From: Ido Schimmel <idosch@nvidia.com>
To: Zhiling Zou <zhilinz@nebusec.ai>
Cc: netdev@vger.kernel.org, bpf@vger.kernel.org, dsahern@kernel.org,
davem@davemloft.net, edumazet@google.com, kuba@kernel.org,
pabeni@redhat.com, horms@kernel.org, ast@kernel.org,
kafai@fb.com, joe@wand.net.nz, vega@nebusec.ai
Subject: Re: [PATCH net v2 1/1] ip: orphan prefetched skbs before multicast forwarding
Date: Mon, 10 Aug 2026 18:23:27 +0300 [thread overview]
Message-ID: <20260810152327.GA2779332@shredder> (raw)
In-Reply-To: <f968f497251dedbd1263c322a7c4e3e1a727161d.1786023177.git.zhilinz@nebusec.ai>
On Thu, Aug 06, 2026 at 11:18:56PM +0800, Zhiling Zou wrote:
> IPv4 and IPv6 input preserve an skb->sk association installed by
> bpf_sk_assign() so that local delivery can use the selected socket under
> RCU. IPv6 can also get such an association from udp_v6_early_demux(),
> which runs in ip6_rcv_finish_core(), after ip6_rcv_core().
Last sentence is not accurate since it doesn't cover IPv4 which is also
fixed here. I suggest something like:
"Both address families can also prefetch a socket in UDP early demux. In
both paths (BPF and UDP early demux) a reference is not guaranteed to be
held on the socket."
>
> The reproduced UDPv6 packet has a multicast IP destination but a unicast
> destination MAC address. It is therefore classified as PACKET_HOST and
> passes the UDP early-demux check.
This is again specific to IPv6 although IPv4 suffers from the same
problem. I think we can drop this paragraph.
>
> When the multicast packet is not locally deliverable, IPv6 hands the
s/When the/When a/
> original skb to ip6_mr_input(). IPv4's ip_mr_input() similarly keeps the
> original skb when local delivery is not needed. Either path can put the
> skb on an unresolved multicast route queue or forward it after the
> receive-side RCU section ends.
>
> After the prefetched socket is destroyed, a later skb free invokes
> sock_pfree() and dereferences the stale skb->sk. Orphan the skb before
> each non-local multicast forwarding path. Local delivery retains the
> original skb; the existing skb_clone() calls provide multicast forwarding
> with a socket-free clone.
>
> Fixes: cf7fbe660f2d ("bpf: Add socket assign support")
> Fixes: 08842c43d016 ("udp: no longer touch sk->sk_refcnt in early demux")
> Cc: stable@vger.kernel.org
> Reported-by: Vega <vega@nebusec.ai>
> Signed-off-by: Zhiling Zou <zhilinz@nebusec.ai>
The rest looks fine to me.
Both sashikos mention other possible instances of the bug, but I believe
they require bpf_sk_assign(), unlike UDP early demux which is used here.
Assuming these issues are real and reproducible, they should be fixed in
a separate patchset.
prev parent reply other threads:[~2026-08-10 15:23 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-06 15:18 [PATCH net v2 1/1] ip: orphan prefetched skbs before multicast forwarding Zhiling Zou
2026-08-07 15:19 ` sashiko-bot
2026-08-10 15:23 ` Ido Schimmel [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260810152327.GA2779332@shredder \
--to=idosch@nvidia.com \
--cc=ast@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=davem@davemloft.net \
--cc=dsahern@kernel.org \
--cc=edumazet@google.com \
--cc=horms@kernel.org \
--cc=joe@wand.net.nz \
--cc=kafai@fb.com \
--cc=kuba@kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=vega@nebusec.ai \
--cc=zhilinz@nebusec.ai \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.