From: Breno Leitao <leitao@debian.org>
To: "David S. Miller" <davem@davemloft.net>,
Eric Dumazet <edumazet@google.com>,
Jakub Kicinski <kuba@kernel.org>,
Paolo Abeni <pabeni@redhat.com>, Simon Horman <horms@kernel.org>,
Kuniyuki Iwashima <kuniyu@google.com>,
Willem de Bruijn <willemb@google.com>,
David Ahern <dsahern@kernel.org>,
Ido Schimmel <idosch@nvidia.com>
Cc: netdev@vger.kernel.org, linux-kernel@vger.kernel.org,
david.laight.linux@gmail.com, Breno Leitao <leitao@debian.org>,
kernel-team@meta.com
Subject: [PATCH net-next 0/2] net: a sockopt_t quirk for the options that write past optlen
Date: Thu, 10 Sep 2026 02:47:10 -0700 [thread overview]
Message-ID: <20260910-getsockopt_phase6-v1-0-e681e102d5b8@debian.org> (raw)
This series continues the migration of our protocols to sockopt_t, as
described in [1].
There are some protocols that use optlen as the header size, and the real
buffer size comes from a field inside the header. This means a bug, given
that optlen should be the full buffer size, but there are indications [2]
that we have programs that use the bad behaviour above, and we want to
avoid breaking them (or, honestly, avoid being cursed by Linus).
That said, create a quirk helper that preserves the same behaviour, even
using sockopt_t. The way to do it is simple:
1) Only do it for userspace callers (ubuf), otherwise a bug here will
corrupt the kernel instead of a simple SIGSEGV.
2) Expand optval mid-air based on the header field.
IP_MSFILTER is the first user, and the smallest one: a single caller, no
compat variant, and a reply written front to back. MCAST_MSFILTER on ipv4
and ipv6 comes next, and TCP_AO_GET_KEYS has the same shape. Do this
quirk on IP_MSFILTER to make sure the dynamic is ok, so, we can expand
it later.
None of this is meant to change what userspace sees.
Link: https://lore.kernel.org/all/20260401-getsockopt-v2-0-611df6771aff@debian.org/ [1]
Link: https://lore.kernel.org/all/20260806-mcast_fix-v1-0-bed0a5518e57@debian.org/ [2]
Signed-off-by: Breno Leitao <leitao@debian.org>
---
Breno Leitao (2):
net: add sockopt_expand_out()
ipv4: igmp: convert ip_mc_msfget() to sockopt_t
include/linux/igmp.h | 3 ++-
include/linux/net.h | 25 +++++++++++++++++++++++++
net/ipv4/igmp.c | 23 ++++++++++++++---------
net/ipv4/ip_sockglue.c | 10 +++++++++-
net/socket.c | 4 ++--
5 files changed, 52 insertions(+), 13 deletions(-)
---
base-commit: 548b86839f7fb819a4d6c83b71c73ec378d24275
change-id: 20260909-getsockopt_phase6-c7c96a21b062
Best regards,
--
Breno Leitao <leitao@debian.org>
next reply other threads:[~2026-09-10 9:47 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-10 9:47 Breno Leitao [this message]
2026-09-10 9:47 ` [PATCH net-next 1/2] net: add sockopt_expand_out() Breno Leitao
2026-09-11 15:56 ` Stanislav Fomichev
2026-09-11 16:09 ` Breno Leitao
2026-09-11 18:10 ` David Laight
2026-09-11 21:17 ` Stanislav Fomichev
2026-09-12 1:19 ` netdev-bot+sashiko
2026-09-10 9:47 ` [PATCH net-next 2/2] ipv4: igmp: convert ip_mc_msfget() to sockopt_t Breno Leitao
2026-09-11 15:56 ` Stanislav Fomichev
2026-09-12 1:19 ` netdev-bot+sashiko
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260910-getsockopt_phase6-v1-0-e681e102d5b8@debian.org \
--to=leitao@debian.org \
--cc=davem@davemloft.net \
--cc=david.laight.linux@gmail.com \
--cc=dsahern@kernel.org \
--cc=edumazet@google.com \
--cc=horms@kernel.org \
--cc=idosch@nvidia.com \
--cc=kernel-team@meta.com \
--cc=kuba@kernel.org \
--cc=kuniyu@google.com \
--cc=linux-kernel@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=willemb@google.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.