diff options
| author | David Gibson <david@gibson.dropbear.id.au> | 2025-11-11 14:25:20 +1100 |
|---|---|---|
| committer | Stefano Brivio <sbrivio@redhat.com> | 2025-11-12 23:09:31 +0100 |
| commit | 75b8bb966b9508693f35df30fbbfbf37aff05b15 (patch) | |
| tree | 3584f2af0dda4332524427840ed07463cc82f26c | |
| parent | a36031a4d807ca3197b6b14c50a93816d4d28f18 (diff) | |
| download | passt-75b8bb966b9508693f35df30fbbfbf37aff05b15.tar passt-75b8bb966b9508693f35df30fbbfbf37aff05b15.tar.gz passt-75b8bb966b9508693f35df30fbbfbf37aff05b15.tar.bz2 passt-75b8bb966b9508693f35df30fbbfbf37aff05b15.tar.lz passt-75b8bb966b9508693f35df30fbbfbf37aff05b15.tar.xz passt-75b8bb966b9508693f35df30fbbfbf37aff05b15.tar.zst passt-75b8bb966b9508693f35df30fbbfbf37aff05b15.zip | |
tcp: Properly remove sockets from epoll loop when connection is closed
Most of the handling for closing a TCP connectin is in conn_event_do() when
it receives a 'CLOSED' event. We specifically check for this case and,
correctly, remove the connection from the flow hash table. However, we
also bypass the call tp tcp_epoll_ctl() which is not correct. By skipping
tcp_epoll_ctl() we skip it's specific handling of the CLOSED event, which
includes removing the TCP socket from epoll.
If we somehow get an event on such a stale socket, we'll get a stale flow
reference. That flow slot might have been re-used, leading to to a crash
in conn_at_sidx().
Fixes: b86afe3559c0 ("tcp: Don't defer hash table removal")
Signed-off-by: David Gibson <david@gibson.dropbear.id.au>
Signed-off-by: Stefano Brivio <sbrivio@redhat.com>
| -rw-r--r-- | tcp.c | 9 |
1 files changed, 5 insertions, 4 deletions
@@ -694,12 +694,13 @@ void conn_event_do(const struct ctx *c, struct tcp_tap_conn *conn, flow_dbg(conn, "%s", num == -1 ? "CLOSED" : tcp_event_str[num]); - if (event == CLOSED) - flow_hash_remove(c, TAP_SIDX(conn)); - else if ((event == TAP_FIN_RCVD) && !(conn->events & SOCK_FIN_RCVD)) + if ((event == TAP_FIN_RCVD) && !(conn->events & SOCK_FIN_RCVD)) { conn_flag(c, conn, ACTIVE_CLOSE); - else + } else { + if (event == CLOSED) + flow_hash_remove(c, TAP_SIDX(conn)); tcp_epoll_ctl(c, conn); + } if (CONN_HAS(conn, SOCK_FIN_SENT | TAP_FIN_ACKED)) tcp_timer_ctl(conn); |
