* [PATCH v1 net-next] tcp: Set unhashed_state in inet_twsk_hashdance_schedule().
@ 2026-09-17 19:15 Kuniyuki Iwashima
2026-09-17 19:26 ` Daniel Zahka
` (2 more replies)
0 siblings, 3 replies; 4+ messages in thread
From: Kuniyuki Iwashima @ 2026-09-17 19:15 UTC (permalink / raw)
To: David S. Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni,
Neal Cardwell
Cc: Simon Horman, Kuniyuki Iwashima, Kuniyuki Iwashima, netdev,
Daniel Zahka
inet_unhash() sets inet_csk(sk)->unhashed_state only when the
socket is hashed because tcp_set_state(sk, TCP_CLOSE) could be
called multiple times, e.g. tcp_abort() calls it directly and
tcp_done_with_error().
However, inet_twsk_hashdance_schedule() also unhashes a socket
when replacing it with twsk, allowing the socket to bypass
checks for inet_csk(sk)->unhashed_state.
Let's update inet_csk(sk)->unhashed_state there as well.
Fixes: 8cc3aef0cb19 ("tcp: Do not allow buggy transitions between ehash and lhash2.")
Reported-by: Daniel Zahka <daniel.zahka@gmail.com>
Closes: https://lore.kernel.org/netdev/DLHLRA8GVI5B.2Q1IRQG5BVJNZ@gmail.com/
Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
---
net/ipv4/inet_timewait_sock.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/net/ipv4/inet_timewait_sock.c b/net/ipv4/inet_timewait_sock.c
index d4c781a0667f..a1d86026aefb 100644
--- a/net/ipv4/inet_timewait_sock.c
+++ b/net/ipv4/inet_timewait_sock.c
@@ -105,10 +105,12 @@ void inet_twsk_hashdance_schedule(struct inet_timewait_sock *tw,
struct inet_hashinfo *hashinfo,
int timeo)
{
- const struct inet_sock *inet = inet_sk(sk);
- const struct inet_connection_sock *icsk = inet_csk(sk);
spinlock_t *lock = inet_ehash_lockp(hashinfo, sk->sk_hash);
+ struct inet_connection_sock *icsk = inet_csk(sk);
struct inet_bind_hashbucket *bhead, *bhead2;
+ const struct inet_sock *inet = inet_sk(sk);
+
+ icsk->unhashed_state = sk->sk_state;
/* Put TW into bind hash. Original socket stays there too.
* Note, that any socket with inet->num != 0 MUST be bound in
--
2.55.0.1082.g2b9226bbc0-goog
^ permalink raw reply related [flat|nested] 4+ messages in thread* Re: [PATCH v1 net-next] tcp: Set unhashed_state in inet_twsk_hashdance_schedule().
2026-09-17 19:15 [PATCH v1 net-next] tcp: Set unhashed_state in inet_twsk_hashdance_schedule() Kuniyuki Iwashima
@ 2026-09-17 19:26 ` Daniel Zahka
2026-09-18 8:50 ` Matthieu Baerts
2026-09-19 0:50 ` patchwork-bot+netdevbpf
2 siblings, 0 replies; 4+ messages in thread
From: Daniel Zahka @ 2026-09-17 19:26 UTC (permalink / raw)
To: Kuniyuki Iwashima, David S. Miller, Eric Dumazet, Jakub Kicinski,
Paolo Abeni, Neal Cardwell
Cc: Simon Horman, Kuniyuki Iwashima, netdev, Daniel Zahka
On Thu Sep 17, 2026 at 3:15 PM EDT, Kuniyuki Iwashima wrote:
> inet_unhash() sets inet_csk(sk)->unhashed_state only when the
> socket is hashed because tcp_set_state(sk, TCP_CLOSE) could be
> called multiple times, e.g. tcp_abort() calls it directly and
> tcp_done_with_error().
>
> However, inet_twsk_hashdance_schedule() also unhashes a socket
> when replacing it with twsk, allowing the socket to bypass
> checks for inet_csk(sk)->unhashed_state.
>
> Let's update inet_csk(sk)->unhashed_state there as well.
>
> Fixes: 8cc3aef0cb19 ("tcp: Do not allow buggy transitions between ehash and lhash2.")
> Reported-by: Daniel Zahka <daniel.zahka@gmail.com>
> Closes: https://lore.kernel.org/netdev/DLHLRA8GVI5B.2Q1IRQG5BVJNZ@gmail.com/
> Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
> ---
Reviewed-by: Daniel Zahka <daniel.zahka@gmail.com>
^ permalink raw reply [flat|nested] 4+ messages in thread* Re: [PATCH v1 net-next] tcp: Set unhashed_state in inet_twsk_hashdance_schedule().
2026-09-17 19:15 [PATCH v1 net-next] tcp: Set unhashed_state in inet_twsk_hashdance_schedule() Kuniyuki Iwashima
2026-09-17 19:26 ` Daniel Zahka
@ 2026-09-18 8:50 ` Matthieu Baerts
2026-09-19 0:50 ` patchwork-bot+netdevbpf
2 siblings, 0 replies; 4+ messages in thread
From: Matthieu Baerts @ 2026-09-18 8:50 UTC (permalink / raw)
To: Kuniyuki Iwashima, David S. Miller, Eric Dumazet, Jakub Kicinski,
Paolo Abeni, Neal Cardwell
Cc: Simon Horman, Kuniyuki Iwashima, netdev, Daniel Zahka
Hi Kuniyuki,
On 17/09/2026 21:15, Kuniyuki Iwashima wrote:
> inet_unhash() sets inet_csk(sk)->unhashed_state only when the
> socket is hashed because tcp_set_state(sk, TCP_CLOSE) could be
> called multiple times, e.g. tcp_abort() calls it directly and
> tcp_done_with_error().
>
> However, inet_twsk_hashdance_schedule() also unhashes a socket
> when replacing it with twsk, allowing the socket to bypass
> checks for inet_csk(sk)->unhashed_state.
>
> Let's update inet_csk(sk)->unhashed_state there as well.
Thank you for the fix!
Reviewed-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Cheers,
Matt
--
Sponsored by the NGI0 Core fund.
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH v1 net-next] tcp: Set unhashed_state in inet_twsk_hashdance_schedule().
2026-09-17 19:15 [PATCH v1 net-next] tcp: Set unhashed_state in inet_twsk_hashdance_schedule() Kuniyuki Iwashima
2026-09-17 19:26 ` Daniel Zahka
2026-09-18 8:50 ` Matthieu Baerts
@ 2026-09-19 0:50 ` patchwork-bot+netdevbpf
2 siblings, 0 replies; 4+ messages in thread
From: patchwork-bot+netdevbpf @ 2026-09-19 0:50 UTC (permalink / raw)
To: Kuniyuki Iwashima
Cc: davem, edumazet, kuba, pabeni, ncardwell, horms, kuni1840, netdev,
daniel.zahka
Hello:
This patch was applied to netdev/net-next.git (main)
by Jakub Kicinski <kuba@kernel.org>:
On Thu, 17 Sep 2026 19:15:52 +0000 you wrote:
> inet_unhash() sets inet_csk(sk)->unhashed_state only when the
> socket is hashed because tcp_set_state(sk, TCP_CLOSE) could be
> called multiple times, e.g. tcp_abort() calls it directly and
> tcp_done_with_error().
>
> However, inet_twsk_hashdance_schedule() also unhashes a socket
> when replacing it with twsk, allowing the socket to bypass
> checks for inet_csk(sk)->unhashed_state.
>
> [...]
Here is the summary with links:
- [v1,net-next] tcp: Set unhashed_state in inet_twsk_hashdance_schedule().
https://git.kernel.org/netdev/net-next/c/404381b4f105
You are awesome, thank you!
--
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-09-19 0:51 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-17 19:15 [PATCH v1 net-next] tcp: Set unhashed_state in inet_twsk_hashdance_schedule() Kuniyuki Iwashima
2026-09-17 19:26 ` Daniel Zahka
2026-09-18 8:50 ` Matthieu Baerts
2026-09-19 0:50 ` patchwork-bot+netdevbpf
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox