tipc: fix skb truesize/datasize ratio control

"Linux Kernel Mailing List" <[email protected]>
Newsgroups gmane.linux.kernel.commits.head
Message-ID <[email protected]>
Web:        https://git.kernel.org/torvalds/c/55b3280d1e471795c08dbbe17325720a843e104c
Commit:     55b3280d1e471795c08dbbe17325720a843e104c
Parent:     eb53f7af6f15285e2f6ada97285395343ce9f433
Refname:    refs/heads/master
Author:     Hoang Le <[email protected]>
AuthorDate: Thu Feb 8 17:16:25 2018 +0100
Committer:  David S. Miller <[email protected]>
CommitDate: Thu Feb 8 15:30:40 2018 -0500

    tipc: fix skb truesize/datasize ratio control
    
    In commit d618d09a68e4 ("tipc: enforce valid ratio between skb truesize
    and contents") we introduced a test for ensuring that the condition
    truesize/datasize <= 4 is true for a received buffer. Unfortunately this
    test has two problems.
    
    - Because of the integer arithmetics the test
      if (skb->truesize / buf_roundup_len(skb) > 4) will miss all
      ratios [4 < ratio < 5], which was not the intention.
    - The buffer returned by skb_copy() inherits skb->truesize of the
      original buffer, which doesn't help the situation at all.
    
    In this commit, we change the ratio condition and replace skb_copy()
    with a call to skb_copy_expand() to finally get this right.
    
    Acked-by: Jon Maloy <[email protected]>
    Signed-off-by: Jon Maloy <[email protected]>
    Signed-off-by: David S. Miller <[email protected]>
---
 net/tipc/msg.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/net/tipc/msg.c b/net/tipc/msg.c
index 55d8ba92291d..4e1c6f6450bb 100644
--- a/net/tipc/msg.c
+++ b/net/tipc/msg.c
@@ -208,8 +208,8 @@ bool tipc_msg_validate(struct sk_buff **_skb)
 	int msz, hsz;
 
 	/* Ensure that flow control ratio condition is satisfied */
-	if (unlikely(skb->truesize / buf_roundup_len(skb) > 4)) {
-		skb = skb_copy(skb, GFP_ATOMIC);
+	if (unlikely(skb->truesize / buf_roundup_len(skb) >= 4)) {
+		skb = skb_copy_expand(skb, BUF_HEADROOM, 0, GFP_ATOMIC);
 		if (!skb)
 			return false;
 		kfree_skb(*_skb);
--
To unsubscribe from this list: send the line "unsubscribe git-commits-head" in
the body of a message to [email protected]
More majordomo info at  http://vger.kernel.org/majordomo-info.html
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.