diff options
author | Denis V. Lunev <den@openvz.org> | 2008-01-19 02:55:19 -0500 |
---|---|---|
committer | David S. Miller <davem@davemloft.net> | 2008-01-28 18:08:08 -0500 |
commit | 775516bfa2bd7993620c9039191a0c30b8d8a496 (patch) | |
tree | 7385f35edda9f4124b802ccf337c55070d2e00bc /net/ipv4 | |
parent | b7c6ba6eb1234e35a74fb8ba8123232a7b1ba9e4 (diff) |
[NETNS]: Namespace stop vs 'ip r l' race.
During network namespace stop process kernel side netlink sockets
belonging to a namespace should be closed. They should not prevent
namespace to stop, so they do not increment namespace usage
counter. Though this counter will be put during last sock_put.
The raplacement of the correct netns for init_ns solves the problem
only partial as socket to be stoped until proper stop is a valid
netlink kernel socket and can be looked up by the user processes. This
is not a problem until it resides in initial namespace (no processes
inside this net), but this is not true for init_net.
So, hold the referrence for a socket, remove it from lookup tables and
only after that change namespace and perform a last put.
Signed-off-by: Denis V. Lunev <den@openvz.org>
Tested-by: Alexey Dobriyan <adobriyan@openvz.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
Diffstat (limited to 'net/ipv4')
-rw-r--r-- | net/ipv4/fib_frontend.c | 7 |
1 files changed, 1 insertions, 6 deletions
diff --git a/net/ipv4/fib_frontend.c b/net/ipv4/fib_frontend.c index e787d2151152..62bd791c204e 100644 --- a/net/ipv4/fib_frontend.c +++ b/net/ipv4/fib_frontend.c | |||
@@ -869,19 +869,14 @@ static int nl_fib_lookup_init(struct net *net) | |||
869 | nl_fib_input, NULL, THIS_MODULE); | 869 | nl_fib_input, NULL, THIS_MODULE); |
870 | if (sk == NULL) | 870 | if (sk == NULL) |
871 | return -EAFNOSUPPORT; | 871 | return -EAFNOSUPPORT; |
872 | /* Don't hold an extra reference on the namespace */ | ||
873 | put_net(sk->sk_net); | ||
874 | net->ipv4.fibnl = sk; | 872 | net->ipv4.fibnl = sk; |
875 | return 0; | 873 | return 0; |
876 | } | 874 | } |
877 | 875 | ||
878 | static void nl_fib_lookup_exit(struct net *net) | 876 | static void nl_fib_lookup_exit(struct net *net) |
879 | { | 877 | { |
880 | /* At the last minute lie and say this is a socket for the | ||
881 | * initial network namespace. So the socket will be safe to free. | ||
882 | */ | ||
883 | net->ipv4.fibnl->sk_net = get_net(&init_net); | ||
884 | netlink_kernel_release(net->ipv4.fibnl); | 878 | netlink_kernel_release(net->ipv4.fibnl); |
879 | net->ipv4.fibnl = NULL; | ||
885 | } | 880 | } |
886 | 881 | ||
887 | static void fib_disable_ip(struct net_device *dev, int force) | 882 | static void fib_disable_ip(struct net_device *dev, int force) |