git: eff554d9f3d6 - releng/15.0 - unix/stream: plug a corner case when control externalization failed
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Tue, 25 Aug 2026 16:01:00 UTC
The branch releng/15.0 has been updated by markj:
URL: https://cgit.FreeBSD.org/src/commit/?id=eff554d9f3d6372c9cbb8ea315f910b81bd44eee
commit eff554d9f3d6372c9cbb8ea315f910b81bd44eee
Author: Gleb Smirnoff <glebius@FreeBSD.org>
AuthorDate: 2025-10-15 20:01:25 +0000
Commit: Mark Johnston <markj@FreeBSD.org>
CommitDate: 2026-08-24 19:29:47 +0000
unix/stream: plug a corner case when control externalization failed
while peer has closed its end.
Approved by: so
Security: FreeBSD-SA-26:57.unix
Reported by: syzbot+ffcc3612ea266e36604e@syzkaller.appspotmail.com
(cherry picked from commit 4548b9f3a8167a340a5086ed51a76d932c9ab3cc)
(cherry picked from commit e7070407aa8eae85bc412b9fd80865628b69f22d)
---
sys/kern/uipc_usrreq.c | 20 ++++++++++++--------
1 file changed, 12 insertions(+), 8 deletions(-)
diff --git a/sys/kern/uipc_usrreq.c b/sys/kern/uipc_usrreq.c
index ecf7218f2ca3..932bda8b568d 100644
--- a/sys/kern/uipc_usrreq.c
+++ b/sys/kern/uipc_usrreq.c
@@ -1552,15 +1552,19 @@ restart:
mc_init_m(&cmc, control);
SOCK_RECVBUF_LOCK(so);
- MPASS(!(sb->sb_state & SBS_CANTRCVMORE));
-
- if (__predict_false(cmc.mc_len + sb->sb_ccc +
- sb->sb_ctl > sb->sb_hiwat)) {
+ if (__predict_false(
+ (sb->sb_state & SBS_CANTRCVMORE) ||
+ cmc.mc_len + sb->sb_ccc + sb->sb_ctl >
+ sb->sb_hiwat)) {
/*
- * Too bad, while unp_externalize() was
- * failing, the other side had filled
- * the buffer and we can't prepend data
- * back. Losing data!
+ * While the lock was dropped and we
+ * were failing in unp_externalize(),
+ * the peer could has a) disconnected,
+ * b) filled the buffer so that we
+ * can't prepend data back.
+ * These are two edge conditions that
+ * we just can't handle, so lose the
+ * data and return the error.
*/
SOCK_RECVBUF_UNLOCK(so);
SOCK_IO_RECV_UNLOCK(so);