From nobody Fri Jul 24 05:21:41 2026 Received: from mail-pf1-f176.google.com (mail-pf1-f176.google.com [209.85.210.176]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1C23D3D647E for ; Thu, 23 Jul 2026 06:55:02 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.176 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784789704; cv=none; b=LnqTsFXd9I6HsgUtOxCAaeeCuWMQoa7N0wC88+hFHBpVNPKtTl9wo1SFxXXsDkDhGYj/NMafKcMJRfBy53UCH5jMKZeIcW/R5GZajzOdfkI97Cd7fScsD/Y6+aEyVM+oEob4xM9adoZB7uyleJN4R0veA/VXpr/UhUqo0ckBS1A= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784789704; c=relaxed/simple; bh=MdSXyYAsOoLOBGcvOWfpvc3qfz93fatlLaVqLMDXGwY=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=FHVeQhpn2cHco91nNGN0+cwZR1YJbGJ5oKCT7h1HQHXk6es+lOwl+alLGoSlireRQWc75wrBGnD9NIDh6sM+5Y5fTxZAdDRQ2/4jUY3RTf7ghUiY9Dw8rV4z1Ebbzwo+IHB8HIUj5liqijmhXJj9IqmDM40d4dOGDvYuSORRV8M= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=Car0MeFc; arc=none smtp.client-ip=209.85.210.176 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="Car0MeFc" Received: by mail-pf1-f176.google.com with SMTP id d2e1a72fcca58-84847482584so95163b3a.0 for ; Wed, 22 Jul 2026 23:55:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784789702; x=1785394502; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=XYF6IhJVH4t/ih25pWa4y8XjdHM5r8QHzlFhQEmGoNg=; b=Car0MeFcAT/tVxKScU5ZhwSmwTYaSVFwNbqX76fuYoLVYlvL2OCJMOlYGb7i3vQwiv nYGpysubd/i92Ep69VepM8vW4lN0D/v1twNkQ+FqbfATCHlvaiUk11Pyeea0aQYcXmn9 WLvxPZotY1zOvZjdNKufA9+wvzufdjHhkRJAnqgfviuHVnHaOXJ0nadwqinccLIZwNFY cNi5WHcVKiUl2ojmWNaJQ7KX5AU5TDXsVV9n8z1x/pZvCUBZh93XCSsRafEdmjU5lTZt 4PExcQ8wgVf6L9sRSd5QqT5TxYroSICEzWYTRmL4ALGKT0myD22R1gq3vOG3eUVB+dvP tD2w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784789702; x=1785394502; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=XYF6IhJVH4t/ih25pWa4y8XjdHM5r8QHzlFhQEmGoNg=; b=jzcgCHIZx/ZLeuesDfQwsRi5gLNZCvc9ISowlIhdd0MwExspnXsutHlkJ4YJTFTVtb cO/ycqWN1vGzbA2xKsrm8bRVGJ4LSlYRYM/hphSFawfEfAhdsQ9Nl9gTFw9hiMR0K3ZD aKySbPdDNUJm5PxiTUgmN+46ZH5pIz4LsEYoVRl7PKxahob8BpXLjWclawL58qdlvahX V1dHhrCfFWHHhDLia91SMap6r+PXU6oENP7Sj4Ygigo9P0HW5ntj810dKaJRx7DKFi6i IDUk/fD7VClaBBC/yi6c0inGA4J1INdaLQPu9qgLWuFksUC6ZkK308/a9o3uYrxVZw0k Kt+g== X-Forwarded-Encrypted: i=1; AHgh+RqRdiDIuKfLLrx36dszUHrsidZ+7b4IvyL7JZ6KLsaHBj4IdOnuuMyZSeSYi7v+ihnXbQFBox72mfMiGpg=@vger.kernel.org X-Gm-Message-State: AOJu0Yxkt7+rfaZR6GV8DVeOdv0id8y8QuHpDp4H1pAO4+qGn0ovxndV mVVHEuDUTLEHmcQsXCyn2hrkrifsFXHX4bARp0A7uIuYXRKWHaRBcbzbaMlzkbVY X-Gm-Gg: AR+sD117yXfmnexCW1TZaID+PA+K2eB5o3iPSjkb/kJw92uMp8he0SsKh4fAieqlbyV 3+sRn6+Bzi+xWptwUeNxYGxlVamnLMovf317oHHFRkpKWUg7yVe2J1AXCLdTop7SI2hxmOn70im So320anQ8ZXwslVm7iCUm89IWwNBLRg3yNbeHzv1dk2vSGpEfetkejqd3uAnhHQoFKMvGJunwiT BnaaHDsR7TDnz1OH9BfqB09yUprvrKdmbDdVej2uHUA8FDX3BYUa+MwR/B4t9fDLB+oKkqYIDsD 66HzPc9mbGzmQTRkJ0RGx0nZXyuq5Z5c3GhS7IxwSnZb/WnKvAGKnUztGxnilpAlarM8TdusDDC p+guWJfV9QOE1utcXh+vyP6bTc0Yk37gOX7/dCNoSS5VTshgGYr7JZBe0cy+uIZaFVfGanqPc X-Received: by 2002:a05:6a00:a17:b0:847:8bd0:1b96 with SMTP id d2e1a72fcca58-84e2e8776e3mr1427666b3a.23.1784789702145; Wed, 22 Jul 2026 23:55:02 -0700 (PDT) Received: from omen-arch ([147.46.174.207]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-84e17292c31sm2445472b3a.26.2026.07.22.23.54.58 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 23:55:01 -0700 (PDT) From: Junseo Lim To: John Fastabend , Jakub Sitnicki , Jiayuan Chen Cc: "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , Martin KaFai Lau , linux-kernel@vger.kernel.org, bpf@vger.kernel.org, netdev@vger.kernel.org, Sechang Lim , Junseo Lim Subject: [PATCH bpf] bpf, sockmap: fix page_counter underflow in strparser SK_PASS Date: Thu, 23 Jul 2026 15:52:44 +0900 Message-ID: <20260723065244.186916-1-zirajs7@gmail.com> X-Mailer: git-send-email 2.55.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" tcp_bpf_strp_read_sock() delays cleanup of SK_PASS bytes by subtracting psock->ingress_bytes from the amount passed to __tcp_cleanup_rbuf(). But when sk_psock_verdict_apply() queues the skb directly through sk_psock_skb_ingress_self(), skb_set_owner_r() is called unconditionally and charges the skb again. The duplicated charge is later released independently and can trigger a page_counter underflow. Add a charge_skb argument to sk_psock_skb_ingress_self() and skip skb_set_owner_r() only for the direct strparser SK_PASS path. Keep existing accounting for the other self-ingress caller and for non-strparser SK_PASS. Fixes: 36b62df5683c ("bpf: Fix wrong copied_seq calculation") Signed-off-by: Junseo Lim --- Crash reproduced on Linux tree 94515f3a7d4256a5062176b7d6ed0471938cd51a with KASAN, MEMCG, panic_on_warn=3D1, and oops=3Dpanic. Reproducer/log/config: https://gist.github.com/ZirAjs/16c95c89972ace73910d9= b5ac78a5807 The reproducer drives the strparser SK_PASS path until teardown reports: page_counter underflow Workqueue: events sk_psock_destroy Kernel panic - not syncing: kernel: panic_on_warn set ... net/core/skmsg.c | 29 +++++++++++++++++------------ 1 file changed, 17 insertions(+), 12 deletions(-) diff --git a/net/core/skmsg.c b/net/core/skmsg.c index 2521b643fa05..17260681479a 100644 --- a/net/core/skmsg.c +++ b/net/core/skmsg.c @@ -586,7 +586,8 @@ static int sk_psock_skb_ingress_enqueue(struct sk_buff = *skb, } =20 static int sk_psock_skb_ingress_self(struct sk_psock *psock, struct sk_buf= f *skb, - u32 off, u32 len, bool take_ref); + u32 off, u32 len, bool take_ref, + bool charge_skb); =20 static int sk_psock_skb_ingress(struct sk_psock *psock, struct sk_buff *sk= b, u32 off, u32 len) @@ -595,12 +596,9 @@ static int sk_psock_skb_ingress(struct sk_psock *psock= , struct sk_buff *skb, struct sk_msg *msg; int err; =20 - /* If we are receiving on the same sock skb->sk is already assigned, - * skip memory accounting and owner transition seeing it already set - * correctly. - */ if (unlikely(skb->sk =3D=3D sk)) - return sk_psock_skb_ingress_self(psock, skb, off, len, true); + return sk_psock_skb_ingress_self(psock, skb, off, len, true, + true); msg =3D sk_psock_create_ingress_msg(sk, skb); if (!msg) return -EAGAIN; @@ -618,12 +616,14 @@ static int sk_psock_skb_ingress(struct sk_psock *psoc= k, struct sk_buff *skb, return err; } =20 -/* Puts an skb on the ingress queue of the socket already assigned to the - * skb. In this case we do not need to check memory limits or skb_set_owne= r_r - * because the skb is already accounted for here. +/* Puts an skb on the ingress queue for psock->sk. + * + * When charge_skb is false, the direct strparser SK_PASS path keeps the T= CP + * receive queue accounting in place and must not call skb_set_owner_r(). */ static int sk_psock_skb_ingress_self(struct sk_psock *psock, struct sk_buf= f *skb, - u32 off, u32 len, bool take_ref) + u32 off, u32 len, bool take_ref, + bool charge_skb) { struct sk_msg *msg =3D alloc_sk_msg(GFP_ATOMIC); struct sock *sk =3D psock->sk; @@ -631,7 +631,8 @@ static int sk_psock_skb_ingress_self(struct sk_psock *p= sock, struct sk_buff *skb =20 if (unlikely(!msg)) return -EAGAIN; - skb_set_owner_r(skb, sk); + if (charge_skb) + skb_set_owner_r(skb, sk); =20 /* This is used in tcp_bpf_recvmsg_parser() to determine whether the * data originates from the socket's own protocol stack. No need to @@ -1017,6 +1018,8 @@ static int sk_psock_verdict_apply(struct sk_psock *ps= ock, struct sk_buff *skb, * retrying later from workqueue. */ if (skb_queue_empty(&psock->ingress_skb)) { + bool charge_skb =3D true; + len =3D skb->len; off =3D 0; if (skb_bpf_strparser(skb)) { @@ -1024,8 +1027,10 @@ static int sk_psock_verdict_apply(struct sk_psock *p= sock, struct sk_buff *skb, =20 off =3D stm->offset; len =3D stm->full_len; + charge_skb =3D false; } - err =3D sk_psock_skb_ingress_self(psock, skb, off, len, false); + err =3D sk_psock_skb_ingress_self(psock, skb, off, len, + false, charge_skb); } if (err < 0) { spin_lock_bh(&psock->ingress_lock); --=20 2.55.0