Thread (3 messages) 3 messages, 3 authors, 15d ago

Re: [PATCH] vsock/hv_sock: reject incoming connections when the listener is being released

flat view

From: Stefano Garzarella <sgarzare@redhat.com>
Date: 2026-09-18 13:17:42
Also in: netdev

On Fri, Sep 18, 2026 at 12:01:54AM +0200, Bartłomiej Dmitruk wrote:
hvs_open_connection() only checks sk_state == TCP_LISTEN and
sk_acceptq_is_full() before creating a child and calling
vsock_enqueue_accept().  __vsock_release() sets sk->sk_shutdown =
SHUTDOWN_MASK and flushes the accept queue while leaving sk_state ==
TCP_LISTEN, so a host channel offer that races close() of the listener
passes both checks and enqueues a child onto the already-flushed queue.
That child socket (and the VMBUS channel opened for it) is never accepted
or cleaned up and leaks.

The virtio transport guards exactly this case in
virtio_transport_recv_listen(); hv_sock lacks the equivalent guard.
hv_sock holds lock_sock(sk) across hvs_open_connection(), so the check is
race-free.
Fixes tag missing.
quoted hunk ↗ jump to hunk
Signed-off-by: Bartłomiej Dmitruk <redacted>
---
diff --git a/net/vmw_vsock/hyperv_transport.c b/net/vmw_vsock/hyperv_transport.c
--- a/net/vmw_vsock/hyperv_transport.c
+++ b/net/vmw_vsock/hyperv_transport.c
@@ -324,6 +324,14 @@
	if (conn_from_host) {
		if (sk_acceptq_is_full(sk))
+			goto out;
+
+		/* __vsock_release() may have already flushed the accept queue
+		 * and set sk_shutdown = SHUTDOWN_MASK while leaving sk_state ==
+		 * TCP_LISTEN.  Enqueuing a child now would leak the child socket
+		 * and its VMBUS channel.  Mirror virtio_transport_recv_listen().
+		 */
+		if (sk->sk_shutdown == SHUTDOWN_MASK)
			goto out;
Should we do this check also if conn_from_host is false?

If it's the case, I guess we can add that check in the checks we do after lock_sock().

Thanks,
Stefano
		new = vsock_create_connected(sk);
  
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help