e2ec8a
From 980418c331293aeb8595fcc95cbc4a9e1a485eda Mon Sep 17 00:00:00 2001
e2ec8a
From: Lennart Poettering <lennart@poettering.net>
e2ec8a
Date: Mon, 25 Feb 2019 11:02:46 +0100
e2ec8a
Subject: [PATCH] sd-bus: deal with cookie overruns
e2ec8a
e2ec8a
Apparently this happens IRL. Let's carefully deal with issues like this:
e2ec8a
when we overrun, let's not go back to zero but instead leave the highest
e2ec8a
cookie bit set. We use that as indication that we are in "overrun
e2ec8a
territory", and then are particularly careful with checking cookies,
e2ec8a
i.e. that they haven't been used for still outstanding replies yet. This
e2ec8a
should retain the quick cookie generation behaviour we used to have, but
e2ec8a
permits dealing with overruns.
e2ec8a
e2ec8a
Replaces: #11804
e2ec8a
Fixes: #11809
e2ec8a
(cherry picked from commit 1f82f5bb4237ed5f015daf93f818e9db95e764b8)
e2ec8a
e2ec8a
Resolves: #1694999
e2ec8a
---
e2ec8a
 src/libsystemd/sd-bus/sd-bus.c | 47 +++++++++++++++++++++++++++++++++-
e2ec8a
 1 file changed, 46 insertions(+), 1 deletion(-)
e2ec8a
e2ec8a
diff --git a/src/libsystemd/sd-bus/sd-bus.c b/src/libsystemd/sd-bus/sd-bus.c
e2ec8a
index f53a98d6bf..3583e24e64 100644
e2ec8a
--- a/src/libsystemd/sd-bus/sd-bus.c
e2ec8a
+++ b/src/libsystemd/sd-bus/sd-bus.c
e2ec8a
@@ -1597,6 +1597,47 @@ _public_ int sd_bus_get_bus_id(sd_bus *bus, sd_id128_t *id) {
e2ec8a
         return 0;
e2ec8a
 }
e2ec8a
 
e2ec8a
+#define COOKIE_CYCLED (UINT32_C(1) << 31)
e2ec8a
+
e2ec8a
+static uint64_t cookie_inc(uint64_t cookie) {
e2ec8a
+
e2ec8a
+        /* Stay within the 32bit range, since classic D-Bus can't deal with more */
e2ec8a
+        if (cookie >= UINT32_MAX)
e2ec8a
+                return COOKIE_CYCLED; /* Don't go back to zero, but use the highest bit for checking
e2ec8a
+                                       * whether we are looping. */
e2ec8a
+
e2ec8a
+        return cookie + 1;
e2ec8a
+}
e2ec8a
+
e2ec8a
+static int next_cookie(sd_bus *b) {
e2ec8a
+        uint64_t new_cookie;
e2ec8a
+
e2ec8a
+        assert(b);
e2ec8a
+
e2ec8a
+        new_cookie = cookie_inc(b->cookie);
e2ec8a
+
e2ec8a
+        /* Small optimization: don't bother with checking for cookie reuse until we overran cookiespace at
e2ec8a
+         * least once, but then do it thorougly. */
e2ec8a
+        if (FLAGS_SET(new_cookie, COOKIE_CYCLED)) {
e2ec8a
+                uint32_t i;
e2ec8a
+
e2ec8a
+                /* Check if the cookie is currently in use. If so, pick the next one */
e2ec8a
+                for (i = 0; i < COOKIE_CYCLED; i++) {
e2ec8a
+                        if (!ordered_hashmap_contains(b->reply_callbacks, &new_cookie))
e2ec8a
+                                goto good;
e2ec8a
+
e2ec8a
+                        new_cookie = cookie_inc(new_cookie);
e2ec8a
+                }
e2ec8a
+
e2ec8a
+                /* Can't fulfill request */
e2ec8a
+                return -EBUSY;
e2ec8a
+        }
e2ec8a
+
e2ec8a
+good:
e2ec8a
+        b->cookie = new_cookie;
e2ec8a
+        return 0;
e2ec8a
+}
e2ec8a
+
e2ec8a
 static int bus_seal_message(sd_bus *b, sd_bus_message *m, usec_t timeout) {
e2ec8a
         int r;
e2ec8a
 
e2ec8a
@@ -1620,7 +1661,11 @@ static int bus_seal_message(sd_bus *b, sd_bus_message *m, usec_t timeout) {
e2ec8a
                         return r;
e2ec8a
         }
e2ec8a
 
e2ec8a
-        return sd_bus_message_seal(m, ++b->cookie, timeout);
e2ec8a
+        r = next_cookie(b);
e2ec8a
+        if (r < 0)
e2ec8a
+                return r;
e2ec8a
+
e2ec8a
+        return sd_bus_message_seal(m, b->cookie, timeout);
e2ec8a
 }
e2ec8a
 
e2ec8a
 static int bus_remarshal_message(sd_bus *b, sd_bus_message **m) {