Thread (14 messages) flat view 14 messages, 3 authors, 2026-02-16

Re: [PATCH v1 bpf/net 5/6] sockmap: Consolidate sk_psock_skb_ingress_self().

From: bot+bpf-ci@kernel.org
Date: 2026-02-15 21:50:44
Also in: bpf

quoted hunk ↗ jump to hunk
diff --git a/net/core/skmsg.c b/net/core/skmsg.c
--- a/net/core/skmsg.c
+++ b/net/core/skmsg.c
[ ... ]
static int sk_psock_skb_ingress(struct sk_psock *psock, struct sk_buff *skb,
-				u32 off, u32 len, gfp_t gfp_flags)
+				u32 off, u32 len, gfp_t gfp_flags, bool take_ref)
{
	struct sock *sk = psock->sk;
	struct sk_msg *msg;
	int err = -EAGAIN;

	msg = alloc_sk_msg(gfp_flags);
	if (!msg)
		goto out;
[ ... ]
	skb_set_owner_r(skb, sk);
-	err = sk_psock_skb_ingress_enqueue(skb, off, len, psock, sk, msg, true);
+	err = sk_psock_skb_ingress_enqueue(skb, off, len, psock, sk, msg, take_ref);
[ ... ]
-/* Puts an skb on the ingress queue of the socket already assigned to the
- * skb. In this case we do not need to check memory limits or skb_set_owner_r
- * because the skb is already accounted for here.
- */
-static int sk_psock_skb_ingress_self(struct sk_psock *psock, struct sk_buff *skb,
-				     u32 off, u32 len, bool take_ref)
-{
-	struct sk_msg *msg = alloc_sk_msg(GFP_ATOMIC);
-	struct sock *sk = psock->sk;
-	int err;
-
-	if (unlikely(!msg))
-		return -EAGAIN;
-	skb_set_owner_r(skb, sk);
-
-	/* This is used in tcp_bpf_recvmsg_parser() to determine whether the
-	 * data originates from the socket's own protocol stack. No need to
-	 * refcount sk because msg's lifetime is bound to sk via the ingress_msg.
-	 */
-	msg->sk = sk;
The consolidated sk_psock_skb_ingress() does not carry forward this
msg->sk = sk assignment. alloc_sk_msg() uses kzalloc, so msg->sk
will be NULL for self-ingress messages.

In __sk_msg_recvmsg(), the from_self flag is set based on msg->sk:

    from_self = msg_rx->sk == sk;

This controls copied_from_self accumulation, which
tcp_bpf_recvmsg_parser() uses to advance tcp->copied_seq:

    seq += copied_from_self;
    ...
    WRITE_ONCE(tcp->copied_seq, seq);

With msg->sk now always NULL, copied_from_self will always be zero
for TCP sockets using a BPF verdict program that returns SK_PASS.
tcp->copied_seq won't advance, which would affect TCP receive window
advertisement.

Should this assignment be preserved in the consolidated function
when skb->sk == sk?
-	err = sk_psock_skb_ingress_enqueue(skb, off, len, psock, sk, msg, take_ref);
-	if (err < 0)
-		kfree(msg);
-	return err;
-}

---
AI reviewed your patch. Please fix the bug or email reply why it's not a bug.
See: https://github.com/kernel-patches/vmtest/blob/master/ci/claude/README.md

CI run summary: https://github.com/kernel-patches/bpf/actions/runs/22042899757

AI-authorship-score: low
AI-authorship-explanation: Commit is part of a coherent series from a known kernel maintainer addressing specific syzbot bugs, with typical kernel commit style and mechanical refactoring consistent with human development workflow.
issues-found: 1
issue-severity-score: medium
issue-severity-explanation: Dropped msg->sk assignment breaks TCP copied_seq tracking for sockmap verdict SK_PASS path, affecting TCP receive window advertisement and potentially stalling connections under sustained traffic.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help