Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more

Commit 49106f36 authored by Eric Dumazet's avatar Eric Dumazet Committed by Greg Kroah-Hartman
Browse files

inet: frags: get rif of inet_frag_evicting()



This refactors ip_expire() since one indentation level is removed.

Note: in the future, we should try hard to avoid the skb_clone()
since this is a serious performance cost.
Under DDOS, the ICMP message wont be sent because of rate limits.

Fact that ip6_expire_frag_queue() does not use skb_clone() is
disturbing too. Presumably IPv6 should have the same
issue than the one we fixed in commit ec4fbd64751d
("inet: frag: release spinlock before calling icmp_send()")

Signed-off-by: default avatarEric Dumazet <edumazet@google.com>
Signed-off-by: default avatarDavid S. Miller <davem@davemloft.net>
(cherry picked from commit 399d1404be660d355192ff4df5ccc3f4159ec1e4)
Signed-off-by: default avatarGreg Kroah-Hartman <gregkh@linuxfoundation.org>
parent ea7496f0
Loading
Loading
Loading
Loading
+0 −5
Original line number Diff line number Diff line
@@ -118,11 +118,6 @@ static inline void inet_frag_put(struct inet_frag_queue *q)
		inet_frag_destroy(q);
}

static inline bool inet_frag_evicting(struct inet_frag_queue *q)
{
	return false;
}

/* Memory Tracking Functions. */

static inline int frag_mem_limit(struct netns_frags *nf)
+32 −33
Original line number Diff line number Diff line
@@ -141,8 +141,11 @@ static bool frag_expire_skip_icmp(u32 user)
 */
static void ip_expire(unsigned long arg)
{
	struct ipq *qp;
	struct sk_buff *clone, *head;
	const struct iphdr *iph;
	struct net *net;
	struct ipq *qp;
	int err;

	qp = container_of((struct inet_frag_queue *) arg, struct ipq, q);
	net = container_of(qp->q.net, struct net, ipv4.frags);
@@ -156,14 +159,11 @@ static void ip_expire(unsigned long arg)
	ipq_kill(qp);
	__IP_INC_STATS(net, IPSTATS_MIB_REASMFAILS);

	if (!inet_frag_evicting(&qp->q)) {
		struct sk_buff *clone, *head = qp->q.fragments;
		const struct iphdr *iph;
		int err;
	head = qp->q.fragments;

	__IP_INC_STATS(net, IPSTATS_MIB_REASMTIMEOUT);

		if (!(qp->q.flags & INET_FRAG_FIRST_IN) || !qp->q.fragments)
	if (!(qp->q.flags & INET_FRAG_FIRST_IN) || !head)
		goto out;

	head->dev = dev_get_by_index_rcu(net, qp->iif);
@@ -195,7 +195,6 @@ static void ip_expire(unsigned long arg)
		consume_skb(clone);
		goto out_rcu_unlock;
	}
	}
out:
	spin_unlock(&qp->q.lock);
out_rcu_unlock:
+0 −4
Original line number Diff line number Diff line
@@ -106,10 +106,6 @@ void ip6_expire_frag_queue(struct net *net, struct frag_queue *fq)
		goto out_rcu_unlock;

	__IP6_INC_STATS(net, __in6_dev_get(dev), IPSTATS_MIB_REASMFAILS);

	if (inet_frag_evicting(&fq->q))
		goto out_rcu_unlock;

	__IP6_INC_STATS(net, __in6_dev_get(dev), IPSTATS_MIB_REASMTIMEOUT);

	/* Don't send error if the first segment did not arrive. */