Linux kernel mirror (for testing) git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
kernel os linux

net/handshake: Unpin sock->file if a handshake is cancelled

If user space never calls DONE, sock->file's reference count remains
elevated. Enable sock->file to be freed eventually in this case.

Reported-by: Jakub Kacinski <kuba@kernel.org>
Fixes: 3b3009ea8abb ("net/handshake: Create a NETLINK service for handling handshake requests")
Signed-off-by: Chuck Lever <chuck.lever@oracle.com>
Signed-off-by: Jakub Kicinski <kuba@kernel.org>

authored by

Chuck Lever and committed by
Jakub Kicinski
1ce77c99 fc490880

+5
+1
net/handshake/handshake.h
··· 31 31 struct list_head hr_list; 32 32 struct rhash_head hr_rhash; 33 33 unsigned long hr_flags; 34 + struct file *hr_file; 34 35 const struct handshake_proto *hr_proto; 35 36 struct sock *hr_sk; 36 37 void (*hr_odestruct)(struct sock *sk);
+4
net/handshake/request.c
··· 239 239 } 240 240 req->hr_odestruct = req->hr_sk->sk_destruct; 241 241 req->hr_sk->sk_destruct = handshake_sk_destruct; 242 + req->hr_file = sock->file; 242 243 243 244 ret = -EOPNOTSUPP; 244 245 net = sock_net(req->hr_sk); ··· 334 333 trace_handshake_cancel_busy(net, req, sk); 335 334 return false; 336 335 } 336 + 337 + /* Request accepted and waiting for DONE */ 338 + fput(req->hr_file); 337 339 338 340 out_true: 339 341 trace_handshake_cancel(net, req, sk);