All of lore.kernel.org
 help / color / mirror / Atom feed
From: Kuniyuki Iwashima <kuniyu@google.com>
To: brian.scott.sampson@gmail.com
Cc: christian@heusel.eu, davem@davemloft.net,
	difrost.kernel@gmail.com,  dnaim@cachyos.org,
	edumazet@google.com, horms@kernel.org, kuba@kernel.org,
	 kuni1840@gmail.com, kuniyu@google.com,
	linux-kernel@vger.kernel.org,  mario.limonciello@amd.com,
	netdev@vger.kernel.org, pabeni@redhat.com,
	 regressions@lists.linux.dev
Subject: Re: [REGRESSION] af_unix: Introduce SO_PASSRIGHTS - break OpenGL
Date: Wed, 17 Sep 2025 01:33:33 +0000	[thread overview]
Message-ID: <20250917013352.722151-1-kuniyu@google.com> (raw)
In-Reply-To: <c36676c1640cefad7f8066a98be9b9e99d233bef.camel@gmail.com>

From: brian.scott.sampson@gmail.com
Date: Tue, 16 Sep 2025 17:16:40 -0500
> > Thanks for the report.
> > 
> > Could you test the diff below ?
> > 
> > look like some programs start listen()ing before setting
> > SO_PASSCRED or SO_PASSPIDFD and there's a small race window.
> > 
> > ---8<---
> > diff --git a/net/unix/af_unix.c b/net/unix/af_unix.c
> > index fd6b5e17f6c4..87439d7f965d 100644
> > --- a/net/unix/af_unix.c
> > +++ b/net/unix/af_unix.c
> > @@ -1971,7 +1971,8 @@ static void unix_maybe_add_creds(struct sk_buff
> > *skb, const struct sock *sk,
> >  	if (UNIXCB(skb).pid)
> >  		return;
> >  
> > -	if (unix_may_passcred(sk) || unix_may_passcred(other)) {
> > +	if (unix_may_passcred(sk) || unix_may_passcred(other) ||
> > +	    !other->sk_socket) {
> >  		UNIXCB(skb).pid = get_pid(task_tgid(current));
> >  		current_uid_gid(&UNIXCB(skb).uid, &UNIXCB(skb).gid);
> >  	}
> > ---8<---
> Just came across this when troubleshooting a resume from suspend issue
> where I'm get a black screen after suspend. Initially saw this with my
> distribution's(Linux 6.16.7-2-cachyos) kernel, and confirmed the issue
> in the latest version of the vanilla mainline kernel. Bisection is also
> pointing to commit 3f84d577b79d2fce8221244f2509734940609ca6.
> 
> This patch appears to be already applied in the mainline kernel, so
> this might be something different. I'm new to mailing lists, so wasn't
> sure if I should report this issue here or start a new email chain.

Could you test it with this diff and see if 2 or 3 splats are logged
in dmesg ?  and in that case, please share the stack traces.

I expect this won't trigger the black screen and you can check dmesg
after resume.

Thanks!

---8<---
diff --git a/include/net/sock.h b/include/net/sock.h
index fb13322a11fc..211084602e01 100644
--- a/include/net/sock.h
+++ b/include/net/sock.h
@@ -539,7 +539,9 @@ struct sock {
 				sk_scm_security : 1,
 				sk_scm_pidfd : 1,
 				sk_scm_rights : 1,
-				sk_scm_unused : 4;
+				sk_scm_embryo_cred: 1,
+				sk_scm_parent_cred: 1,
+				sk_scm_unused : 2;
 		};
 	};
 	u8			sk_clockid;
diff --git a/net/core/scm.c b/net/core/scm.c
index 072d5742440a..e603bf5400e0 100644
--- a/net/core/scm.c
+++ b/net/core/scm.c
@@ -510,7 +510,7 @@ static bool __scm_recv_common(struct sock *sk, struct msghdr *msg,
 		return false;
 	}
 
-	if (sk->sk_scm_credentials) {
+	if (sk->sk_scm_credentials || sk->sk_scm_parent_cred) {
 		struct user_namespace *current_ns = current_user_ns();
 		struct ucred ucreds = {
 			.pid = scm->creds.pid,
@@ -518,6 +518,11 @@ static bool __scm_recv_common(struct sock *sk, struct msghdr *msg,
 			.gid = from_kgid_munged(current_ns, scm->creds.gid),
 		};
 
+		WARN_ON_ONCE(!sk->sk_scm_credentials && sk->sk_scm_parent_cred &&
+			     sk->sk_scm_embryo_cred);
+		WARN_ON_ONCE(!sk->sk_scm_credentials && sk->sk_scm_parent_cred &&
+			     !sk->sk_scm_embryo_cred);
+
 		put_cmsg(msg, SOL_SOCKET, SCM_CREDENTIALS, sizeof(ucreds), &ucreds);
 	}
 
diff --git a/net/core/sock.c b/net/core/sock.c
index 158bddd23134..ff68b8f7c119 100644
--- a/net/core/sock.c
+++ b/net/core/sock.c
@@ -1545,6 +1545,9 @@ int sk_setsockopt(struct sock *sk, int level, int optname,
 		break;
 
 	case SO_PASSCRED:
+		WARN_ON_ONCE(sk_is_unix(sk) && sk->sk_state == TCP_LISTEN &&
+			     skb_queue_len_lockless(&sk->sk_receive_queue));
+
 		if (sk_may_scm_recv(sk))
 			sk->sk_scm_credentials = valbool;
 		else
diff --git a/net/unix/af_unix.c b/net/unix/af_unix.c
index 6d7c110814ff..c8ea44f6d1d7 100644
--- a/net/unix/af_unix.c
+++ b/net/unix/af_unix.c
@@ -1897,6 +1897,7 @@ static int unix_accept(struct socket *sock, struct socket *newsock,
 	unix_state_lock(tsk);
 	unix_update_edges(unix_sk(tsk));
 	newsock->state = SS_CONNECTED;
+	tsk->sk_scm_parent_cred = sk->sk_scm_credentials;
 	sock_graft(tsk, newsock);
 	unix_state_unlock(tsk);
 	return 0;
@@ -2037,7 +2038,7 @@ static void unix_skb_to_scm(struct sk_buff *skb, struct scm_cookie *scm)
  * Return: On success zero, on error a negative error code is returned.
  */
 static int unix_maybe_add_creds(struct sk_buff *skb, const struct sock *sk,
-				const struct sock *other)
+				struct sock *other)
 {
 	if (UNIXCB(skb).pid)
 		return 0;
@@ -2047,6 +2048,9 @@ static int unix_maybe_add_creds(struct sk_buff *skb, const struct sock *sk,
 		struct pid *pid;
 		int err;
 
+		if (!other->sk_socket)
+			other->sk_scm_embryo_cred = true;
+
 		pid = task_tgid(current);
 		err = pidfs_register_pid(pid);
 		if (unlikely(err))
---8<---

  reply	other threads:[~2025-09-17  1:33 UTC|newest]

Thread overview: 14+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-06-10 19:22 [REGRESSION] af_unix: Introduce SO_PASSRIGHTS - break OpenGL Jacek Łuczak
2025-06-11 11:46 ` Christian Heusel
2025-06-11 16:42   ` Kuniyuki Iwashima
2025-06-11 17:10     ` Christian Heusel
2025-06-11 19:24     ` André Almeida
2025-06-18  7:30     ` Matthew Schwartz
2025-09-16 22:16     ` brian.scott.sampson
2025-09-17  1:33       ` Kuniyuki Iwashima [this message]
2025-09-17 14:40         ` brian.scott.sampson
2025-09-17 18:42           ` Kuniyuki Iwashima
2025-09-17 20:25             ` brian.scott.sampson
2025-09-20  3:50               ` Kuniyuki Iwashima
2025-09-20 22:28                 ` brian.scott.sampson
2025-11-09 16:07                   ` brian.scott.sampson

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20250917013352.722151-1-kuniyu@google.com \
    --to=kuniyu@google.com \
    --cc=brian.scott.sampson@gmail.com \
    --cc=christian@heusel.eu \
    --cc=davem@davemloft.net \
    --cc=difrost.kernel@gmail.com \
    --cc=dnaim@cachyos.org \
    --cc=edumazet@google.com \
    --cc=horms@kernel.org \
    --cc=kuba@kernel.org \
    --cc=kuni1840@gmail.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=mario.limonciello@amd.com \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    --cc=regressions@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.