All of lore.kernel.org
 help / color / mirror / Atom feed
From: Shuangpeng Bai <shuangpeng.kernel@gmail.com>
To: david@ixit.cz, oe-linux-nfc@lists.linux.dev
Cc: davem@davemloft.net, edumazet@google.com, kuba@kernel.org,
	pabeni@redhat.com, horms@kernel.org, netdev@vger.kernel.org,
	linux-kernel@vger.kernel.org,
	Shuangpeng Bai <shuangpeng.kernel@gmail.com>
Subject: [PATCH v2] nfc: llcp: Fix nfc_dev refcount leak in connect
Date: Mon, 20 Jul 2026 15:37:59 -0400	[thread overview]
Message-ID: <20260720193759.1773705-1-shuangpeng.kernel@gmail.com> (raw)

llcp_sock_connect() takes a reference to the NFC device and keeps it
while a connection is active. For a nonblocking connection,
sock_wait_state() returns -EINPROGRESS while the socket remains in
LLCP_CONNECTING.

If the socket is released before reaching LLCP_CONNECTED,
llcp_sock_destruct() does not drop the reference because it only handles
connected sockets.

Drop the device reference in llcp_sock_release() when unlinking a
connecting socket. At this point llcp_sock->dev is still valid, unlike
after a failed blocking connection has cleared it.

Fixes: b4011239a08e ("NFC: llcp: Fix non blocking sockets connections")
Link: https://lore.kernel.org/r/20260707183518.1888697-1-shuangpeng.kernel@gmail.com
Signed-off-by: Shuangpeng Bai <shuangpeng.kernel@gmail.com>
---
Changes in v2:
- Move the device put from llcp_sock_destruct() to llcp_sock_release()
  to avoid dereferencing a NULL llcp_sock->dev after a failed blocking
  connect.
- Add Fixes and Link tags.

 net/nfc/llcp_sock.c | 6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)

diff --git a/net/nfc/llcp_sock.c b/net/nfc/llcp_sock.c
index feab29fc62f4..0a3d87c2c9b3 100644
--- a/net/nfc/llcp_sock.c
+++ b/net/nfc/llcp_sock.c
@@ -633,10 +633,12 @@ static int llcp_sock_release(struct socket *sock)
 
 	if (sock->type == SOCK_RAW)
 		nfc_llcp_sock_unlink(&local->raw_sockets, sk);
-	else if (sk->sk_state == LLCP_CONNECTING)
+	else if (sk->sk_state == LLCP_CONNECTING) {
 		nfc_llcp_sock_unlink(&local->connecting_sockets, sk);
-	else
+		nfc_put_device(llcp_sock->dev);
+	} else {
 		nfc_llcp_sock_unlink(&local->sockets, sk);
+	}
 
 	if (llcp_sock->reserved_ssap < LLCP_SAP_MAX)
 		nfc_llcp_put_ssap(llcp_sock->local, llcp_sock->ssap);
-- 
2.43.0

                 reply	other threads:[~2026-07-20 19:38 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260720193759.1773705-1-shuangpeng.kernel@gmail.com \
    --to=shuangpeng.kernel@gmail.com \
    --cc=davem@davemloft.net \
    --cc=david@ixit.cz \
    --cc=edumazet@google.com \
    --cc=horms@kernel.org \
    --cc=kuba@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=oe-linux-nfc@lists.linux.dev \
    --cc=pabeni@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.