From: sashiko-bot@kernel.org
To: "Bobby Eshleman" <bobbyeshleman@gmail.com>
Cc: "Michael S. Tsirkin" <mst@redhat.com>,
kvm@vger.kernel.org, "Eugenio Perez" <eperezma@redhat.com>,
virtualization@lists.linux.dev
Subject: Re: [PATCH net-next v2 4/6] vsock/virtio: support guest device network namespace
Date: Wed, 23 Sep 2026 01:18:42 +0000 [thread overview]
Message-ID: <20260923011842.91A501F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260921-vsock-guest-ns-v2-4-693bd78fde9e@meta.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] vsock: unprotected socket state modification in vsock_g2h_reset_unreachable()
--
commit 22f9613466fe3520fb04ad3d32779638f9afe30e
Author: Bobby Eshleman <bobbyeshleman@meta.com>
vsock: add a netlink command to assign the g2h device to a netns
This commit introduces the VSOCK_CMD_DEV_NETNS_SET netlink command to move
the guest-to-host vsock device to a different network namespace. It resets
established connections that are no longer able to reach the device from
their respective namespaces. The commit also updates CID discovery and
socket creation paths to honour the new namespace assignments.
Link: https://lore.kernel.org/all/20200427142518.uwssa6dtasrp3bfc@steredhat/
> diff --git a/net/vmw_vsock/af_vsock.c b/net/vmw_vsock/af_vsock.c
> index 95a435aef512b..9938dd5010192 100644
> --- a/net/vmw_vsock/af_vsock.c
> +++ b/net/vmw_vsock/af_vsock.c
[ ... ]
> @@ -742,6 +812,173 @@ bool vsock_find_cid(unsigned int cid)
[ ... ]
> +/* Reset every connected socket of @t that can no longer reach the g2h device,
> + * and let the transport tell each peer.
> + */
> +static void vsock_g2h_reset_unreachable(const struct vsock_transport *t)
> +{
> + struct vsock_sock *vsk, *tmp;
> + LIST_HEAD(reset_list);
> + struct sock *sk;
> + int i;
> +
> + /* The calling context must hold vsock_register_mutex, which serializes
> + * concurrent netns assignments' use of vsk->pending_reset.
> + */
> + lockdep_assert_held(&vsock_register_mutex);
> +
> + spin_lock_bh(&vsock_table_lock);
> +
> + for (i = 0; i < ARRAY_SIZE(vsock_connected_table); i++) {
> + list_for_each_entry(vsk, &vsock_connected_table[i],
> + connected_table) {
> + sk = sk_vsock(vsk);
> +
> + if (vsk->transport != t ||
> + sk->sk_state == TCP_CLOSE ||
> + vsock_g2h_reachable_sk(vsk))
> + continue;
> +
> + sk->sk_state = TCP_CLOSE;
> + sk->sk_err = ECONNRESET;
> + sk_error_report(sk);
[Severity: High]
Does this code modify the socket state locklessly?
sk->sk_state and sk->sk_err are modified here while holding only the
vsock_table_lock spinlock, without acquiring the socket lock (lock_sock).
Core socket operations, such as vsock_connectible_sendmsg(), rely on
lock_sock() to protect state transitions and evaluate sk->sk_state to
determine if data can be enqueued. Modifying the state here without the socket
lock introduces a race condition. For example, a thread holding lock_sock()
might read an established state and proceed to enqueue data, while this
function concurrently sets the state to TCP_CLOSE.
Should the state modification be deferred to the second loop where
lock_sock() can be acquired?
> +
> + sock_hold(sk);
> + list_add_tail(&vsk->pending_reset, &reset_list);
> + }
> + }
> +
> + spin_unlock_bh(&vsock_table_lock);
> +
> + /* Reset outside of spinlock because the transport may sleep
> + * (e.g., GFP_KERNEL alloc).
> + */
> + list_for_each_entry_safe(vsk, tmp, &reset_list, pending_reset) {
> + list_del_init(&vsk->pending_reset);
> + t->reset(vsk, NULL);
> + sock_put(sk_vsock(vsk));
> + }
> +}
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260921-vsock-guest-ns-v2-0-693bd78fde9e@meta.com?part=4
next prev parent reply other threads:[~2026-09-23 1:18 UTC|newest]
Thread overview: 22+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-22 1:18 [PATCH net-next v2 0/6] vsock: assign the guest vsock device to a network namespace Bobby Eshleman
2026-09-22 1:18 ` [PATCH net-next v2 1/6] vsock: constify the transport in vsock_for_each_connected_socket() Bobby Eshleman
2026-09-23 1:18 ` sashiko-bot
2026-09-22 1:18 ` [PATCH net-next v2 2/6] vsock: rename the vsock pernet operations Bobby Eshleman
2026-09-23 1:18 ` sashiko-bot
2026-09-22 1:18 ` [PATCH net-next v2 3/6] vsock: add a netlink command to assign the g2h device to a netns Bobby Eshleman
2026-09-23 1:18 ` sashiko-bot
2026-09-23 19:21 ` netdev-bot+sashiko
2026-09-24 22:40 ` Bobby Eshleman
2026-09-22 1:18 ` [PATCH net-next v2 4/6] vsock/virtio: support guest device network namespace Bobby Eshleman
2026-09-23 1:18 ` sashiko-bot [this message]
2026-09-23 19:21 ` netdev-bot+sashiko
2026-09-24 1:16 ` Bobby Eshleman
2026-09-22 1:18 ` [PATCH net-next v2 5/6] selftests/vsock: test the guest vsock " Bobby Eshleman
2026-09-23 1:18 ` sashiko-bot
2026-09-23 19:21 ` netdev-bot+sashiko
2026-09-24 0:42 ` Bobby Eshleman
2026-09-22 1:18 ` [PATCH net-next v2 6/6] selftests/vsock: test the netns assign privilege checks Bobby Eshleman
2026-09-23 1:18 ` sashiko-bot
2026-09-23 19:21 ` netdev-bot+sashiko
2026-09-24 0:24 ` Bobby Eshleman
2026-09-24 0:55 ` Bobby Eshleman
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260923011842.91A501F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=bobbyeshleman@gmail.com \
--cc=eperezma@redhat.com \
--cc=kvm@vger.kernel.org \
--cc=mst@redhat.com \
--cc=sashiko-reviews@lists.linux.dev \
--cc=virtualization@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox