Thread (7 messages) flat view 7 messages, 3 authors, 11h ago

Re: [PATCH bpf v3 0/2] bpf: Fix socket leaks around connect(AF_UNSPEC)+listen()

From: Kuniyuki Iwashima <kuniyu@google.com>
Date: 2026-09-02 23:06:53
Also in: bpf, lkml, netfilter-devel

On Wed, Sep 2, 2026 at 4:04 PM Kuniyuki Iwashima [off-list ref] wrote:
On Wed, Sep 2, 2026 at 3:52 PM Jakub Kicinski [off-list ref] wrote:
quoted
On Wed, 2 Sep 2026 11:58:49 -0700 Kuniyuki Iwashima wrote:
quoted
quoted
Several BPF socket helpers acquire a socket reference only when
sk_is_refcounted() == true, and release it, independently, by
re-evaluating sk_is_refcounted() again at the time the release runs. TCP
connect(AF_UNSPEC)+listen() sets SOCK_RCU_FREE on an established socket.
Due to several bug reports, we are now inclined to forbid the
buggy transformation.
https://lore.kernel.org/netdev/CANn89i+px52TtJy3S9=uHxGj3s-WueguRo1Z_4FxO=02KLmwmQ@mail.gmail.com/ (local)
Kuniyuki, would you be willing to send a patch to do that?
Not sure if anyone else is planning to, I wasn't..
Sure, I'll post one like this with s/synchronize_rcu()/-EINVAL/g
https://lore.kernel.org/netdev/20260804015349.2353056-1-kuniyu@google.com/ (local)
and cover IPV6_ADDRFORM.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help