From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 10135399351; Sat, 12 Sep 2026 20:01:31 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789243292; cv=none; b=O4Ulo36Llb5suq+pSfeOpIHYxBB+WAj64iaCUNc99ihx8+4+RUuzes7JbLWWbDJSqoPyhFReC7YhgfoXBwF1PMUhhL19lUdJi3T9eER7e1x5adGmR7wctXMykA0UYyHBcgl5RZwKdySM6WLNRkiD0ngPjzpIK+BPCTKt6TSNrT4= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789243292; c=relaxed/simple; bh=cYaULsHyWszBgCgGOsxasSrhDWaEyUX7TZ2coBhAcQA=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=ueviSupuK/z3YhjFfnPQpjpcDUNAv9oeBpZqmV9Pzhvb0SFaQxex86aQocxNH/ubd8BwXJYN097N7D0GMMCd2+NUMaqKAdTIZvDnNubYsGaGaDhvPVHhl752DNUqztxci3Taa5eVMCuCYSh39vsOPkbgrV5/oTa3vsieZ0z0z5U= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=PlSNIdpv; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="PlSNIdpv" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 612371F000FF; Sat, 12 Sep 2026 20:01:30 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789243290; bh=vNZKrBiN3dLbq2S4/K3TXzJoLKgMICkIGUSIS+lToys=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=PlSNIdpvor6pNyx/O8AbAjl/LeQhoL3SLrsbDAsZs6LE3CepNqYE3DGZpbCZDeGL9 GikI4IatQYwmt1G/0Umd2YyFKA0f9sAJ5CNC1y97PHp46HFh/6J0yCDRrWA6chCyBh GKq27kf07D+hbMgesPU4EkEcMyIf7saND8WxqRsU= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Yuan Chen , Andrii Nakryiko , Sasha Levin Subject: [PATCH 5.10 705/798] bpftool: Fix double close in map dump Date: Sat, 12 Sep 2026 09:05:33 +0200 Message-ID: <20260912065533.248273139@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260912065516.948645775@linuxfoundation.org> References: <20260912065516.948645775@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 5.10-stable review patch. If anyone has any objections, please let me know. ------------------ From: Yuan Chen [ Upstream commit 259d60f5bfa41056fe01cbf2ba3f6f0331865a16 ] map_dump() closes the map fd in its error path, and do_dump() then closes the same fd again after a successful dump. Closing an already closed fd leaves errno set to EBADF, which poisons later errno checks such as the batch file read check in do_batch(). Let do_dump() own the fd and remove the close from map_dump(). The same double-close pattern exists in do_show_subset(): both show_map_close_json() and show_map_close_plain() already close the fd, so drop the extra close() there as well. Also propagate the error when bpf_map_get_info_by_fd() fails on a subsequent map in do_dump(): set err = -1 before breaking out of the loop, so a later failure is not silently hidden after an earlier iteration succeeded. Fixes: 99f9863a0c45f ("bpftool: Match maps by name") Signed-off-by: Yuan Chen Signed-off-by: Andrii Nakryiko Link: https://lore.kernel.org/bpf/20260810142224.2907373-2-chenyuan_fl@163.com Signed-off-by: Sasha Levin --- tools/bpf/bpftool/map.c | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) diff --git a/tools/bpf/bpftool/map.c b/tools/bpf/bpftool/map.c index ce6faf1b90e83..6346d43b6a893 100644 --- a/tools/bpf/bpftool/map.c +++ b/tools/bpf/bpftool/map.c @@ -674,8 +674,6 @@ static int do_show_subset(int argc, char **argv) show_map_close_json(fds[i], &info); else show_map_close_plain(fds[i], &info); - - close(fds[i]); } if (json_output && nb_fds > 1) jsonw_end_array(json_wtr); /* root array */ @@ -892,7 +890,6 @@ map_dump(int fd, struct bpf_map_info *info, json_writer_t *wtr, exit_free: free(key); free(value); - close(fd); free_map_kv_btf(btf); return err; @@ -941,6 +938,7 @@ static int do_dump(int argc, char **argv) for (i = 0; i < nb_fds; i++) { if (bpf_obj_get_info_by_fd(fds[i], &info, &len)) { p_err("can't get map info: %s", strerror(errno)); + err = -1; break; } err = map_dump(fds[i], &info, wtr, nb_fds > 1); -- 2.53.0