From: Stefano Garzarella <sgarzare@redhat.com>
To: mawupeng <mawupeng1@huawei.com>
Cc: phind.uet@gmail.com, davem@davemloft.net, edumazet@google.com,
kuba@kernel.org, pabeni@redhat.com, horms@kernel.org,
acking@vmware.com, dtor@vmware.com, georgezhang@vmware.com,
syzbot+1b2c9c4a0f8708082678@syzkaller.appspotmail.com,
virtualization@lists.linux.dev, netdev@vger.kernel.org,
linux-kernel@vger.kernel.org
Subject: Re: [PATCH v2] vsock: use sock_error() to consume sk_err after a
Date: Wed, 29 Jul 2026 15:21:16 +0200 [thread overview]
Message-ID: <amn9-HWi5L8DlXy5@sgarzare-redhat> (raw)
In-Reply-To: <33c73960-a44c-44e4-bfba-c4ebe85b336c@huawei.com>
On Tue, Jul 28, 2026 at 11:14:31AM +0800, mawupeng wrote:
>
>
>On 周一 2026-7-27 15:13, phind.uet@gmail.com wrote:
>> From: Nguyen Dinh Phi <phind.uet@gmail.com>
>>
>> Syzbot report an issue which can be reproduced with these steps:
>> r0 = socket(AF_VSOCK, SOCK_STREAM, 0)
>> bind(r0, {VMADDR_CID_ANY, PORT})
>> connect(r0, {VMADDR_CID_LOCAL, PORT})
>> listen(r0, backlog)
>>
>> r1 = socket(AF_VSOCK, SOCK_STREAM, 0)
>> connect(r1, {VMADDR_CID_LOCAL, PORT})
>> connect(r0 -> self) -> -1, EPROTO
>>
>> listen(r0) -> 0
>> connect(r1 -> r0) -> 0
>> accept(r0) -> -1, EPROTO
>>
>> Basically, it creates a socket (r0) and triggers a self-connect after
>> binding it. This self-connect fails with EPROTO because it loops back to
>> r0 while the socket is still in the TCP_SYN_SENT state, causing it to be
>> incorrectly dispatched to the connecting-client path. The unexpected
>> packet type encountered there sets sk_err to EPROTO.
>>
>> After that, it invokes a listen() call on the same socket. This listen()
>> call succeeds because the kernel's listening path never inspects or
>> clears sk_err. Then, a new socket (r1) is created as a normal client and
>> connects to r0. However, vsock_accept() rejects this incoming connection
>> because the listener's sk_err still holds the EPROTO error from the
>> earlier failed self-connect.
>>
>> This rejection causes the child socket created for r1's connection to
>> never be freed on virtio or hyperv transports; only the VMCI transport
>> implements pending_work to revisit and clean up a rejected socket
>>
>> Fix the issue by using sock_error() to read the sk_err to prevent the
>> rejection branch from occurring in this scenario.
>>
>> sock_error() atomically reads and clears sk_err, ensuring the error is
>> consumed when vsock_connect() returns and cannot affect subsequent
>> operations on the same socket. This matches the established pattern
>> used by other protocol connect() implementations in the network
>> stack like __inet_stream_connect(), tipc_wait_for_connect()...
>>
>> Reported-by: syzbot+1b2c9c4a0f8708082678@syzkaller.appspotmail.com
>> Closes: https://syzkaller.appspot.com/bug?extid=1b2c9c4a0f8708082678
>> Fixes: d021c344051af ("VSOCK: Introduce VM Sockets")
>> Signed-off-by: Nguyen Dinh Phi <phind.uet@gmail.com>
>
>Thanks for your patch.
>
>Test-by: Wupeng Ma <mawupeng1@huawei.com>
Thanks for testing, just a note, the right tag should be Tested-by:
Anyway, @Phi can you bring this with the right tag to the v3 if the code
will not change?
Thanks,
Stefano
next prev parent reply other threads:[~2026-07-29 13:21 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-27 7:13 [PATCH v2] vsock: use sock_error() to consume sk_err after a phind.uet
2026-07-28 3:14 ` mawupeng
2026-07-29 13:21 ` Stefano Garzarella [this message]
2026-07-29 13:19 ` Stefano Garzarella
2026-07-30 8:25 ` Nguyen Dinh Phi [SG]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=amn9-HWi5L8DlXy5@sgarzare-redhat \
--to=sgarzare@redhat.com \
--cc=acking@vmware.com \
--cc=davem@davemloft.net \
--cc=dtor@vmware.com \
--cc=edumazet@google.com \
--cc=georgezhang@vmware.com \
--cc=horms@kernel.org \
--cc=kuba@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=mawupeng1@huawei.com \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=phind.uet@gmail.com \
--cc=syzbot+1b2c9c4a0f8708082678@syzkaller.appspotmail.com \
--cc=virtualization@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.