android_kernel_motorola_sm6375/include
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Jakub Sitnicki f4e72872b3
UPSTREAM: net, sk_msg: Clear sk_user_data pointer on clone if tagged
sk_user_data can hold a pointer to an object that is not intended to be
shared between the parent socket and the child that gets a pointer copy on
clone. This is the case when sk_user_data points at reference-counted
object, like struct sk_psock.

One way to resolve it is to tag the pointer with a no-copy flag by
repurposing its lowest bit. Based on the bit-flag value we clear the child
sk_user_data pointer after cloning the parent socket.

The no-copy flag is stored in the pointer itself as opposed to externally,
say in socket flags, to guarantee that the pointer and the flag are copied
from parent to child socket in an atomic fashion. Parent socket state is
subject to change while copying, we don't hold any locks at that time.

This approach relies on an assumption that sk_user_data holds a pointer to
an object aligned at least 2 bytes. A manual audit of existing users of
rcu_dereference_sk_user_data helper confirms our assumption.

Also, an RCU-protected sk_user_data is not likely to hold a pointer to a
char value or a pathological case of "struct { char c; }". To be safe, warn
when the flag-bit is set when setting sk_user_data to catch any future
misuses.

It is worth considering why clearing sk_user_data unconditionally is not an
option. There exist users, DRBD, NVMe, and Xen drivers being among them,
that rely on the pointer being copied when cloning the listening socket.

Potentially we could distinguish these users by checking if the listening
socket has been created in kernel-space via sock_create_kern, and hence has
sk_kern_sock flag set. However, this is not the case for NVMe and Xen
drivers, which create sockets without marking them as belonging to the
kernel.

Change-Id: I9b5d753faa1e1c3e105cb9071b22080831cbf061
Signed-off-by: Jakub Sitnicki <jakub@cloudflare.com>
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Acked-by: John Fastabend <john.fastabend@gmail.com>
Acked-by: Martin KaFai Lau <kafai@fb.com>
Link: https://lore.kernel.org/bpf/20200218171023.844439-3-jakub@cloudflare.com
2026-01-14 18:12:02 -08:00
..
acpi ACPICA: Avoid sequence overread in call to strncmp() 2025-06-27 11:02:52 +01:00
asm-generic UPSTREAM: mm/tlb: Provide default nmi_uaccess_okay() 2025-12-23 13:35:38 -08:00
clocksource
crypto UPSTREAM: crypto: poly1305 - fix poly1305_core_setkey() declaration 2025-09-24 12:16:39 +02:00
drm This is the 5.4.296 stable release 2025-07-18 10:57:54 +00:00
dt-bindings
keys
kvm
linux UPSTREAM: bpf: Add BPF_CGROUP_INET_SOCK_RELEASE hook 2026-01-14 18:12:01 -08:00
math-emu
media
misc
net UPSTREAM: net, sk_msg: Clear sk_user_data pointer on clone if tagged 2026-01-14 18:12:02 -08:00
pcmcia
ras
rdma This is the 5.4.296 stable release 2025-07-18 10:57:54 +00:00
scsi This is the 5.4.301 stable release 2025-10-30 07:52:10 +00:00
soc
sound Merge tag 'ASB-2025-08-05_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina 2025-09-01 13:17:46 +03:00
target
trace UPSTREAM: cgroup: use cgrp->kn->id as the cgroup ID 2025-12-23 13:36:09 -08:00
uapi UPSTREAM: bpf: Add BPF_CGROUP_INET_SOCK_RELEASE hook 2026-01-14 18:12:01 -08:00
vdso
video
xen
OWNERS