Re: [PATCH bpf v3 0/2] bpf: Fix socket leaks around connect(AF_UNSPEC)+listen()

Kuniyuki Iwashima <[email protected]>
Newsgroups gmane.linux.network,gmane.linux.kernel.bpf,gmane.linux.kernel,gmane.comp.security.firewalls.netfilter.devel
Message-ID <CAAVpQUATOCCc0N1jnfy2+tkD_zj1su-a-4+bV6qXOSzR7y_iQQ@mail.gmail.com>
On Wed, Sep 2, 2026 at 4:04 PM Kuniyuki Iwashima <[email protected]> wrote:
>
> On Wed, Sep 2, 2026 at 3:52 PM Jakub Kicinski <[email protected]> wrote:
> >
> > On Wed, 2 Sep 2026 11:58:49 -0700 Kuniyuki Iwashima wrote:
> > > > Several BPF socket helpers acquire a socket reference only when
> > > > sk_is_refcounted() == true, and release it, independently, by
> > > > re-evaluating sk_is_refcounted() again at the time the release runs. TCP
> > > > connect(AF_UNSPEC)+listen() sets SOCK_RCU_FREE on an established socket.
> > >
> > > Due to several bug reports, we are now inclined to forbid the
> > > buggy transformation.
> > > https://lore.kernel.org/netdev/CANn89i+px52TtJy3S9=uHxGj3s-WueguRo1Z_4FxO=02KLmwmQ@mail.gmail.com/
> >
> > Kuniyuki, would you be willing to send a patch to do that?
> > Not sure if anyone else is planning to, I wasn't..
>
> Sure, I'll post one like this with s/synchronize_rcu()/-EINVAL/g
> https://lore.kernel.org/netdev/[email protected]/

and cover IPV6_ADDRFORM.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.