Re: [PATCH bpf v3 0/2] bpf: Fix socket leaks around connect(AF_UNSPEC)+listen()
Kuniyuki Iwashima <[email protected]>
| Newsgroups | gmane.linux.network,gmane.linux.kernel.bpf,gmane.linux.kernel,gmane.comp.security.firewalls.netfilter.devel |
|---|---|
| Message-ID | <CAAVpQUC==6KEBs3XgFjZ536mJ23cbHma8HuiWMu1DRc_=YYOHg@mail.gmail.com> |
On Wed, Sep 2, 2026 at 10:55 AM Michal Luczaj <[email protected]> wrote: > > This is a follow-up to Sashiko's report[1]. > > Several BPF socket helpers acquire a socket reference only when > sk_is_refcounted() == true, and release it, independently, by > re-evaluating sk_is_refcounted() again at the time the release runs. TCP > connect(AF_UNSPEC)+listen() sets SOCK_RCU_FREE on an established socket. Due to several bug reports, we are now inclined to forbid the buggy transformation. https://lore.kernel.org/netdev/CANn89i+px52TtJy3S9=uHxGj3s-WueguRo1Z_4FxO=02KLmwmQ@mail.gmail.com/ > If that happens while a reference is outstanding, the release side sees > sk_is_refcounted() == false and skips the put; the socket is leaked. > > unreferenced object 0xffff88811617ce00 (size 3200): > comm "softirq", pid 0, jiffies 4294848512 > hex dump (first 32 bytes): > 7f 00 00 01 7f 00 00 01 4d 43 02 f6 00 00 00 00 ........MC...... > 02 00 07 41 00 00 00 00 00 00 00 00 00 00 00 00 ...A............ > backtrace (crc fb5bd4c8): > kmem_cache_alloc_noprof+0x53e/0x640 > sk_prot_alloc+0x69/0x240 > sk_clone+0x79/0x1230 > inet_csk_clone_lock+0x30/0x760 > tcp_create_openreq_child+0x34/0x2750 > tcp_v4_syn_recv_sock+0x12e/0x1080 > tcp_check_req+0x447/0x2310 > tcp_v4_rcv+0x1026/0x3c90 > ip_protocol_deliver_rcu+0x93/0x340 > ip_local_deliver_finish+0x356/0x5c0 > ip_local_deliver+0x184/0x4a0 > ip_rcv+0x4f4/0x5b0 > __netif_receive_skb_one_core+0x153/0x1b0 > process_backlog+0x28d/0x1190 > __napi_poll+0xab/0x520 > net_rx_action+0x3f0/0xca0 > > [1]: https://lore.kernel.org/bpf/[email protected]/ > > Signed-off-by: Michal Luczaj <[email protected]> > --- > Changes in v3: > - Add a fix for TC bpf_sk_assign() (patch #2) > - Clean up commit messages > - Non-fixes went to bpf-next: https://lore.kernel.org/bpf/[email protected]/ > - Link to v2: https://patch.msgid.link/[email protected] > > Changes in v2: > - Defer "Use sock_hold() instead of refcount_inc_not_zero() in lookup" to > bpf-next [John] > - Fix comment style [Sashiko] > - Link to v1: https://patch.msgid.link/[email protected] > > To: Alexei Starovoitov <[email protected]> > To: Daniel Borkmann <[email protected]> > To: Andrii Nakryiko <[email protected]> > To: Eduard Zingerman <[email protected]> > To: Kumar Kartikeya Dwivedi <[email protected]> > To: Martin KaFai Lau <[email protected]> > To: Song Liu <[email protected]> > To: Yonghong Song <[email protected]> > To: Jiri Olsa <[email protected]> > To: Emil Tsalapatis <[email protected]> > To: John Fastabend <[email protected]> > To: Stanislav Fomichev <[email protected]> > To: "David S. Miller" <[email protected]> > To: Eric Dumazet <[email protected]> > To: Jakub Kicinski <[email protected]> > To: Paolo Abeni <[email protected]> > To: Simon Horman <[email protected]> > To: Kuniyuki Iwashima <[email protected]> > To: Willem de Bruijn <[email protected]> > To: Jakub Sitnicki <[email protected]> > To: Jiayuan Chen <[email protected]> > To: Joe Stringer <[email protected]> > To: Ihor Solodrai <[email protected]> > To: Pablo Neira Ayuso <[email protected]> > To: Florian Westphal <[email protected]> > To: Phil Sutter <[email protected]> > Cc: [email protected] > Cc: [email protected] > Cc: [email protected] > Cc: [email protected] > Cc: [email protected] > > --- > Michal Luczaj (2): > bpf: Unconditionally take socket references in lookup helpers > bpf: Fix reference leak in bpf_sk_assign() > > include/net/inet6_hashtables.h | 9 ++++---- > include/net/inet_hashtables.h | 9 ++++---- > include/net/request_sock.h | 2 +- > include/net/sock.h | 11 ++++++++++ > net/core/filter.c | 49 +++++++++++++++++++++++++++++------------- > net/core/sock_map.c | 8 ++----- > net/netfilter/nf_queue.c | 18 ++++++++-------- > 7 files changed, 67 insertions(+), 39 deletions(-) > --- > base-commit: ce6b9e5dd873de532cd924e2abc928220cdc2738 > change-id: 20260628-sockmap-lookup-tcp-leak-bdaba3e083c5 > > Best regards, > -- > Michal Luczaj <[email protected]> >