All of lore.kernel.org
 help / color / mirror / Atom feed
From: Simon Horman <horms@kernel.org>
To: Wentao Liang <vulab@iscas.ac.cn>
Cc: andrew+netdev@lunn.ch, ayush.sawal@chelsio.com,
	davem@davemloft.net, edumazet@google.com, kuba@kernel.org,
	linux-kernel@vger.kernel.org, netdev@vger.kernel.org,
	pabeni@redhat.com, rohitm@chelsio.com, stable@vger.kernel.org,
	Sabrina Dubroca <sd@queasysnail.net>
Subject: Re: [PATCH] chtls: Fix skb reference leak in chtls_send_reset()
Date: Sat, 19 Sep 2026 09:04:28 +0100	[thread overview]
Message-ID: <20260919080428.GX51261@horms.kernel.org> (raw)
In-Reply-To: <20260917105846.2147976-1-vulab@iscas.ac.cn>

+ Sabrina

On Thu, Sep 17, 2026 at 10:58:46AM +0000, Wentao Liang wrote:
> chtls_send_reset() is given a skb holding one reference, to be sent as
> CPL_ABORT_REQ. It consumes that reference on every path except the
> TCP_SYN_RECV one: there it sends a TCB field reply built from a freshly
> allocated skb and never releases the passed-in one.
> 
> This leaks the reference taken by reset_listen_child(), which resets
> half-open children in TCP_SYN_RECV found on the SYN queue.
> 
> Release the skb on the TCP_SYN_RECV path as well.
> 
> Fixes: 8ad2a970d201 ("cxgb4/chtls: Fix tid stuck due to wrong update of qid")
> Cc: stable@vger.kernel.org
> Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
> ---
>  drivers/net/ethernet/chelsio/inline_crypto/chtls/chtls_cm.c | 6 ++++--
>  1 file changed, 4 insertions(+), 2 deletions(-)
> 
> diff --git a/drivers/net/ethernet/chelsio/inline_crypto/chtls/chtls_cm.c b/drivers/net/ethernet/chelsio/inline_crypto/chtls/chtls_cm.c
> index 0e3e5cf52c2c..a363f20452fa 100644
> --- a/drivers/net/ethernet/chelsio/inline_crypto/chtls/chtls_cm.c
> +++ b/drivers/net/ethernet/chelsio/inline_crypto/chtls/chtls_cm.c
> @@ -265,12 +265,14 @@ static void chtls_send_reset(struct sock *sk, int mode, struct sk_buff *skb)
>  	chtls_purge_write_queue(sk);
>  
>  	csk_set_flag(csk, CSK_ABORT_SHUTDOWN);
> -	if (sk->sk_state != TCP_SYN_RECV)
> +	if (sk->sk_state != TCP_SYN_RECV) {
>  		chtls_send_abort(sk, mode, skb);
> -	else
> +	} else {
>  		chtls_set_tcb_field_rpl_skb(sk, TCB_T_FLAGS_W,
>  					    TCB_T_FLAGS_V(TCB_T_FLAGS_M), 0,
>  					    TCB_FIELD_COOKIE_TFLAG, 1);
> +		kfree_skb(skb);
> +	}
>  
>  	return;
>  out:

This code change looks reasonable to me.
But the driver was removed in v7.2 by
cdae65fc43f2 ("tls: remove tls_toe and the related driver")
And, as a result it didn't run through our CI.

So while I think it could go to stable
It probably needs more eyes on it.

As an aside, I notice that this driver still appears
in MAINTAINERS in net-next. I will send a patch to remove it.



  reply	other threads:[~2026-09-19  8:04 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-17 10:58 [PATCH] chtls: Fix skb reference leak in chtls_send_reset() Wentao Liang
2026-09-19  8:04 ` Simon Horman [this message]
2026-09-20 16:25   ` Sabrina Dubroca
2026-09-21 12:13     ` Simon Horman

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260919080428.GX51261@horms.kernel.org \
    --to=horms@kernel.org \
    --cc=andrew+netdev@lunn.ch \
    --cc=ayush.sawal@chelsio.com \
    --cc=davem@davemloft.net \
    --cc=edumazet@google.com \
    --cc=kuba@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    --cc=rohitm@chelsio.com \
    --cc=sd@queasysnail.net \
    --cc=stable@vger.kernel.org \
    --cc=vulab@iscas.ac.cn \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.