summaryrefslogtreecommitdiff
path: root/net/core
diff options
context:
space:
mode:
authorMichal Luczaj <mhal@rbox.co>2026-08-13 14:42:00 +0200
committerDaniel Borkmann <daniel@iogearbox.net>2026-08-17 10:22:19 +0200
commit34e0eb763becfee4487a7105e3204d9fc486be93 (patch)
tree5f39aef465cc51cc663a4163c4cb836f7ac0dcf1 /net/core
parent3c3d2c09ec4e11bf7f5419163643b3b02d3f5add (diff)
bpf, sockmap: Use sock_hold() instead of refcount_inc_not_zero() in lookup
psock's hold on the looked up socket isn't dropped until sk_psock_drop() -> queue_rcu_work() -> sk_psock_destroy() runs, which happens only after the entry is unlinked and an RCU grace period elapses. Since the lookup runs under RCU, a non-NULL result guarantees sk_refcnt >= 1: refcount_inc_not_zero() can never fail here. Use sock_hold() instead. Signed-off-by: Michal Luczaj <mhal@rbox.co> Signed-off-by: Daniel Borkmann <daniel@iogearbox.net> Reviewed-by: Emil Tsalapatis <emil@etsalapatis.com> Reviewed-by: Jakub Sitnicki <jakub@cloudflare.com> Link: https://lore.kernel.org/bpf/20260813-sockmap-lookup-get-ref-v1-2-31f5d55f44ac@rbox.co
Diffstat (limited to 'net/core')
-rw-r--r--net/core/sock_map.c8
1 files changed, 4 insertions, 4 deletions
diff --git a/net/core/sock_map.c b/net/core/sock_map.c
index 9efbd8ca7db8..ca49bc7f8687 100644
--- a/net/core/sock_map.c
+++ b/net/core/sock_map.c
@@ -392,8 +392,8 @@ static void *sock_map_lookup(struct bpf_map *map, void *key)
sk = __sock_map_lookup_elem(map, *(u32 *)key);
if (!sk)
return NULL;
- if (sk_is_refcounted(sk) && !refcount_inc_not_zero(&sk->sk_refcnt))
- return NULL;
+ if (sk_is_refcounted(sk))
+ sock_hold(sk);
return sk;
}
@@ -1218,8 +1218,8 @@ static void *sock_hash_lookup(struct bpf_map *map, void *key)
sk = __sock_hash_lookup_elem(map, key);
if (!sk)
return NULL;
- if (sk_is_refcounted(sk) && !refcount_inc_not_zero(&sk->sk_refcnt))
- return NULL;
+ if (sk_is_refcounted(sk))
+ sock_hold(sk);
return sk;
}