From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pf1-f178.google.com (mail-pf1-f178.google.com [209.85.210.178]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id CB32322A80D for ; Wed, 26 Aug 2026 00:39:45 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.178 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787704787; cv=none; b=qDTiCIFeYWKPUKyd8QdDuLfLwZKtAQKioAJBM9BACL37gduThQkmrxGIdaLb0K+PXoRxdiBD8zMYWNQF2dQu8ybIU5hNyTzugqd4Cc550bM3s0hJ/XBNzQXFpiu+NnkhuEN8nxk5gAK8HPd+W+aIHWfx2iq4n1ZEB2mqJpKkJOg= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787704787; c=relaxed/simple; bh=kHJYeCK03N4sVT6BcZHnRJF/EyIgOKmsMbTVuSX3Q8E=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=Huxy4GXWdRy6uMjLBySzBxUSTlodoxTonkrxdEnAfOf+Qa6WQffp0+QHUzRY1qse63eIi4LKV91mJOyvy5y1tOpEzq/LZqt50F/MJwBl2TpSQL6D1DtuTyl2xTiqe9D/wPri0IdER6aB7aWQ6W0DQGzInyeEN9q8vOCqsC/4mNo= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=PAg6+SaJ; arc=none smtp.client-ip=209.85.210.178 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="PAg6+SaJ" Received: by mail-pf1-f178.google.com with SMTP id d2e1a72fcca58-84830c774a0so573837b3a.1 for ; Tue, 25 Aug 2026 17:39:45 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787704785; x=1788309585; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=oi+0Ngf9vOWuRTniUDFfPIIsu68mB10Me8n+jj7RJuY=; b=PAg6+SaJ4Liidwc7SmjxZp3Kf8OjYFAbuBavHFf0V7Sgt5OJHJuiphq7MXdjgmx2dA mvGbf85RRMdmrld1DgR9Ylpauu5KqWOb/59n4I6bCIc03iiabyRyUojuQAUb04Y+C03y CQjnr2I5qyrJbuZK93BAQbsfJ8MxQtJ9NOsHDPyAhr6UGb+g89fNIaKjDiKggpU35pxW KxBNKVY2w6eJo7C3lxKcMqCBmTElg8ejyUKgfD9TeGoB3h1wW891JiNVOX6/nIuH3ypN BZOicR21kx1GrCWi1Q1FirIPbcwtWZkRUvI8ktZ4CM6ZcMWS0VWd8NAMHSEWi7hvOrer sNmA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787704785; x=1788309585; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=oi+0Ngf9vOWuRTniUDFfPIIsu68mB10Me8n+jj7RJuY=; b=FmN0XPPoAl6hMcUrD/h8c2aMkAzjRdNUV812vjQ4x+arAzaPu9ppubuqqDtf39UL4q fB3ezZ9+6k7KcBETd8TkHZ7Kzfu8Mhknucdv0FJx3eff+xxot8ZWXJRBVk00OoFX3z49 rgJ0INCwDflgrdKk5Dyb4QxlRMKVn1AFFW78ADIFdZ67B6e/aETWt3eN8owUTBt5mdRY AgUZ+A1mLdq3unx6tnwBuzumyDrn23Ctgfqle2cpvL3okyMOTSVhO6jCuBZRWnaoUBj0 7LZQqLEbBbmVEdqSqYkDgUwPSsZGNmeSLd48LT92jD4zTW06SrlQRfy1T0z5Wc4CXDCL CVNg== X-Gm-Message-State: AFuF++kW1sQKRXTwNZN8WBgD6GoL9wD8uPw/sUsqCY5Xfj7aoWZZLDBd /93UafmCtQlRTmTD6wRxja82Iaj6iYTnIEBl9IxMYkwQpEyQdorxPHem2s8aMsqE X-Gm-Gg: AR+sD12YYK2LMzTqwyj30jEwhVCcBGDw2gTDnbKT5+EXNVWWBot3CyBaHbxGmKmt/sG /VZRcEm8PoG6FzaEVO8DbBgS9o0xQO60xk8TxQVrFi3o1n+iLPHLiOx6T07TYTsquVSZOotOzCL fLoWi3NbQ1xY818b7B4uOqDSityIA6DYiE2TQOEyPH26iY+kV8CAPMkq95poOzBizMY6i7e31um 4Acm3WSIhgkq4wnjvFfe/mj70X8JMYqkaHtWf+f7I0JH1/DeXwILZh3X+3Wirt4fBwE77pPnyRc cl6ApS+A082hP06hR5fHPDBOfzvLarZHDjzt53GS7dN6InR5r0PZ0Eaj8FmirxZ1gRiK7yLDKzx Spi226numgpvY8VoGGbF9kBN881rCbj8kSYQeK/mbiO2b24/4iw8phQRalERZOp84KWoJlCJDDY fsMmdFL6xiYhOgcd8D1sRJpnyXLdNMGi4t25v/TPh/dZvKAOUQpbaVmEPt/I4VD3wZYY3hJJ5J X-Received: by 2002:a05:6a00:6c83:b0:845:e7ee:eae7 with SMTP id d2e1a72fcca58-853720ab337mr5049138b3a.5.1787704784879; Tue, 25 Aug 2026 17:39:44 -0700 (PDT) Received: from ancienth-X870E-Nova-WiFi ([125.186.72.2]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-8535cdc038dsm339377b3a.38.2026.08.25.17.39.39 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 25 Aug 2026 17:39:44 -0700 (PDT) From: Daehyeon Ko <4ncienth@gmail.com> To: netdev@vger.kernel.org Cc: sgarzare@redhat.com, stefanha@redhat.com, bobbyeshleman@gmail.com, davem@davemloft.net, edumazet@google.com, kuba@kernel.org, pabeni@redhat.com, horms@kernel.org, mst@redhat.com, jasowangio@gmail.com, xuanzhuo@linux.alibaba.com, eperezma@redhat.com, bryan-bt.tan@broadcom.com, vishnu.dasa@broadcom.com, bcm-kernel-feedback-list@broadcom.com, virtualization@lists.linux.dev, kvm@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH net v4 0/2] vsock: validate packet sources after bound lookup fallback Date: Wed, 26 Aug 2026 09:39:26 +0900 Message-ID: <20260826003929.966160-1-4ncienth@gmail.com> X-Mailer: git-send-email 2.54.0 Precedence: bulk X-Mailing-List: netdev@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Both virtio and VMCI look up connected sockets by the full tuple before falling back to a destination-only bound lookup. The fallback can select a non-listening socket without validating the packet source. V2 covered only the virtio path. Following Stefano's review, this series moves the source and transport validation into a documented AF_VSOCK helper and uses it for both virtio and VMCI. The VMCI patch checks both its bottom-half and deferred workqueue receive paths. V4 preserves VMCI's existing RST behavior when source validation fails. The reset is addressed from the received packet so that a bound but non-listening or concurrently closed socket still notifies the sender, without directing the reset to a connected socket's stored peer. The v3 regression was reproduced in three x86_64 KASAN boots: a REQUEST to a bound but non-listening socket returned VMCI_ERROR_NO_ACCESS but no RST arrived within one second. With v4, the sending context received the expected RST in all three boots. The original VMCI source-validation oracle also passed in three v4 boots: a matched RST reset the pending socket while a mismatched-context RST left it pending. No KASAN report occurred. Patch 1 is unchanged from v3 (identical stable patch-id) and carries Bobby's Reviewed-by for that revision. Its v3 validation covered the cross-UID injection oracle, local CID aliases, selected VSOCK selftests, and W=1 changed-object builds under allmodconfig and allyesconfig. The current-tree guest-CID vhost probe could not be rerun because the test user lacks access to /dev/vhost-vsock. --- Changes in v4: - Preserve RST replies when VMCI source validation rejects a packet. - Address those replies from the received packet rather than the socket's stored peer. - Add a bound-but-not-listening VMCI regression oracle. - Rebase to the current net tree. Changes in v3: - Move transport and source validation into vsock_check_source(). - Trust the internally generated source CID for the local transport. - Add VMCI validation in the bottom-half and workqueue receive paths. - Send the related virtio and VMCI fixes in one series. - Do not carry Bobby's v2 Reviewed-by because the helper and loopback logic changed; renewed review is requested. v3: https://lore.kernel.org/r/20260823175858.351431-1-4ncienth@gmail.com v2: https://lore.kernel.org/r/20260820001517.2148196-1-4ncienth@gmail.com v1: https://lore.kernel.org/r/20260813121236.2328599-1-4ncienth@gmail.com Daehyeon Ko (2): vsock/virtio: validate packet source for connected sockets vsock/vmci: validate packet source for connected sockets include/net/af_vsock.h | 3 +++ net/vmw_vsock/af_vsock.c | 32 +++++++++++++++++++++++ net/vmw_vsock/virtio_transport_common.c | 3 ++- net/vmw_vsock/vmci_transport.c | 34 ++++++++++++++++++++----- 4 files changed, 65 insertions(+), 7 deletions(-) base-commit: dc4b95b8fee95113587e93ca116356032d271371