aboutsummaryrefslogtreecommitdiffstats
path: root/net/ipv4/tcp_ipv4.c
diff options
context:
space:
mode:
authorHaishuang Yan <yanhaishuang@cmss.chinamobile.com>2017-09-26 23:35:42 -0400
committerDavid S. Miller <davem@davemloft.net>2017-10-01 20:55:54 -0400
commit437138485656c41e32b8c63c0987cfa0348be0e6 (patch)
tree942ae784a68f7d351f62fd3ac48c1330d629ce31 /net/ipv4/tcp_ipv4.c
parentdd000598a39b6937fcefdf143720ec9fb5250e72 (diff)
ipv4: Namespaceify tcp_fastopen_key knob
Different namespace application might require different tcp_fastopen_key independently of the host. David Miller pointed out there is a leak without releasing the context of tcp_fastopen_key during netns teardown. So add the release action in exit_batch path. Tested: 1. Container namespace: # cat /proc/sys/net/ipv4/tcp_fastopen_key: 2817fff2-f803cf97-eadfd1f3-78c0992b cookie key in tcp syn packets: Fast Open Cookie Kind: TCP Fast Open Cookie (34) Length: 10 Fast Open Cookie: 1e5dd82a8c492ca9 2. Host: # cat /proc/sys/net/ipv4/tcp_fastopen_key: 107d7c5f-68eb2ac7-02fb06e6-ed341702 cookie key in tcp syn packets: Fast Open Cookie Kind: TCP Fast Open Cookie (34) Length: 10 Fast Open Cookie: e213c02bf0afbc8a Signed-off-by: Haishuang Yan <yanhaishuang@cmss.chinamobile.com> Signed-off-by: David S. Miller <davem@davemloft.net>
Diffstat (limited to 'net/ipv4/tcp_ipv4.c')
-rw-r--r--net/ipv4/tcp_ipv4.c6
1 files changed, 6 insertions, 0 deletions
diff --git a/net/ipv4/tcp_ipv4.c b/net/ipv4/tcp_ipv4.c
index 88409b13c9d2..49c74c0d0d21 100644
--- a/net/ipv4/tcp_ipv4.c
+++ b/net/ipv4/tcp_ipv4.c
@@ -2473,6 +2473,7 @@ static int __net_init tcp_sk_init(struct net *net)
2473 net->ipv4.sysctl_tcp_timestamps = 1; 2473 net->ipv4.sysctl_tcp_timestamps = 1;
2474 2474
2475 net->ipv4.sysctl_tcp_fastopen = TFO_CLIENT_ENABLE; 2475 net->ipv4.sysctl_tcp_fastopen = TFO_CLIENT_ENABLE;
2476 spin_lock_init(&net->ipv4.tcp_fastopen_ctx_lock);
2476 2477
2477 return 0; 2478 return 0;
2478fail: 2479fail:
@@ -2483,7 +2484,12 @@ fail:
2483 2484
2484static void __net_exit tcp_sk_exit_batch(struct list_head *net_exit_list) 2485static void __net_exit tcp_sk_exit_batch(struct list_head *net_exit_list)
2485{ 2486{
2487 struct net *net;
2488
2486 inet_twsk_purge(&tcp_hashinfo, AF_INET); 2489 inet_twsk_purge(&tcp_hashinfo, AF_INET);
2490
2491 list_for_each_entry(net, net_exit_list, exit_list)
2492 tcp_fastopen_ctx_destroy(net);
2487} 2493}
2488 2494
2489static struct pernet_operations __net_initdata tcp_sk_ops = { 2495static struct pernet_operations __net_initdata tcp_sk_ops = {