| From 2c4e7a775b884664ca308ec90ac76c2c0a4b8537 Mon Sep 17 00:00:00 2001 |
| From: Sasha Levin <sashal@kernel.org> |
| Date: Thu, 14 Apr 2022 15:51:03 +0800 |
| Subject: net/smc: Fix sock leak when release after smc_shutdown() |
| |
| From: Tony Lu <tonylu@linux.alibaba.com> |
| |
| [ Upstream commit 1a74e99323746353bba11562a2f2d0aa8102f402 ] |
| |
| Since commit e5d5aadcf3cd ("net/smc: fix sk_refcnt underflow on linkdown |
| and fallback"), for a fallback connection, __smc_release() does not call |
| sock_put() if its state is already SMC_CLOSED. |
| |
| When calling smc_shutdown() after falling back, its state is set to |
| SMC_CLOSED but does not call sock_put(), so this patch calls it. |
| |
| Reported-and-tested-by: syzbot+6e29a053eb165bd50de5@syzkaller.appspotmail.com |
| Fixes: e5d5aadcf3cd ("net/smc: fix sk_refcnt underflow on linkdown and fallback") |
| Signed-off-by: Tony Lu <tonylu@linux.alibaba.com> |
| Acked-by: Karsten Graul <kgraul@linux.ibm.com> |
| Signed-off-by: David S. Miller <davem@davemloft.net> |
| Signed-off-by: Sasha Levin <sashal@kernel.org> |
| --- |
| net/smc/af_smc.c | 4 +++- |
| 1 file changed, 3 insertions(+), 1 deletion(-) |
| |
| diff --git a/net/smc/af_smc.c b/net/smc/af_smc.c |
| index 06684ac346ab..5221092cc66d 100644 |
| --- a/net/smc/af_smc.c |
| +++ b/net/smc/af_smc.c |
| @@ -1698,8 +1698,10 @@ static int smc_shutdown(struct socket *sock, int how) |
| if (smc->use_fallback) { |
| rc = kernel_sock_shutdown(smc->clcsock, how); |
| sk->sk_shutdown = smc->clcsock->sk->sk_shutdown; |
| - if (sk->sk_shutdown == SHUTDOWN_MASK) |
| + if (sk->sk_shutdown == SHUTDOWN_MASK) { |
| sk->sk_state = SMC_CLOSED; |
| + sock_put(sk); |
| + } |
| goto out; |
| } |
| switch (how) { |
| -- |
| 2.35.1 |
| |