Skip to content

Commit

Permalink
Merge branch 'bpf-af-xdp-barrier-fixes'
Browse files Browse the repository at this point in the history
Björn Töpel says:

====================
This is a four patch series of various barrier, {READ, WRITE}_ONCE
cleanups in the AF_XDP socket code. More details can be found in the
corresponding commit message. Previous revisions: v1 [4] and v2 [5].

For an AF_XDP socket, most control plane operations are done under the
control mutex (struct xdp_sock, mutex), but there are some places
where members of the struct is read outside the control mutex. The
dev, queue_id members are set in bind() and cleared at cleanup. The
umem, fq, cq, tx, rx, and state member are all assigned in various
places, e.g. bind() and setsockopt(). When the members are assigned,
they are protected by the control mutex, but since they are read
outside the mutex, a WRITE_ONCE is required to avoid store-tearing on
the read-side.

Prior the state variable was introduced by Ilya, the dev member was
used to determine whether the socket was bound or not. However, when
dev was read, proper SMP barriers and READ_ONCE were missing. In order
to address the missing barriers and READ_ONCE, we start using the
state variable as a point of synchronization. The state member
read/write is paired with proper SMP barriers, and from this follows
that the members described above does not need READ_ONCE statements if
used in conjunction with state check.

To summarize: The members struct xdp_sock members dev, queue_id, umem,
fq, cq, tx, rx, and state were read lock-less, with incorrect barriers
and missing {READ, WRITE}_ONCE. After this series umem, fq, cq, tx,
rx, and state are read lock-less. When these members are updated,
WRITE_ONCE is used. When read, READ_ONCE are only used when read
outside the control mutex (e.g. mmap) or, not synchronized with the
state member (XSK_BOUND plus smp_rmb())

[1] https://lore.kernel.org/bpf/[email protected]/
[2] https://lwn.net/Articles/793253/
[3] https://github.com/google/ktsan/wiki/READ_ONCE-and-WRITE_ONCE
[4] https://lore.kernel.org/bpf/[email protected]/
[5] https://lore.kernel.org/bpf/[email protected]/

v2->v3:
  Minor restructure of commits.
  Improve cover and commit messages. (Daniel)
v1->v2:
  Removed redundant dev check. (Jonathan)
====================

Signed-off-by: Daniel Borkmann <[email protected]>
  • Loading branch information
borkmann committed Sep 5, 2019
2 parents 310f420 + 25dc18f commit 593f191
Show file tree
Hide file tree
Showing 2 changed files with 45 additions and 18 deletions.
60 changes: 42 additions & 18 deletions net/xdp/xsk.c
Original file line number Diff line number Diff line change
Expand Up @@ -186,10 +186,23 @@ static int __xsk_rcv_zc(struct xdp_sock *xs, struct xdp_buff *xdp, u32 len)
return err;
}

static bool xsk_is_bound(struct xdp_sock *xs)
{
if (READ_ONCE(xs->state) == XSK_BOUND) {
/* Matches smp_wmb() in bind(). */
smp_rmb();
return true;
}
return false;
}

int xsk_rcv(struct xdp_sock *xs, struct xdp_buff *xdp)
{
u32 len;

if (!xsk_is_bound(xs))
return -EINVAL;

if (xs->dev != xdp->rxq->dev || xs->queue_id != xdp->rxq->queue_index)
return -EINVAL;

Expand Down Expand Up @@ -387,7 +400,7 @@ static int xsk_sendmsg(struct socket *sock, struct msghdr *m, size_t total_len)
struct sock *sk = sock->sk;
struct xdp_sock *xs = xdp_sk(sk);

if (unlikely(!xs->dev))
if (unlikely(!xsk_is_bound(xs)))
return -ENXIO;
if (unlikely(!(xs->dev->flags & IFF_UP)))
return -ENETDOWN;
Expand All @@ -403,10 +416,15 @@ static unsigned int xsk_poll(struct file *file, struct socket *sock,
struct poll_table_struct *wait)
{
unsigned int mask = datagram_poll(file, sock, wait);
struct sock *sk = sock->sk;
struct xdp_sock *xs = xdp_sk(sk);
struct net_device *dev = xs->dev;
struct xdp_umem *umem = xs->umem;
struct xdp_sock *xs = xdp_sk(sock->sk);
struct net_device *dev;
struct xdp_umem *umem;

if (unlikely(!xsk_is_bound(xs)))
return mask;

dev = xs->dev;
umem = xs->umem;

if (umem->need_wakeup)
dev->netdev_ops->ndo_xsk_wakeup(dev, xs->queue_id,
Expand Down Expand Up @@ -434,18 +452,17 @@ static int xsk_init_queue(u32 entries, struct xsk_queue **queue,

/* Make sure queue is ready before it can be seen by others */
smp_wmb();
*queue = q;
WRITE_ONCE(*queue, q);
return 0;
}

static void xsk_unbind_dev(struct xdp_sock *xs)
{
struct net_device *dev = xs->dev;

if (!dev || xs->state != XSK_BOUND)
if (xs->state != XSK_BOUND)
return;

xs->state = XSK_UNBOUND;
WRITE_ONCE(xs->state, XSK_UNBOUND);

/* Wait for driver to stop using the xdp socket. */
xdp_del_sk_umem(xs->umem, xs);
Expand Down Expand Up @@ -520,7 +537,9 @@ static int xsk_release(struct socket *sock)
local_bh_enable();

xsk_delete_from_maps(xs);
mutex_lock(&xs->mutex);
xsk_unbind_dev(xs);
mutex_unlock(&xs->mutex);

xskq_destroy(xs->rx);
xskq_destroy(xs->tx);
Expand Down Expand Up @@ -632,19 +651,19 @@ static int xsk_bind(struct socket *sock, struct sockaddr *addr, int addr_len)
}

umem_xs = xdp_sk(sock->sk);
if (!umem_xs->umem) {
/* No umem to inherit. */
if (!xsk_is_bound(umem_xs)) {
err = -EBADF;
sockfd_put(sock);
goto out_unlock;
} else if (umem_xs->dev != dev || umem_xs->queue_id != qid) {
}
if (umem_xs->dev != dev || umem_xs->queue_id != qid) {
err = -EINVAL;
sockfd_put(sock);
goto out_unlock;
}

xdp_get_umem(umem_xs->umem);
xs->umem = umem_xs->umem;
WRITE_ONCE(xs->umem, umem_xs->umem);
sockfd_put(sock);
} else if (!xs->umem || !xdp_umem_validate_queues(xs->umem)) {
err = -EINVAL;
Expand All @@ -671,10 +690,15 @@ static int xsk_bind(struct socket *sock, struct sockaddr *addr, int addr_len)
xdp_add_sk_umem(xs->umem, xs);

out_unlock:
if (err)
if (err) {
dev_put(dev);
else
xs->state = XSK_BOUND;
} else {
/* Matches smp_rmb() in bind() for shared umem
* sockets, and xsk_is_bound().
*/
smp_wmb();
WRITE_ONCE(xs->state, XSK_BOUND);
}
out_release:
mutex_unlock(&xs->mutex);
rtnl_unlock();
Expand Down Expand Up @@ -751,7 +775,7 @@ static int xsk_setsockopt(struct socket *sock, int level, int optname,

/* Make sure umem is ready before it can be seen by others */
smp_wmb();
xs->umem = umem;
WRITE_ONCE(xs->umem, umem);
mutex_unlock(&xs->mutex);
return 0;
}
Expand Down Expand Up @@ -927,7 +951,7 @@ static int xsk_mmap(struct file *file, struct socket *sock,
unsigned long pfn;
struct page *qpg;

if (xs->state != XSK_READY)
if (READ_ONCE(xs->state) != XSK_READY)
return -EBUSY;

if (offset == XDP_PGOFF_RX_RING) {
Expand Down
3 changes: 3 additions & 0 deletions net/xdp/xsk_diag.c
Original file line number Diff line number Diff line change
Expand Up @@ -97,6 +97,7 @@ static int xsk_diag_fill(struct sock *sk, struct sk_buff *nlskb,
msg->xdiag_ino = sk_ino;
sock_diag_save_cookie(sk, msg->xdiag_cookie);

mutex_lock(&xs->mutex);
if ((req->xdiag_show & XDP_SHOW_INFO) && xsk_diag_put_info(xs, nlskb))
goto out_nlmsg_trim;

Expand All @@ -117,10 +118,12 @@ static int xsk_diag_fill(struct sock *sk, struct sk_buff *nlskb,
sock_diag_put_meminfo(sk, nlskb, XDP_DIAG_MEMINFO))
goto out_nlmsg_trim;

mutex_unlock(&xs->mutex);
nlmsg_end(nlskb, nlh);
return 0;

out_nlmsg_trim:
mutex_unlock(&xs->mutex);
nlmsg_cancel(nlskb, nlh);
return -EMSGSIZE;
}
Expand Down

0 comments on commit 593f191

Please sign in to comment.