[PATCH bpf v3 0/2] bpf, sockmap: fix forward allocation accounting in strparser self-pass path
From: Junseo Lim <hidden>
Date: 2026-08-17 15:50:17
Also in:
bpf, lkml
The strparser SK_PASS path can queue cloned skbs back to the same socket. When one TCP receive skb is split into many strparser messages, repeated receive-owner assignments for unowned clones can leave sk_forward_alloc in deficit before the next skb_set_owner_r() charge. Teardown can then uncharge more memcg pages than were reserved and trigger a page_counter underflow warning. Fix by avoiding another receive-owner transition for same-socket skbs that are already receive-owned by the socket. For unowned strparser self-pass skbs, settle any existing sk_forward_alloc deficit with sk_rmem_schedule(sk, skb, 0) before skb_set_owner_r(). Patch 1 also fixes psock backlog retries by restoring the original skb redirect metadata after skb_bpf_redirect_clear(). If a deferred strparser self-pass skb needs forward-allocation settlement, that work is done under the socket lock. The selftest adds a sockmap_strp case using a one-byte stream parser and an SK_PASS verdict program. The test checks INET_DIAG_MEMINFO to verify that sk_forward_alloc does not go negative after exercising the self-pass delivery path. Changelog: v2 -> v3: - Do not call skb_set_owner_r() again for already receive-owned same-socket skbs. - Preserve the original _sk_redir value across psock backlog retries. - Add a backlog-specific self-pass path so deferred strparser forward-allocation settlement runs under the socket lock. v1 -> v2: - Keep skb_set_owner_r() and use sk_rmem_schedule(sk, skb, 0) to settle sk_forward_alloc instead of skipping the owner transition. (Emil Tsalapatis) - Apply the same handling to psock backlog retries. - Add a sockmap_strp selftest based on the reproducer. - Add a Reported-by tag. - Change the Fixes tag to point to the commit that introduced the issue. v1: https://lore.kernel.org/bpf/20260723065244.186916-1-zirajs7@gmail.com/T/ (local) v2: https://lore.kernel.org/bpf/20260801102633.1872012-1-zirajs7@gmail.com/T/ (local) Junseo Lim (2): bpf, sockmap: settle sk_forward_alloc for strparser SK_PASS selftests/bpf: Cover strparser self-pass forward allocation net/core/skmsg.c | 125 +++++++++++-- .../selftests/bpf/prog_tests/sockmap_strp.c | 171 ++++++++++++++++++ .../selftests/bpf/progs/test_sockmap_strp.c | 6 + 3 files changed, 282 insertions(+), 20 deletions(-) -- 2.55.0