <= TCP_PAWS_MSL) {
|
2005-04-17 06:20:36 +08:00
|
|
|
tp->rx_opt.ts_recent_stamp = peer->tcp_ts_stamp;
|
|
|
|
tp->rx_opt.ts_recent = peer->tcp_ts;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2009-10-15 14:30:45 +08:00
|
|
|
inet->inet_dport = usin->sin_port;
|
|
|
|
inet->inet_daddr = daddr;
|
2005-04-17 06:20:36 +08:00
|
|
|
|
2005-12-14 15:26:10 +08:00
|
|
|
inet_csk(sk)->icsk_ext_hdr_len = 0;
|
2005-04-17 06:20:36 +08:00
|
|
|
if (inet->opt)
|
2005-12-14 15:26:10 +08:00
|
|
|
inet_csk(sk)->icsk_ext_hdr_len = inet->opt->optlen;
|
2005-04-17 06:20:36 +08:00
|
|
|
|
2009-11-10 17:51:18 +08:00
|
|
|
tp->rx_opt.mss_clamp = TCP_MSS_DEFAULT;
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
/* Socket identity is still unknown (sport may be zero).
|
|
|
|
* However we set state to SYN-SENT and not releasing socket
|
|
|
|
* lock select source port, enter ourselves into the hash tables and
|
|
|
|
* complete initialization after this.
|
|
|
|
*/
|
|
|
|
tcp_set_state(sk, TCP_SYN_SENT);
|
2005-12-14 15:25:31 +08:00
|
|
|
err = inet_hash_connect(&tcp_death_row, sk);
|
2005-04-17 06:20:36 +08:00
|
|
|
if (err)
|
|
|
|
goto failure;
|
|
|
|
|
2006-11-17 20:57:30 +08:00
|
|
|
err = ip_route_newports(&rt, IPPROTO_TCP,
|
2009-10-15 14:30:45 +08:00
|
|
|
inet->inet_sport, inet->inet_dport, sk);
|
2005-04-17 06:20:36 +08:00
|
|
|
if (err)
|
|
|
|
goto failure;
|
|
|
|
|
|
|
|
/* OK, now commit destination to socket. */
|
2006-07-01 04:36:35 +08:00
|
|
|
sk->sk_gso_type = SKB_GSO_TCPV4;
|
2005-08-10 10:49:02 +08:00
|
|
|
sk_setup_caps(sk, &rt->u.dst);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
if (!tp->write_seq)
|
2009-10-15 14:30:45 +08:00
|
|
|
tp->write_seq = secure_tcp_sequence_number(inet->inet_saddr,
|
|
|
|
inet->inet_daddr,
|
|
|
|
inet->inet_sport,
|
2005-04-17 06:20:36 +08:00
|
|
|
usin->sin_port);
|
|
|
|
|
2009-10-15 14:30:45 +08:00
|
|
|
inet->inet_id = tp->write_seq ^ jiffies;
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
err = tcp_connect(sk);
|
|
|
|
rt = NULL;
|
|
|
|
if (err)
|
|
|
|
goto failure;
|
|
|
|
|
|
|
|
return 0;
|
|
|
|
|
|
|
|
failure:
|
2006-11-17 20:57:30 +08:00
|
|
|
/*
|
|
|
|
* This unhashes the socket and releases the local port,
|
|
|
|
* if necessary.
|
|
|
|
*/
|
2005-04-17 06:20:36 +08:00
|
|
|
tcp_set_state(sk, TCP_CLOSE);
|
|
|
|
ip_rt_put(rt);
|
|
|
|
sk->sk_route_caps = 0;
|
2009-10-15 14:30:45 +08:00
|
|
|
inet->inet_dport = 0;
|
2005-04-17 06:20:36 +08:00
|
|
|
return err;
|
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* This routine does path mtu discovery as defined in RFC1191.
|
|
|
|
*/
|
2006-01-04 08:03:49 +08:00
|
|
|
static void do_pmtu_discovery(struct sock *sk, struct iphdr *iph, u32 mtu)
|
2005-04-17 06:20:36 +08:00
|
|
|
{
|
|
|
|
struct dst_entry *dst;
|
|
|
|
struct inet_sock *inet = inet_sk(sk);
|
|
|
|
|
|
|
|
/* We are not interested in TCP_LISTEN and open_requests (SYN-ACKs
|
|
|
|
* send out by Linux are always <576bytes so they should go through
|
|
|
|
* unfragmented).
|
|
|
|
*/
|
|
|
|
if (sk->sk_state == TCP_LISTEN)
|
|
|
|
return;
|
|
|
|
|
|
|
|
/* We don't check in the destentry if pmtu discovery is forbidden
|
|
|
|
* on this route. We just assume that no packet_to_big packets
|
|
|
|
* are send back when pmtu discovery is not active.
|
2007-02-09 22:24:47 +08:00
|
|
|
* There is a small race when the user changes this flag in the
|
2005-04-17 06:20:36 +08:00
|
|
|
* route, but I think that's acceptable.
|
|
|
|
*/
|
|
|
|
if ((dst = __sk_dst_check(sk, 0)) == NULL)
|
|
|
|
return;
|
|
|
|
|
|
|
|
dst->ops->update_pmtu(dst, mtu);
|
|
|
|
|
|
|
|
/* Something is about to be wrong... Remember soft error
|
|
|
|
* for the case, if this connection will not able to recover.
|
|
|
|
*/
|
|
|
|
if (mtu < dst_mtu(dst) && ip_dont_fragment(sk, dst))
|
|
|
|
sk->sk_err_soft = EMSGSIZE;
|
|
|
|
|
|
|
|
mtu = dst_mtu(dst);
|
|
|
|
|
|
|
|
if (inet->pmtudisc != IP_PMTUDISC_DONT &&
|
2005-12-14 15:26:10 +08:00
|
|
|
inet_csk(sk)->icsk_pmtu_cookie > mtu) {
|
2005-04-17 06:20:36 +08:00
|
|
|
tcp_sync_mss(sk, mtu);
|
|
|
|
|
|
|
|
/* Resend the TCP packet because it's
|
|
|
|
* clear that the old packet has been
|
|
|
|
* dropped. This is the new "fast" path mtu
|
|
|
|
* discovery.
|
|
|
|
*/
|
|
|
|
tcp_simple_retransmit(sk);
|
|
|
|
} /* else let the usual retransmit timer handle it */
|
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* This routine is called by the ICMP module when it gets some
|
|
|
|
* sort of error condition. If err < 0 then the socket should
|
|
|
|
* be closed and the error returned to the user. If err > 0
|
|
|
|
* it's just the icmp type << 8 | icmp code. After adjustment
|
|
|
|
* header points to the first 8 bytes of the tcp header. We need
|
|
|
|
* to find the appropriate port.
|
|
|
|
*
|
|
|
|
* The locking strategy used here is very "optimistic". When
|
|
|
|
* someone else accesses the socket the ICMP is just dropped
|
|
|
|
* and for some paths there is no check at all.
|
|
|
|
* A more general error queue to queue errors for later handling
|
|
|
|
* is probably better.
|
|
|
|
*
|
|
|
|
*/
|
|
|
|
|
2009-08-26 08:16:27 +08:00
|
|
|
void tcp_v4_err(struct sk_buff *icmp_skb, u32 info)
|
2005-04-17 06:20:36 +08:00
|
|
|
{
|
2009-08-26 08:16:27 +08:00
|
|
|
struct iphdr *iph = (struct iphdr *)icmp_skb->data;
|
|
|
|
struct tcphdr *th = (struct tcphdr *)(icmp_skb->data + (iph->ihl << 2));
|
Revert Backoff [v3]: Revert RTO on ICMP destination unreachable
Here, an ICMP host/network unreachable message, whose payload fits to
TCP's SND.UNA, is taken as an indication that the RTO retransmission has
not been lost due to congestion, but because of a route failure
somewhere along the path.
With true congestion, a router won't trigger such a message and the
patched TCP will operate as standard TCP.
This patch reverts one RTO backoff, if an ICMP host/network unreachable
message, whose payload fits to TCP's SND.UNA, arrives.
Based on the new RTO, the retransmission timer is reset to reflect the
remaining time, or - if the revert clocked out the timer - a retransmission
is sent out immediately.
Backoffs are only reverted, if TCP is in RTO loss recovery, i.e. if
there have been retransmissions and reversible backoffs, already.
Changes from v2:
1) Renaming of skb in tcp_v4_err() moved to another patch.
2) Reintroduced tcp_bound_rto() and __tcp_set_rto().
3) Fixed code comments.
Signed-off-by: Damian Lukowski <damian@tvk.rwth-aachen.de>
Acked-by: Ilpo Järvinen <ilpo.jarvinen@helsinki.fi>
Signed-off-by: David S. Miller <davem@davemloft.net>
2009-08-26 08:16:31 +08:00
|
|
|
struct inet_connection_sock *icsk;
|
2005-04-17 06:20:36 +08:00
|
|
|
struct tcp_sock *tp;
|
|
|
|
struct inet_sock *inet;
|
2009-08-26 08:16:27 +08:00
|
|
|
const int type = icmp_hdr(icmp_skb)->type;
|
|
|
|
const int code = icmp_hdr(icmp_skb)->code;
|
2005-04-17 06:20:36 +08:00
|
|
|
struct sock *sk;
|
Revert Backoff [v3]: Revert RTO on ICMP destination unreachable
Here, an ICMP host/network unreachable message, whose payload fits to
TCP's SND.UNA, is taken as an indication that the RTO retransmission has
not been lost due to congestion, but because of a route failure
somewhere along the path.
With true congestion, a router won't trigger such a message and the
patched TCP will operate as standard TCP.
This patch reverts one RTO backoff, if an ICMP host/network unreachable
message, whose payload fits to TCP's SND.UNA, arrives.
Based on the new RTO, the retransmission timer is reset to reflect the
remaining time, or - if the revert clocked out the timer - a retransmission
is sent out immediately.
Backoffs are only reverted, if TCP is in RTO loss recovery, i.e. if
there have been retransmissions and reversible backoffs, already.
Changes from v2:
1) Renaming of skb in tcp_v4_err() moved to another patch.
2) Reintroduced tcp_bound_rto() and __tcp_set_rto().
3) Fixed code comments.
Signed-off-by: Damian Lukowski <damian@tvk.rwth-aachen.de>
Acked-by: Ilpo Järvinen <ilpo.jarvinen@helsinki.fi>
Signed-off-by: David S. Miller <davem@davemloft.net>
2009-08-26 08:16:31 +08:00
|
|
|
struct sk_buff *skb;
|
2005-04-17 06:20:36 +08:00
|
|
|
__u32 seq;
|
Revert Backoff [v3]: Revert RTO on ICMP destination unreachable
Here, an ICMP host/network unreachable message, whose payload fits to
TCP's SND.UNA, is taken as an indication that the RTO retransmission has
not been lost due to congestion, but because of a route failure
somewhere along the path.
With true congestion, a router won't trigger such a message and the
patched TCP will operate as standard TCP.
This patch reverts one RTO backoff, if an ICMP host/network unreachable
message, whose payload fits to TCP's SND.UNA, arrives.
Based on the new RTO, the retransmission timer is reset to reflect the
remaining time, or - if the revert clocked out the timer - a retransmission
is sent out immediately.
Backoffs are only reverted, if TCP is in RTO loss recovery, i.e. if
there have been retransmissions and reversible backoffs, already.
Changes from v2:
1) Renaming of skb in tcp_v4_err() moved to another patch.
2) Reintroduced tcp_bound_rto() and __tcp_set_rto().
3) Fixed code comments.
Signed-off-by: Damian Lukowski <damian@tvk.rwth-aachen.de>
Acked-by: Ilpo Järvinen <ilpo.jarvinen@helsinki.fi>
Signed-off-by: David S. Miller <davem@davemloft.net>
2009-08-26 08:16:31 +08:00
|
|
|
__u32 remaining;
|
2005-04-17 06:20:36 +08:00
|
|
|
int err;
|
2009-08-26 08:16:27 +08:00
|
|
|
struct net *net = dev_net(icmp_skb->dev);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
2009-08-26 08:16:27 +08:00
|
|
|
if (icmp_skb->len < (iph->ihl << 2) + 8) {
|
2008-07-15 14:03:00 +08:00
|
|
|
ICMP_INC_STATS_BH(net, ICMP_MIB_INERRORS);
|
2005-04-17 06:20:36 +08:00
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
2008-07-15 14:01:40 +08:00
|
|
|
sk = inet_lookup(net, &tcp_hashinfo, iph->daddr, th->dest,
|
2009-08-26 08:16:27 +08:00
|
|
|
iph->saddr, th->source, inet_iif(icmp_skb));
|
2005-04-17 06:20:36 +08:00
|
|
|
if (!sk) {
|
2008-07-15 14:03:00 +08:00
|
|
|
ICMP_INC_STATS_BH(net, ICMP_MIB_INERRORS);
|
2005-04-17 06:20:36 +08:00
|
|
|
return;
|
|
|
|
}
|
|
|
|
if (sk->sk_state == TCP_TIME_WAIT) {
|
2006-10-11 10:41:46 +08:00
|
|
|
inet_twsk_put(inet_twsk(sk));
|
2005-04-17 06:20:36 +08:00
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
|
|
|
bh_lock_sock(sk);
|
|
|
|
/* If too many ICMPs get dropped on busy
|
|
|
|
* servers this needs to be solved differently.
|
|
|
|
*/
|
|
|
|
if (sock_owned_by_user(sk))
|
2008-07-17 11:31:16 +08:00
|
|
|
NET_INC_STATS_BH(net, LINUX_MIB_LOCKDROPPEDICMPS);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
if (sk->sk_state == TCP_CLOSE)
|
|
|
|
goto out;
|
|
|
|
|
Revert Backoff [v3]: Revert RTO on ICMP destination unreachable
Here, an ICMP host/network unreachable message, whose payload fits to
TCP's SND.UNA, is taken as an indication that the RTO retransmission has
not been lost due to congestion, but because of a route failure
somewhere along the path.
With true congestion, a router won't trigger such a message and the
patched TCP will operate as standard TCP.
This patch reverts one RTO backoff, if an ICMP host/network unreachable
message, whose payload fits to TCP's SND.UNA, arrives.
Based on the new RTO, the retransmission timer is reset to reflect the
remaining time, or - if the revert clocked out the timer - a retransmission
is sent out immediately.
Backoffs are only reverted, if TCP is in RTO loss recovery, i.e. if
there have been retransmissions and reversible backoffs, already.
Changes from v2:
1) Renaming of skb in tcp_v4_err() moved to another patch.
2) Reintroduced tcp_bound_rto() and __tcp_set_rto().
3) Fixed code comments.
Signed-off-by: Damian Lukowski <damian@tvk.rwth-aachen.de>
Acked-by: Ilpo Järvinen <ilpo.jarvinen@helsinki.fi>
Signed-off-by: David S. Miller <davem@davemloft.net>
2009-08-26 08:16:31 +08:00
|
|
|
icsk = inet_csk(sk);
|
2005-04-17 06:20:36 +08:00
|
|
|
tp = tcp_sk(sk);
|
|
|
|
seq = ntohl(th->seq);
|
|
|
|
if (sk->sk_state != TCP_LISTEN &&
|
|
|
|
!between(seq, tp->snd_una, tp->snd_nxt)) {
|
2008-07-17 11:31:16 +08:00
|
|
|
NET_INC_STATS_BH(net, LINUX_MIB_OUTOFWINDOWICMPS);
|
2005-04-17 06:20:36 +08:00
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
|
|
|
|
switch (type) {
|
|
|
|
case ICMP_SOURCE_QUENCH:
|
|
|
|
/* Just silently ignore these. */
|
|
|
|
goto out;
|
|
|
|
case ICMP_PARAMETERPROB:
|
|
|
|
err = EPROTO;
|
|
|
|
break;
|
|
|
|
case ICMP_DEST_UNREACH:
|
|
|
|
if (code > NR_ICMP_UNREACH)
|
|
|
|
goto out;
|
|
|
|
|
|
|
|
if (code == ICMP_FRAG_NEEDED) { /* PMTU discovery (RFC1191) */
|
|
|
|
if (!sock_owned_by_user(sk))
|
|
|
|
do_pmtu_discovery(sk, iph, info);
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
|
|
|
|
err = icmp_err_convert[code].errno;
|
Revert Backoff [v3]: Revert RTO on ICMP destination unreachable
Here, an ICMP host/network unreachable message, whose payload fits to
TCP's SND.UNA, is taken as an indication that the RTO retransmission has
not been lost due to congestion, but because of a route failure
somewhere along the path.
With true congestion, a router won't trigger such a message and the
patched TCP will operate as standard TCP.
This patch reverts one RTO backoff, if an ICMP host/network unreachable
message, whose payload fits to TCP's SND.UNA, arrives.
Based on the new RTO, the retransmission timer is reset to reflect the
remaining time, or - if the revert clocked out the timer - a retransmission
is sent out immediately.
Backoffs are only reverted, if TCP is in RTO loss recovery, i.e. if
there have been retransmissions and reversible backoffs, already.
Changes from v2:
1) Renaming of skb in tcp_v4_err() moved to another patch.
2) Reintroduced tcp_bound_rto() and __tcp_set_rto().
3) Fixed code comments.
Signed-off-by: Damian Lukowski <damian@tvk.rwth-aachen.de>
Acked-by: Ilpo Järvinen <ilpo.jarvinen@helsinki.fi>
Signed-off-by: David S. Miller <davem@davemloft.net>
2009-08-26 08:16:31 +08:00
|
|
|
/* check if icmp_skb allows revert of backoff
|
|
|
|
* (see draft-zimmermann-tcp-lcd) */
|
|
|
|
if (code != ICMP_NET_UNREACH && code != ICMP_HOST_UNREACH)
|
|
|
|
break;
|
|
|
|
if (seq != tp->snd_una || !icsk->icsk_retransmits ||
|
|
|
|
!icsk->icsk_backoff)
|
|
|
|
break;
|
|
|
|
|
|
|
|
icsk->icsk_backoff--;
|
|
|
|
inet_csk(sk)->icsk_rto = __tcp_set_rto(tp) <<
|
|
|
|
icsk->icsk_backoff;
|
|
|
|
tcp_bound_rto(sk);
|
|
|
|
|
|
|
|
skb = tcp_write_queue_head(sk);
|
|
|
|
BUG_ON(!skb);
|
|
|
|
|
|
|
|
remaining = icsk->icsk_rto - min(icsk->icsk_rto,
|
|
|
|
tcp_time_stamp - TCP_SKB_CB(skb)->when);
|
|
|
|
|
|
|
|
if (remaining) {
|
|
|
|
inet_csk_reset_xmit_timer(sk, ICSK_TIME_RETRANS,
|
|
|
|
remaining, TCP_RTO_MAX);
|
|
|
|
} else if (sock_owned_by_user(sk)) {
|
|
|
|
/* RTO revert clocked out retransmission,
|
|
|
|
* but socket is locked. Will defer. */
|
|
|
|
inet_csk_reset_xmit_timer(sk, ICSK_TIME_RETRANS,
|
|
|
|
HZ/20, TCP_RTO_MAX);
|
|
|
|
} else {
|
|
|
|
/* RTO revert clocked out retransmission.
|
|
|
|
* Will retransmit now */
|
|
|
|
tcp_retransmit_timer(sk);
|
|
|
|
}
|
|
|
|
|
2005-04-17 06:20:36 +08:00
|
|
|
break;
|
|
|
|
case ICMP_TIME_EXCEEDED:
|
|
|
|
err = EHOSTUNREACH;
|
|
|
|
break;
|
|
|
|
default:
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
|
|
|
|
switch (sk->sk_state) {
|
2005-06-19 13:47:21 +08:00
|
|
|
struct request_sock *req, **prev;
|
2005-04-17 06:20:36 +08:00
|
|
|
case TCP_LISTEN:
|
|
|
|
if (sock_owned_by_user(sk))
|
|
|
|
goto out;
|
|
|
|
|
2005-08-10 11:10:42 +08:00
|
|
|
req = inet_csk_search_req(sk, &prev, th->dest,
|
|
|
|
iph->daddr, iph->saddr);
|
2005-04-17 06:20:36 +08:00
|
|
|
if (!req)
|
|
|
|
goto out;
|
|
|
|
|
|
|
|
/* ICMPs are not backlogged, hence we cannot get
|
|
|
|
an established socket here.
|
|
|
|
*/
|
2008-07-26 12:43:18 +08:00
|
|
|
WARN_ON(req->sk);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
[NET] Generalise TCP's struct open_request minisock infrastructure
Kept this first changeset minimal, without changing existing names to
ease peer review.
Basicaly tcp_openreq_alloc now receives the or_calltable, that in turn
has two new members:
->slab, that replaces tcp_openreq_cachep
->obj_size, to inform the size of the openreq descendant for
a specific protocol
The protocol specific fields in struct open_request were moved to a
class hierarchy, with the things that are common to all connection
oriented PF_INET protocols in struct inet_request_sock, the TCP ones
in tcp_request_sock, that is an inet_request_sock, that is an
open_request.
I.e. this uses the same approach used for the struct sock class
hierarchy, with sk_prot indicating if the protocol wants to use the
open_request infrastructure by filling in sk_prot->rsk_prot with an
or_calltable.
Results? Performance is improved and TCP v4 now uses only 64 bytes per
open request minisock, down from 96 without this patch :-)
Next changeset will rename some of the structs, fields and functions
mentioned above, struct or_calltable is way unclear, better name it
struct request_sock_ops, s/struct open_request/struct request_sock/g,
etc.
Signed-off-by: Arnaldo Carvalho de Melo <acme@ghostprotocols.net>
Signed-off-by: David S. Miller <davem@davemloft.net>
2005-06-19 13:46:52 +08:00
|
|
|
if (seq != tcp_rsk(req)->snt_isn) {
|
2008-07-17 11:31:16 +08:00
|
|
|
NET_INC_STATS_BH(net, LINUX_MIB_OUTOFWINDOWICMPS);
|
2005-04-17 06:20:36 +08:00
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Still in SYN_RECV, just remove it silently.
|
|
|
|
* There is no good way to pass the error to the newly
|
|
|
|
* created socket, and POSIX does not want network
|
|
|
|
* errors returned from accept().
|
|
|
|
*/
|
2005-08-10 11:10:42 +08:00
|
|
|
inet_csk_reqsk_queue_drop(sk, req, prev);
|
2005-04-17 06:20:36 +08:00
|
|
|
goto out;
|
|
|
|
|
|
|
|
case TCP_SYN_SENT:
|
|
|
|
case TCP_SYN_RECV: /* Cannot happen.
|
|
|
|
It can f.e. if SYNs crossed.
|
|
|
|
*/
|
|
|
|
if (!sock_owned_by_user(sk)) {
|
|
|
|
sk->sk_err = err;
|
|
|
|
|
|
|
|
sk->sk_error_report(sk);
|
|
|
|
|
|
|
|
tcp_done(sk);
|
|
|
|
} else {
|
|
|
|
sk->sk_err_soft = err;
|
|
|
|
}
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
|
|
|
|
/* If we've already connected we will keep trying
|
|
|
|
* until we time out, or the user gives up.
|
|
|
|
*
|
|
|
|
* rfc1122 4.2.3.9 allows to consider as hard errors
|
|
|
|
* only PROTO_UNREACH and PORT_UNREACH (well, FRAG_FAILED too,
|
|
|
|
* but it is obsoleted by pmtu discovery).
|
|
|
|
*
|
|
|
|
* Note, that in modern internet, where routing is unreliable
|
|
|
|
* and in each dark corner broken firewalls sit, sending random
|
|
|
|
* errors ordered by their masters even this two messages finally lose
|
|
|
|
* their original sense (even Linux sends invalid PORT_UNREACHs)
|
|
|
|
*
|
|
|
|
* Now we are in compliance with RFCs.
|
|
|
|
* --ANK (980905)
|
|
|
|
*/
|
|
|
|
|
|
|
|
inet = inet_sk(sk);
|
|
|
|
if (!sock_owned_by_user(sk) && inet->recverr) {
|
|
|
|
sk->sk_err = err;
|
|
|
|
sk->sk_error_report(sk);
|
|
|
|
} else { /* Only an error on timeout */
|
|
|
|
sk->sk_err_soft = err;
|
|
|
|
}
|
|
|
|
|
|
|
|
out:
|
|
|
|
bh_unlock_sock(sk);
|
|
|
|
sock_put(sk);
|
|
|
|
}
|
|
|
|
|
|
|
|
/* This routine computes an IPv4 TCP checksum. */
|
2005-12-14 15:15:52 +08:00
|
|
|
void tcp_v4_send_check(struct sock *sk, int len, struct sk_buff *skb)
|
2005-04-17 06:20:36 +08:00
|
|
|
{
|
|
|
|
struct inet_sock *inet = inet_sk(sk);
|
2007-04-11 12:04:22 +08:00
|
|
|
struct tcphdr *th = tcp_hdr(skb);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
2006-08-30 07:44:56 +08:00
|
|
|
if (skb->ip_summed == CHECKSUM_PARTIAL) {
|
2009-10-15 14:30:45 +08:00
|
|
|
th->check = ~tcp_v4_check(len, inet->inet_saddr,
|
|
|
|
inet->inet_daddr, 0);
|
2007-04-10 02:59:07 +08:00
|
|
|
skb->csum_start = skb_transport_header(skb) - skb->head;
|
2006-11-21 10:07:29 +08:00
|
|
|
skb->csum_offset = offsetof(struct tcphdr, check);
|
2005-04-17 06:20:36 +08:00
|
|
|
} else {
|
2009-10-15 14:30:45 +08:00
|
|
|
th->check = tcp_v4_check(len, inet->inet_saddr,
|
|
|
|
inet->inet_daddr,
|
2008-11-20 07:44:53 +08:00
|
|
|
csum_partial(th,
|
2005-04-17 06:20:36 +08:00
|
|
|
th->doff << 2,
|
|
|
|
skb->csum));
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2006-07-09 04:34:56 +08:00
|
|
|
int tcp_v4_gso_send_check(struct sk_buff *skb)
|
|
|
|
{
|
2007-04-21 13:47:35 +08:00
|
|
|
const struct iphdr *iph;
|
2006-07-09 04:34:56 +08:00
|
|
|
struct tcphdr *th;
|
|
|
|
|
|
|
|
if (!pskb_may_pull(skb, sizeof(*th)))
|
|
|
|
return -EINVAL;
|
|
|
|
|
2007-04-21 13:47:35 +08:00
|
|
|
iph = ip_hdr(skb);
|
2007-04-11 12:04:22 +08:00
|
|
|
th = tcp_hdr(skb);
|
2006-07-09 04:34:56 +08:00
|
|
|
|
|
|
|
th->check = 0;
|
2007-02-05 12:15:27 +08:00
|
|
|
th->check = ~tcp_v4_check(skb->len, iph->saddr, iph->daddr, 0);
|
2007-04-10 02:59:07 +08:00
|
|
|
skb->csum_start = skb_transport_header(skb) - skb->head;
|
2006-11-21 10:07:29 +08:00
|
|
|
skb->csum_offset = offsetof(struct tcphdr, check);
|
2006-08-30 07:44:56 +08:00
|
|
|
skb->ip_summed = CHECKSUM_PARTIAL;
|
2006-07-09 04:34:56 +08:00
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
2005-04-17 06:20:36 +08:00
|
|
|
/*
|
|
|
|
* This routine will send an RST to the other tcp.
|
|
|
|
*
|
|
|
|
* Someone asks: why I NEVER use socket parameters (TOS, TTL etc.)
|
|
|
|
* for reset.
|
|
|
|
* Answer: if a packet caused RST, it is not for a socket
|
|
|
|
* existing in our system, if it is matched to a socket,
|
|
|
|
* it is just duplicate segment or bug in other side's TCP.
|
|
|
|
* So that we build reply only basing on parameters
|
|
|
|
* arrived with segment.
|
|
|
|
* Exception: precedence violation. We do not implement it in any case.
|
|
|
|
*/
|
|
|
|
|
2006-11-15 11:07:45 +08:00
|
|
|
static void tcp_v4_send_reset(struct sock *sk, struct sk_buff *skb)
|
2005-04-17 06:20:36 +08:00
|
|
|
{
|
2007-04-11 12:04:22 +08:00
|
|
|
struct tcphdr *th = tcp_hdr(skb);
|
2006-11-15 11:07:45 +08:00
|
|
|
struct {
|
|
|
|
struct tcphdr th;
|
|
|
|
#ifdef CONFIG_TCP_MD5SIG
|
2006-11-15 12:51:49 +08:00
|
|
|
__be32 opt[(TCPOLEN_MD5SIG_ALIGNED >> 2)];
|
2006-11-15 11:07:45 +08:00
|
|
|
#endif
|
|
|
|
} rep;
|
2005-04-17 06:20:36 +08:00
|
|
|
struct ip_reply_arg arg;
|
2006-11-15 11:07:45 +08:00
|
|
|
#ifdef CONFIG_TCP_MD5SIG
|
|
|
|
struct tcp_md5sig_key *key;
|
|
|
|
#endif
|
2008-07-17 11:20:58 +08:00
|
|
|
struct net *net;
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
/* Never send a reset in response to a reset. */
|
|
|
|
if (th->rst)
|
|
|
|
return;
|
|
|
|
|
2009-06-02 13:14:27 +08:00
|
|
|
if (skb_rtable(skb)->rt_type != RTN_LOCAL)
|
2005-04-17 06:20:36 +08:00
|
|
|
return;
|
|
|
|
|
|
|
|
/* Swap the send and the receive. */
|
2006-11-15 11:07:45 +08:00
|
|
|
memset(&rep, 0, sizeof(rep));
|
|
|
|
rep.th.dest = th->source;
|
|
|
|
rep.th.source = th->dest;
|
|
|
|
rep.th.doff = sizeof(struct tcphdr) / 4;
|
|
|
|
rep.th.rst = 1;
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
if (th->ack) {
|
2006-11-15 11:07:45 +08:00
|
|
|
rep.th.seq = th->ack_seq;
|
2005-04-17 06:20:36 +08:00
|
|
|
} else {
|
2006-11-15 11:07:45 +08:00
|
|
|
rep.th.ack = 1;
|
|
|
|
rep.th.ack_seq = htonl(ntohl(th->seq) + th->syn + th->fin +
|
|
|
|
skb->len - (th->doff << 2));
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
|
|
|
|
2006-11-17 20:57:30 +08:00
|
|
|
memset(&arg, 0, sizeof(arg));
|
2006-11-15 11:07:45 +08:00
|
|
|
arg.iov[0].iov_base = (unsigned char *)&rep;
|
|
|
|
arg.iov[0].iov_len = sizeof(rep.th);
|
|
|
|
|
|
|
|
#ifdef CONFIG_TCP_MD5SIG
|
2007-04-21 13:47:35 +08:00
|
|
|
key = sk ? tcp_v4_md5_do_lookup(sk, ip_hdr(skb)->daddr) : NULL;
|
2006-11-15 11:07:45 +08:00
|
|
|
if (key) {
|
|
|
|
rep.opt[0] = htonl((TCPOPT_NOP << 24) |
|
|
|
|
(TCPOPT_NOP << 16) |
|
|
|
|
(TCPOPT_MD5SIG << 8) |
|
|
|
|
TCPOLEN_MD5SIG);
|
|
|
|
/* Update length and the length the header thinks exists */
|
|
|
|
arg.iov[0].iov_len += TCPOLEN_MD5SIG_ALIGNED;
|
|
|
|
rep.th.doff = arg.iov[0].iov_len / 4;
|
|
|
|
|
2008-07-19 15:01:42 +08:00
|
|
|
tcp_v4_md5_hash_hdr((__u8 *) &rep.opt[1],
|
2008-10-10 05:37:47 +08:00
|
|
|
key, ip_hdr(skb)->saddr,
|
|
|
|
ip_hdr(skb)->daddr, &rep.th);
|
2006-11-15 11:07:45 +08:00
|
|
|
}
|
|
|
|
#endif
|
2007-04-21 13:47:35 +08:00
|
|
|
arg.csum = csum_tcpudp_nofold(ip_hdr(skb)->daddr,
|
|
|
|
ip_hdr(skb)->saddr, /* XXX */
|
2008-10-09 02:34:06 +08:00
|
|
|
arg.iov[0].iov_len, IPPROTO_TCP, 0);
|
2005-04-17 06:20:36 +08:00
|
|
|
arg.csumoffset = offsetof(struct tcphdr, check) / 2;
|
2008-10-01 22:41:00 +08:00
|
|
|
arg.flags = (sk && inet_sk(sk)->transparent) ? IP_REPLY_ARG_NOSRCCHECK : 0;
|
2005-04-17 06:20:36 +08:00
|
|
|
|
2009-06-02 13:19:30 +08:00
|
|
|
net = dev_net(skb_dst(skb)->dev);
|
2008-07-17 11:20:58 +08:00
|
|
|
ip_send_reply(net->ipv4.tcp_sock, skb,
|
2008-04-04 05:32:00 +08:00
|
|
|
&arg, arg.iov[0].iov_len);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
2008-07-17 11:22:25 +08:00
|
|
|
TCP_INC_STATS_BH(net, TCP_MIB_OUTSEGS);
|
|
|
|
TCP_INC_STATS_BH(net, TCP_MIB_OUTRSTS);
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
/* The code following below sending ACKs in SYN-RECV and TIME-WAIT states
|
|
|
|
outside socket context is ugly, certainly. What can I do?
|
|
|
|
*/
|
|
|
|
|
2008-04-18 11:45:16 +08:00
|
|
|
static void tcp_v4_send_ack(struct sk_buff *skb, u32 seq, u32 ack,
|
|
|
|
u32 win, u32 ts, int oif,
|
2008-10-01 22:41:00 +08:00
|
|
|
struct tcp_md5sig_key *key,
|
|
|
|
int reply_flags)
|
2005-04-17 06:20:36 +08:00
|
|
|
{
|
2007-04-11 12:04:22 +08:00
|
|
|
struct tcphdr *th = tcp_hdr(skb);
|
2005-04-17 06:20:36 +08:00
|
|
|
struct {
|
|
|
|
struct tcphdr th;
|
2006-11-15 12:51:49 +08:00
|
|
|
__be32 opt[(TCPOLEN_TSTAMP_ALIGNED >> 2)
|
2006-11-15 11:07:45 +08:00
|
|
|
#ifdef CONFIG_TCP_MD5SIG
|
2006-11-15 12:51:49 +08:00
|
|
|
+ (TCPOLEN_MD5SIG_ALIGNED >> 2)
|
2006-11-15 11:07:45 +08:00
|
|
|
#endif
|
|
|
|
];
|
2005-04-17 06:20:36 +08:00
|
|
|
} rep;
|
|
|
|
struct ip_reply_arg arg;
|
2009-06-02 13:19:30 +08:00
|
|
|
struct net *net = dev_net(skb_dst(skb)->dev);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
memset(&rep.th, 0, sizeof(struct tcphdr));
|
2006-11-17 20:57:30 +08:00
|
|
|
memset(&arg, 0, sizeof(arg));
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
arg.iov[0].iov_base = (unsigned char *)&rep;
|
|
|
|
arg.iov[0].iov_len = sizeof(rep.th);
|
|
|
|
if (ts) {
|
2006-11-15 11:07:45 +08:00
|
|
|
rep.opt[0] = htonl((TCPOPT_NOP << 24) | (TCPOPT_NOP << 16) |
|
|
|
|
(TCPOPT_TIMESTAMP << 8) |
|
|
|
|
TCPOLEN_TIMESTAMP);
|
|
|
|
rep.opt[1] = htonl(tcp_time_stamp);
|
|
|
|
rep.opt[2] = htonl(ts);
|
2007-01-09 16:11:15 +08:00
|
|
|
arg.iov[0].iov_len += TCPOLEN_TSTAMP_ALIGNED;
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
/* Swap the send and the receive. */
|
|
|
|
rep.th.dest = th->source;
|
|
|
|
rep.th.source = th->dest;
|
|
|
|
rep.th.doff = arg.iov[0].iov_len / 4;
|
|
|
|
rep.th.seq = htonl(seq);
|
|
|
|
rep.th.ack_seq = htonl(ack);
|
|
|
|
rep.th.ack = 1;
|
|
|
|
rep.th.window = htons(win);
|
|
|
|
|
2006-11-15 11:07:45 +08:00
|
|
|
#ifdef CONFIG_TCP_MD5SIG
|
|
|
|
if (key) {
|
|
|
|
int offset = (ts) ? 3 : 0;
|
|
|
|
|
|
|
|
rep.opt[offset++] = htonl((TCPOPT_NOP << 24) |
|
|
|
|
(TCPOPT_NOP << 16) |
|
|
|
|
(TCPOPT_MD5SIG << 8) |
|
|
|
|
TCPOLEN_MD5SIG);
|
|
|
|
arg.iov[0].iov_len += TCPOLEN_MD5SIG_ALIGNED;
|
|
|
|
rep.th.doff = arg.iov[0].iov_len/4;
|
|
|
|
|
2008-07-19 15:01:42 +08:00
|
|
|
tcp_v4_md5_hash_hdr((__u8 *) &rep.opt[offset],
|
2008-08-01 11:49:48 +08:00
|
|
|
key, ip_hdr(skb)->saddr,
|
|
|
|
ip_hdr(skb)->daddr, &rep.th);
|
2006-11-15 11:07:45 +08:00
|
|
|
}
|
|
|
|
#endif
|
2008-10-01 22:41:00 +08:00
|
|
|
arg.flags = reply_flags;
|
2007-04-21 13:47:35 +08:00
|
|
|
arg.csum = csum_tcpudp_nofold(ip_hdr(skb)->daddr,
|
|
|
|
ip_hdr(skb)->saddr, /* XXX */
|
2005-04-17 06:20:36 +08:00
|
|
|
arg.iov[0].iov_len, IPPROTO_TCP, 0);
|
|
|
|
arg.csumoffset = offsetof(struct tcphdr, check) / 2;
|
2008-04-18 11:45:16 +08:00
|
|
|
if (oif)
|
|
|
|
arg.bound_dev_if = oif;
|
2005-04-17 06:20:36 +08:00
|
|
|
|
2008-07-17 11:20:58 +08:00
|
|
|
ip_send_reply(net->ipv4.tcp_sock, skb,
|
2008-04-04 05:32:00 +08:00
|
|
|
&arg, arg.iov[0].iov_len);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
2008-07-17 11:22:25 +08:00
|
|
|
TCP_INC_STATS_BH(net, TCP_MIB_OUTSEGS);
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
static void tcp_v4_timewait_ack(struct sock *sk, struct sk_buff *skb)
|
|
|
|
{
|
2005-08-10 11:09:30 +08:00
|
|
|
struct inet_timewait_sock *tw = inet_twsk(sk);
|
2006-11-15 11:07:45 +08:00
|
|
|
struct tcp_timewait_sock *tcptw = tcp_twsk(sk);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
2008-04-18 11:45:16 +08:00
|
|
|
tcp_v4_send_ack(skb, tcptw->tw_snd_nxt, tcptw->tw_rcv_nxt,
|
2006-11-17 20:57:30 +08:00
|
|
|
tcptw->tw_rcv_wnd >> tw->tw_rcv_wscale,
|
2008-04-18 11:45:16 +08:00
|
|
|
tcptw->tw_ts_recent,
|
|
|
|
tw->tw_bound_dev_if,
|
2008-10-01 22:41:00 +08:00
|
|
|
tcp_twsk_md5_key(tcptw),
|
|
|
|
tw->tw_transparent ? IP_REPLY_ARG_NOSRCCHECK : 0
|
2008-04-18 11:45:16 +08:00
|
|
|
);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
2005-08-10 11:09:30 +08:00
|
|
|
inet_twsk_put(tw);
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
|
|
|
|
2008-08-07 14:50:04 +08:00
|
|
|
static void tcp_v4_reqsk_send_ack(struct sock *sk, struct sk_buff *skb,
|
2006-11-17 20:57:30 +08:00
|
|
|
struct request_sock *req)
|
2005-04-17 06:20:36 +08:00
|
|
|
{
|
2008-04-18 11:45:16 +08:00
|
|
|
tcp_v4_send_ack(skb, tcp_rsk(req)->snt_isn + 1,
|
2006-11-15 11:07:45 +08:00
|
|
|
tcp_rsk(req)->rcv_isn + 1, req->rcv_wnd,
|
2008-04-18 11:45:16 +08:00
|
|
|
req->ts_recent,
|
|
|
|
0,
|
2008-10-01 22:41:00 +08:00
|
|
|
tcp_v4_md5_do_lookup(sk, ip_hdr(skb)->daddr),
|
|
|
|
inet_rsk(req)->no_srccheck ? IP_REPLY_ARG_NOSRCCHECK : 0);
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
2008-02-18 14:29:19 +08:00
|
|
|
* Send a SYN-ACK after having received a SYN.
|
2005-06-19 13:47:21 +08:00
|
|
|
* This still operates on a request_sock only, not on a big
|
2005-04-17 06:20:36 +08:00
|
|
|
* socket.
|
|
|
|
*/
|
2009-12-03 02:07:39 +08:00
|
|
|
static int __tcp_v4_send_synack(struct sock *sk, struct dst_entry *dst,
|
|
|
|
struct request_sock *req,
|
|
|
|
struct request_values *rvp)
|
2005-04-17 06:20:36 +08:00
|
|
|
{
|
[NET] Generalise TCP's struct open_request minisock infrastructure
Kept this first changeset minimal, without changing existing names to
ease peer review.
Basicaly tcp_openreq_alloc now receives the or_calltable, that in turn
has two new members:
->slab, that replaces tcp_openreq_cachep
->obj_size, to inform the size of the openreq descendant for
a specific protocol
The protocol specific fields in struct open_request were moved to a
class hierarchy, with the things that are common to all connection
oriented PF_INET protocols in struct inet_request_sock, the TCP ones
in tcp_request_sock, that is an inet_request_sock, that is an
open_request.
I.e. this uses the same approach used for the struct sock class
hierarchy, with sk_prot indicating if the protocol wants to use the
open_request infrastructure by filling in sk_prot->rsk_prot with an
or_calltable.
Results? Performance is improved and TCP v4 now uses only 64 bytes per
open request minisock, down from 96 without this patch :-)
Next changeset will rename some of the structs, fields and functions
mentioned above, struct or_calltable is way unclear, better name it
struct request_sock_ops, s/struct open_request/struct request_sock/g,
etc.
Signed-off-by: Arnaldo Carvalho de Melo <acme@ghostprotocols.net>
Signed-off-by: David S. Miller <davem@davemloft.net>
2005-06-19 13:46:52 +08:00
|
|
|
const struct inet_request_sock *ireq = inet_rsk(req);
|
2005-04-17 06:20:36 +08:00
|
|
|
int err = -1;
|
|
|
|
struct sk_buff * skb;
|
|
|
|
|
|
|
|
/* First, grab a route. */
|
2005-08-10 11:10:42 +08:00
|
|
|
if (!dst && (dst = inet_csk_route_req(sk, req)) == NULL)
|
2008-03-01 03:43:03 +08:00
|
|
|
return -1;
|
2005-04-17 06:20:36 +08:00
|
|
|
|
2009-12-03 02:07:39 +08:00
|
|
|
skb = tcp_make_synack(sk, dst, req, rvp);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
if (skb) {
|
2007-04-11 12:04:22 +08:00
|
|
|
struct tcphdr *th = tcp_hdr(skb);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
2007-02-05 12:15:27 +08:00
|
|
|
th->check = tcp_v4_check(skb->len,
|
[NET] Generalise TCP's struct open_request minisock infrastructure
Kept this first changeset minimal, without changing existing names to
ease peer review.
Basicaly tcp_openreq_alloc now receives the or_calltable, that in turn
has two new members:
->slab, that replaces tcp_openreq_cachep
->obj_size, to inform the size of the openreq descendant for
a specific protocol
The protocol specific fields in struct open_request were moved to a
class hierarchy, with the things that are common to all connection
oriented PF_INET protocols in struct inet_request_sock, the TCP ones
in tcp_request_sock, that is an inet_request_sock, that is an
open_request.
I.e. this uses the same approach used for the struct sock class
hierarchy, with sk_prot indicating if the protocol wants to use the
open_request infrastructure by filling in sk_prot->rsk_prot with an
or_calltable.
Results? Performance is improved and TCP v4 now uses only 64 bytes per
open request minisock, down from 96 without this patch :-)
Next changeset will rename some of the structs, fields and functions
mentioned above, struct or_calltable is way unclear, better name it
struct request_sock_ops, s/struct open_request/struct request_sock/g,
etc.
Signed-off-by: Arnaldo Carvalho de Melo <acme@ghostprotocols.net>
Signed-off-by: David S. Miller <davem@davemloft.net>
2005-06-19 13:46:52 +08:00
|
|
|
ireq->loc_addr,
|
|
|
|
ireq->rmt_addr,
|
2008-11-20 07:44:53 +08:00
|
|
|
csum_partial(th, skb->len,
|
2005-04-17 06:20:36 +08:00
|
|
|
skb->csum));
|
|
|
|
|
[NET] Generalise TCP's struct open_request minisock infrastructure
Kept this first changeset minimal, without changing existing names to
ease peer review.
Basicaly tcp_openreq_alloc now receives the or_calltable, that in turn
has two new members:
->slab, that replaces tcp_openreq_cachep
->obj_size, to inform the size of the openreq descendant for
a specific protocol
The protocol specific fields in struct open_request were moved to a
class hierarchy, with the things that are common to all connection
oriented PF_INET protocols in struct inet_request_sock, the TCP ones
in tcp_request_sock, that is an inet_request_sock, that is an
open_request.
I.e. this uses the same approach used for the struct sock class
hierarchy, with sk_prot indicating if the protocol wants to use the
open_request infrastructure by filling in sk_prot->rsk_prot with an
or_calltable.
Results? Performance is improved and TCP v4 now uses only 64 bytes per
open request minisock, down from 96 without this patch :-)
Next changeset will rename some of the structs, fields and functions
mentioned above, struct or_calltable is way unclear, better name it
struct request_sock_ops, s/struct open_request/struct request_sock/g,
etc.
Signed-off-by: Arnaldo Carvalho de Melo <acme@ghostprotocols.net>
Signed-off-by: David S. Miller <davem@davemloft.net>
2005-06-19 13:46:52 +08:00
|
|
|
err = ip_build_and_send_pkt(skb, sk, ireq->loc_addr,
|
|
|
|
ireq->rmt_addr,
|
|
|
|
ireq->opt);
|
2006-11-14 21:21:36 +08:00
|
|
|
err = net_xmit_eval(err);
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
dst_release(dst);
|
|
|
|
return err;
|
|
|
|
}
|
|
|
|
|
2009-12-03 02:07:39 +08:00
|
|
|
static int tcp_v4_send_synack(struct sock *sk, struct request_sock *req,
|
|
|
|
struct request_values *rvp)
|
2008-03-01 03:43:03 +08:00
|
|
|
{
|
2009-12-03 02:07:39 +08:00
|
|
|
return __tcp_v4_send_synack(sk, NULL, req, rvp);
|
2008-03-01 03:43:03 +08:00
|
|
|
}
|
|
|
|
|
2005-04-17 06:20:36 +08:00
|
|
|
/*
|
2005-06-19 13:47:21 +08:00
|
|
|
* IPv4 request_sock destructor.
|
2005-04-17 06:20:36 +08:00
|
|
|
*/
|
2005-06-19 13:47:21 +08:00
|
|
|
static void tcp_v4_reqsk_destructor(struct request_sock *req)
|
2005-04-17 06:20:36 +08:00
|
|
|
{
|
2005-11-09 01:41:34 +08:00
|
|
|
kfree(inet_rsk(req)->opt);
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
|
|
|
|
2006-01-04 11:58:06 +08:00
|
|
|
#ifdef CONFIG_SYN_COOKIES
|
2006-01-04 08:03:49 +08:00
|
|
|
static void syn_flood_warning(struct sk_buff *skb)
|
2005-04-17 06:20:36 +08:00
|
|
|
{
|
|
|
|
static unsigned long warntime;
|
|
|
|
|
|
|
|
if (time_after(jiffies, (warntime + HZ * 60))) {
|
|
|
|
warntime = jiffies;
|
|
|
|
printk(KERN_INFO
|
|
|
|
"possible SYN flooding on port %d. Sending cookies.\n",
|
2007-04-11 12:04:22 +08:00
|
|
|
ntohs(tcp_hdr(skb)->dest));
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
|
|
|
}
|
2006-01-04 11:58:06 +08:00
|
|
|
#endif
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
/*
|
2005-06-19 13:47:21 +08:00
|
|
|
* Save and compile IPv4 options into the request_sock if needed.
|
2005-04-17 06:20:36 +08:00
|
|
|
*/
|
2006-01-04 08:03:49 +08:00
|
|
|
static struct ip_options *tcp_v4_save_options(struct sock *sk,
|
|
|
|
struct sk_buff *skb)
|
2005-04-17 06:20:36 +08:00
|
|
|
{
|
|
|
|
struct ip_options *opt = &(IPCB(skb)->opt);
|
|
|
|
struct ip_options *dopt = NULL;
|
|
|
|
|
|
|
|
if (opt && opt->optlen) {
|
|
|
|
int opt_size = optlength(opt);
|
|
|
|
dopt = kmalloc(opt_size, GFP_ATOMIC);
|
|
|
|
if (dopt) {
|
|
|
|
if (ip_options_echo(dopt, skb)) {
|
|
|
|
kfree(dopt);
|
|
|
|
dopt = NULL;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
return dopt;
|
|
|
|
}
|
|
|
|
|
2006-11-15 11:07:45 +08:00
|
|
|
#ifdef CONFIG_TCP_MD5SIG
|
|
|
|
/*
|
|
|
|
* RFC2385 MD5 checksumming requires a mapping of
|
|
|
|
* IP address->MD5 Key.
|
|
|
|
* We need to maintain these in the sk structure.
|
|
|
|
*/
|
|
|
|
|
|
|
|
/* Find the Key structure for an address. */
|
2006-11-17 20:57:30 +08:00
|
|
|
static struct tcp_md5sig_key *
|
|
|
|
tcp_v4_md5_do_lookup(struct sock *sk, __be32 addr)
|
2006-11-15 11:07:45 +08:00
|
|
|
{
|
|
|
|
struct tcp_sock *tp = tcp_sk(sk);
|
|
|
|
int i;
|
|
|
|
|
|
|
|
if (!tp->md5sig_info || !tp->md5sig_info->entries4)
|
|
|
|
return NULL;
|
|
|
|
for (i = 0; i < tp->md5sig_info->entries4; i++) {
|
|
|
|
if (tp->md5sig_info->keys4[i].addr == addr)
|
2007-09-29 06:18:35 +08:00
|
|
|
return &tp->md5sig_info->keys4[i].base;
|
2006-11-15 11:07:45 +08:00
|
|
|
}
|
|
|
|
return NULL;
|
|
|
|
}
|
|
|
|
|
|
|
|
struct tcp_md5sig_key *tcp_v4_md5_lookup(struct sock *sk,
|
|
|
|
struct sock *addr_sk)
|
|
|
|
{
|
2009-10-15 14:30:45 +08:00
|
|
|
return tcp_v4_md5_do_lookup(sk, inet_sk(addr_sk)->inet_daddr);
|
2006-11-15 11:07:45 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
EXPORT_SYMBOL(tcp_v4_md5_lookup);
|
|
|
|
|
2006-12-01 09:22:29 +08:00
|
|
|
static struct tcp_md5sig_key *tcp_v4_reqsk_md5_lookup(struct sock *sk,
|
|
|
|
struct request_sock *req)
|
2006-11-15 11:07:45 +08:00
|
|
|
{
|
|
|
|
return tcp_v4_md5_do_lookup(sk, inet_rsk(req)->rmt_addr);
|
|
|
|
}
|
|
|
|
|
|
|
|
/* This can be called on a newly created socket, from other files */
|
|
|
|
int tcp_v4_md5_do_add(struct sock *sk, __be32 addr,
|
|
|
|
u8 *newkey, u8 newkeylen)
|
|
|
|
{
|
|
|
|
/* Add Key to the list */
|
2007-10-30 11:55:27 +08:00
|
|
|
struct tcp_md5sig_key *key;
|
2006-11-15 11:07:45 +08:00
|
|
|
struct tcp_sock *tp = tcp_sk(sk);
|
|
|
|
struct tcp4_md5sig_key *keys;
|
|
|
|
|
2007-10-30 11:55:27 +08:00
|
|
|
key = tcp_v4_md5_do_lookup(sk, addr);
|
2006-11-15 11:07:45 +08:00
|
|
|
if (key) {
|
|
|
|
/* Pre-existing entry - just update that one. */
|
2007-10-30 11:55:27 +08:00
|
|
|
kfree(key->key);
|
|
|
|
key->key = newkey;
|
|
|
|
key->keylen = newkeylen;
|
2006-11-15 11:07:45 +08:00
|
|
|
} else {
|
2006-11-17 21:06:01 +08:00
|
|
|
struct tcp_md5sig_info *md5sig;
|
|
|
|
|
2006-11-15 11:07:45 +08:00
|
|
|
if (!tp->md5sig_info) {
|
2006-11-17 21:06:01 +08:00
|
|
|
tp->md5sig_info = kzalloc(sizeof(*tp->md5sig_info),
|
|
|
|
GFP_ATOMIC);
|
2006-11-15 11:07:45 +08:00
|
|
|
if (!tp->md5sig_info) {
|
|
|
|
kfree(newkey);
|
|
|
|
return -ENOMEM;
|
|
|
|
}
|
2007-06-13 05:36:42 +08:00
|
|
|
sk->sk_route_caps &= ~NETIF_F_GSO_MASK;
|
2006-11-15 11:07:45 +08:00
|
|
|
}
|
2009-09-03 14:45:45 +08:00
|
|
|
if (tcp_alloc_md5sig_pool(sk) == NULL) {
|
2006-11-15 11:07:45 +08:00
|
|
|
kfree(newkey);
|
|
|
|
return -ENOMEM;
|
|
|
|
}
|
2006-11-17 21:06:01 +08:00
|
|
|
md5sig = tp->md5sig_info;
|
|
|
|
|
|
|
|
if (md5sig->alloced4 == md5sig->entries4) {
|
|
|
|
keys = kmalloc((sizeof(*keys) *
|
2007-02-09 22:24:47 +08:00
|
|
|
(md5sig->entries4 + 1)), GFP_ATOMIC);
|
2006-11-15 11:07:45 +08:00
|
|
|
if (!keys) {
|
|
|
|
kfree(newkey);
|
|
|
|
tcp_free_md5sig_pool();
|
|
|
|
return -ENOMEM;
|
|
|
|
}
|
|
|
|
|
2006-11-17 21:06:01 +08:00
|
|
|
if (md5sig->entries4)
|
|
|
|
memcpy(keys, md5sig->keys4,
|
|
|
|
sizeof(*keys) * md5sig->entries4);
|
2006-11-15 11:07:45 +08:00
|
|
|
|
|
|
|
/* Free old key list, and reference new one */
|
2007-11-21 09:30:06 +08:00
|
|
|
kfree(md5sig->keys4);
|
2006-11-17 21:06:01 +08:00
|
|
|
md5sig->keys4 = keys;
|
|
|
|
md5sig->alloced4++;
|
2006-11-15 11:07:45 +08:00
|
|
|
}
|
2006-11-17 21:06:01 +08:00
|
|
|
md5sig->entries4++;
|
2007-09-29 06:18:35 +08:00
|
|
|
md5sig->keys4[md5sig->entries4 - 1].addr = addr;
|
|
|
|
md5sig->keys4[md5sig->entries4 - 1].base.key = newkey;
|
|
|
|
md5sig->keys4[md5sig->entries4 - 1].base.keylen = newkeylen;
|
2006-11-15 11:07:45 +08:00
|
|
|
}
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
EXPORT_SYMBOL(tcp_v4_md5_do_add);
|
|
|
|
|
|
|
|
static int tcp_v4_md5_add_func(struct sock *sk, struct sock *addr_sk,
|
|
|
|
u8 *newkey, u8 newkeylen)
|
|
|
|
{
|
2009-10-15 14:30:45 +08:00
|
|
|
return tcp_v4_md5_do_add(sk, inet_sk(addr_sk)->inet_daddr,
|
2006-11-15 11:07:45 +08:00
|
|
|
newkey, newkeylen);
|
|
|
|
}
|
|
|
|
|
|
|
|
int tcp_v4_md5_do_del(struct sock *sk, __be32 addr)
|
|
|
|
{
|
|
|
|
struct tcp_sock *tp = tcp_sk(sk);
|
|
|
|
int i;
|
|
|
|
|
|
|
|
for (i = 0; i < tp->md5sig_info->entries4; i++) {
|
|
|
|
if (tp->md5sig_info->keys4[i].addr == addr) {
|
|
|
|
/* Free the key */
|
2007-09-29 06:18:35 +08:00
|
|
|
kfree(tp->md5sig_info->keys4[i].base.key);
|
2006-11-15 11:07:45 +08:00
|
|
|
tp->md5sig_info->entries4--;
|
|
|
|
|
|
|
|
if (tp->md5sig_info->entries4 == 0) {
|
|
|
|
kfree(tp->md5sig_info->keys4);
|
|
|
|
tp->md5sig_info->keys4 = NULL;
|
2006-12-18 09:12:30 +08:00
|
|
|
tp->md5sig_info->alloced4 = 0;
|
2006-11-17 20:57:30 +08:00
|
|
|
} else if (tp->md5sig_info->entries4 != i) {
|
2006-11-15 11:07:45 +08:00
|
|
|
/* Need to do some manipulation */
|
2007-11-21 09:30:31 +08:00
|
|
|
memmove(&tp->md5sig_info->keys4[i],
|
|
|
|
&tp->md5sig_info->keys4[i+1],
|
|
|
|
(tp->md5sig_info->entries4 - i) *
|
|
|
|
sizeof(struct tcp4_md5sig_key));
|
2006-11-15 11:07:45 +08:00
|
|
|
}
|
|
|
|
tcp_free_md5sig_pool();
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
return -ENOENT;
|
|
|
|
}
|
|
|
|
|
|
|
|
EXPORT_SYMBOL(tcp_v4_md5_do_del);
|
|
|
|
|
2006-11-17 20:57:30 +08:00
|
|
|
static void tcp_v4_clear_md5_list(struct sock *sk)
|
2006-11-15 11:07:45 +08:00
|
|
|
{
|
|
|
|
struct tcp_sock *tp = tcp_sk(sk);
|
|
|
|
|
|
|
|
/* Free each key, then the set of key keys,
|
|
|
|
* the crypto element, and then decrement our
|
|
|
|
* hold on the last resort crypto.
|
|
|
|
*/
|
|
|
|
if (tp->md5sig_info->entries4) {
|
|
|
|
int i;
|
|
|
|
for (i = 0; i < tp->md5sig_info->entries4; i++)
|
2007-09-29 06:18:35 +08:00
|
|
|
kfree(tp->md5sig_info->keys4[i].base.key);
|
2006-11-15 11:07:45 +08:00
|
|
|
tp->md5sig_info->entries4 = 0;
|
|
|
|
tcp_free_md5sig_pool();
|
|
|
|
}
|
|
|
|
if (tp->md5sig_info->keys4) {
|
|
|
|
kfree(tp->md5sig_info->keys4);
|
|
|
|
tp->md5sig_info->keys4 = NULL;
|
|
|
|
tp->md5sig_info->alloced4 = 0;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2006-11-17 20:57:30 +08:00
|
|
|
static int tcp_v4_parse_md5_keys(struct sock *sk, char __user *optval,
|
|
|
|
int optlen)
|
2006-11-15 11:07:45 +08:00
|
|
|
{
|
|
|
|
struct tcp_md5sig cmd;
|
|
|
|
struct sockaddr_in *sin = (struct sockaddr_in *)&cmd.tcpm_addr;
|
|
|
|
u8 *newkey;
|
|
|
|
|
|
|
|
if (optlen < sizeof(cmd))
|
|
|
|
return -EINVAL;
|
|
|
|
|
2006-11-17 20:57:30 +08:00
|
|
|
if (copy_from_user(&cmd, optval, sizeof(cmd)))
|
2006-11-15 11:07:45 +08:00
|
|
|
return -EFAULT;
|
|
|
|
|
|
|
|
if (sin->sin_family != AF_INET)
|
|
|
|
return -EINVAL;
|
|
|
|
|
|
|
|
if (!cmd.tcpm_key || !cmd.tcpm_keylen) {
|
|
|
|
if (!tcp_sk(sk)->md5sig_info)
|
|
|
|
return -ENOENT;
|
|
|
|
return tcp_v4_md5_do_del(sk, sin->sin_addr.s_addr);
|
|
|
|
}
|
|
|
|
|
|
|
|
if (cmd.tcpm_keylen > TCP_MD5SIG_MAXKEYLEN)
|
|
|
|
return -EINVAL;
|
|
|
|
|
|
|
|
if (!tcp_sk(sk)->md5sig_info) {
|
|
|
|
struct tcp_sock *tp = tcp_sk(sk);
|
2009-09-03 14:45:45 +08:00
|
|
|
struct tcp_md5sig_info *p;
|
2006-11-15 11:07:45 +08:00
|
|
|
|
2009-09-03 14:45:45 +08:00
|
|
|
p = kzalloc(sizeof(*p), sk->sk_allocation);
|
2006-11-15 11:07:45 +08:00
|
|
|
if (!p)
|
|
|
|
return -EINVAL;
|
|
|
|
|
|
|
|
tp->md5sig_info = p;
|
2007-06-13 05:36:42 +08:00
|
|
|
sk->sk_route_caps &= ~NETIF_F_GSO_MASK;
|
2006-11-15 11:07:45 +08:00
|
|
|
}
|
|
|
|
|
2009-09-03 14:45:45 +08:00
|
|
|
newkey = kmemdup(cmd.tcpm_key, cmd.tcpm_keylen, sk->sk_allocation);
|
2006-11-15 11:07:45 +08:00
|
|
|
if (!newkey)
|
|
|
|
return -ENOMEM;
|
|
|
|
return tcp_v4_md5_do_add(sk, sin->sin_addr.s_addr,
|
|
|
|
newkey, cmd.tcpm_keylen);
|
|
|
|
}
|
|
|
|
|
2008-07-19 15:01:42 +08:00
|
|
|
static int tcp_v4_md5_hash_pseudoheader(struct tcp_md5sig_pool *hp,
|
|
|
|
__be32 daddr, __be32 saddr, int nbytes)
|
2006-11-15 11:07:45 +08:00
|
|
|
{
|
|
|
|
struct tcp4_pseudohdr *bp;
|
2008-07-19 15:01:42 +08:00
|
|
|
struct scatterlist sg;
|
2006-11-15 11:07:45 +08:00
|
|
|
|
|
|
|
bp = &hp->md5_blk.ip4;
|
|
|
|
|
|
|
|
/*
|
2008-07-19 15:01:42 +08:00
|
|
|
* 1. the TCP pseudo-header (in the order: source IP address,
|
2006-11-15 11:07:45 +08:00
|
|
|
* destination IP address, zero-padded protocol number, and
|
|
|
|
* segment length)
|
|
|
|
*/
|
|
|
|
bp->saddr = saddr;
|
|
|
|
bp->daddr = daddr;
|
|
|
|
bp->pad = 0;
|
2008-04-17 11:48:12 +08:00
|
|
|
bp->protocol = IPPROTO_TCP;
|
2008-07-19 15:01:42 +08:00
|
|
|
bp->len = cpu_to_be16(nbytes);
|
2007-10-26 15:41:21 +08:00
|
|
|
|
2008-07-19 15:01:42 +08:00
|
|
|
sg_init_one(&sg, bp, sizeof(*bp));
|
|
|
|
return crypto_hash_update(&hp->md5_desc, &sg, sizeof(*bp));
|
|
|
|
}
|
|
|
|
|
|
|
|
static int tcp_v4_md5_hash_hdr(char *md5_hash, struct tcp_md5sig_key *key,
|
|
|
|
__be32 daddr, __be32 saddr, struct tcphdr *th)
|
|
|
|
{
|
|
|
|
struct tcp_md5sig_pool *hp;
|
|
|
|
struct hash_desc *desc;
|
|
|
|
|
|
|
|
hp = tcp_get_md5sig_pool();
|
|
|
|
if (!hp)
|
|
|
|
goto clear_hash_noput;
|
|
|
|
desc = &hp->md5_desc;
|
|
|
|
|
|
|
|
if (crypto_hash_init(desc))
|
|
|
|
goto clear_hash;
|
|
|
|
if (tcp_v4_md5_hash_pseudoheader(hp, daddr, saddr, th->doff << 2))
|
|
|
|
goto clear_hash;
|
|
|
|
if (tcp_md5_hash_header(hp, th))
|
|
|
|
goto clear_hash;
|
|
|
|
if (tcp_md5_hash_key(hp, key))
|
|
|
|
goto clear_hash;
|
|
|
|
if (crypto_hash_final(desc, md5_hash))
|
2006-11-15 11:07:45 +08:00
|
|
|
goto clear_hash;
|
|
|
|
|
|
|
|
tcp_put_md5sig_pool();
|
|
|
|
return 0;
|
2008-07-19 15:01:42 +08:00
|
|
|
|
2006-11-15 11:07:45 +08:00
|
|
|
clear_hash:
|
|
|
|
tcp_put_md5sig_pool();
|
|
|
|
clear_hash_noput:
|
|
|
|
memset(md5_hash, 0, 16);
|
2008-07-19 15:01:42 +08:00
|
|
|
return 1;
|
2006-11-15 11:07:45 +08:00
|
|
|
}
|
|
|
|
|
2008-07-19 15:01:42 +08:00
|
|
|
int tcp_v4_md5_hash_skb(char *md5_hash, struct tcp_md5sig_key *key,
|
|
|
|
struct sock *sk, struct request_sock *req,
|
|
|
|
struct sk_buff *skb)
|
2006-11-15 11:07:45 +08:00
|
|
|
{
|
2008-07-19 15:01:42 +08:00
|
|
|
struct tcp_md5sig_pool *hp;
|
|
|
|
struct hash_desc *desc;
|
|
|
|
struct tcphdr *th = tcp_hdr(skb);
|
2006-11-15 11:07:45 +08:00
|
|
|
__be32 saddr, daddr;
|
|
|
|
|
|
|
|
if (sk) {
|
2009-10-15 14:30:45 +08:00
|
|
|
saddr = inet_sk(sk)->inet_saddr;
|
|
|
|
daddr = inet_sk(sk)->inet_daddr;
|
2008-07-19 15:01:42 +08:00
|
|
|
} else if (req) {
|
|
|
|
saddr = inet_rsk(req)->loc_addr;
|
|
|
|
daddr = inet_rsk(req)->rmt_addr;
|
2006-11-15 11:07:45 +08:00
|
|
|
} else {
|
2008-07-19 15:01:42 +08:00
|
|
|
const struct iphdr *iph = ip_hdr(skb);
|
|
|
|
saddr = iph->saddr;
|
|
|
|
daddr = iph->daddr;
|
2006-11-15 11:07:45 +08:00
|
|
|
}
|
2008-07-19 15:01:42 +08:00
|
|
|
|
|
|
|
hp = tcp_get_md5sig_pool();
|
|
|
|
if (!hp)
|
|
|
|
goto clear_hash_noput;
|
|
|
|
desc = &hp->md5_desc;
|
|
|
|
|
|
|
|
if (crypto_hash_init(desc))
|
|
|
|
goto clear_hash;
|
|
|
|
|
|
|
|
if (tcp_v4_md5_hash_pseudoheader(hp, daddr, saddr, skb->len))
|
|
|
|
goto clear_hash;
|
|
|
|
if (tcp_md5_hash_header(hp, th))
|
|
|
|
goto clear_hash;
|
|
|
|
if (tcp_md5_hash_skb_data(hp, skb, th->doff << 2))
|
|
|
|
goto clear_hash;
|
|
|
|
if (tcp_md5_hash_key(hp, key))
|
|
|
|
goto clear_hash;
|
|
|
|
if (crypto_hash_final(desc, md5_hash))
|
|
|
|
goto clear_hash;
|
|
|
|
|
|
|
|
tcp_put_md5sig_pool();
|
|
|
|
return 0;
|
|
|
|
|
|
|
|
clear_hash:
|
|
|
|
tcp_put_md5sig_pool();
|
|
|
|
clear_hash_noput:
|
|
|
|
memset(md5_hash, 0, 16);
|
|
|
|
return 1;
|
2006-11-15 11:07:45 +08:00
|
|
|
}
|
|
|
|
|
2008-07-19 15:01:42 +08:00
|
|
|
EXPORT_SYMBOL(tcp_v4_md5_hash_skb);
|
2006-11-15 11:07:45 +08:00
|
|
|
|
2006-11-17 20:57:30 +08:00
|
|
|
static int tcp_v4_inbound_md5_hash(struct sock *sk, struct sk_buff *skb)
|
2006-11-15 11:07:45 +08:00
|
|
|
{
|
|
|
|
/*
|
|
|
|
* This gets called for each TCP segment that arrives
|
|
|
|
* so we want to be efficient.
|
|
|
|
* We have 3 drop cases:
|
|
|
|
* o No MD5 hash and one expected.
|
|
|
|
* o MD5 hash and we're not expecting one.
|
|
|
|
* o MD5 hash and its wrong.
|
|
|
|
*/
|
|
|
|
__u8 *hash_location = NULL;
|
|
|
|
struct tcp_md5sig_key *hash_expected;
|
2007-04-21 13:47:35 +08:00
|
|
|
const struct iphdr *iph = ip_hdr(skb);
|
2007-04-11 12:04:22 +08:00
|
|
|
struct tcphdr *th = tcp_hdr(skb);
|
2006-11-15 11:07:45 +08:00
|
|
|
int genhash;
|
|
|
|
unsigned char newhash[16];
|
|
|
|
|
|
|
|
hash_expected = tcp_v4_md5_do_lookup(sk, iph->saddr);
|
2008-04-17 11:29:53 +08:00
|
|
|
hash_location = tcp_parse_md5sig_option(th);
|
2006-11-15 11:07:45 +08:00
|
|
|
|
|
|
|
/* We've parsed the options - do we have a hash? */
|
|
|
|
if (!hash_expected && !hash_location)
|
|
|
|
return 0;
|
|
|
|
|
|
|
|
if (hash_expected && !hash_location) {
|
2008-07-30 18:03:15 +08:00
|
|
|
NET_INC_STATS_BH(sock_net(sk), LINUX_MIB_TCPMD5NOTFOUND);
|
2006-11-15 11:07:45 +08:00
|
|
|
return 1;
|
|
|
|
}
|
|
|
|
|
|
|
|
if (!hash_expected && hash_location) {
|
2008-07-30 18:03:15 +08:00
|
|
|
NET_INC_STATS_BH(sock_net(sk), LINUX_MIB_TCPMD5UNEXPECTED);
|
2006-11-15 11:07:45 +08:00
|
|
|
return 1;
|
|
|
|
}
|
|
|
|
|
|
|
|
/* Okay, so this is hash_expected and hash_location -
|
|
|
|
* so we need to calculate the checksum.
|
|
|
|
*/
|
2008-07-19 15:01:42 +08:00
|
|
|
genhash = tcp_v4_md5_hash_skb(newhash,
|
|
|
|
hash_expected,
|
|
|
|
NULL, NULL, skb);
|
2006-11-15 11:07:45 +08:00
|
|
|
|
|
|
|
if (genhash || memcmp(hash_location, newhash, 16) != 0) {
|
|
|
|
if (net_ratelimit()) {
|
2008-10-31 15:53:57 +08:00
|
|
|
printk(KERN_INFO "MD5 Hash failed for (%pI4, %d)->(%pI4, %d)%s\n",
|
|
|
|
&iph->saddr, ntohs(th->source),
|
|
|
|
&iph->daddr, ntohs(th->dest),
|
2006-11-15 11:07:45 +08:00
|
|
|
genhash ? " tcp_v4_calc_md5_hash failed" : "");
|
|
|
|
}
|
|
|
|
return 1;
|
|
|
|
}
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
#endif
|
|
|
|
|
2006-11-16 18:30:37 +08:00
|
|
|
struct request_sock_ops tcp_request_sock_ops __read_mostly = {
|
2005-04-17 06:20:36 +08:00
|
|
|
.family = PF_INET,
|
[NET] Generalise TCP's struct open_request minisock infrastructure
Kept this first changeset minimal, without changing existing names to
ease peer review.
Basicaly tcp_openreq_alloc now receives the or_calltable, that in turn
has two new members:
->slab, that replaces tcp_openreq_cachep
->obj_size, to inform the size of the openreq descendant for
a specific protocol
The protocol specific fields in struct open_request were moved to a
class hierarchy, with the things that are common to all connection
oriented PF_INET protocols in struct inet_request_sock, the TCP ones
in tcp_request_sock, that is an inet_request_sock, that is an
open_request.
I.e. this uses the same approach used for the struct sock class
hierarchy, with sk_prot indicating if the protocol wants to use the
open_request infrastructure by filling in sk_prot->rsk_prot with an
or_calltable.
Results? Performance is improved and TCP v4 now uses only 64 bytes per
open request minisock, down from 96 without this patch :-)
Next changeset will rename some of the structs, fields and functions
mentioned above, struct or_calltable is way unclear, better name it
struct request_sock_ops, s/struct open_request/struct request_sock/g,
etc.
Signed-off-by: Arnaldo Carvalho de Melo <acme@ghostprotocols.net>
Signed-off-by: David S. Miller <davem@davemloft.net>
2005-06-19 13:46:52 +08:00
|
|
|
.obj_size = sizeof(struct tcp_request_sock),
|
2005-04-17 06:20:36 +08:00
|
|
|
.rtx_syn_ack = tcp_v4_send_synack,
|
2005-06-19 13:47:21 +08:00
|
|
|
.send_ack = tcp_v4_reqsk_send_ack,
|
|
|
|
.destructor = tcp_v4_reqsk_destructor,
|
2005-04-17 06:20:36 +08:00
|
|
|
.send_reset = tcp_v4_send_reset,
|
|
|
|
};
|
|
|
|
|
2006-11-15 11:07:45 +08:00
|
|
|
#ifdef CONFIG_TCP_MD5SIG
|
2009-09-02 03:25:03 +08:00
|
|
|
static const struct tcp_request_sock_ops tcp_request_sock_ipv4_ops = {
|
2006-11-15 11:07:45 +08:00
|
|
|
.md5_lookup = tcp_v4_reqsk_md5_lookup,
|
2009-07-16 13:04:51 +08:00
|
|
|
.calc_md5_hash = tcp_v4_md5_hash_skb,
|
2006-11-15 11:07:45 +08:00
|
|
|
};
|
2006-12-01 11:16:28 +08:00
|
|
|
#endif
|
2006-11-15 11:07:45 +08:00
|
|
|
|
2005-12-14 15:25:19 +08:00
|
|
|
static struct timewait_sock_ops tcp_timewait_sock_ops = {
|
|
|
|
.twsk_obj_size = sizeof(struct tcp_timewait_sock),
|
|
|
|
.twsk_unique = tcp_twsk_unique,
|
2006-11-15 11:07:45 +08:00
|
|
|
.twsk_destructor= tcp_twsk_destructor,
|
2005-12-14 15:25:19 +08:00
|
|
|
};
|
|
|
|
|
2005-04-17 06:20:36 +08:00
|
|
|
int tcp_v4_conn_request(struct sock *sk, struct sk_buff *skb)
|
|
|
|
{
|
|
|
|
struct tcp_options_received tmp_opt;
|
2005-06-19 13:47:21 +08:00
|
|
|
struct request_sock *req;
|
2009-12-03 02:07:39 +08:00
|
|
|
struct inet_request_sock *ireq;
|
|
|
|
struct dst_entry *dst = NULL;
|
2007-04-21 13:47:35 +08:00
|
|
|
__be32 saddr = ip_hdr(skb)->saddr;
|
|
|
|
__be32 daddr = ip_hdr(skb)->daddr;
|
2005-04-17 06:20:36 +08:00
|
|
|
__u32 isn = TCP_SKB_CB(skb)->when;
|
|
|
|
#ifdef CONFIG_SYN_COOKIES
|
|
|
|
int want_cookie = 0;
|
|
|
|
#else
|
|
|
|
#define want_cookie 0 /* Argh, why doesn't gcc optimize this :( */
|
|
|
|
#endif
|
|
|
|
|
|
|
|
/* Never answer to SYNs send to broadcast or multicast */
|
2009-06-02 13:14:27 +08:00
|
|
|
if (skb_rtable(skb)->rt_flags & (RTCF_BROADCAST | RTCF_MULTICAST))
|
2005-04-17 06:20:36 +08:00
|
|
|
goto drop;
|
|
|
|
|
|
|
|
/* TW buckets are converted to open requests without
|
|
|
|
* limitations, they conserve resources and peer is
|
|
|
|
* evidently real one.
|
|
|
|
*/
|
2005-08-10 11:10:42 +08:00
|
|
|
if (inet_csk_reqsk_queue_is_full(sk) && !isn) {
|
2005-04-17 06:20:36 +08:00
|
|
|
#ifdef CONFIG_SYN_COOKIES
|
|
|
|
if (sysctl_tcp_syncookies) {
|
|
|
|
want_cookie = 1;
|
|
|
|
} else
|
|
|
|
#endif
|
|
|
|
goto drop;
|
|
|
|
}
|
|
|
|
|
|
|
|
/* Accept backlog is full. If we have already queued enough
|
|
|
|
* of warm entries in syn queue, drop request. It is better than
|
|
|
|
* clogging syn queue with openreqs with exponentially increasing
|
|
|
|
* timeout.
|
|
|
|
*/
|
2005-08-10 11:10:42 +08:00
|
|
|
if (sk_acceptq_is_full(sk) && inet_csk_reqsk_queue_young(sk) > 1)
|
2005-04-17 06:20:36 +08:00
|
|
|
goto drop;
|
|
|
|
|
2008-06-11 03:39:35 +08:00
|
|
|
req = inet_reqsk_alloc(&tcp_request_sock_ops);
|
2005-04-17 06:20:36 +08:00
|
|
|
if (!req)
|
|
|
|
goto drop;
|
|
|
|
|
2006-11-15 11:07:45 +08:00
|
|
|
#ifdef CONFIG_TCP_MD5SIG
|
|
|
|
tcp_rsk(req)->af_specific = &tcp_request_sock_ipv4_ops;
|
|
|
|
#endif
|
|
|
|
|
2009-10-28 12:15:22 +08:00
|
|
|
ireq = inet_rsk(req);
|
|
|
|
ireq->loc_addr = daddr;
|
|
|
|
ireq->rmt_addr = saddr;
|
|
|
|
ireq->no_srccheck = inet_sk(sk)->transparent;
|
|
|
|
ireq->opt = tcp_v4_save_options(sk, skb);
|
|
|
|
|
|
|
|
dst = inet_csk_route_req(sk, req);
|
|
|
|
if(!dst)
|
|
|
|
goto drop_and_free;
|
|
|
|
|
2005-04-17 06:20:36 +08:00
|
|
|
tcp_clear_options(&tmp_opt);
|
2009-11-10 17:51:18 +08:00
|
|
|
tmp_opt.mss_clamp = TCP_MSS_DEFAULT;
|
2005-04-17 06:20:36 +08:00
|
|
|
tmp_opt.user_mss = tcp_sk(sk)->rx_opt.user_mss;
|
|
|
|
|
2009-10-28 12:15:22 +08:00
|
|
|
tcp_parse_options(skb, &tmp_opt, 0, dst);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
2008-04-10 18:12:40 +08:00
|
|
|
if (want_cookie && !tmp_opt.saw_tstamp)
|
2005-04-17 06:20:36 +08:00
|
|
|
tcp_clear_options(&tmp_opt);
|
|
|
|
|
|
|
|
tmp_opt.tstamp_ok = tmp_opt.saw_tstamp;
|
|
|
|
|
|
|
|
tcp_openreq_init(req, &tmp_opt, skb);
|
|
|
|
|
2009-03-28 05:10:28 +08:00
|
|
|
if (security_inet_conn_request(sk, skb, req))
|
2009-10-28 12:15:22 +08:00
|
|
|
goto drop_and_release;
|
2009-03-28 05:10:28 +08:00
|
|
|
|
2005-04-17 06:20:36 +08:00
|
|
|
if (!want_cookie)
|
2007-04-11 12:04:22 +08:00
|
|
|
TCP_ECN_create_request(req, tcp_hdr(skb));
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
if (want_cookie) {
|
|
|
|
#ifdef CONFIG_SYN_COOKIES
|
|
|
|
syn_flood_warning(skb);
|
2008-04-10 18:12:40 +08:00
|
|
|
req->cookie_ts = tmp_opt.tstamp_ok;
|
2005-04-17 06:20:36 +08:00
|
|
|
#endif
|
|
|
|
isn = cookie_v4_init_sequence(sk, skb, &req->mss);
|
|
|
|
} else if (!isn) {
|
|
|
|
struct inet_peer *peer = NULL;
|
|
|
|
|
|
|
|
/* VJ's idea. We save last timestamp seen
|
|
|
|
* from the destination in peer table, when entering
|
|
|
|
* state TIME-WAIT, and check against it before
|
|
|
|
* accepting new connection request.
|
|
|
|
*
|
|
|
|
* If "isn" is not zero, this request hit alive
|
|
|
|
* timewait bucket, so that all the necessary checks
|
|
|
|
* are made in the function processing timewait state.
|
|
|
|
*/
|
|
|
|
if (tmp_opt.saw_tstamp &&
|
2005-08-10 11:44:40 +08:00
|
|
|
tcp_death_row.sysctl_tw_recycle &&
|
2005-04-17 06:20:36 +08:00
|
|
|
(peer = rt_get_peer((struct rtable *)dst)) != NULL &&
|
|
|
|
peer->v4daddr == saddr) {
|
2009-11-12 17:33:09 +08:00
|
|
|
if ((u32)get_seconds() - peer->tcp_ts_stamp < TCP_PAWS_MSL &&
|
2005-04-17 06:20:36 +08:00
|
|
|
(s32)(peer->tcp_ts - req->ts_recent) >
|
|
|
|
TCP_PAWS_WINDOW) {
|
2008-07-17 11:31:16 +08:00
|
|
|
NET_INC_STATS_BH(sock_net(sk), LINUX_MIB_PAWSPASSIVEREJECTED);
|
2008-03-04 03:59:32 +08:00
|
|
|
goto drop_and_release;
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
|
|
|
}
|
|
|
|
/* Kill the following clause, if you dislike this way. */
|
|
|
|
else if (!sysctl_tcp_syncookies &&
|
2005-08-10 11:10:42 +08:00
|
|
|
(sysctl_max_syn_backlog - inet_csk_reqsk_queue_len(sk) <
|
2005-04-17 06:20:36 +08:00
|
|
|
(sysctl_max_syn_backlog >> 2)) &&
|
|
|
|
(!peer || !peer->tcp_ts_stamp) &&
|
|
|
|
(!dst || !dst_metric(dst, RTAX_RTT))) {
|
|
|
|
/* Without syncookies last quarter of
|
|
|
|
* backlog is filled with destinations,
|
|
|
|
* proven to be alive.
|
|
|
|
* It means that we continue to communicate
|
|
|
|
* to destinations, already remembered
|
|
|
|
* to the moment of synflood.
|
|
|
|
*/
|
2008-10-31 15:53:57 +08:00
|
|
|
LIMIT_NETDEBUG(KERN_DEBUG "TCP: drop open request from %pI4/%u\n",
|
|
|
|
&saddr, ntohs(tcp_hdr(skb)->source));
|
2008-03-04 03:59:32 +08:00
|
|
|
goto drop_and_release;
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
|
|
|
|
2006-11-11 06:06:49 +08:00
|
|
|
isn = tcp_v4_init_sequence(skb);
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
[NET] Generalise TCP's struct open_request minisock infrastructure
Kept this first changeset minimal, without changing existing names to
ease peer review.
Basicaly tcp_openreq_alloc now receives the or_calltable, that in turn
has two new members:
->slab, that replaces tcp_openreq_cachep
->obj_size, to inform the size of the openreq descendant for
a specific protocol
The protocol specific fields in struct open_request were moved to a
class hierarchy, with the things that are common to all connection
oriented PF_INET protocols in struct inet_request_sock, the TCP ones
in tcp_request_sock, that is an inet_request_sock, that is an
open_request.
I.e. this uses the same approach used for the struct sock class
hierarchy, with sk_prot indicating if the protocol wants to use the
open_request infrastructure by filling in sk_prot->rsk_prot with an
or_calltable.
Results? Performance is improved and TCP v4 now uses only 64 bytes per
open request minisock, down from 96 without this patch :-)
Next changeset will rename some of the structs, fields and functions
mentioned above, struct or_calltable is way unclear, better name it
struct request_sock_ops, s/struct open_request/struct request_sock/g,
etc.
Signed-off-by: Arnaldo Carvalho de Melo <acme@ghostprotocols.net>
Signed-off-by: David S. Miller <davem@davemloft.net>
2005-06-19 13:46:52 +08:00
|
|
|
tcp_rsk(req)->snt_isn = isn;
|
2005-04-17 06:20:36 +08:00
|
|
|
|
2009-12-03 02:07:39 +08:00
|
|
|
if (__tcp_v4_send_synack(sk, dst, req, NULL) || want_cookie)
|
2005-04-17 06:20:36 +08:00
|
|
|
goto drop_and_free;
|
|
|
|
|
2008-03-04 03:59:32 +08:00
|
|
|
inet_csk_reqsk_queue_hash_add(sk, req, TCP_TIMEOUT_INIT);
|
2005-04-17 06:20:36 +08:00
|
|
|
return 0;
|
|
|
|
|
2008-03-04 03:59:32 +08:00
|
|
|
drop_and_release:
|
|
|
|
dst_release(dst);
|
2005-04-17 06:20:36 +08:00
|
|
|
drop_and_free:
|
2005-06-19 13:47:21 +08:00
|
|
|
reqsk_free(req);
|
2005-04-17 06:20:36 +08:00
|
|
|
drop:
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/*
|
|
|
|
* The three way handshake has completed - we got a valid synack -
|
|
|
|
* now create the new socket.
|
|
|
|
*/
|
|
|
|
struct sock *tcp_v4_syn_recv_sock(struct sock *sk, struct sk_buff *skb,
|
2005-06-19 13:47:21 +08:00
|
|
|
struct request_sock *req,
|
2005-04-17 06:20:36 +08:00
|
|
|
struct dst_entry *dst)
|
|
|
|
{
|
[NET] Generalise TCP's struct open_request minisock infrastructure
Kept this first changeset minimal, without changing existing names to
ease peer review.
Basicaly tcp_openreq_alloc now receives the or_calltable, that in turn
has two new members:
->slab, that replaces tcp_openreq_cachep
->obj_size, to inform the size of the openreq descendant for
a specific protocol
The protocol specific fields in struct open_request were moved to a
class hierarchy, with the things that are common to all connection
oriented PF_INET protocols in struct inet_request_sock, the TCP ones
in tcp_request_sock, that is an inet_request_sock, that is an
open_request.
I.e. this uses the same approach used for the struct sock class
hierarchy, with sk_prot indicating if the protocol wants to use the
open_request infrastructure by filling in sk_prot->rsk_prot with an
or_calltable.
Results? Performance is improved and TCP v4 now uses only 64 bytes per
open request minisock, down from 96 without this patch :-)
Next changeset will rename some of the structs, fields and functions
mentioned above, struct or_calltable is way unclear, better name it
struct request_sock_ops, s/struct open_request/struct request_sock/g,
etc.
Signed-off-by: Arnaldo Carvalho de Melo <acme@ghostprotocols.net>
Signed-off-by: David S. Miller <davem@davemloft.net>
2005-06-19 13:46:52 +08:00
|
|
|
struct inet_request_sock *ireq;
|
2005-04-17 06:20:36 +08:00
|
|
|
struct inet_sock *newinet;
|
|
|
|
struct tcp_sock *newtp;
|
|
|
|
struct sock *newsk;
|
2006-11-15 11:07:45 +08:00
|
|
|
#ifdef CONFIG_TCP_MD5SIG
|
|
|
|
struct tcp_md5sig_key *key;
|
|
|
|
#endif
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
if (sk_acceptq_is_full(sk))
|
|
|
|
goto exit_overflow;
|
|
|
|
|
2005-08-10 11:10:42 +08:00
|
|
|
if (!dst && (dst = inet_csk_route_req(sk, req)) == NULL)
|
2005-04-17 06:20:36 +08:00
|
|
|
goto exit;
|
|
|
|
|
|
|
|
newsk = tcp_create_openreq_child(sk, req, skb);
|
|
|
|
if (!newsk)
|
|
|
|
goto exit;
|
|
|
|
|
2006-07-01 04:36:35 +08:00
|
|
|
newsk->sk_gso_type = SKB_GSO_TCPV4;
|
2005-08-10 10:49:02 +08:00
|
|
|
sk_setup_caps(newsk, dst);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
newtp = tcp_sk(newsk);
|
|
|
|
newinet = inet_sk(newsk);
|
[NET] Generalise TCP's struct open_request minisock infrastructure
Kept this first changeset minimal, without changing existing names to
ease peer review.
Basicaly tcp_openreq_alloc now receives the or_calltable, that in turn
has two new members:
->slab, that replaces tcp_openreq_cachep
->obj_size, to inform the size of the openreq descendant for
a specific protocol
The protocol specific fields in struct open_request were moved to a
class hierarchy, with the things that are common to all connection
oriented PF_INET protocols in struct inet_request_sock, the TCP ones
in tcp_request_sock, that is an inet_request_sock, that is an
open_request.
I.e. this uses the same approach used for the struct sock class
hierarchy, with sk_prot indicating if the protocol wants to use the
open_request infrastructure by filling in sk_prot->rsk_prot with an
or_calltable.
Results? Performance is improved and TCP v4 now uses only 64 bytes per
open request minisock, down from 96 without this patch :-)
Next changeset will rename some of the structs, fields and functions
mentioned above, struct or_calltable is way unclear, better name it
struct request_sock_ops, s/struct open_request/struct request_sock/g,
etc.
Signed-off-by: Arnaldo Carvalho de Melo <acme@ghostprotocols.net>
Signed-off-by: David S. Miller <davem@davemloft.net>
2005-06-19 13:46:52 +08:00
|
|
|
ireq = inet_rsk(req);
|
2009-10-15 14:30:45 +08:00
|
|
|
newinet->inet_daddr = ireq->rmt_addr;
|
|
|
|
newinet->inet_rcv_saddr = ireq->loc_addr;
|
|
|
|
newinet->inet_saddr = ireq->loc_addr;
|
[NET] Generalise TCP's struct open_request minisock infrastructure
Kept this first changeset minimal, without changing existing names to
ease peer review.
Basicaly tcp_openreq_alloc now receives the or_calltable, that in turn
has two new members:
->slab, that replaces tcp_openreq_cachep
->obj_size, to inform the size of the openreq descendant for
a specific protocol
The protocol specific fields in struct open_request were moved to a
class hierarchy, with the things that are common to all connection
oriented PF_INET protocols in struct inet_request_sock, the TCP ones
in tcp_request_sock, that is an inet_request_sock, that is an
open_request.
I.e. this uses the same approach used for the struct sock class
hierarchy, with sk_prot indicating if the protocol wants to use the
open_request infrastructure by filling in sk_prot->rsk_prot with an
or_calltable.
Results? Performance is improved and TCP v4 now uses only 64 bytes per
open request minisock, down from 96 without this patch :-)
Next changeset will rename some of the structs, fields and functions
mentioned above, struct or_calltable is way unclear, better name it
struct request_sock_ops, s/struct open_request/struct request_sock/g,
etc.
Signed-off-by: Arnaldo Carvalho de Melo <acme@ghostprotocols.net>
Signed-off-by: David S. Miller <davem@davemloft.net>
2005-06-19 13:46:52 +08:00
|
|
|
newinet->opt = ireq->opt;
|
|
|
|
ireq->opt = NULL;
|
2005-08-10 11:10:42 +08:00
|
|
|
newinet->mc_index = inet_iif(skb);
|
2007-04-21 13:47:35 +08:00
|
|
|
newinet->mc_ttl = ip_hdr(skb)->ttl;
|
2005-12-14 15:26:10 +08:00
|
|
|
inet_csk(newsk)->icsk_ext_hdr_len = 0;
|
2005-04-17 06:20:36 +08:00
|
|
|
if (newinet->opt)
|
2005-12-14 15:26:10 +08:00
|
|
|
inet_csk(newsk)->icsk_ext_hdr_len = newinet->opt->optlen;
|
2009-10-15 14:30:45 +08:00
|
|
|
newinet->inet_id = newtp->write_seq ^ jiffies;
|
2005-04-17 06:20:36 +08:00
|
|
|
|
2006-03-21 09:53:41 +08:00
|
|
|
tcp_mtup_init(newsk);
|
2005-04-17 06:20:36 +08:00
|
|
|
tcp_sync_mss(newsk, dst_mtu(dst));
|
|
|
|
newtp->advmss = dst_metric(dst, RTAX_ADVMSS);
|
2008-09-21 15:21:51 +08:00
|
|
|
if (tcp_sk(sk)->rx_opt.user_mss &&
|
|
|
|
tcp_sk(sk)->rx_opt.user_mss < newtp->advmss)
|
|
|
|
newtp->advmss = tcp_sk(sk)->rx_opt.user_mss;
|
|
|
|
|
2005-04-17 06:20:36 +08:00
|
|
|
tcp_initialize_rcv_mss(newsk);
|
|
|
|
|
2006-11-15 11:07:45 +08:00
|
|
|
#ifdef CONFIG_TCP_MD5SIG
|
|
|
|
/* Copy over the MD5 key from the original socket */
|
2009-10-15 14:30:45 +08:00
|
|
|
key = tcp_v4_md5_do_lookup(sk, newinet->inet_daddr);
|
|
|
|
if (key != NULL) {
|
2006-11-15 11:07:45 +08:00
|
|
|
/*
|
|
|
|
* We're using one, so create a matching key
|
|
|
|
* on the newsk structure. If we fail to get
|
|
|
|
* memory, then we end up not copying the key
|
|
|
|
* across. Shucks.
|
|
|
|
*/
|
2006-11-17 21:06:01 +08:00
|
|
|
char *newkey = kmemdup(key->key, key->keylen, GFP_ATOMIC);
|
|
|
|
if (newkey != NULL)
|
2009-10-15 14:30:45 +08:00
|
|
|
tcp_v4_md5_do_add(newsk, newinet->inet_daddr,
|
2006-11-15 11:07:45 +08:00
|
|
|
newkey, key->keylen);
|
2008-07-19 15:01:42 +08:00
|
|
|
newsk->sk_route_caps &= ~NETIF_F_GSO_MASK;
|
2006-11-15 11:07:45 +08:00
|
|
|
}
|
|
|
|
#endif
|
|
|
|
|
[SOCK] proto: Add hashinfo member to struct proto
This way we can remove TCP and DCCP specific versions of
sk->sk_prot->get_port: both v4 and v6 use inet_csk_get_port
sk->sk_prot->hash: inet_hash is directly used, only v6 need
a specific version to deal with mapped sockets
sk->sk_prot->unhash: both v4 and v6 use inet_hash directly
struct inet_connection_sock_af_ops also gets a new member, bind_conflict, so
that inet_csk_get_port can find the per family routine.
Now only the lookup routines receive as a parameter a struct inet_hashtable.
With this we further reuse code, reducing the difference among INET transport
protocols.
Eventually work has to be done on UDP and SCTP to make them share this
infrastructure and get as a bonus inet_diag interfaces so that iproute can be
used with these protocols.
net-2.6/net/ipv4/inet_hashtables.c:
struct proto | +8
struct inet_connection_sock_af_ops | +8
2 structs changed
__inet_hash_nolisten | +18
__inet_hash | -210
inet_put_port | +8
inet_bind_bucket_create | +1
__inet_hash_connect | -8
5 functions changed, 27 bytes added, 218 bytes removed, diff: -191
net-2.6/net/core/sock.c:
proto_seq_show | +3
1 function changed, 3 bytes added, diff: +3
net-2.6/net/ipv4/inet_connection_sock.c:
inet_csk_get_port | +15
1 function changed, 15 bytes added, diff: +15
net-2.6/net/ipv4/tcp.c:
tcp_set_state | -7
1 function changed, 7 bytes removed, diff: -7
net-2.6/net/ipv4/tcp_ipv4.c:
tcp_v4_get_port | -31
tcp_v4_hash | -48
tcp_v4_destroy_sock | -7
tcp_v4_syn_recv_sock | -2
tcp_unhash | -179
5 functions changed, 267 bytes removed, diff: -267
net-2.6/net/ipv6/inet6_hashtables.c:
__inet6_hash | +8
1 function changed, 8 bytes added, diff: +8
net-2.6/net/ipv4/inet_hashtables.c:
inet_unhash | +190
inet_hash | +242
2 functions changed, 432 bytes added, diff: +432
vmlinux:
16 functions changed, 485 bytes added, 492 bytes removed, diff: -7
/home/acme/git/net-2.6/net/ipv6/tcp_ipv6.c:
tcp_v6_get_port | -31
tcp_v6_hash | -7
tcp_v6_syn_recv_sock | -9
3 functions changed, 47 bytes removed, diff: -47
/home/acme/git/net-2.6/net/dccp/proto.c:
dccp_destroy_sock | -7
dccp_unhash | -179
dccp_hash | -49
dccp_set_state | -7
dccp_done | +1
5 functions changed, 1 bytes added, 242 bytes removed, diff: -241
/home/acme/git/net-2.6/net/dccp/ipv4.c:
dccp_v4_get_port | -31
dccp_v4_request_recv_sock | -2
2 functions changed, 33 bytes removed, diff: -33
/home/acme/git/net-2.6/net/dccp/ipv6.c:
dccp_v6_get_port | -31
dccp_v6_hash | -7
dccp_v6_request_recv_sock | +5
3 functions changed, 5 bytes added, 38 bytes removed, diff: -33
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2008-02-03 20:06:04 +08:00
|
|
|
__inet_hash_nolisten(newsk);
|
|
|
|
__inet_inherit_port(sk, newsk);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
return newsk;
|
|
|
|
|
|
|
|
exit_overflow:
|
2008-07-17 11:31:16 +08:00
|
|
|
NET_INC_STATS_BH(sock_net(sk), LINUX_MIB_LISTENOVERFLOWS);
|
2005-04-17 06:20:36 +08:00
|
|
|
exit:
|
2008-07-17 11:31:16 +08:00
|
|
|
NET_INC_STATS_BH(sock_net(sk), LINUX_MIB_LISTENDROPS);
|
2005-04-17 06:20:36 +08:00
|
|
|
dst_release(dst);
|
|
|
|
return NULL;
|
|
|
|
}
|
|
|
|
|
|
|
|
static struct sock *tcp_v4_hnd_req(struct sock *sk, struct sk_buff *skb)
|
|
|
|
{
|
2007-04-11 12:04:22 +08:00
|
|
|
struct tcphdr *th = tcp_hdr(skb);
|
2007-04-21 13:47:35 +08:00
|
|
|
const struct iphdr *iph = ip_hdr(skb);
|
2005-04-17 06:20:36 +08:00
|
|
|
struct sock *nsk;
|
2005-06-19 13:47:21 +08:00
|
|
|
struct request_sock **prev;
|
2005-04-17 06:20:36 +08:00
|
|
|
/* Find possible connection requests. */
|
2005-08-10 11:10:42 +08:00
|
|
|
struct request_sock *req = inet_csk_search_req(sk, &prev, th->source,
|
|
|
|
iph->saddr, iph->daddr);
|
2005-04-17 06:20:36 +08:00
|
|
|
if (req)
|
|
|
|
return tcp_check_req(sk, skb, req, prev);
|
|
|
|
|
2008-03-26 01:26:21 +08:00
|
|
|
nsk = inet_lookup_established(sock_net(sk), &tcp_hashinfo, iph->saddr,
|
2008-01-31 21:06:40 +08:00
|
|
|
th->source, iph->daddr, th->dest, inet_iif(skb));
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
if (nsk) {
|
|
|
|
if (nsk->sk_state != TCP_TIME_WAIT) {
|
|
|
|
bh_lock_sock(nsk);
|
|
|
|
return nsk;
|
|
|
|
}
|
2006-10-11 10:41:46 +08:00
|
|
|
inet_twsk_put(inet_twsk(nsk));
|
2005-04-17 06:20:36 +08:00
|
|
|
return NULL;
|
|
|
|
}
|
|
|
|
|
|
|
|
#ifdef CONFIG_SYN_COOKIES
|
|
|
|
if (!th->rst && !th->syn && th->ack)
|
|
|
|
sk = cookie_v4_check(sk, skb, &(IPCB(skb)->opt));
|
|
|
|
#endif
|
|
|
|
return sk;
|
|
|
|
}
|
|
|
|
|
2006-11-15 13:40:42 +08:00
|
|
|
static __sum16 tcp_v4_checksum_init(struct sk_buff *skb)
|
2005-04-17 06:20:36 +08:00
|
|
|
{
|
2007-04-21 13:47:35 +08:00
|
|
|
const struct iphdr *iph = ip_hdr(skb);
|
|
|
|
|
2006-08-30 07:44:56 +08:00
|
|
|
if (skb->ip_summed == CHECKSUM_COMPLETE) {
|
2007-04-21 13:47:35 +08:00
|
|
|
if (!tcp_v4_check(skb->len, iph->saddr,
|
|
|
|
iph->daddr, skb->csum)) {
|
2005-11-11 05:01:24 +08:00
|
|
|
skb->ip_summed = CHECKSUM_UNNECESSARY;
|
2005-04-17 06:20:36 +08:00
|
|
|
return 0;
|
2005-11-11 05:01:24 +08:00
|
|
|
}
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
2005-11-11 05:01:24 +08:00
|
|
|
|
2007-04-21 13:47:35 +08:00
|
|
|
skb->csum = csum_tcpudp_nofold(iph->saddr, iph->daddr,
|
2005-11-11 05:01:24 +08:00
|
|
|
skb->len, IPPROTO_TCP, 0);
|
|
|
|
|
2005-04-17 06:20:36 +08:00
|
|
|
if (skb->len <= 76) {
|
2005-11-11 05:01:24 +08:00
|
|
|
return __skb_checksum_complete(skb);
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/* The socket must have it's spinlock held when we get
|
|
|
|
* here.
|
|
|
|
*
|
|
|
|
* We have a potential double-lock case here, so even when
|
|
|
|
* doing backlog processing we use the BH locking scheme.
|
|
|
|
* This is because we cannot sleep with the original spinlock
|
|
|
|
* held.
|
|
|
|
*/
|
|
|
|
int tcp_v4_do_rcv(struct sock *sk, struct sk_buff *skb)
|
|
|
|
{
|
2006-11-15 11:07:45 +08:00
|
|
|
struct sock *rsk;
|
|
|
|
#ifdef CONFIG_TCP_MD5SIG
|
|
|
|
/*
|
|
|
|
* We really want to reject the packet as early as possible
|
|
|
|
* if:
|
|
|
|
* o We're expecting an MD5'd packet and this is no MD5 tcp option
|
|
|
|
* o There is an MD5 option and we're not expecting one
|
|
|
|
*/
|
2006-11-17 20:57:30 +08:00
|
|
|
if (tcp_v4_inbound_md5_hash(sk, skb))
|
2006-11-15 11:07:45 +08:00
|
|
|
goto discard;
|
|
|
|
#endif
|
|
|
|
|
2005-04-17 06:20:36 +08:00
|
|
|
if (sk->sk_state == TCP_ESTABLISHED) { /* Fast path */
|
|
|
|
TCP_CHECK_TIMER(sk);
|
2007-04-11 12:04:22 +08:00
|
|
|
if (tcp_rcv_established(sk, skb, tcp_hdr(skb), skb->len)) {
|
2006-11-15 11:07:45 +08:00
|
|
|
rsk = sk;
|
2005-04-17 06:20:36 +08:00
|
|
|
goto reset;
|
2006-11-15 11:07:45 +08:00
|
|
|
}
|
2005-04-17 06:20:36 +08:00
|
|
|
TCP_CHECK_TIMER(sk);
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
2007-03-19 08:43:48 +08:00
|
|
|
if (skb->len < tcp_hdrlen(skb) || tcp_checksum_complete(skb))
|
2005-04-17 06:20:36 +08:00
|
|
|
goto csum_err;
|
|
|
|
|
|
|
|
if (sk->sk_state == TCP_LISTEN) {
|
|
|
|
struct sock *nsk = tcp_v4_hnd_req(sk, skb);
|
|
|
|
if (!nsk)
|
|
|
|
goto discard;
|
|
|
|
|
|
|
|
if (nsk != sk) {
|
2006-11-15 11:07:45 +08:00
|
|
|
if (tcp_child_process(sk, nsk, skb)) {
|
|
|
|
rsk = nsk;
|
2005-04-17 06:20:36 +08:00
|
|
|
goto reset;
|
2006-11-15 11:07:45 +08:00
|
|
|
}
|
2005-04-17 06:20:36 +08:00
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
TCP_CHECK_TIMER(sk);
|
2007-04-11 12:04:22 +08:00
|
|
|
if (tcp_rcv_state_process(sk, skb, tcp_hdr(skb), skb->len)) {
|
2006-11-15 11:07:45 +08:00
|
|
|
rsk = sk;
|
2005-04-17 06:20:36 +08:00
|
|
|
goto reset;
|
2006-11-15 11:07:45 +08:00
|
|
|
}
|
2005-04-17 06:20:36 +08:00
|
|
|
TCP_CHECK_TIMER(sk);
|
|
|
|
return 0;
|
|
|
|
|
|
|
|
reset:
|
2006-11-15 11:07:45 +08:00
|
|
|
tcp_v4_send_reset(rsk, skb);
|
2005-04-17 06:20:36 +08:00
|
|
|
discard:
|
|
|
|
kfree_skb(skb);
|
|
|
|
/* Be careful here. If this function gets more complicated and
|
|
|
|
* gcc suffers from register pressure on the x86, sk (in %ebx)
|
|
|
|
* might be destroyed here. This current version compiles correctly,
|
|
|
|
* but you have been warned.
|
|
|
|
*/
|
|
|
|
return 0;
|
|
|
|
|
|
|
|
csum_err:
|
2008-07-17 11:22:25 +08:00
|
|
|
TCP_INC_STATS_BH(sock_net(sk), TCP_MIB_INERRS);
|
2005-04-17 06:20:36 +08:00
|
|
|
goto discard;
|
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* From tcp_input.c
|
|
|
|
*/
|
|
|
|
|
|
|
|
int tcp_v4_rcv(struct sk_buff *skb)
|
|
|
|
{
|
2007-04-21 13:47:35 +08:00
|
|
|
const struct iphdr *iph;
|
2005-04-17 06:20:36 +08:00
|
|
|
struct tcphdr *th;
|
|
|
|
struct sock *sk;
|
|
|
|
int ret;
|
2008-07-17 11:20:58 +08:00
|
|
|
struct net *net = dev_net(skb->dev);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
if (skb->pkt_type != PACKET_HOST)
|
|
|
|
goto discard_it;
|
|
|
|
|
|
|
|
/* Count it even if it's bad */
|
2008-07-17 11:22:25 +08:00
|
|
|
TCP_INC_STATS_BH(net, TCP_MIB_INSEGS);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
if (!pskb_may_pull(skb, sizeof(struct tcphdr)))
|
|
|
|
goto discard_it;
|
|
|
|
|
2007-04-11 12:04:22 +08:00
|
|
|
th = tcp_hdr(skb);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
if (th->doff < sizeof(struct tcphdr) / 4)
|
|
|
|
goto bad_packet;
|
|
|
|
if (!pskb_may_pull(skb, th->doff * 4))
|
|
|
|
goto discard_it;
|
|
|
|
|
|
|
|
/* An explanation is required here, I think.
|
|
|
|
* Packet length and doff are validated by header prediction,
|
2005-11-11 09:13:47 +08:00
|
|
|
* provided case of th->doff==0 is eliminated.
|
2005-04-17 06:20:36 +08:00
|
|
|
* So, we defer the checks. */
|
2007-04-10 02:59:39 +08:00
|
|
|
if (!skb_csum_unnecessary(skb) && tcp_v4_checksum_init(skb))
|
2005-04-17 06:20:36 +08:00
|
|
|
goto bad_packet;
|
|
|
|
|
2007-04-11 12:04:22 +08:00
|
|
|
th = tcp_hdr(skb);
|
2007-04-21 13:47:35 +08:00
|
|
|
iph = ip_hdr(skb);
|
2005-04-17 06:20:36 +08:00
|
|
|
TCP_SKB_CB(skb)->seq = ntohl(th->seq);
|
|
|
|
TCP_SKB_CB(skb)->end_seq = (TCP_SKB_CB(skb)->seq + th->syn + th->fin +
|
|
|
|
skb->len - th->doff * 4);
|
|
|
|
TCP_SKB_CB(skb)->ack_seq = ntohl(th->ack_seq);
|
|
|
|
TCP_SKB_CB(skb)->when = 0;
|
2007-04-21 13:47:35 +08:00
|
|
|
TCP_SKB_CB(skb)->flags = iph->tos;
|
2005-04-17 06:20:36 +08:00
|
|
|
TCP_SKB_CB(skb)->sacked = 0;
|
|
|
|
|
2008-10-08 02:41:57 +08:00
|
|
|
sk = __inet_lookup_skb(&tcp_hashinfo, skb, th->source, th->dest);
|
2005-04-17 06:20:36 +08:00
|
|
|
if (!sk)
|
|
|
|
goto no_tcp_socket;
|
|
|
|
|
|
|
|
process:
|
|
|
|
if (sk->sk_state == TCP_TIME_WAIT)
|
|
|
|
goto do_time_wait;
|
|
|
|
|
|
|
|
if (!xfrm4_policy_check(sk, XFRM_POLICY_IN, skb))
|
|
|
|
goto discard_and_relse;
|
2006-01-07 15:06:10 +08:00
|
|
|
nf_reset(skb);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
2006-09-01 06:28:39 +08:00
|
|
|
if (sk_filter(sk, skb))
|
2005-04-17 06:20:36 +08:00
|
|
|
goto discard_and_relse;
|
|
|
|
|
|
|
|
skb->dev = NULL;
|
|
|
|
|
2006-07-03 15:25:13 +08:00
|
|
|
bh_lock_sock_nested(sk);
|
2005-04-17 06:20:36 +08:00
|
|
|
ret = 0;
|
|
|
|
if (!sock_owned_by_user(sk)) {
|
2006-05-24 09:05:53 +08:00
|
|
|
#ifdef CONFIG_NET_DMA
|
|
|
|
struct tcp_sock *tp = tcp_sk(sk);
|
|
|
|
if (!tp->ucopy.dma_chan && tp->ucopy.pinned_list)
|
2009-01-07 02:38:15 +08:00
|
|
|
tp->ucopy.dma_chan = dma_find_channel(DMA_MEMCPY);
|
2006-05-24 09:05:53 +08:00
|
|
|
if (tp->ucopy.dma_chan)
|
2005-04-17 06:20:36 +08:00
|
|
|
ret = tcp_v4_do_rcv(sk, skb);
|
2006-05-24 09:05:53 +08:00
|
|
|
else
|
|
|
|
#endif
|
|
|
|
{
|
|
|
|
if (!tcp_prequeue(sk, skb))
|
2009-05-05 09:01:29 +08:00
|
|
|
ret = tcp_v4_do_rcv(sk, skb);
|
2006-05-24 09:05:53 +08:00
|
|
|
}
|
2005-04-17 06:20:36 +08:00
|
|
|
} else
|
|
|
|
sk_add_backlog(sk, skb);
|
|
|
|
bh_unlock_sock(sk);
|
|
|
|
|
|
|
|
sock_put(sk);
|
|
|
|
|
|
|
|
return ret;
|
|
|
|
|
|
|
|
no_tcp_socket:
|
|
|
|
if (!xfrm4_policy_check(NULL, XFRM_POLICY_IN, skb))
|
|
|
|
goto discard_it;
|
|
|
|
|
|
|
|
if (skb->len < (th->doff << 2) || tcp_checksum_complete(skb)) {
|
|
|
|
bad_packet:
|
2008-07-17 11:22:25 +08:00
|
|
|
TCP_INC_STATS_BH(net, TCP_MIB_INERRS);
|
2005-04-17 06:20:36 +08:00
|
|
|
} else {
|
2006-11-15 11:07:45 +08:00
|
|
|
tcp_v4_send_reset(NULL, skb);
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
discard_it:
|
|
|
|
/* Discard frame. */
|
|
|
|
kfree_skb(skb);
|
2007-02-09 22:24:47 +08:00
|
|
|
return 0;
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
discard_and_relse:
|
|
|
|
sock_put(sk);
|
|
|
|
goto discard_it;
|
|
|
|
|
|
|
|
do_time_wait:
|
|
|
|
if (!xfrm4_policy_check(NULL, XFRM_POLICY_IN, skb)) {
|
2006-10-11 10:41:46 +08:00
|
|
|
inet_twsk_put(inet_twsk(sk));
|
2005-04-17 06:20:36 +08:00
|
|
|
goto discard_it;
|
|
|
|
}
|
|
|
|
|
|
|
|
if (skb->len < (th->doff << 2) || tcp_checksum_complete(skb)) {
|
2008-07-17 11:22:25 +08:00
|
|
|
TCP_INC_STATS_BH(net, TCP_MIB_INERRS);
|
2006-10-11 10:41:46 +08:00
|
|
|
inet_twsk_put(inet_twsk(sk));
|
2005-04-17 06:20:36 +08:00
|
|
|
goto discard_it;
|
|
|
|
}
|
2006-10-11 10:41:46 +08:00
|
|
|
switch (tcp_timewait_state_process(inet_twsk(sk), skb, th)) {
|
2005-04-17 06:20:36 +08:00
|
|
|
case TCP_TW_SYN: {
|
2008-03-25 20:47:49 +08:00
|
|
|
struct sock *sk2 = inet_lookup_listener(dev_net(skb->dev),
|
2008-01-31 21:06:40 +08:00
|
|
|
&tcp_hashinfo,
|
2007-04-21 13:47:35 +08:00
|
|
|
iph->daddr, th->dest,
|
2005-08-10 11:10:42 +08:00
|
|
|
inet_iif(skb));
|
2005-04-17 06:20:36 +08:00
|
|
|
if (sk2) {
|
2006-10-11 10:41:46 +08:00
|
|
|
inet_twsk_deschedule(inet_twsk(sk), &tcp_death_row);
|
|
|
|
inet_twsk_put(inet_twsk(sk));
|
2005-04-17 06:20:36 +08:00
|
|
|
sk = sk2;
|
|
|
|
goto process;
|
|
|
|
}
|
|
|
|
/* Fall through to ACK */
|
|
|
|
}
|
|
|
|
case TCP_TW_ACK:
|
|
|
|
tcp_v4_timewait_ack(sk, skb);
|
|
|
|
break;
|
|
|
|
case TCP_TW_RST:
|
|
|
|
goto no_tcp_socket;
|
|
|
|
case TCP_TW_SUCCESS:;
|
|
|
|
}
|
|
|
|
goto discard_it;
|
|
|
|
}
|
|
|
|
|
|
|
|
/* VJ's idea. Save last timestamp seen from this destination
|
|
|
|
* and hold it at least for normal timewait interval to use for duplicate
|
|
|
|
* segment detection in subsequent connections, before they enter synchronized
|
|
|
|
* state.
|
|
|
|
*/
|
|
|
|
|
|
|
|
int tcp_v4_remember_stamp(struct sock *sk)
|
|
|
|
{
|
|
|
|
struct inet_sock *inet = inet_sk(sk);
|
|
|
|
struct tcp_sock *tp = tcp_sk(sk);
|
|
|
|
struct rtable *rt = (struct rtable *)__sk_dst_get(sk);
|
|
|
|
struct inet_peer *peer = NULL;
|
|
|
|
int release_it = 0;
|
|
|
|
|
2009-10-15 14:30:45 +08:00
|
|
|
if (!rt || rt->rt_dst != inet->inet_daddr) {
|
|
|
|
peer = inet_getpeer(inet->inet_daddr, 1);
|
2005-04-17 06:20:36 +08:00
|
|
|
release_it = 1;
|
|
|
|
} else {
|
|
|
|
if (!rt->peer)
|
|
|
|
rt_bind_peer(rt, 1);
|
|
|
|
peer = rt->peer;
|
|
|
|
}
|
|
|
|
|
|
|
|
if (peer) {
|
|
|
|
if ((s32)(peer->tcp_ts - tp->rx_opt.ts_recent) <= 0 ||
|
2009-11-12 17:33:09 +08:00
|
|
|
((u32)get_seconds() - peer->tcp_ts_stamp > TCP_PAWS_MSL &&
|
|
|
|
peer->tcp_ts_stamp <= (u32)tp->rx_opt.ts_recent_stamp)) {
|
|
|
|
peer->tcp_ts_stamp = (u32)tp->rx_opt.ts_recent_stamp;
|
2005-04-17 06:20:36 +08:00
|
|
|
peer->tcp_ts = tp->rx_opt.ts_recent;
|
|
|
|
}
|
|
|
|
if (release_it)
|
|
|
|
inet_putpeer(peer);
|
|
|
|
return 1;
|
|
|
|
}
|
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
2005-08-10 11:09:30 +08:00
|
|
|
int tcp_v4_tw_remember_stamp(struct inet_timewait_sock *tw)
|
2005-04-17 06:20:36 +08:00
|
|
|
{
|
2005-08-10 11:09:30 +08:00
|
|
|
struct inet_peer *peer = inet_getpeer(tw->tw_daddr, 1);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
if (peer) {
|
2005-08-10 11:09:30 +08:00
|
|
|
const struct tcp_timewait_sock *tcptw = tcp_twsk((struct sock *)tw);
|
|
|
|
|
|
|
|
if ((s32)(peer->tcp_ts - tcptw->tw_ts_recent) <= 0 ||
|
2009-11-12 17:33:09 +08:00
|
|
|
((u32)get_seconds() - peer->tcp_ts_stamp > TCP_PAWS_MSL &&
|
|
|
|
peer->tcp_ts_stamp <= (u32)tcptw->tw_ts_recent_stamp)) {
|
|
|
|
peer->tcp_ts_stamp = (u32)tcptw->tw_ts_recent_stamp;
|
2005-08-10 11:09:30 +08:00
|
|
|
peer->tcp_ts = tcptw->tw_ts_recent;
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
|
|
|
inet_putpeer(peer);
|
|
|
|
return 1;
|
|
|
|
}
|
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
2009-09-02 03:25:04 +08:00
|
|
|
const struct inet_connection_sock_af_ops ipv4_specific = {
|
2006-03-21 14:48:35 +08:00
|
|
|
.queue_xmit = ip_queue_xmit,
|
|
|
|
.send_check = tcp_v4_send_check,
|
|
|
|
.rebuild_header = inet_sk_rebuild_header,
|
|
|
|
.conn_request = tcp_v4_conn_request,
|
|
|
|
.syn_recv_sock = tcp_v4_syn_recv_sock,
|
|
|
|
.remember_stamp = tcp_v4_remember_stamp,
|
|
|
|
.net_header_len = sizeof(struct iphdr),
|
|
|
|
.setsockopt = ip_setsockopt,
|
|
|
|
.getsockopt = ip_getsockopt,
|
|
|
|
.addr2sockaddr = inet_csk_addr2sockaddr,
|
|
|
|
.sockaddr_len = sizeof(struct sockaddr_in),
|
[SOCK] proto: Add hashinfo member to struct proto
This way we can remove TCP and DCCP specific versions of
sk->sk_prot->get_port: both v4 and v6 use inet_csk_get_port
sk->sk_prot->hash: inet_hash is directly used, only v6 need
a specific version to deal with mapped sockets
sk->sk_prot->unhash: both v4 and v6 use inet_hash directly
struct inet_connection_sock_af_ops also gets a new member, bind_conflict, so
that inet_csk_get_port can find the per family routine.
Now only the lookup routines receive as a parameter a struct inet_hashtable.
With this we further reuse code, reducing the difference among INET transport
protocols.
Eventually work has to be done on UDP and SCTP to make them share this
infrastructure and get as a bonus inet_diag interfaces so that iproute can be
used with these protocols.
net-2.6/net/ipv4/inet_hashtables.c:
struct proto | +8
struct inet_connection_sock_af_ops | +8
2 structs changed
__inet_hash_nolisten | +18
__inet_hash | -210
inet_put_port | +8
inet_bind_bucket_create | +1
__inet_hash_connect | -8
5 functions changed, 27 bytes added, 218 bytes removed, diff: -191
net-2.6/net/core/sock.c:
proto_seq_show | +3
1 function changed, 3 bytes added, diff: +3
net-2.6/net/ipv4/inet_connection_sock.c:
inet_csk_get_port | +15
1 function changed, 15 bytes added, diff: +15
net-2.6/net/ipv4/tcp.c:
tcp_set_state | -7
1 function changed, 7 bytes removed, diff: -7
net-2.6/net/ipv4/tcp_ipv4.c:
tcp_v4_get_port | -31
tcp_v4_hash | -48
tcp_v4_destroy_sock | -7
tcp_v4_syn_recv_sock | -2
tcp_unhash | -179
5 functions changed, 267 bytes removed, diff: -267
net-2.6/net/ipv6/inet6_hashtables.c:
__inet6_hash | +8
1 function changed, 8 bytes added, diff: +8
net-2.6/net/ipv4/inet_hashtables.c:
inet_unhash | +190
inet_hash | +242
2 functions changed, 432 bytes added, diff: +432
vmlinux:
16 functions changed, 485 bytes added, 492 bytes removed, diff: -7
/home/acme/git/net-2.6/net/ipv6/tcp_ipv6.c:
tcp_v6_get_port | -31
tcp_v6_hash | -7
tcp_v6_syn_recv_sock | -9
3 functions changed, 47 bytes removed, diff: -47
/home/acme/git/net-2.6/net/dccp/proto.c:
dccp_destroy_sock | -7
dccp_unhash | -179
dccp_hash | -49
dccp_set_state | -7
dccp_done | +1
5 functions changed, 1 bytes added, 242 bytes removed, diff: -241
/home/acme/git/net-2.6/net/dccp/ipv4.c:
dccp_v4_get_port | -31
dccp_v4_request_recv_sock | -2
2 functions changed, 33 bytes removed, diff: -33
/home/acme/git/net-2.6/net/dccp/ipv6.c:
dccp_v6_get_port | -31
dccp_v6_hash | -7
dccp_v6_request_recv_sock | +5
3 functions changed, 5 bytes added, 38 bytes removed, diff: -33
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2008-02-03 20:06:04 +08:00
|
|
|
.bind_conflict = inet_csk_bind_conflict,
|
2006-03-21 14:45:21 +08:00
|
|
|
#ifdef CONFIG_COMPAT
|
2006-03-21 14:48:35 +08:00
|
|
|
.compat_setsockopt = compat_ip_setsockopt,
|
|
|
|
.compat_getsockopt = compat_ip_getsockopt,
|
2006-03-21 14:45:21 +08:00
|
|
|
#endif
|
2005-04-17 06:20:36 +08:00
|
|
|
};
|
|
|
|
|
2006-11-15 11:07:45 +08:00
|
|
|
#ifdef CONFIG_TCP_MD5SIG
|
2009-09-02 03:25:03 +08:00
|
|
|
static const struct tcp_sock_af_ops tcp_sock_ipv4_specific = {
|
2006-11-15 11:07:45 +08:00
|
|
|
.md5_lookup = tcp_v4_md5_lookup,
|
2008-07-19 15:01:42 +08:00
|
|
|
.calc_md5_hash = tcp_v4_md5_hash_skb,
|
2006-11-15 11:07:45 +08:00
|
|
|
.md5_add = tcp_v4_md5_add_func,
|
|
|
|
.md5_parse = tcp_v4_parse_md5_keys,
|
|
|
|
};
|
2006-12-01 11:16:28 +08:00
|
|
|
#endif
|
2006-11-15 11:07:45 +08:00
|
|
|
|
2005-04-17 06:20:36 +08:00
|
|
|
/* NOTE: A lot of things set to zero explicitly by call to
|
|
|
|
* sk_alloc() so need not be done here.
|
|
|
|
*/
|
|
|
|
static int tcp_v4_init_sock(struct sock *sk)
|
|
|
|
{
|
2005-08-10 15:03:31 +08:00
|
|
|
struct inet_connection_sock *icsk = inet_csk(sk);
|
2005-04-17 06:20:36 +08:00
|
|
|
struct tcp_sock *tp = tcp_sk(sk);
|
|
|
|
|
|
|
|
skb_queue_head_init(&tp->out_of_order_queue);
|
|
|
|
tcp_init_xmit_timers(sk);
|
|
|
|
tcp_prequeue_init(tp);
|
|
|
|
|
2005-08-10 15:03:31 +08:00
|
|
|
icsk->icsk_rto = TCP_TIMEOUT_INIT;
|
2005-04-17 06:20:36 +08:00
|
|
|
tp->mdev = TCP_TIMEOUT_INIT;
|
|
|
|
|
|
|
|
/* So many TCP implementations out there (incorrectly) count the
|
|
|
|
* initial SYN frame in their delayed-ACK and congestion control
|
|
|
|
* algorithms that we must have the following bandaid to talk
|
|
|
|
* efficiently to them. -DaveM
|
|
|
|
*/
|
|
|
|
tp->snd_cwnd = 2;
|
|
|
|
|
|
|
|
/* See draft-stevens-tcpca-spec-01 for discussion of the
|
|
|
|
* initialization of these values.
|
|
|
|
*/
|
2009-09-15 16:30:10 +08:00
|
|
|
tp->snd_ssthresh = TCP_INFINITE_SSTHRESH;
|
2005-04-17 06:20:36 +08:00
|
|
|
tp->snd_cwnd_clamp = ~0;
|
2009-11-10 17:51:18 +08:00
|
|
|
tp->mss_cache = TCP_MSS_DEFAULT;
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
tp->reordering = sysctl_tcp_reordering;
|
2005-08-10 15:03:31 +08:00
|
|
|
icsk->icsk_ca_ops = &tcp_init_congestion_ops;
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
sk->sk_state = TCP_CLOSE;
|
|
|
|
|
|
|
|
sk->sk_write_space = sk_stream_write_space;
|
|
|
|
sock_set_flag(sk, SOCK_USE_WRITE_QUEUE);
|
|
|
|
|
2005-12-14 15:15:52 +08:00
|
|
|
icsk->icsk_af_ops = &ipv4_specific;
|
2005-12-14 15:26:10 +08:00
|
|
|
icsk->icsk_sync_mss = tcp_sync_mss;
|
2006-11-15 11:07:45 +08:00
|
|
|
#ifdef CONFIG_TCP_MD5SIG
|
|
|
|
tp->af_specific = &tcp_sock_ipv4_specific;
|
|
|
|
#endif
|
2005-04-17 06:20:36 +08:00
|
|
|
|
TCPCT part 1d: define TCP cookie option, extend existing struct's
Data structures are carefully composed to require minimal additions.
For example, the struct tcp_options_received cookie_plus variable fits
between existing 16-bit and 8-bit variables, requiring no additional
space (taking alignment into consideration). There are no additions to
tcp_request_sock, and only 1 pointer in tcp_sock.
This is a significantly revised implementation of an earlier (year-old)
patch that no longer applies cleanly, with permission of the original
author (Adam Langley):
http://thread.gmane.org/gmane.linux.network/102586
The principle difference is using a TCP option to carry the cookie nonce,
instead of a user configured offset in the data. This is more flexible and
less subject to user configuration error. Such a cookie option has been
suggested for many years, and is also useful without SYN data, allowing
several related concepts to use the same extension option.
"Re: SYN floods (was: does history repeat itself?)", September 9, 1996.
http://www.merit.net/mail.archives/nanog/1996-09/msg00235.html
"Re: what a new TCP header might look like", May 12, 1998.
ftp://ftp.isi.edu/end2end/end2end-interest-1998.mail
These functions will also be used in subsequent patches that implement
additional features.
Requires:
TCPCT part 1a: add request_values parameter for sending SYNACK
TCPCT part 1b: generate Responder Cookie secret
TCPCT part 1c: sysctl_tcp_cookie_size, socket option TCP_COOKIE_TRANSACTIONS
Signed-off-by: William.Allen.Simpson@gmail.com
Signed-off-by: David S. Miller <davem@davemloft.net>
2009-12-03 02:17:05 +08:00
|
|
|
/* TCP Cookie Transactions */
|
|
|
|
if (sysctl_tcp_cookie_size > 0) {
|
|
|
|
/* Default, cookies without s_data_payload. */
|
|
|
|
tp->cookie_values =
|
|
|
|
kzalloc(sizeof(*tp->cookie_values),
|
|
|
|
sk->sk_allocation);
|
|
|
|
if (tp->cookie_values != NULL)
|
|
|
|
kref_init(&tp->cookie_values->kref);
|
|
|
|
}
|
|
|
|
/* Presumed zeroed, in order of appearance:
|
|
|
|
* cookie_in_always, cookie_out_never,
|
|
|
|
* s_data_constant, s_data_in, s_data_out
|
|
|
|
*/
|
2005-04-17 06:20:36 +08:00
|
|
|
sk->sk_sndbuf = sysctl_tcp_wmem[1];
|
|
|
|
sk->sk_rcvbuf = sysctl_tcp_rmem[1];
|
|
|
|
|
2008-12-30 15:04:08 +08:00
|
|
|
local_bh_disable();
|
2008-11-26 13:16:35 +08:00
|
|
|
percpu_counter_inc(&tcp_sockets_allocated);
|
2008-12-30 15:04:08 +08:00
|
|
|
local_bh_enable();
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
2008-06-15 08:04:49 +08:00
|
|
|
void tcp_v4_destroy_sock(struct sock *sk)
|
2005-04-17 06:20:36 +08:00
|
|
|
{
|
|
|
|
struct tcp_sock *tp = tcp_sk(sk);
|
|
|
|
|
|
|
|
tcp_clear_xmit_timers(sk);
|
|
|
|
|
2005-08-10 15:03:31 +08:00
|
|
|
tcp_cleanup_congestion_control(sk);
|
2005-06-24 03:19:55 +08:00
|
|
|
|
2005-04-17 06:20:36 +08:00
|
|
|
/* Cleanup up the write buffer. */
|
2007-03-08 04:12:44 +08:00
|
|
|
tcp_write_queue_purge(sk);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
/* Cleans up our, hopefully empty, out_of_order_queue. */
|
2007-02-09 22:24:47 +08:00
|
|
|
__skb_queue_purge(&tp->out_of_order_queue);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
2006-11-15 11:07:45 +08:00
|
|
|
#ifdef CONFIG_TCP_MD5SIG
|
|
|
|
/* Clean up the MD5 key list, if any */
|
|
|
|
if (tp->md5sig_info) {
|
|
|
|
tcp_v4_clear_md5_list(sk);
|
|
|
|
kfree(tp->md5sig_info);
|
|
|
|
tp->md5sig_info = NULL;
|
|
|
|
}
|
|
|
|
#endif
|
|
|
|
|
2006-05-24 09:05:53 +08:00
|
|
|
#ifdef CONFIG_NET_DMA
|
|
|
|
/* Cleans up our sk_async_wait_queue */
|
2007-02-09 22:24:47 +08:00
|
|
|
__skb_queue_purge(&sk->sk_async_wait_queue);
|
2006-05-24 09:05:53 +08:00
|
|
|
#endif
|
|
|
|
|
2005-04-17 06:20:36 +08:00
|
|
|
/* Clean prequeue, it must be empty really */
|
|
|
|
__skb_queue_purge(&tp->ucopy.prequeue);
|
|
|
|
|
|
|
|
/* Clean up a referenced TCP bind bucket. */
|
2005-08-10 11:10:42 +08:00
|
|
|
if (inet_csk(sk)->icsk_bind_hash)
|
[SOCK] proto: Add hashinfo member to struct proto
This way we can remove TCP and DCCP specific versions of
sk->sk_prot->get_port: both v4 and v6 use inet_csk_get_port
sk->sk_prot->hash: inet_hash is directly used, only v6 need
a specific version to deal with mapped sockets
sk->sk_prot->unhash: both v4 and v6 use inet_hash directly
struct inet_connection_sock_af_ops also gets a new member, bind_conflict, so
that inet_csk_get_port can find the per family routine.
Now only the lookup routines receive as a parameter a struct inet_hashtable.
With this we further reuse code, reducing the difference among INET transport
protocols.
Eventually work has to be done on UDP and SCTP to make them share this
infrastructure and get as a bonus inet_diag interfaces so that iproute can be
used with these protocols.
net-2.6/net/ipv4/inet_hashtables.c:
struct proto | +8
struct inet_connection_sock_af_ops | +8
2 structs changed
__inet_hash_nolisten | +18
__inet_hash | -210
inet_put_port | +8
inet_bind_bucket_create | +1
__inet_hash_connect | -8
5 functions changed, 27 bytes added, 218 bytes removed, diff: -191
net-2.6/net/core/sock.c:
proto_seq_show | +3
1 function changed, 3 bytes added, diff: +3
net-2.6/net/ipv4/inet_connection_sock.c:
inet_csk_get_port | +15
1 function changed, 15 bytes added, diff: +15
net-2.6/net/ipv4/tcp.c:
tcp_set_state | -7
1 function changed, 7 bytes removed, diff: -7
net-2.6/net/ipv4/tcp_ipv4.c:
tcp_v4_get_port | -31
tcp_v4_hash | -48
tcp_v4_destroy_sock | -7
tcp_v4_syn_recv_sock | -2
tcp_unhash | -179
5 functions changed, 267 bytes removed, diff: -267
net-2.6/net/ipv6/inet6_hashtables.c:
__inet6_hash | +8
1 function changed, 8 bytes added, diff: +8
net-2.6/net/ipv4/inet_hashtables.c:
inet_unhash | +190
inet_hash | +242
2 functions changed, 432 bytes added, diff: +432
vmlinux:
16 functions changed, 485 bytes added, 492 bytes removed, diff: -7
/home/acme/git/net-2.6/net/ipv6/tcp_ipv6.c:
tcp_v6_get_port | -31
tcp_v6_hash | -7
tcp_v6_syn_recv_sock | -9
3 functions changed, 47 bytes removed, diff: -47
/home/acme/git/net-2.6/net/dccp/proto.c:
dccp_destroy_sock | -7
dccp_unhash | -179
dccp_hash | -49
dccp_set_state | -7
dccp_done | +1
5 functions changed, 1 bytes added, 242 bytes removed, diff: -241
/home/acme/git/net-2.6/net/dccp/ipv4.c:
dccp_v4_get_port | -31
dccp_v4_request_recv_sock | -2
2 functions changed, 33 bytes removed, diff: -33
/home/acme/git/net-2.6/net/dccp/ipv6.c:
dccp_v6_get_port | -31
dccp_v6_hash | -7
dccp_v6_request_recv_sock | +5
3 functions changed, 5 bytes added, 38 bytes removed, diff: -33
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2008-02-03 20:06:04 +08:00
|
|
|
inet_put_port(sk);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
/*
|
|
|
|
* If sendmsg cached page exists, toss it.
|
|
|
|
*/
|
|
|
|
if (sk->sk_sndmsg_page) {
|
|
|
|
__free_page(sk->sk_sndmsg_page);
|
|
|
|
sk->sk_sndmsg_page = NULL;
|
|
|
|
}
|
|
|
|
|
TCPCT part 1d: define TCP cookie option, extend existing struct's
Data structures are carefully composed to require minimal additions.
For example, the struct tcp_options_received cookie_plus variable fits
between existing 16-bit and 8-bit variables, requiring no additional
space (taking alignment into consideration). There are no additions to
tcp_request_sock, and only 1 pointer in tcp_sock.
This is a significantly revised implementation of an earlier (year-old)
patch that no longer applies cleanly, with permission of the original
author (Adam Langley):
http://thread.gmane.org/gmane.linux.network/102586
The principle difference is using a TCP option to carry the cookie nonce,
instead of a user configured offset in the data. This is more flexible and
less subject to user configuration error. Such a cookie option has been
suggested for many years, and is also useful without SYN data, allowing
several related concepts to use the same extension option.
"Re: SYN floods (was: does history repeat itself?)", September 9, 1996.
http://www.merit.net/mail.archives/nanog/1996-09/msg00235.html
"Re: what a new TCP header might look like", May 12, 1998.
ftp://ftp.isi.edu/end2end/end2end-interest-1998.mail
These functions will also be used in subsequent patches that implement
additional features.
Requires:
TCPCT part 1a: add request_values parameter for sending SYNACK
TCPCT part 1b: generate Responder Cookie secret
TCPCT part 1c: sysctl_tcp_cookie_size, socket option TCP_COOKIE_TRANSACTIONS
Signed-off-by: William.Allen.Simpson@gmail.com
Signed-off-by: David S. Miller <davem@davemloft.net>
2009-12-03 02:17:05 +08:00
|
|
|
/* TCP Cookie Transactions */
|
|
|
|
if (tp->cookie_values != NULL) {
|
|
|
|
kref_put(&tp->cookie_values->kref,
|
|
|
|
tcp_cookie_values_release);
|
|
|
|
tp->cookie_values = NULL;
|
|
|
|
}
|
|
|
|
|
2008-11-26 13:16:35 +08:00
|
|
|
percpu_counter_dec(&tcp_sockets_allocated);
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
EXPORT_SYMBOL(tcp_v4_destroy_sock);
|
|
|
|
|
|
|
|
#ifdef CONFIG_PROC_FS
|
|
|
|
/* Proc filesystem TCP sock list dumping. */
|
|
|
|
|
2008-11-17 11:40:17 +08:00
|
|
|
static inline struct inet_timewait_sock *tw_head(struct hlist_nulls_head *head)
|
2005-04-17 06:20:36 +08:00
|
|
|
{
|
2008-11-17 11:40:17 +08:00
|
|
|
return hlist_nulls_empty(head) ? NULL :
|
2005-08-10 11:09:30 +08:00
|
|
|
list_entry(head->first, struct inet_timewait_sock, tw_node);
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
|
|
|
|
2005-08-10 11:09:30 +08:00
|
|
|
static inline struct inet_timewait_sock *tw_next(struct inet_timewait_sock *tw)
|
2005-04-17 06:20:36 +08:00
|
|
|
{
|
2008-11-17 11:40:17 +08:00
|
|
|
return !is_a_nulls(tw->tw_node.next) ?
|
|
|
|
hlist_nulls_entry(tw->tw_node.next, typeof(*tw), tw_node) : NULL;
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
static void *listening_get_next(struct seq_file *seq, void *cur)
|
|
|
|
{
|
2005-08-10 11:10:42 +08:00
|
|
|
struct inet_connection_sock *icsk;
|
2008-11-24 09:22:55 +08:00
|
|
|
struct hlist_nulls_node *node;
|
2005-04-17 06:20:36 +08:00
|
|
|
struct sock *sk = cur;
|
2008-11-20 16:40:07 +08:00
|
|
|
struct inet_listen_hashbucket *ilb;
|
2008-11-03 18:49:10 +08:00
|
|
|
struct tcp_iter_state *st = seq->private;
|
2008-04-14 13:11:14 +08:00
|
|
|
struct net *net = seq_file_net(seq);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
if (!sk) {
|
|
|
|
st->bucket = 0;
|
2008-11-20 16:40:07 +08:00
|
|
|
ilb = &tcp_hashinfo.listening_hash[0];
|
|
|
|
spin_lock_bh(&ilb->lock);
|
2008-11-24 09:22:55 +08:00
|
|
|
sk = sk_nulls_head(&ilb->head);
|
2005-04-17 06:20:36 +08:00
|
|
|
goto get_sk;
|
|
|
|
}
|
2008-11-20 16:40:07 +08:00
|
|
|
ilb = &tcp_hashinfo.listening_hash[st->bucket];
|
2005-04-17 06:20:36 +08:00
|
|
|
++st->num;
|
|
|
|
|
|
|
|
if (st->state == TCP_SEQ_STATE_OPENREQ) {
|
2005-06-19 13:47:21 +08:00
|
|
|
struct request_sock *req = cur;
|
2005-04-17 06:20:36 +08:00
|
|
|
|
2006-11-16 18:30:37 +08:00
|
|
|
icsk = inet_csk(st->syn_wait_sk);
|
2005-04-17 06:20:36 +08:00
|
|
|
req = req->dl_next;
|
|
|
|
while (1) {
|
|
|
|
while (req) {
|
2008-07-19 15:15:13 +08:00
|
|
|
if (req->rsk_ops->family == st->family) {
|
2005-04-17 06:20:36 +08:00
|
|
|
cur = req;
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
req = req->dl_next;
|
|
|
|
}
|
2006-11-16 18:30:37 +08:00
|
|
|
if (++st->sbucket >= icsk->icsk_accept_queue.listen_opt->nr_table_entries)
|
2005-04-17 06:20:36 +08:00
|
|
|
break;
|
|
|
|
get_req:
|
2005-08-10 11:10:42 +08:00
|
|
|
req = icsk->icsk_accept_queue.listen_opt->syn_table[st->sbucket];
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
|
|
|
sk = sk_next(st->syn_wait_sk);
|
|
|
|
st->state = TCP_SEQ_STATE_LISTENING;
|
2005-08-10 11:10:42 +08:00
|
|
|
read_unlock_bh(&icsk->icsk_accept_queue.syn_wait_lock);
|
2005-04-17 06:20:36 +08:00
|
|
|
} else {
|
2007-02-09 22:24:47 +08:00
|
|
|
icsk = inet_csk(sk);
|
2005-08-10 11:10:42 +08:00
|
|
|
read_lock_bh(&icsk->icsk_accept_queue.syn_wait_lock);
|
|
|
|
if (reqsk_queue_len(&icsk->icsk_accept_queue))
|
2005-04-17 06:20:36 +08:00
|
|
|
goto start_req;
|
2005-08-10 11:10:42 +08:00
|
|
|
read_unlock_bh(&icsk->icsk_accept_queue.syn_wait_lock);
|
2005-04-17 06:20:36 +08:00
|
|
|
sk = sk_next(sk);
|
|
|
|
}
|
|
|
|
get_sk:
|
2008-11-24 09:22:55 +08:00
|
|
|
sk_nulls_for_each_from(sk, node) {
|
2008-03-26 02:57:35 +08:00
|
|
|
if (sk->sk_family == st->family && net_eq(sock_net(sk), net)) {
|
2005-04-17 06:20:36 +08:00
|
|
|
cur = sk;
|
|
|
|
goto out;
|
|
|
|
}
|
2007-02-09 22:24:47 +08:00
|
|
|
icsk = inet_csk(sk);
|
2005-08-10 11:10:42 +08:00
|
|
|
read_lock_bh(&icsk->icsk_accept_queue.syn_wait_lock);
|
|
|
|
if (reqsk_queue_len(&icsk->icsk_accept_queue)) {
|
2005-04-17 06:20:36 +08:00
|
|
|
start_req:
|
|
|
|
st->uid = sock_i_uid(sk);
|
|
|
|
st->syn_wait_sk = sk;
|
|
|
|
st->state = TCP_SEQ_STATE_OPENREQ;
|
|
|
|
st->sbucket = 0;
|
|
|
|
goto get_req;
|
|
|
|
}
|
2005-08-10 11:10:42 +08:00
|
|
|
read_unlock_bh(&icsk->icsk_accept_queue.syn_wait_lock);
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
2008-11-20 16:40:07 +08:00
|
|
|
spin_unlock_bh(&ilb->lock);
|
2005-08-10 10:59:44 +08:00
|
|
|
if (++st->bucket < INET_LHTABLE_SIZE) {
|
2008-11-20 16:40:07 +08:00
|
|
|
ilb = &tcp_hashinfo.listening_hash[st->bucket];
|
|
|
|
spin_lock_bh(&ilb->lock);
|
2008-11-24 09:22:55 +08:00
|
|
|
sk = sk_nulls_head(&ilb->head);
|
2005-04-17 06:20:36 +08:00
|
|
|
goto get_sk;
|
|
|
|
}
|
|
|
|
cur = NULL;
|
|
|
|
out:
|
|
|
|
return cur;
|
|
|
|
}
|
|
|
|
|
|
|
|
static void *listening_get_idx(struct seq_file *seq, loff_t *pos)
|
|
|
|
{
|
|
|
|
void *rc = listening_get_next(seq, NULL);
|
|
|
|
|
|
|
|
while (rc && *pos) {
|
|
|
|
rc = listening_get_next(seq, rc);
|
|
|
|
--*pos;
|
|
|
|
}
|
|
|
|
return rc;
|
|
|
|
}
|
|
|
|
|
2008-08-28 16:08:02 +08:00
|
|
|
static inline int empty_bucket(struct tcp_iter_state *st)
|
|
|
|
{
|
2008-11-17 11:40:17 +08:00
|
|
|
return hlist_nulls_empty(&tcp_hashinfo.ehash[st->bucket].chain) &&
|
|
|
|
hlist_nulls_empty(&tcp_hashinfo.ehash[st->bucket].twchain);
|
2008-08-28 16:08:02 +08:00
|
|
|
}
|
|
|
|
|
2005-04-17 06:20:36 +08:00
|
|
|
static void *established_get_first(struct seq_file *seq)
|
|
|
|
{
|
2008-11-03 18:49:10 +08:00
|
|
|
struct tcp_iter_state *st = seq->private;
|
2008-04-14 13:11:14 +08:00
|
|
|
struct net *net = seq_file_net(seq);
|
2005-04-17 06:20:36 +08:00
|
|
|
void *rc = NULL;
|
|
|
|
|
2009-10-09 08:16:19 +08:00
|
|
|
for (st->bucket = 0; st->bucket <= tcp_hashinfo.ehash_mask; ++st->bucket) {
|
2005-04-17 06:20:36 +08:00
|
|
|
struct sock *sk;
|
2008-11-17 11:40:17 +08:00
|
|
|
struct hlist_nulls_node *node;
|
2005-08-10 11:09:30 +08:00
|
|
|
struct inet_timewait_sock *tw;
|
2008-11-21 12:39:09 +08:00
|
|
|
spinlock_t *lock = inet_ehash_lockp(&tcp_hashinfo, st->bucket);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
2008-08-28 16:08:02 +08:00
|
|
|
/* Lockless fast path for the common case of empty buckets */
|
|
|
|
if (empty_bucket(st))
|
|
|
|
continue;
|
|
|
|
|
2008-11-21 12:39:09 +08:00
|
|
|
spin_lock_bh(lock);
|
2008-11-17 11:40:17 +08:00
|
|
|
sk_nulls_for_each(sk, node, &tcp_hashinfo.ehash[st->bucket].chain) {
|
2008-03-21 19:13:54 +08:00
|
|
|
if (sk->sk_family != st->family ||
|
2008-03-26 02:57:35 +08:00
|
|
|
!net_eq(sock_net(sk), net)) {
|
2005-04-17 06:20:36 +08:00
|
|
|
continue;
|
|
|
|
}
|
|
|
|
rc = sk;
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
st->state = TCP_SEQ_STATE_TIME_WAIT;
|
2005-08-10 11:09:30 +08:00
|
|
|
inet_twsk_for_each(tw, node,
|
[NET]: change layout of ehash table
ehash table layout is currently this one :
First half of this table is used by sockets not in TIME_WAIT state
Second half of it is used by sockets in TIME_WAIT state.
This is non optimal because of for a given hash or socket, the two chain heads
are located in separate cache lines.
Moreover the locks of the second half are never used.
If instead of this halving, we use two list heads in inet_ehash_bucket instead
of only one, we probably can avoid one cache miss, and reduce ram usage,
particularly if sizeof(rwlock_t) is big (various CONFIG_DEBUG_SPINLOCK,
CONFIG_DEBUG_LOCK_ALLOC settings). So we still halves the table but we keep
together related chains to speedup lookups and socket state change.
In this patch I did not try to align struct inet_ehash_bucket, but a future
patch could try to make this structure have a convenient size (a power of two
or a multiple of L1_CACHE_SIZE).
I guess rwlock will just vanish as soon as RCU is plugged into ehash :) , so
maybe we dont need to scratch our heads to align the bucket...
Note : In case struct inet_ehash_bucket is not a power of two, we could
probably change alloc_large_system_hash() (in case it use __get_free_pages())
to free the unused space. It currently allocates a big zone, but the last
quarter of it could be freed. Again, this should be a temporary 'problem'.
Patch tested on ipv4 tcp only, but should be OK for IPV6 and DCCP.
Signed-off-by: Eric Dumazet <dada1@cosmosbay.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2007-02-09 06:16:46 +08:00
|
|
|
&tcp_hashinfo.ehash[st->bucket].twchain) {
|
2008-03-22 06:52:00 +08:00
|
|
|
if (tw->tw_family != st->family ||
|
2008-03-26 02:57:35 +08:00
|
|
|
!net_eq(twsk_net(tw), net)) {
|
2005-04-17 06:20:36 +08:00
|
|
|
continue;
|
|
|
|
}
|
|
|
|
rc = tw;
|
|
|
|
goto out;
|
|
|
|
}
|
2008-11-21 12:39:09 +08:00
|
|
|
spin_unlock_bh(lock);
|
2005-04-17 06:20:36 +08:00
|
|
|
st->state = TCP_SEQ_STATE_ESTABLISHED;
|
|
|
|
}
|
|
|
|
out:
|
|
|
|
return rc;
|
|
|
|
}
|
|
|
|
|
|
|
|
static void *established_get_next(struct seq_file *seq, void *cur)
|
|
|
|
{
|
|
|
|
struct sock *sk = cur;
|
2005-08-10 11:09:30 +08:00
|
|
|
struct inet_timewait_sock *tw;
|
2008-11-17 11:40:17 +08:00
|
|
|
struct hlist_nulls_node *node;
|
2008-11-03 18:49:10 +08:00
|
|
|
struct tcp_iter_state *st = seq->private;
|
2008-04-14 13:11:14 +08:00
|
|
|
struct net *net = seq_file_net(seq);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
++st->num;
|
|
|
|
|
|
|
|
if (st->state == TCP_SEQ_STATE_TIME_WAIT) {
|
|
|
|
tw = cur;
|
|
|
|
tw = tw_next(tw);
|
|
|
|
get_tw:
|
2008-03-26 02:57:35 +08:00
|
|
|
while (tw && (tw->tw_family != st->family || !net_eq(twsk_net(tw), net))) {
|
2005-04-17 06:20:36 +08:00
|
|
|
tw = tw_next(tw);
|
|
|
|
}
|
|
|
|
if (tw) {
|
|
|
|
cur = tw;
|
|
|
|
goto out;
|
|
|
|
}
|
2008-11-21 12:39:09 +08:00
|
|
|
spin_unlock_bh(inet_ehash_lockp(&tcp_hashinfo, st->bucket));
|
2005-04-17 06:20:36 +08:00
|
|
|
st->state = TCP_SEQ_STATE_ESTABLISHED;
|
|
|
|
|
2008-08-28 16:08:02 +08:00
|
|
|
/* Look for next non empty bucket */
|
2009-10-09 08:16:19 +08:00
|
|
|
while (++st->bucket <= tcp_hashinfo.ehash_mask &&
|
2008-08-28 16:08:02 +08:00
|
|
|
empty_bucket(st))
|
|
|
|
;
|
2009-10-09 08:16:19 +08:00
|
|
|
if (st->bucket > tcp_hashinfo.ehash_mask)
|
2008-08-28 16:08:02 +08:00
|
|
|
return NULL;
|
|
|
|
|
2008-11-21 12:39:09 +08:00
|
|
|
spin_lock_bh(inet_ehash_lockp(&tcp_hashinfo, st->bucket));
|
2008-11-17 11:40:17 +08:00
|
|
|
sk = sk_nulls_head(&tcp_hashinfo.ehash[st->bucket].chain);
|
2005-04-17 06:20:36 +08:00
|
|
|
} else
|
2008-11-17 11:40:17 +08:00
|
|
|
sk = sk_nulls_next(sk);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
2008-11-17 11:40:17 +08:00
|
|
|
sk_nulls_for_each_from(sk, node) {
|
2008-03-26 02:57:35 +08:00
|
|
|
if (sk->sk_family == st->family && net_eq(sock_net(sk), net))
|
2005-04-17 06:20:36 +08:00
|
|
|
goto found;
|
|
|
|
}
|
|
|
|
|
|
|
|
st->state = TCP_SEQ_STATE_TIME_WAIT;
|
[NET]: change layout of ehash table
ehash table layout is currently this one :
First half of this table is used by sockets not in TIME_WAIT state
Second half of it is used by sockets in TIME_WAIT state.
This is non optimal because of for a given hash or socket, the two chain heads
are located in separate cache lines.
Moreover the locks of the second half are never used.
If instead of this halving, we use two list heads in inet_ehash_bucket instead
of only one, we probably can avoid one cache miss, and reduce ram usage,
particularly if sizeof(rwlock_t) is big (various CONFIG_DEBUG_SPINLOCK,
CONFIG_DEBUG_LOCK_ALLOC settings). So we still halves the table but we keep
together related chains to speedup lookups and socket state change.
In this patch I did not try to align struct inet_ehash_bucket, but a future
patch could try to make this structure have a convenient size (a power of two
or a multiple of L1_CACHE_SIZE).
I guess rwlock will just vanish as soon as RCU is plugged into ehash :) , so
maybe we dont need to scratch our heads to align the bucket...
Note : In case struct inet_ehash_bucket is not a power of two, we could
probably change alloc_large_system_hash() (in case it use __get_free_pages())
to free the unused space. It currently allocates a big zone, but the last
quarter of it could be freed. Again, this should be a temporary 'problem'.
Patch tested on ipv4 tcp only, but should be OK for IPV6 and DCCP.
Signed-off-by: Eric Dumazet <dada1@cosmosbay.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2007-02-09 06:16:46 +08:00
|
|
|
tw = tw_head(&tcp_hashinfo.ehash[st->bucket].twchain);
|
2005-04-17 06:20:36 +08:00
|
|
|
goto get_tw;
|
|
|
|
found:
|
|
|
|
cur = sk;
|
|
|
|
out:
|
|
|
|
return cur;
|
|
|
|
}
|
|
|
|
|
|
|
|
static void *established_get_idx(struct seq_file *seq, loff_t pos)
|
|
|
|
{
|
|
|
|
void *rc = established_get_first(seq);
|
|
|
|
|
|
|
|
while (rc && pos) {
|
|
|
|
rc = established_get_next(seq, rc);
|
|
|
|
--pos;
|
2006-11-17 20:57:30 +08:00
|
|
|
}
|
2005-04-17 06:20:36 +08:00
|
|
|
return rc;
|
|
|
|
}
|
|
|
|
|
|
|
|
static void *tcp_get_idx(struct seq_file *seq, loff_t pos)
|
|
|
|
{
|
|
|
|
void *rc;
|
2008-11-03 18:49:10 +08:00
|
|
|
struct tcp_iter_state *st = seq->private;
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
st->state = TCP_SEQ_STATE_LISTENING;
|
|
|
|
rc = listening_get_idx(seq, &pos);
|
|
|
|
|
|
|
|
if (!rc) {
|
|
|
|
st->state = TCP_SEQ_STATE_ESTABLISHED;
|
|
|
|
rc = established_get_idx(seq, pos);
|
|
|
|
}
|
|
|
|
|
|
|
|
return rc;
|
|
|
|
}
|
|
|
|
|
|
|
|
static void *tcp_seq_start(struct seq_file *seq, loff_t *pos)
|
|
|
|
{
|
2008-11-03 18:49:10 +08:00
|
|
|
struct tcp_iter_state *st = seq->private;
|
2005-04-17 06:20:36 +08:00
|
|
|
st->state = TCP_SEQ_STATE_LISTENING;
|
|
|
|
st->num = 0;
|
|
|
|
return *pos ? tcp_get_idx(seq, *pos - 1) : SEQ_START_TOKEN;
|
|
|
|
}
|
|
|
|
|
|
|
|
static void *tcp_seq_next(struct seq_file *seq, void *v, loff_t *pos)
|
|
|
|
{
|
|
|
|
void *rc = NULL;
|
2008-11-03 18:49:10 +08:00
|
|
|
struct tcp_iter_state *st;
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
if (v == SEQ_START_TOKEN) {
|
|
|
|
rc = tcp_get_idx(seq, 0);
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
st = seq->private;
|
|
|
|
|
|
|
|
switch (st->state) {
|
|
|
|
case TCP_SEQ_STATE_OPENREQ:
|
|
|
|
case TCP_SEQ_STATE_LISTENING:
|
|
|
|
rc = listening_get_next(seq, v);
|
|
|
|
if (!rc) {
|
|
|
|
st->state = TCP_SEQ_STATE_ESTABLISHED;
|
|
|
|
rc = established_get_first(seq);
|
|
|
|
}
|
|
|
|
break;
|
|
|
|
case TCP_SEQ_STATE_ESTABLISHED:
|
|
|
|
case TCP_SEQ_STATE_TIME_WAIT:
|
|
|
|
rc = established_get_next(seq, v);
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
out:
|
|
|
|
++*pos;
|
|
|
|
return rc;
|
|
|
|
}
|
|
|
|
|
|
|
|
static void tcp_seq_stop(struct seq_file *seq, void *v)
|
|
|
|
{
|
2008-11-03 18:49:10 +08:00
|
|
|
struct tcp_iter_state *st = seq->private;
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
switch (st->state) {
|
|
|
|
case TCP_SEQ_STATE_OPENREQ:
|
|
|
|
if (v) {
|
2005-08-10 11:10:42 +08:00
|
|
|
struct inet_connection_sock *icsk = inet_csk(st->syn_wait_sk);
|
|
|
|
read_unlock_bh(&icsk->icsk_accept_queue.syn_wait_lock);
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
|
|
|
case TCP_SEQ_STATE_LISTENING:
|
|
|
|
if (v != SEQ_START_TOKEN)
|
2008-11-20 16:40:07 +08:00
|
|
|
spin_unlock_bh(&tcp_hashinfo.listening_hash[st->bucket].lock);
|
2005-04-17 06:20:36 +08:00
|
|
|
break;
|
|
|
|
case TCP_SEQ_STATE_TIME_WAIT:
|
|
|
|
case TCP_SEQ_STATE_ESTABLISHED:
|
|
|
|
if (v)
|
2008-11-21 12:39:09 +08:00
|
|
|
spin_unlock_bh(inet_ehash_lockp(&tcp_hashinfo, st->bucket));
|
2005-04-17 06:20:36 +08:00
|
|
|
break;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
static int tcp_seq_open(struct inode *inode, struct file *file)
|
|
|
|
{
|
|
|
|
struct tcp_seq_afinfo *afinfo = PDE(inode)->data;
|
|
|
|
struct tcp_iter_state *s;
|
2008-04-14 13:12:41 +08:00
|
|
|
int err;
|
2005-04-17 06:20:36 +08:00
|
|
|
|
2008-04-14 13:12:41 +08:00
|
|
|
err = seq_open_net(inode, file, &afinfo->seq_ops,
|
|
|
|
sizeof(struct tcp_iter_state));
|
|
|
|
if (err < 0)
|
|
|
|
return err;
|
2008-03-21 19:13:54 +08:00
|
|
|
|
2008-04-14 13:12:41 +08:00
|
|
|
s = ((struct seq_file *)file->private_data)->private;
|
2005-04-17 06:20:36 +08:00
|
|
|
s->family = afinfo->family;
|
2008-03-21 19:13:54 +08:00
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
2008-03-21 19:14:45 +08:00
|
|
|
int tcp_proc_register(struct net *net, struct tcp_seq_afinfo *afinfo)
|
2005-04-17 06:20:36 +08:00
|
|
|
{
|
|
|
|
int rc = 0;
|
|
|
|
struct proc_dir_entry *p;
|
|
|
|
|
2008-04-14 13:13:30 +08:00
|
|
|
afinfo->seq_fops.open = tcp_seq_open;
|
|
|
|
afinfo->seq_fops.read = seq_read;
|
|
|
|
afinfo->seq_fops.llseek = seq_lseek;
|
|
|
|
afinfo->seq_fops.release = seq_release_net;
|
2006-11-17 20:57:30 +08:00
|
|
|
|
2008-04-14 13:12:13 +08:00
|
|
|
afinfo->seq_ops.start = tcp_seq_start;
|
|
|
|
afinfo->seq_ops.next = tcp_seq_next;
|
|
|
|
afinfo->seq_ops.stop = tcp_seq_stop;
|
|
|
|
|
2008-05-02 19:10:08 +08:00
|
|
|
p = proc_create_data(afinfo->name, S_IRUGO, net->proc_net,
|
|
|
|
&afinfo->seq_fops, afinfo);
|
|
|
|
if (!p)
|
2005-04-17 06:20:36 +08:00
|
|
|
rc = -ENOMEM;
|
|
|
|
return rc;
|
|
|
|
}
|
|
|
|
|
2008-03-21 19:14:45 +08:00
|
|
|
void tcp_proc_unregister(struct net *net, struct tcp_seq_afinfo *afinfo)
|
2005-04-17 06:20:36 +08:00
|
|
|
{
|
2008-03-21 19:14:45 +08:00
|
|
|
proc_net_remove(net, afinfo->name);
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
|
|
|
|
2005-06-19 13:47:21 +08:00
|
|
|
static void get_openreq4(struct sock *sk, struct request_sock *req,
|
2008-04-24 16:02:16 +08:00
|
|
|
struct seq_file *f, int i, int uid, int *len)
|
2005-04-17 06:20:36 +08:00
|
|
|
{
|
[NET] Generalise TCP's struct open_request minisock infrastructure
Kept this first changeset minimal, without changing existing names to
ease peer review.
Basicaly tcp_openreq_alloc now receives the or_calltable, that in turn
has two new members:
->slab, that replaces tcp_openreq_cachep
->obj_size, to inform the size of the openreq descendant for
a specific protocol
The protocol specific fields in struct open_request were moved to a
class hierarchy, with the things that are common to all connection
oriented PF_INET protocols in struct inet_request_sock, the TCP ones
in tcp_request_sock, that is an inet_request_sock, that is an
open_request.
I.e. this uses the same approach used for the struct sock class
hierarchy, with sk_prot indicating if the protocol wants to use the
open_request infrastructure by filling in sk_prot->rsk_prot with an
or_calltable.
Results? Performance is improved and TCP v4 now uses only 64 bytes per
open request minisock, down from 96 without this patch :-)
Next changeset will rename some of the structs, fields and functions
mentioned above, struct or_calltable is way unclear, better name it
struct request_sock_ops, s/struct open_request/struct request_sock/g,
etc.
Signed-off-by: Arnaldo Carvalho de Melo <acme@ghostprotocols.net>
Signed-off-by: David S. Miller <davem@davemloft.net>
2005-06-19 13:46:52 +08:00
|
|
|
const struct inet_request_sock *ireq = inet_rsk(req);
|
2005-04-17 06:20:36 +08:00
|
|
|
int ttd = req->expires - jiffies;
|
|
|
|
|
2008-04-24 16:02:16 +08:00
|
|
|
seq_printf(f, "%4d: %08X:%04X %08X:%04X"
|
|
|
|
" %02X %08X:%08X %02X:%08lX %08X %5d %8d %u %d %p%n",
|
2005-04-17 06:20:36 +08:00
|
|
|
i,
|
[NET] Generalise TCP's struct open_request minisock infrastructure
Kept this first changeset minimal, without changing existing names to
ease peer review.
Basicaly tcp_openreq_alloc now receives the or_calltable, that in turn
has two new members:
->slab, that replaces tcp_openreq_cachep
->obj_size, to inform the size of the openreq descendant for
a specific protocol
The protocol specific fields in struct open_request were moved to a
class hierarchy, with the things that are common to all connection
oriented PF_INET protocols in struct inet_request_sock, the TCP ones
in tcp_request_sock, that is an inet_request_sock, that is an
open_request.
I.e. this uses the same approach used for the struct sock class
hierarchy, with sk_prot indicating if the protocol wants to use the
open_request infrastructure by filling in sk_prot->rsk_prot with an
or_calltable.
Results? Performance is improved and TCP v4 now uses only 64 bytes per
open request minisock, down from 96 without this patch :-)
Next changeset will rename some of the structs, fields and functions
mentioned above, struct or_calltable is way unclear, better name it
struct request_sock_ops, s/struct open_request/struct request_sock/g,
etc.
Signed-off-by: Arnaldo Carvalho de Melo <acme@ghostprotocols.net>
Signed-off-by: David S. Miller <davem@davemloft.net>
2005-06-19 13:46:52 +08:00
|
|
|
ireq->loc_addr,
|
2009-10-15 14:30:45 +08:00
|
|
|
ntohs(inet_sk(sk)->inet_sport),
|
[NET] Generalise TCP's struct open_request minisock infrastructure
Kept this first changeset minimal, without changing existing names to
ease peer review.
Basicaly tcp_openreq_alloc now receives the or_calltable, that in turn
has two new members:
->slab, that replaces tcp_openreq_cachep
->obj_size, to inform the size of the openreq descendant for
a specific protocol
The protocol specific fields in struct open_request were moved to a
class hierarchy, with the things that are common to all connection
oriented PF_INET protocols in struct inet_request_sock, the TCP ones
in tcp_request_sock, that is an inet_request_sock, that is an
open_request.
I.e. this uses the same approach used for the struct sock class
hierarchy, with sk_prot indicating if the protocol wants to use the
open_request infrastructure by filling in sk_prot->rsk_prot with an
or_calltable.
Results? Performance is improved and TCP v4 now uses only 64 bytes per
open request minisock, down from 96 without this patch :-)
Next changeset will rename some of the structs, fields and functions
mentioned above, struct or_calltable is way unclear, better name it
struct request_sock_ops, s/struct open_request/struct request_sock/g,
etc.
Signed-off-by: Arnaldo Carvalho de Melo <acme@ghostprotocols.net>
Signed-off-by: David S. Miller <davem@davemloft.net>
2005-06-19 13:46:52 +08:00
|
|
|
ireq->rmt_addr,
|
|
|
|
ntohs(ireq->rmt_port),
|
2005-04-17 06:20:36 +08:00
|
|
|
TCP_SYN_RECV,
|
|
|
|
0, 0, /* could print option size, but that is af dependent. */
|
|
|
|
1, /* timers active (only the expire timer) */
|
|
|
|
jiffies_to_clock_t(ttd),
|
|
|
|
req->retrans,
|
|
|
|
uid,
|
|
|
|
0, /* non standard timer */
|
|
|
|
0, /* open_requests have no inode */
|
|
|
|
atomic_read(&sk->sk_refcnt),
|
2008-04-24 16:02:16 +08:00
|
|
|
req,
|
|
|
|
len);
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
|
|
|
|
2008-04-24 16:02:16 +08:00
|
|
|
static void get_tcp4_sock(struct sock *sk, struct seq_file *f, int i, int *len)
|
2005-04-17 06:20:36 +08:00
|
|
|
{
|
|
|
|
int timer_active;
|
|
|
|
unsigned long timer_expires;
|
2007-02-22 17:13:58 +08:00
|
|
|
struct tcp_sock *tp = tcp_sk(sk);
|
|
|
|
const struct inet_connection_sock *icsk = inet_csk(sk);
|
|
|
|
struct inet_sock *inet = inet_sk(sk);
|
2009-10-15 14:30:45 +08:00
|
|
|
__be32 dest = inet->inet_daddr;
|
|
|
|
__be32 src = inet->inet_rcv_saddr;
|
|
|
|
__u16 destp = ntohs(inet->inet_dport);
|
|
|
|
__u16 srcp = ntohs(inet->inet_sport);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
2005-08-10 11:10:42 +08:00
|
|
|
if (icsk->icsk_pending == ICSK_TIME_RETRANS) {
|
2005-04-17 06:20:36 +08:00
|
|
|
timer_active = 1;
|
2005-08-10 11:10:42 +08:00
|
|
|
timer_expires = icsk->icsk_timeout;
|
|
|
|
} else if (icsk->icsk_pending == ICSK_TIME_PROBE0) {
|
2005-04-17 06:20:36 +08:00
|
|
|
timer_active = 4;
|
2005-08-10 11:10:42 +08:00
|
|
|
timer_expires = icsk->icsk_timeout;
|
2007-02-22 17:13:58 +08:00
|
|
|
} else if (timer_pending(&sk->sk_timer)) {
|
2005-04-17 06:20:36 +08:00
|
|
|
timer_active = 2;
|
2007-02-22 17:13:58 +08:00
|
|
|
timer_expires = sk->sk_timer.expires;
|
2005-04-17 06:20:36 +08:00
|
|
|
} else {
|
|
|
|
timer_active = 0;
|
|
|
|
timer_expires = jiffies;
|
|
|
|
}
|
|
|
|
|
2008-04-24 16:02:16 +08:00
|
|
|
seq_printf(f, "%4d: %08X:%04X %08X:%04X %02X %08X:%08X %02X:%08lX "
|
2008-06-28 11:00:19 +08:00
|
|
|
"%08X %5d %8d %lu %d %p %lu %lu %u %u %d%n",
|
2007-02-22 17:13:58 +08:00
|
|
|
i, src, srcp, dest, destp, sk->sk_state,
|
2006-06-28 04:29:00 +08:00
|
|
|
tp->write_seq - tp->snd_una,
|
2007-02-22 17:13:58 +08:00
|
|
|
sk->sk_state == TCP_LISTEN ? sk->sk_ack_backlog :
|
2006-11-17 20:57:30 +08:00
|
|
|
(tp->rcv_nxt - tp->copied_seq),
|
2005-04-17 06:20:36 +08:00
|
|
|
timer_active,
|
|
|
|
jiffies_to_clock_t(timer_expires - jiffies),
|
2005-08-10 11:10:42 +08:00
|
|
|
icsk->icsk_retransmits,
|
2007-02-22 17:13:58 +08:00
|
|
|
sock_i_uid(sk),
|
2005-08-10 15:03:31 +08:00
|
|
|
icsk->icsk_probes_out,
|
2007-02-22 17:13:58 +08:00
|
|
|
sock_i_ino(sk),
|
|
|
|
atomic_read(&sk->sk_refcnt), sk,
|
2008-06-28 11:00:19 +08:00
|
|
|
jiffies_to_clock_t(icsk->icsk_rto),
|
|
|
|
jiffies_to_clock_t(icsk->icsk_ack.ato),
|
2005-08-10 11:10:42 +08:00
|
|
|
(icsk->icsk_ack.quick << 1) | icsk->icsk_ack.pingpong,
|
2005-04-17 06:20:36 +08:00
|
|
|
tp->snd_cwnd,
|
2009-09-15 16:30:10 +08:00
|
|
|
tcp_in_initial_slowstart(tp) ? -1 : tp->snd_ssthresh,
|
2008-04-24 16:02:16 +08:00
|
|
|
len);
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
|
|
|
|
2006-11-17 20:57:30 +08:00
|
|
|
static void get_timewait4_sock(struct inet_timewait_sock *tw,
|
2008-04-24 16:02:16 +08:00
|
|
|
struct seq_file *f, int i, int *len)
|
2005-04-17 06:20:36 +08:00
|
|
|
{
|
2006-09-28 09:43:50 +08:00
|
|
|
__be32 dest, src;
|
2005-04-17 06:20:36 +08:00
|
|
|
__u16 destp, srcp;
|
|
|
|
int ttd = tw->tw_ttd - jiffies;
|
|
|
|
|
|
|
|
if (ttd < 0)
|
|
|
|
ttd = 0;
|
|
|
|
|
|
|
|
dest = tw->tw_daddr;
|
|
|
|
src = tw->tw_rcv_saddr;
|
|
|
|
destp = ntohs(tw->tw_dport);
|
|
|
|
srcp = ntohs(tw->tw_sport);
|
|
|
|
|
2008-04-24 16:02:16 +08:00
|
|
|
seq_printf(f, "%4d: %08X:%04X %08X:%04X"
|
|
|
|
" %02X %08X:%08X %02X:%08lX %08X %5d %8d %d %d %p%n",
|
2005-04-17 06:20:36 +08:00
|
|
|
i, src, srcp, dest, destp, tw->tw_substate, 0, 0,
|
|
|
|
3, jiffies_to_clock_t(ttd), 0, 0, 0, 0,
|
2008-04-24 16:02:16 +08:00
|
|
|
atomic_read(&tw->tw_refcnt), tw, len);
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
#define TMPSZ 150
|
|
|
|
|
|
|
|
static int tcp4_seq_show(struct seq_file *seq, void *v)
|
|
|
|
{
|
2008-11-03 18:49:10 +08:00
|
|
|
struct tcp_iter_state *st;
|
2008-04-24 16:02:16 +08:00
|
|
|
int len;
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
if (v == SEQ_START_TOKEN) {
|
|
|
|
seq_printf(seq, "%-*s\n", TMPSZ - 1,
|
|
|
|
" sl local_address rem_address st tx_queue "
|
|
|
|
"rx_queue tr tm->when retrnsmt uid timeout "
|
|
|
|
"inode");
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
st = seq->private;
|
|
|
|
|
|
|
|
switch (st->state) {
|
|
|
|
case TCP_SEQ_STATE_LISTENING:
|
|
|
|
case TCP_SEQ_STATE_ESTABLISHED:
|
2008-04-24 16:02:16 +08:00
|
|
|
get_tcp4_sock(v, seq, st->num, &len);
|
2005-04-17 06:20:36 +08:00
|
|
|
break;
|
|
|
|
case TCP_SEQ_STATE_OPENREQ:
|
2008-04-24 16:02:16 +08:00
|
|
|
get_openreq4(st->syn_wait_sk, v, seq, st->num, st->uid, &len);
|
2005-04-17 06:20:36 +08:00
|
|
|
break;
|
|
|
|
case TCP_SEQ_STATE_TIME_WAIT:
|
2008-04-24 16:02:16 +08:00
|
|
|
get_timewait4_sock(v, seq, st->num, &len);
|
2005-04-17 06:20:36 +08:00
|
|
|
break;
|
|
|
|
}
|
2008-04-24 16:02:16 +08:00
|
|
|
seq_printf(seq, "%*s\n", TMPSZ - 1 - len, "");
|
2005-04-17 06:20:36 +08:00
|
|
|
out:
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
static struct tcp_seq_afinfo tcp4_seq_afinfo = {
|
|
|
|
.name = "tcp",
|
|
|
|
.family = AF_INET,
|
2008-04-14 13:13:53 +08:00
|
|
|
.seq_fops = {
|
|
|
|
.owner = THIS_MODULE,
|
|
|
|
},
|
2008-04-14 13:12:13 +08:00
|
|
|
.seq_ops = {
|
|
|
|
.show = tcp4_seq_show,
|
|
|
|
},
|
2005-04-17 06:20:36 +08:00
|
|
|
};
|
|
|
|
|
2008-03-25 05:56:02 +08:00
|
|
|
static int tcp4_proc_init_net(struct net *net)
|
|
|
|
{
|
|
|
|
return tcp_proc_register(net, &tcp4_seq_afinfo);
|
|
|
|
}
|
|
|
|
|
|
|
|
static void tcp4_proc_exit_net(struct net *net)
|
|
|
|
{
|
|
|
|
tcp_proc_unregister(net, &tcp4_seq_afinfo);
|
|
|
|
}
|
|
|
|
|
|
|
|
static struct pernet_operations tcp4_net_ops = {
|
|
|
|
.init = tcp4_proc_init_net,
|
|
|
|
.exit = tcp4_proc_exit_net,
|
|
|
|
};
|
|
|
|
|
2005-04-17 06:20:36 +08:00
|
|
|
int __init tcp4_proc_init(void)
|
|
|
|
{
|
2008-03-25 05:56:02 +08:00
|
|
|
return register_pernet_subsys(&tcp4_net_ops);
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
void tcp4_proc_exit(void)
|
|
|
|
{
|
2008-03-25 05:56:02 +08:00
|
|
|
unregister_pernet_subsys(&tcp4_net_ops);
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
|
|
|
#endif /* CONFIG_PROC_FS */
|
|
|
|
|
2008-12-16 15:43:36 +08:00
|
|
|
struct sk_buff **tcp4_gro_receive(struct sk_buff **head, struct sk_buff *skb)
|
|
|
|
{
|
2009-04-27 20:44:45 +08:00
|
|
|
struct iphdr *iph = skb_gro_network_header(skb);
|
2008-12-16 15:43:36 +08:00
|
|
|
|
|
|
|
switch (skb->ip_summed) {
|
|
|
|
case CHECKSUM_COMPLETE:
|
2009-01-29 22:19:50 +08:00
|
|
|
if (!tcp_v4_check(skb_gro_len(skb), iph->saddr, iph->daddr,
|
2008-12-16 15:43:36 +08:00
|
|
|
skb->csum)) {
|
|
|
|
skb->ip_summed = CHECKSUM_UNNECESSARY;
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
|
|
|
|
/* fall through */
|
|
|
|
case CHECKSUM_NONE:
|
|
|
|
NAPI_GRO_CB(skb)->flush = 1;
|
|
|
|
return NULL;
|
|
|
|
}
|
|
|
|
|
|
|
|
return tcp_gro_receive(head, skb);
|
|
|
|
}
|
|
|
|
EXPORT_SYMBOL(tcp4_gro_receive);
|
|
|
|
|
|
|
|
int tcp4_gro_complete(struct sk_buff *skb)
|
|
|
|
{
|
|
|
|
struct iphdr *iph = ip_hdr(skb);
|
|
|
|
struct tcphdr *th = tcp_hdr(skb);
|
|
|
|
|
|
|
|
th->check = ~tcp_v4_check(skb->len - skb_transport_offset(skb),
|
|
|
|
iph->saddr, iph->daddr, 0);
|
|
|
|
skb_shinfo(skb)->gso_type = SKB_GSO_TCPV4;
|
|
|
|
|
|
|
|
return tcp_gro_complete(skb);
|
|
|
|
}
|
|
|
|
EXPORT_SYMBOL(tcp4_gro_complete);
|
|
|
|
|
2005-04-17 06:20:36 +08:00
|
|
|
struct proto tcp_prot = {
|
|
|
|
.name = "TCP",
|
|
|
|
.owner = THIS_MODULE,
|
|
|
|
.close = tcp_close,
|
|
|
|
.connect = tcp_v4_connect,
|
|
|
|
.disconnect = tcp_disconnect,
|
2005-08-10 11:10:42 +08:00
|
|
|
.accept = inet_csk_accept,
|
2005-04-17 06:20:36 +08:00
|
|
|
.ioctl = tcp_ioctl,
|
|
|
|
.init = tcp_v4_init_sock,
|
|
|
|
.destroy = tcp_v4_destroy_sock,
|
|
|
|
.shutdown = tcp_shutdown,
|
|
|
|
.setsockopt = tcp_setsockopt,
|
|
|
|
.getsockopt = tcp_getsockopt,
|
|
|
|
.recvmsg = tcp_recvmsg,
|
|
|
|
.backlog_rcv = tcp_v4_do_rcv,
|
[SOCK] proto: Add hashinfo member to struct proto
This way we can remove TCP and DCCP specific versions of
sk->sk_prot->get_port: both v4 and v6 use inet_csk_get_port
sk->sk_prot->hash: inet_hash is directly used, only v6 need
a specific version to deal with mapped sockets
sk->sk_prot->unhash: both v4 and v6 use inet_hash directly
struct inet_connection_sock_af_ops also gets a new member, bind_conflict, so
that inet_csk_get_port can find the per family routine.
Now only the lookup routines receive as a parameter a struct inet_hashtable.
With this we further reuse code, reducing the difference among INET transport
protocols.
Eventually work has to be done on UDP and SCTP to make them share this
infrastructure and get as a bonus inet_diag interfaces so that iproute can be
used with these protocols.
net-2.6/net/ipv4/inet_hashtables.c:
struct proto | +8
struct inet_connection_sock_af_ops | +8
2 structs changed
__inet_hash_nolisten | +18
__inet_hash | -210
inet_put_port | +8
inet_bind_bucket_create | +1
__inet_hash_connect | -8
5 functions changed, 27 bytes added, 218 bytes removed, diff: -191
net-2.6/net/core/sock.c:
proto_seq_show | +3
1 function changed, 3 bytes added, diff: +3
net-2.6/net/ipv4/inet_connection_sock.c:
inet_csk_get_port | +15
1 function changed, 15 bytes added, diff: +15
net-2.6/net/ipv4/tcp.c:
tcp_set_state | -7
1 function changed, 7 bytes removed, diff: -7
net-2.6/net/ipv4/tcp_ipv4.c:
tcp_v4_get_port | -31
tcp_v4_hash | -48
tcp_v4_destroy_sock | -7
tcp_v4_syn_recv_sock | -2
tcp_unhash | -179
5 functions changed, 267 bytes removed, diff: -267
net-2.6/net/ipv6/inet6_hashtables.c:
__inet6_hash | +8
1 function changed, 8 bytes added, diff: +8
net-2.6/net/ipv4/inet_hashtables.c:
inet_unhash | +190
inet_hash | +242
2 functions changed, 432 bytes added, diff: +432
vmlinux:
16 functions changed, 485 bytes added, 492 bytes removed, diff: -7
/home/acme/git/net-2.6/net/ipv6/tcp_ipv6.c:
tcp_v6_get_port | -31
tcp_v6_hash | -7
tcp_v6_syn_recv_sock | -9
3 functions changed, 47 bytes removed, diff: -47
/home/acme/git/net-2.6/net/dccp/proto.c:
dccp_destroy_sock | -7
dccp_unhash | -179
dccp_hash | -49
dccp_set_state | -7
dccp_done | +1
5 functions changed, 1 bytes added, 242 bytes removed, diff: -241
/home/acme/git/net-2.6/net/dccp/ipv4.c:
dccp_v4_get_port | -31
dccp_v4_request_recv_sock | -2
2 functions changed, 33 bytes removed, diff: -33
/home/acme/git/net-2.6/net/dccp/ipv6.c:
dccp_v6_get_port | -31
dccp_v6_hash | -7
dccp_v6_request_recv_sock | +5
3 functions changed, 5 bytes added, 38 bytes removed, diff: -33
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2008-02-03 20:06:04 +08:00
|
|
|
.hash = inet_hash,
|
|
|
|
.unhash = inet_unhash,
|
|
|
|
.get_port = inet_csk_get_port,
|
2005-04-17 06:20:36 +08:00
|
|
|
.enter_memory_pressure = tcp_enter_memory_pressure,
|
|
|
|
.sockets_allocated = &tcp_sockets_allocated,
|
2005-08-10 11:11:41 +08:00
|
|
|
.orphan_count = &tcp_orphan_count,
|
2005-04-17 06:20:36 +08:00
|
|
|
.memory_allocated = &tcp_memory_allocated,
|
|
|
|
.memory_pressure = &tcp_memory_pressure,
|
|
|
|
.sysctl_mem = sysctl_tcp_mem,
|
|
|
|
.sysctl_wmem = sysctl_tcp_wmem,
|
|
|
|
.sysctl_rmem = sysctl_tcp_rmem,
|
|
|
|
.max_header = MAX_TCP_HEADER,
|
|
|
|
.obj_size = sizeof(struct tcp_sock),
|
2008-11-17 11:40:17 +08:00
|
|
|
.slab_flags = SLAB_DESTROY_BY_RCU,
|
2005-12-14 15:25:19 +08:00
|
|
|
.twsk_prot = &tcp_timewait_sock_ops,
|
2005-06-19 13:47:21 +08:00
|
|
|
.rsk_prot = &tcp_request_sock_ops,
|
2008-03-23 07:50:58 +08:00
|
|
|
.h.hashinfo = &tcp_hashinfo,
|
2006-03-21 14:48:35 +08:00
|
|
|
#ifdef CONFIG_COMPAT
|
|
|
|
.compat_setsockopt = compat_tcp_setsockopt,
|
|
|
|
.compat_getsockopt = compat_tcp_getsockopt,
|
|
|
|
#endif
|
2005-04-17 06:20:36 +08:00
|
|
|
};
|
|
|
|
|
2008-04-04 05:31:33 +08:00
|
|
|
|
|
|
|
static int __net_init tcp_sk_init(struct net *net)
|
|
|
|
{
|
|
|
|
return inet_ctl_sock_create(&net->ipv4.tcp_sock,
|
|
|
|
PF_INET, SOCK_RAW, IPPROTO_TCP, net);
|
|
|
|
}
|
|
|
|
|
|
|
|
static void __net_exit tcp_sk_exit(struct net *net)
|
|
|
|
{
|
|
|
|
inet_ctl_sock_destroy(net->ipv4.tcp_sock);
|
netns : fix kernel panic in timewait socket destruction
How to reproduce ?
- create a network namespace
- use tcp protocol and get timewait socket
- exit the network namespace
- after a moment (when the timewait socket is destroyed), the kernel
panics.
# BUG: unable to handle kernel NULL pointer dereference at
0000000000000007
IP: [<ffffffff821e394d>] inet_twdr_do_twkill_work+0x6e/0xb8
PGD 119985067 PUD 11c5c0067 PMD 0
Oops: 0000 [1] SMP
CPU 1
Modules linked in: ipv6 button battery ac loop dm_mod tg3 libphy ext3 jbd
edd fan thermal processor thermal_sys sg sata_svw libata dock serverworks
sd_mod scsi_mod ide_disk ide_core [last unloaded: freq_table]
Pid: 0, comm: swapper Not tainted 2.6.27-rc2 #3
RIP: 0010:[<ffffffff821e394d>] [<ffffffff821e394d>]
inet_twdr_do_twkill_work+0x6e/0xb8
RSP: 0018:ffff88011ff7fed0 EFLAGS: 00010246
RAX: ffffffffffffffff RBX: ffffffff82339420 RCX: ffff88011ff7ff30
RDX: 0000000000000001 RSI: ffff88011a4d03c0 RDI: ffff88011ac2fc00
RBP: ffffffff823392e0 R08: 0000000000000000 R09: ffff88002802a200
R10: ffff8800a5c4b000 R11: ffffffff823e4080 R12: ffff88011ac2fc00
R13: 0000000000000001 R14: 0000000000000001 R15: 0000000000000000
FS: 0000000041cbd940(0000) GS:ffff8800bff839c0(0000)
knlGS:0000000000000000
CS: 0010 DS: 0018 ES: 0018 CR0: 000000008005003b
CR2: 0000000000000007 CR3: 00000000bd87c000 CR4: 00000000000006e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000400
Process swapper (pid: 0, threadinfo ffff8800bff9e000, task
ffff88011ff76690)
Stack: ffffffff823392e0 0000000000000100 ffffffff821e3a3a
0000000000000008
0000000000000000 ffffffff821e3a61 ffff8800bff7c000 ffffffff8203c7e7
ffff88011ff7ff10 ffff88011ff7ff10 0000000000000021 ffffffff82351108
Call Trace:
<IRQ> [<ffffffff821e3a3a>] ? inet_twdr_hangman+0x0/0x9e
[<ffffffff821e3a61>] ? inet_twdr_hangman+0x27/0x9e
[<ffffffff8203c7e7>] ? run_timer_softirq+0x12c/0x193
[<ffffffff820390d1>] ? __do_softirq+0x5e/0xcd
[<ffffffff8200d08c>] ? call_softirq+0x1c/0x28
[<ffffffff8200e611>] ? do_softirq+0x2c/0x68
[<ffffffff8201a055>] ? smp_apic_timer_interrupt+0x8e/0xa9
[<ffffffff8200cad6>] ? apic_timer_interrupt+0x66/0x70
<EOI> [<ffffffff82011f4c>] ? default_idle+0x27/0x3b
[<ffffffff8200abbd>] ? cpu_idle+0x5f/0x7d
Code: e8 01 00 00 4c 89 e7 41 ff c5 e8 8d fd ff ff 49 8b 44 24 38 4c 89 e7
65 8b 14 25 24 00 00 00 89 d2 48 8b 80 e8 00 00 00 48 f7 d0 <48> 8b 04 d0
48 ff 40 58 e8 fc fc ff ff 48 89 df e8 c0 5f 04 00
RIP [<ffffffff821e394d>] inet_twdr_do_twkill_work+0x6e/0xb8
RSP <ffff88011ff7fed0>
CR2: 0000000000000007
This patch provides a function to purge all timewait sockets related
to a network namespace. The timewait sockets life cycle is not tied with
the network namespace, that means the timewait sockets stay alive while
the network namespace dies. The timewait sockets are for avoiding to
receive a duplicate packet from the network, if the network namespace is
freed, the network stack is removed, so no chance to receive any packets
from the outside world. Furthermore, having a pending destruction timer
on these sockets with a network namespace freed is not safe and will lead
to an oops if the timer callback which try to access data belonging to
the namespace like for example in:
inet_twdr_do_twkill_work
-> NET_INC_STATS_BH(twsk_net(tw), LINUX_MIB_TIMEWAITED);
Purging the timewait sockets at the network namespace destruction will:
1) speed up memory freeing for the namespace
2) fix kernel panic on asynchronous timewait destruction
Signed-off-by: Daniel Lezcano <dlezcano@fr.ibm.com>
Acked-by: Denis V. Lunev <den@openvz.org>
Acked-by: Eric W. Biederman <ebiederm@xmission.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2008-09-09 04:17:27 +08:00
|
|
|
inet_twsk_purge(net, &tcp_hashinfo, &tcp_death_row, AF_INET);
|
2008-04-04 05:31:33 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
static struct pernet_operations __net_initdata tcp_sk_ops = {
|
|
|
|
.init = tcp_sk_init,
|
|
|
|
.exit = tcp_sk_exit,
|
|
|
|
};
|
|
|
|
|
2008-03-01 03:13:15 +08:00
|
|
|
void __init tcp_v4_init(void)
|
2005-04-17 06:20:36 +08:00
|
|
|
{
|
2008-11-20 16:40:07 +08:00
|
|
|
inet_hashinfo_init(&tcp_hashinfo);
|
2009-02-22 16:10:18 +08:00
|
|
|
if (register_pernet_subsys(&tcp_sk_ops))
|
2005-04-17 06:20:36 +08:00
|
|
|
panic("Failed to create the TCP control socket.\n");
|
|
|
|
}
|
|
|
|
|
|
|
|
EXPORT_SYMBOL(ipv4_specific);
|
|
|
|
EXPORT_SYMBOL(tcp_hashinfo);
|
|
|
|
EXPORT_SYMBOL(tcp_prot);
|
|
|
|
EXPORT_SYMBOL(tcp_v4_conn_request);
|
|
|
|
EXPORT_SYMBOL(tcp_v4_connect);
|
|
|
|
EXPORT_SYMBOL(tcp_v4_do_rcv);
|
|
|
|
EXPORT_SYMBOL(tcp_v4_remember_stamp);
|
|
|
|
EXPORT_SYMBOL(tcp_v4_send_check);
|
|
|
|
EXPORT_SYMBOL(tcp_v4_syn_recv_sock);
|
|
|
|
|
|
|
|
#ifdef CONFIG_PROC_FS
|
|
|
|
EXPORT_SYMBOL(tcp_proc_register);
|
|
|
|
EXPORT_SYMBOL(tcp_proc_unregister);
|
|
|
|
#endif
|
|
|
|
EXPORT_SYMBOL(sysctl_tcp_low_latency);
|
|
|
|
|