[PATCH 05/10] Scrub data in tcp socket buffers

Aruna Balakrishnaiah aruna at linux.vnet.ibm.com
Thu Feb 27 01:31:27 EST 2014


     Find tcp domain sockets (struct sock *sk)

     tcp sockets:

       Iterate from 0 to INET_LHTABLE_SIZE and get inet_list_hashbucket from
       tcp_hash_info.listening_hash[<index>]
         for (i = 0; i < INET_LHTABLE_SIZE; i++) {
             struct inet_listen_hashbucket *ilb = &tcp_hashinfo.listening_hash[i];
         }
         for (i = 0; i < INET_LHTABLE_SIZE; i++) {
             struct inet_listen_hashbucket *ilb = &tcp_hashinfo.listening_hash[i];
         }
       For each hash bucket iterate over ilb->head null list to get sockets:
         struct sock *sk;
         sk_nulls_for_each(sk, node, &ilb->head) {
             ...
         }


      For each socket iterate over the socket buffers in
       sk_receive_queue and sk_write_queue:

       struct sock {
            ...
            struct sk_buff_head     sk_receive_queue;
            ...
            struct sk_buff_head     sk_write_queue;
            ...
       };

       struct sk_buff_head {
            struct sk_buff  *next;
            struct sk_buff  *prev;
       };

       For each struct sk_buff in the two lists clear the memory referenced
       by skb->data / skb->data_len:

       struct sk_buff {
            ...
            unsigned int            data_len;
            ...
            unsigned char           *data;
            ...
       };

Signed-off-by: Aruna Balakrishnaiah <aruna at linux.vnet.ibm.com>
---
 eppic_scripts/tcp_sk_buf.c |   78 ++++++++++++++++++++++++++++++++++++++++++++
 1 file changed, 78 insertions(+)
 create mode 100644 eppic_scripts/tcp_sk_buf.c

diff --git a/eppic_scripts/tcp_sk_buf.c b/eppic_scripts/tcp_sk_buf.c
new file mode 100644
index 0000000..4c3efc3
--- /dev/null
+++ b/eppic_scripts/tcp_sk_buf.c
@@ -0,0 +1,78 @@
+string
+tcp_opt()
+{
+	    return "l";
+}
+
+string
+tcp_usage()
+{
+	    return "\n";
+}
+
+static void
+tcp_showusage()
+{
+	    printf("usage : tcp %s", tcp_non_legacy_usage());
+}
+
+string
+tcp_help()
+{
+	    return "Help";
+}
+
+int
+tcp()
+{
+	int i;
+	struct inet_hashinfo *tab;
+	struct sock_common *off = 0;
+
+	tab = &tcp_hashinfo;
+
+	for (i = 0; i < 32; i++) {
+		struct hlist_nulls_node *pos;
+
+		pos = tab->listening_hash[i].head.first;
+
+		while (!((unsigned long)pos & 1)) {
+			struct sock *sk;
+			struct sk_buff *next;
+			struct sk_buff_head *head;
+			struct hlist_nulls_node *node;
+
+			sk  = (struct sock *)((unsigned long)pos - (unsigned long)&(off->skc_dontcopy_begin));
+
+			head = (struct sk_buff_head *)&(sk->sk_receive_queue);
+			next = (struct sk_buff *)sk->sk_receive_queue.next;
+
+			while (next != head)
+			{
+				struct sk_buff *buff = (struct sk_buff *) next;
+
+				memset((char *)buff->data, 'L', buff->data_len);
+				memset((char *)&(buff->data_len), 'L', 0x4);
+
+				next = buff->next;
+			}
+
+			head = (struct sk_buff_head *)&(sk->sk_write_queue);
+			next = (struct sk_buff *)sk->sk_write_queue.next;
+
+			while (next != head)
+			{
+				struct sk_buff *buff = (struct sk_buff *) next;
+
+				memset((char *)buff->data, 'L', buff->data_len);
+				memset((char *)&(buff->data_len), 'L', 0x4);
+
+				next = buff->next;
+			}
+
+			node = (struct hlist_nulls_node *)((unsigned long)sk + (unsigned long)&(off->skc_dontcopy_begin));
+			pos = node->next;
+		}
+	}
+	return 1;
+}




More information about the kexec mailing list