Re: [PATCH v4] net/smc: release the internal TCP sock on IPPROTO_SMC socket creation failure
| Newsgroups | org.kernel.vger.linux-s390 |
|---|---|
| Message-ID | <[email protected]> |
> IPPROTO_SMC sockets create an internal TCP sock ("clcsock") from the
> proto->init hook. When socket creation fails after proto->init has
> run - e.g. a cgroup BPF program attached to BPF_CGROUP_INET_SOCK_CREATE
> denies the socket - sk_common_release() only invokes sk_prot->destroy
> if it is set, but neither smc_inet_prot nor smc_inet6_prot defines it,
> and smc_destruct() returns early unless sk_state is SMC_CLOSED. As a
> result, every failing socket(AF_INET, SOCK_STREAM, IPPROTO_SMC) call
> leaks one tcp_sock, so an unprivileged task able to attach a deny-all
> BPF_CGROUP_INET_SOCK_CREATE program to its own cgroup can grow kernel
> memory unboundedly.
>
> Add a .destroy hook to both protos that releases the clcsock via
> smc_clcsock_release(). smc_sk_init() hashes the sock into the smc
> hashinfo before the clcsock is created, and smc_diag dumps walk that
> hash dereferencing smc->clcsock without taking clcsock_release_lock,
> while sk_common_release() calls .destroy before .unhash. Unhash the
> sock before releasing the clcsock, as __smc_release() does, so a
> concurrent dump cannot observe the release; the second unhash in
> sk_common_release() is a no-op.
>
> Fixes: d25a92ccae6b ("net/smc: Introduce IPPROTO_SMC")
> Reported-by: Abaci <[email protected]>
> Assisted-by: abaci:qwen3.8-max
> Signed-off-by: Yifei Chu <[email protected]>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/[email protected]?part=1