netdev
[Top] [All Lists]

Re: [PATCH] fix dst_entry leak in icmp_push_reply()

To: Ollie Wild <aaw@xxxxxxxxxxxx>
Subject: Re: [PATCH] fix dst_entry leak in icmp_push_reply()
From: Patrick McHardy <kaber@xxxxxxxxx>
Date: Thu, 18 Aug 2005 20:59:37 +0200
Cc: linux-kernel@xxxxxxxxxxxxxxx, Maillist netdev <netdev@xxxxxxxxxxx>
In-reply-to: <4304D763.4090001@xxxxxxxxxxxx>
References: <43039C3F.2000207@xxxxxxxxxxxx> <4303CEC5.3010502@xxxxxxxxx> <43042D94.4030303@xxxxxxxxxxxx> <4304D763.4090001@xxxxxxxxxxxx>
Sender: netdev-bounce@xxxxxxxxxxx
User-agent: Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.7.10) Gecko/20050803 Debian/1.7.10-1
Ollie Wild wrote:
> That said, I appreciate that the if-else condition doesn't seem quite
> right.  The problem is, the icmp_push_reply() routine is implicitly
> using the queue as a success indicator.  I put the
> ip_flush_pending_frames() call inside the else block because I wanted to
> guarantee that one of ip_push_pending_frames() and
> ip_flush_pending_frames() is always called.  Both will do proper cleanup.
> 
> I'm open to suggestions if you think there's a cleaner way to implement
> this.

Checking the return value of ip_append_data seems cleaner to me.
Patch attached.

Signed-off-by: Patrick McHardy <kaber@xxxxxxxxx>
diff --git a/net/ipv4/icmp.c b/net/ipv4/icmp.c
--- a/net/ipv4/icmp.c
+++ b/net/ipv4/icmp.c
@@ -349,12 +349,12 @@ static void icmp_push_reply(struct icmp_
 {
        struct sk_buff *skb;
 
-       ip_append_data(icmp_socket->sk, icmp_glue_bits, icmp_param,
-                      icmp_param->data_len+icmp_param->head_len,
-                      icmp_param->head_len,
-                      ipc, rt, MSG_DONTWAIT);
-
-       if ((skb = skb_peek(&icmp_socket->sk->sk_write_queue)) != NULL) {
+       if (ip_append_data(icmp_socket->sk, icmp_glue_bits, icmp_param,
+                          icmp_param->data_len+icmp_param->head_len,
+                          icmp_param->head_len,
+                          ipc, rt, MSG_DONTWAIT) < 0)
+               ip_flush_pending_frames(icmp_socket->sk);
+       else if ((skb = skb_peek(&icmp_socket->sk->sk_write_queue)) != NULL) {
                struct icmphdr *icmph = skb->h.icmph;
                unsigned int csum = 0;
                struct sk_buff *skb1;
<Prev in Thread] Current Thread [Next in Thread>