aboutsummaryrefslogtreecommitdiffstats
path: root/net/ipv4/tcp_output.c
diff options
context:
space:
mode:
authorEric Dumazet <edumazet@google.com>2015-04-21 21:32:24 -0400
committerDavid S. Miller <davem@davemloft.net>2015-04-22 14:13:11 -0400
commitd83769a580f1132ac26439f50068a29b02be535e (patch)
treeb18a104e87454d5505c3d0e5f1c2e7f26ce9b89c /net/ipv4/tcp_output.c
parent5e6c94a999f67f120c6bbba71bbee840dfee6338 (diff)
tcp: fix possible deadlock in tcp_send_fin()
Using sk_stream_alloc_skb() in tcp_send_fin() is dangerous in case a huge process is killed by OOM, and tcp_mem[2] is hit. To be able to free memory we need to make progress, so this patch allows FIN packets to not care about tcp_mem[2], if skb allocation succeeded. In a follow-up patch, we might abort tcp_send_fin() infinite loop in case TIF_MEMDIE is set on this thread, as memory allocator did its best getting extra memory already. This patch reverts d22e15371811 ("tcp: fix tcp fin memory accounting") Fixes: d22e15371811 ("tcp: fix tcp fin memory accounting") Signed-off-by: Eric Dumazet <edumazet@google.com> Signed-off-by: David S. Miller <davem@davemloft.net>
Diffstat (limited to 'net/ipv4/tcp_output.c')
-rw-r--r--net/ipv4/tcp_output.c20
1 files changed, 19 insertions, 1 deletions
diff --git a/net/ipv4/tcp_output.c b/net/ipv4/tcp_output.c
index 8c8d7e06b72f..2ade67b7cdb0 100644
--- a/net/ipv4/tcp_output.c
+++ b/net/ipv4/tcp_output.c
@@ -2812,6 +2812,21 @@ begin_fwd:
2812 } 2812 }
2813} 2813}
2814 2814
2815/* We allow to exceed memory limits for FIN packets to expedite
2816 * connection tear down and (memory) recovery.
2817 * Otherwise tcp_send_fin() could loop forever.
2818 */
2819static void sk_forced_wmem_schedule(struct sock *sk, int size)
2820{
2821 int amt, status;
2822
2823 if (size <= sk->sk_forward_alloc)
2824 return;
2825 amt = sk_mem_pages(size);
2826 sk->sk_forward_alloc += amt * SK_MEM_QUANTUM;
2827 sk_memory_allocated_add(sk, amt, &status);
2828}
2829
2815/* Send a fin. The caller locks the socket for us. This cannot be 2830/* Send a fin. The caller locks the socket for us. This cannot be
2816 * allowed to fail queueing a FIN frame under any circumstances. 2831 * allowed to fail queueing a FIN frame under any circumstances.
2817 */ 2832 */
@@ -2834,11 +2849,14 @@ void tcp_send_fin(struct sock *sk)
2834 } else { 2849 } else {
2835 /* Socket is locked, keep trying until memory is available. */ 2850 /* Socket is locked, keep trying until memory is available. */
2836 for (;;) { 2851 for (;;) {
2837 skb = sk_stream_alloc_skb(sk, 0, sk->sk_allocation); 2852 skb = alloc_skb_fclone(MAX_TCP_HEADER,
2853 sk->sk_allocation);
2838 if (skb) 2854 if (skb)
2839 break; 2855 break;
2840 yield(); 2856 yield();
2841 } 2857 }
2858 skb_reserve(skb, MAX_TCP_HEADER);
2859 sk_forced_wmem_schedule(sk, skb->truesize);
2842 /* FIN eats a sequence byte, write_seq advanced by tcp_queue_skb(). */ 2860 /* FIN eats a sequence byte, write_seq advanced by tcp_queue_skb(). */
2843 tcp_init_nondata_skb(skb, tp->write_seq, 2861 tcp_init_nondata_skb(skb, tp->write_seq,
2844 TCPHDR_ACK | TCPHDR_FIN); 2862 TCPHDR_ACK | TCPHDR_FIN);