Thread (8 messages) flat view 8 messages, 4 authors, 20h ago

Re: [PATCH bpf v3 0/2] bpf: Fix socket leaks around connect(AF_UNSPEC)+listen()

From: Alexei Starovoitov <hidden>
Date: 2026-09-05 01:20:40
Also in: bpf, lkml, netfilter-devel

On Wed, Sep 2, 2026 at 4:06 PM Kuniyuki Iwashima [off-list ref] wrote:
On Wed, Sep 2, 2026 at 4:04 PM Kuniyuki Iwashima [off-list ref] wrote:
quoted
On Wed, Sep 2, 2026 at 3:52 PM Jakub Kicinski [off-list ref] wrote:
quoted
On Wed, 2 Sep 2026 11:58:49 -0700 Kuniyuki Iwashima wrote:
quoted
quoted
Several BPF socket helpers acquire a socket reference only when
sk_is_refcounted() == true, and release it, independently, by
re-evaluating sk_is_refcounted() again at the time the release runs. TCP
connect(AF_UNSPEC)+listen() sets SOCK_RCU_FREE on an established socket.
Due to several bug reports, we are now inclined to forbid the
buggy transformation.
https://lore.kernel.org/netdev/CANn89i+px52TtJy3S9=uHxGj3s-WueguRo1Z_4FxO=02KLmwmQ@mail.gmail.com/ (local)
Kuniyuki, would you be willing to send a patch to do that?
Not sure if anyone else is planning to, I wasn't..
Sure, I'll post one like this with s/synchronize_rcu()/-EINVAL/g
https://lore.kernel.org/netdev/20260804015349.2353056-1-kuniyu@google.com/ (local)
and cover IPV6_ADDRFORM.
sounds like the fixes in this patch set won't be needed,
so I tossed them out of patchwork.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help