diff options
author | Trond Myklebust <trond.myklebust@primarydata.com> | 2016-07-26 09:51:19 -0400 |
---|---|---|
committer | J. Bruce Fields <bfields@redhat.com> | 2016-08-01 17:53:41 -0400 |
commit | b2f21f7d85758309f94eafd502fe555e8e5a7f06 (patch) | |
tree | 55262bcba32ed561db0953883f1f73090925f413 /net | |
parent | 8a4c3926889e7bf226e9f0254e7eface1f85f312 (diff) |
SUNRPC: accept() may return sockets that are still in SYN_RECV
We're seeing traces of the following form:
[10952.396347] svc: transport ffff88042ba4a 000 dequeued, inuse=2
[10952.396351] svc: tcp_accept ffff88042ba4 a000 sock ffff88042a6e4c80
[10952.396362] nfsd: connect from 10.2.6.1, port=187
[10952.396364] svc: svc_setup_socket ffff8800b99bcf00
[10952.396368] setting up TCP socket for reading
[10952.396370] svc: svc_setup_socket created ffff8803eb10a000 (inet ffff88042b75b800)
[10952.396373] svc: transport ffff8803eb10a000 put into queue
[10952.396375] svc: transport ffff88042ba4a000 put into queue
[10952.396377] svc: server ffff8800bb0ec000 waiting for data (to = 3600000)
[10952.396380] svc: transport ffff8803eb10a000 dequeued, inuse=2
[10952.396381] svc_recv: found XPT_CLOSE
[10952.396397] svc: svc_delete_xprt(ffff8803eb10a000)
[10952.396398] svc: svc_tcp_sock_detach(ffff8803eb10a000)
[10952.396399] svc: svc_sock_detach(ffff8803eb10a000)
[10952.396412] svc: svc_sock_free(ffff8803eb10a000)
i.e. an immediate close of the socket after initialisation.
The culprit appears to be the test at the end of svc_tcp_init, which
checks if the newly created socket is in the TCP_ESTABLISHED state,
and immediately closes it if not. The evidence appears to suggest that
the socket might still be in the SYN_RECV state at this time.
The fix is to check for both states, and then to add a check in
svc_tcp_state_change() to ensure we don't close the socket when
it transitions into TCP_ESTABLISHED.
Signed-off-by: Trond Myklebust <trond.myklebust@primarydata.com>
Signed-off-by: J. Bruce Fields <bfields@redhat.com>
Diffstat (limited to 'net')
-rw-r--r-- | net/sunrpc/svcsock.c | 13 |
1 files changed, 10 insertions, 3 deletions
diff --git a/net/sunrpc/svcsock.c b/net/sunrpc/svcsock.c index bc3ef0734f2f..a11ddc8975c3 100644 --- a/net/sunrpc/svcsock.c +++ b/net/sunrpc/svcsock.c | |||
@@ -763,8 +763,10 @@ static void svc_tcp_state_change(struct sock *sk) | |||
763 | printk("svc: socket %p: no user data\n", sk); | 763 | printk("svc: socket %p: no user data\n", sk); |
764 | else { | 764 | else { |
765 | svsk->sk_ostate(sk); | 765 | svsk->sk_ostate(sk); |
766 | set_bit(XPT_CLOSE, &svsk->sk_xprt.xpt_flags); | 766 | if (sk->sk_state != TCP_ESTABLISHED) { |
767 | svc_xprt_enqueue(&svsk->sk_xprt); | 767 | set_bit(XPT_CLOSE, &svsk->sk_xprt.xpt_flags); |
768 | svc_xprt_enqueue(&svsk->sk_xprt); | ||
769 | } | ||
768 | } | 770 | } |
769 | } | 771 | } |
770 | 772 | ||
@@ -1290,8 +1292,13 @@ static void svc_tcp_init(struct svc_sock *svsk, struct svc_serv *serv) | |||
1290 | tcp_sk(sk)->nonagle |= TCP_NAGLE_OFF; | 1292 | tcp_sk(sk)->nonagle |= TCP_NAGLE_OFF; |
1291 | 1293 | ||
1292 | set_bit(XPT_DATA, &svsk->sk_xprt.xpt_flags); | 1294 | set_bit(XPT_DATA, &svsk->sk_xprt.xpt_flags); |
1293 | if (sk->sk_state != TCP_ESTABLISHED) | 1295 | switch (sk->sk_state) { |
1296 | case TCP_SYN_RECV: | ||
1297 | case TCP_ESTABLISHED: | ||
1298 | break; | ||
1299 | default: | ||
1294 | set_bit(XPT_CLOSE, &svsk->sk_xprt.xpt_flags); | 1300 | set_bit(XPT_CLOSE, &svsk->sk_xprt.xpt_flags); |
1301 | } | ||
1295 | } | 1302 | } |
1296 | } | 1303 | } |
1297 | 1304 | ||