Re: [PATCH] selftests/net: ovpn: fix socket leak in ovpn_socket() error paths

Antonio Quartulli <[email protected]>
Newsgroups org.kernel.vger.linux-kselftest,org.kernel.vger.linux-kernel,org.kernel.vger.netdev
Organization OpenVPN Inc.
Message-ID <[email protected]>
Hi there,

On 07/08/2026 08:48, Qingshuang Fu wrote:
> From: Qingshuang Fu <[email protected]>
> 
> The ovpn_socket() function creates a socket but fails to close it on
> several error paths, leading to a file descriptor leak:
> 
> 1. When the address family is neither AF_INET nor AF_INET6, the socket
>     is leaked in the switch default case.
> 2. When setsockopt() for SO_REUSEADDR, SO_REUSEPORT, or SO_MARK fails,
>     the socket is leaked.
> 3. When setsockopt() for IPV6_V6ONLY fails, the socket is leaked.
> 
> The existing err_socket label already handles closing the socket for
> the bind() failure path. Fix all other error paths to use goto
> err_socket instead of returning directly, ensuring the socket is
> properly closed on every error path.
> 
> Fixes: 959bc330a439 ("testing/selftests: add test tool and scripts for ovpn module")

We'd rather send changes like this to net-next, so no Fixes tag required.

> Signed-off-by: Qingshuang Fu <[email protected]>

This said, we already have a patch reworking this part of the selftest 
with, which is also addressing this issue:

https://patchwork.openvpn.net/project/ovpn/patch/[email protected]/

It is pending to be sent to net-next as soon as we're finished with the 
fixes in our pipe.

Thanks for your contribution in any case!


Regards,



-- 
Antonio Quartulli
OpenVPN Inc.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.