diff options
author | Haishuang Yan <yanhaishuang@cmss.chinamobile.com> | 2017-09-26 23:35:42 -0400 |
---|---|---|
committer | David S. Miller <davem@davemloft.net> | 2017-10-01 20:55:54 -0400 |
commit | 437138485656c41e32b8c63c0987cfa0348be0e6 (patch) | |
tree | 942ae784a68f7d351f62fd3ac48c1330d629ce31 /net/ipv4/tcp_ipv4.c | |
parent | dd000598a39b6937fcefdf143720ec9fb5250e72 (diff) |
ipv4: Namespaceify tcp_fastopen_key knob
Different namespace application might require different tcp_fastopen_key
independently of the host.
David Miller pointed out there is a leak without releasing the context
of tcp_fastopen_key during netns teardown. So add the release action in
exit_batch path.
Tested:
1. Container namespace:
# cat /proc/sys/net/ipv4/tcp_fastopen_key:
2817fff2-f803cf97-eadfd1f3-78c0992b
cookie key in tcp syn packets:
Fast Open Cookie
Kind: TCP Fast Open Cookie (34)
Length: 10
Fast Open Cookie: 1e5dd82a8c492ca9
2. Host:
# cat /proc/sys/net/ipv4/tcp_fastopen_key:
107d7c5f-68eb2ac7-02fb06e6-ed341702
cookie key in tcp syn packets:
Fast Open Cookie
Kind: TCP Fast Open Cookie (34)
Length: 10
Fast Open Cookie: e213c02bf0afbc8a
Signed-off-by: Haishuang Yan <yanhaishuang@cmss.chinamobile.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Diffstat (limited to 'net/ipv4/tcp_ipv4.c')
-rw-r--r-- | net/ipv4/tcp_ipv4.c | 6 |
1 files changed, 6 insertions, 0 deletions
diff --git a/net/ipv4/tcp_ipv4.c b/net/ipv4/tcp_ipv4.c index 88409b13c9d2..49c74c0d0d21 100644 --- a/net/ipv4/tcp_ipv4.c +++ b/net/ipv4/tcp_ipv4.c | |||
@@ -2473,6 +2473,7 @@ static int __net_init tcp_sk_init(struct net *net) | |||
2473 | net->ipv4.sysctl_tcp_timestamps = 1; | 2473 | net->ipv4.sysctl_tcp_timestamps = 1; |
2474 | 2474 | ||
2475 | net->ipv4.sysctl_tcp_fastopen = TFO_CLIENT_ENABLE; | 2475 | net->ipv4.sysctl_tcp_fastopen = TFO_CLIENT_ENABLE; |
2476 | spin_lock_init(&net->ipv4.tcp_fastopen_ctx_lock); | ||
2476 | 2477 | ||
2477 | return 0; | 2478 | return 0; |
2478 | fail: | 2479 | fail: |
@@ -2483,7 +2484,12 @@ fail: | |||
2483 | 2484 | ||
2484 | static void __net_exit tcp_sk_exit_batch(struct list_head *net_exit_list) | 2485 | static void __net_exit tcp_sk_exit_batch(struct list_head *net_exit_list) |
2485 | { | 2486 | { |
2487 | struct net *net; | ||
2488 | |||
2486 | inet_twsk_purge(&tcp_hashinfo, AF_INET); | 2489 | inet_twsk_purge(&tcp_hashinfo, AF_INET); |
2490 | |||
2491 | list_for_each_entry(net, net_exit_list, exit_list) | ||
2492 | tcp_fastopen_ctx_destroy(net); | ||
2487 | } | 2493 | } |
2488 | 2494 | ||
2489 | static struct pernet_operations __net_initdata tcp_sk_ops = { | 2495 | static struct pernet_operations __net_initdata tcp_sk_ops = { |