[PATCH v3 05/10] net: turn sk_peer_pid into an array indexed by pid type
flat view
COOLING10d
REVIEWED: 1 (0M)
From: Andrew Halaney <hidden>
Date: 2026-09-28 09:27:41
Also in:
linux-fsdevel, lkml
Subsystem:
bluetooth subsystem, filesystems (vfs and infrastructure), landlock security module, networking [general], networking [sockets], networking [unix sockets], the rest, tracing · Maintainers:
Marcel Holtmann, Luiz Augusto von Dentz, Alexander Viro, Christian Brauner, Mickaël Salaün, "David S. Miller", Eric Dumazet, Jakub Kicinski, Paolo Abeni, Kuniyuki Iwashima, Willem de Bruijn, Linus Torvalds, Steven Rostedt, Masami Hiramatsu
1 review trailer.
From: Christian Brauner <brauner@kernel.org> Currently only the struct pid of the thread-group leader is recorded for a socket's peer. To make room for the struct pid of the thread that called connect(), listen() or socketpair() turn sk_peer_pid into an array indexed by pid type. All users, including bluetooth and the coredump socket, keep using the PIDTYPE_TGID slot. Nothing fills the PIDTYPE_PID slot yet. No functional changes. Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org> Reviewed-by: Alexander Mikhalitsyn <redacted> Signed-off-by: Andrew Halaney <redacted> --- fs/coredump.c | 2 +- include/net/sock.h | 4 ++-- include/trace/events/landlock.h | 2 +- net/bluetooth/af_bluetooth.c | 6 +++--- net/bluetooth/hci_sock.c | 8 ++++---- net/bluetooth/l2cap_sock.c | 2 +- net/core/sock.c | 9 +++++---- net/unix/af_unix.c | 14 +++++++------- 8 files changed, 24 insertions(+), 23 deletions(-)
diff --git a/fs/coredump.c b/fs/coredump.c
index 6114839f5178..9b267d3c0ed7 100644
--- a/fs/coredump.c
+++ b/fs/coredump.c@@ -722,7 +722,7 @@ static bool coredump_sock_connect(struct core_name *cn, struct coredump_params * } /* ... and validate that @sk_peer_pid matches @cprm.pid. */ - if (WARN_ON_ONCE(unix_peer(socket->sk)->sk_peer_pid != cprm->pid)) + if (WARN_ON_ONCE(unix_peer(socket->sk)->sk_peer_pid[PIDTYPE_TGID] != cprm->pid)) return false; cprm->limit = RLIM_INFINITY;
diff --git a/include/net/sock.h b/include/net/sock.h
index 14df0fb68259..efc64c60e4ac 100644
--- a/include/net/sock.h
+++ b/include/net/sock.h@@ -301,7 +301,7 @@ struct sk_filter; * @sk_type: socket type (%SOCK_STREAM, etc) * @sk_protocol: which protocol this socket belongs in this network family * @sk_peer_lock: lock protecting @sk_peer_pid and @sk_peer_cred - * @sk_peer_pid: &struct pid for this socket's peer + * @sk_peer_pid: &struct pid for this socket's peer, by pid type * @sk_peer_cred: %SO_PEERCRED setting * @sk_rcvlowat: %SO_RCVLOWAT setting * @sk_rcvtimeo: %SO_RCVTIMEO setting
@@ -546,7 +546,7 @@ struct sock { u64 sk_ino; spinlock_t sk_peer_lock; int sk_bind_phc; - struct pid *sk_peer_pid; + DECLARE_PIDS(sk_peer_pid, PIDTYPE_TGID); const struct cred *sk_peer_cred; ktime_t sk_stamp;
diff --git a/include/trace/events/landlock.h b/include/trace/events/landlock.h
index 3a43638c9bc2..9e172ea22d95 100644
--- a/include/trace/events/landlock.h
+++ b/include/trace/events/landlock.h@@ -1037,7 +1037,7 @@ TRACE_EVENT(landlock_deny_scope_abstract_unix_socket, * updates. The peer socket keeps a reference to sk_peer_pid * through pid_nr(); sun_path is the reliable identifier. */ - peer_pid = READ_ONCE(peer->sk_peer_pid); + peer_pid = READ_ONCE(peer->sk_peer_pid[PIDTYPE_TGID]); __entry->peer_pid = peer_pid ? pid_nr(peer_pid) : 0; __assign_str(sun_path); ),
diff --git a/net/bluetooth/af_bluetooth.c b/net/bluetooth/af_bluetooth.c
index 411d66f24393..7758e9ea3848 100644
--- a/net/bluetooth/af_bluetooth.c
+++ b/net/bluetooth/af_bluetooth.c@@ -161,7 +161,7 @@ struct sock *bt_sock_alloc(struct net *net, struct socket *sock, /* Init peer information so it can be properly monitored */ if (!kern) { spin_lock(&sk->sk_peer_lock); - sk->sk_peer_pid = get_pid(task_tgid(current)); + sk->sk_peer_pid[PIDTYPE_TGID] = get_pid(task_tgid(current)); sk->sk_peer_cred = get_current_cred(); spin_unlock(&sk->sk_peer_lock); }
@@ -235,9 +235,9 @@ void bt_accept_enqueue(struct sock *parent, struct sock *sk, bool bh) * socket is allocated by the kernel. */ spin_lock(&sk->sk_peer_lock); - old_pid = sk->sk_peer_pid; + old_pid = sk->sk_peer_pid[PIDTYPE_TGID]; old_cred = sk->sk_peer_cred; - sk->sk_peer_pid = get_pid(parent->sk_peer_pid); + sk->sk_peer_pid[PIDTYPE_TGID] = get_pid(parent->sk_peer_pid[PIDTYPE_TGID]); sk->sk_peer_cred = get_cred(parent->sk_peer_cred); spin_unlock(&sk->sk_peer_lock);
diff --git a/net/bluetooth/hci_sock.c b/net/bluetooth/hci_sock.c
index 6d56c77741e1..4c40068ba5fb 100644
--- a/net/bluetooth/hci_sock.c
+++ b/net/bluetooth/hci_sock.c@@ -284,21 +284,21 @@ static void hci_sock_copy_creds(struct sock *sk, struct sk_buff *skb) creds = &bt_cb(skb)->creds; /* Check if peer credentials is set */ - if (!sk->sk_peer_pid) { + if (!sk->sk_peer_pid[PIDTYPE_TGID]) { /* Check if parent peer credentials is set */ - if (bt_sk(sk)->parent && bt_sk(sk)->parent->sk_peer_pid) + if (bt_sk(sk)->parent && bt_sk(sk)->parent->sk_peer_pid[PIDTYPE_TGID]) sk = bt_sk(sk)->parent; else return; } /* Check if scm_creds already set */ - if (creds->pid == pid_vnr(sk->sk_peer_pid)) + if (creds->pid == pid_vnr(sk->sk_peer_pid[PIDTYPE_TGID])) return; memset(creds, 0, sizeof(*creds)); - creds->pid = pid_vnr(sk->sk_peer_pid); + creds->pid = pid_vnr(sk->sk_peer_pid[PIDTYPE_TGID]); if (sk->sk_peer_cred) { creds->uid = sk->sk_peer_cred->uid; creds->gid = sk->sk_peer_cred->gid;
diff --git a/net/bluetooth/l2cap_sock.c b/net/bluetooth/l2cap_sock.c
index 1194c37e466f..872d8fb31b6f 100644
--- a/net/bluetooth/l2cap_sock.c
+++ b/net/bluetooth/l2cap_sock.c@@ -1890,7 +1890,7 @@ static struct pid *l2cap_sock_get_peer_pid_cb(struct l2cap_chan *chan) { struct sock *sk = chan->data; - return sk->sk_peer_pid; + return sk->sk_peer_pid[PIDTYPE_TGID]; } static void l2cap_sock_suspend_cb(struct l2cap_chan *chan)
diff --git a/net/core/sock.c b/net/core/sock.c
index 3b5f28573752..dfe98463ad0e 100644
--- a/net/core/sock.c
+++ b/net/core/sock.c@@ -1921,7 +1921,8 @@ int sk_getsockopt(struct sock *sk, int level, int optname, len = sizeof(peercred); spin_lock(&sk->sk_peer_lock); - cred_to_ucred(sk->sk_peer_pid, sk->sk_peer_cred, &peercred); + cred_to_ucred(sk->sk_peer_pid[PIDTYPE_TGID], sk->sk_peer_cred, + &peercred); spin_unlock(&sk->sk_peer_lock); if (copy_to_sockptr(optval, &peercred, len))
@@ -1940,7 +1941,7 @@ int sk_getsockopt(struct sock *sk, int level, int optname, len = sizeof(pidfd); spin_lock(&sk->sk_peer_lock); - peer_pid = get_pid(sk->sk_peer_pid); + peer_pid = get_pid(sk->sk_peer_pid[PIDTYPE_TGID]); spin_unlock(&sk->sk_peer_lock); if (!peer_pid)
@@ -2394,7 +2395,7 @@ static void __sk_destruct(struct rcu_head *head) /* We do not need to acquire sk->sk_peer_lock, we are the last user. */ put_cred(sk->sk_peer_cred); - put_pid(sk->sk_peer_pid); + put_pids(sk->sk_peer_pid); if (likely(sk->sk_net_refcnt)) { put_net_track(net, &sk->ns_tracker);
@@ -3799,7 +3800,7 @@ void sock_init_data_uid(struct socket *sock, struct sock *sk, kuid_t uid) sk->sk_frag.offset = 0; sk->sk_peek_off = -1; - sk->sk_peer_pid = NULL; + memset(sk->sk_peer_pid, 0, sizeof(sk->sk_peer_pid)); sk->sk_peer_cred = NULL; spin_lock_init(&sk->sk_peer_lock);
diff --git a/net/unix/af_unix.c b/net/unix/af_unix.c
index 6cc2873d9a4f..66a26a10871b 100644
--- a/net/unix/af_unix.c
+++ b/net/unix/af_unix.c@@ -737,7 +737,7 @@ static void unix_release_sock(struct sock *sk, int embrion) } struct unix_peercred { - struct pid *peer_pid; + DECLARE_PIDS(peer_pid, PIDTYPE_TGID); const struct cred *peer_cred; };
@@ -749,7 +749,7 @@ static inline int prepare_peercred(struct unix_peercred *peercred) pid = task_tgid(current); err = pidfs_register_pid(pid); if (likely(!err)) { - peercred->peer_pid = get_pid(pid); + peercred->peer_pid[PIDTYPE_TGID] = get_pid(pid); peercred->peer_cred = get_current_cred(); } return err;
@@ -762,7 +762,7 @@ static void drop_peercred(struct unix_peercred *peercred) might_sleep(); - swap(peercred->peer_pid, pid); + swap(peercred->peer_pid[PIDTYPE_TGID], pid); swap(peercred->peer_cred, cred); put_pid(pid);
@@ -772,7 +772,7 @@ static void drop_peercred(struct unix_peercred *peercred) static inline void init_peercred(struct sock *sk, const struct unix_peercred *peercred) { - sk->sk_peer_pid = peercred->peer_pid; + sk->sk_peer_pid[PIDTYPE_TGID] = peercred->peer_pid[PIDTYPE_TGID]; sk->sk_peer_cred = peercred->peer_cred; }
@@ -782,12 +782,12 @@ static void update_peercred(struct sock *sk, struct unix_peercred *peercred) struct pid *old_pid; spin_lock(&sk->sk_peer_lock); - old_pid = sk->sk_peer_pid; + old_pid = sk->sk_peer_pid[PIDTYPE_TGID]; old_cred = sk->sk_peer_cred; init_peercred(sk, peercred); spin_unlock(&sk->sk_peer_lock); - peercred->peer_pid = old_pid; + peercred->peer_pid[PIDTYPE_TGID] = old_pid; peercred->peer_cred = old_cred; }
@@ -796,7 +796,7 @@ static void copy_peercred(struct sock *sk, struct sock *peersk) lockdep_assert_held(&unix_sk(peersk)->lock); spin_lock(&sk->sk_peer_lock); - sk->sk_peer_pid = get_pid(peersk->sk_peer_pid); + sk->sk_peer_pid[PIDTYPE_TGID] = get_pid(peersk->sk_peer_pid[PIDTYPE_TGID]); sk->sk_peer_cred = get_cred(peersk->sk_peer_cred); spin_unlock(&sk->sk_peer_lock); }
--
2.55.0