From nobody Fri Nov 21 14:25:37 2025 X-Original-To: dev-commits-src-branches@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4dCcvP4Pr6z6HH64 for ; Fri, 21 Nov 2025 14:25:37 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R12" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4dCcvP2Xs9z3frG for ; Fri, 21 Nov 2025 14:25:37 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1763735137; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=BjPVH4rU0dCMlso/daGPIL9y9FZ2IGc3/PTYzr9nI+Q=; b=fYKel2fp8f/AK7N/2+xpi/IHigCm4ltvhlhhjKc6b7D4MzA6NmYopIWiiY4V1cqPPu9IhY LRWZZdL6HPi2AXtIZMMNBSb27Joc4a6VR4OA8aYABSQb9R73YooP45eaFGPPrruZuHibi8 490ECVjS2Ay3qFEGLNmPOgAvJLWMnhsjWJlQovKJDusfDfajMiZjecR7gLXcZb4zuyA6gQ G14b9ZS8meZrJuhic69MUjwoDOrGqNMDRf6mooHbG4XmDCbId61qxidjyxAy4SPICiDghl H5acBL83PiLJdqOEDvd0c75FQpZx8RsKs16bI9qDNZkSQe/qNyxvYcsLxLt9qg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1763735137; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=BjPVH4rU0dCMlso/daGPIL9y9FZ2IGc3/PTYzr9nI+Q=; b=SEWFy1sfFherqZ94sIUonLgatubYdazKq/luEiLv82zXz5CySrn5I9gZyMilo/I1EuL4Ea WVSlfixcmBQbZyqx/XyKKkA5ifEnGdeVLK4S0nkVHEbZ1v4qYT9uEwWmy6C7HwPWiu0zYT 230ZH6GwHjGVCKZz4CDwGHQ31EVJCXBdIoDAS4EAO9bQB12AkLhzMJJgIW2LyO3vi0j3Nn ZD3qmpshJLeZeYtiC/BDz3lI0z47N3WvRR7m1CVNqMhHdNkL61jSddOEp8dDVWyIPQPdMp /bf0Ma5hla/Q53ZkVqrQr0b5bO4SoWsSfESyP222BpaHazJmjydJItmzj8JRTQ== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1763735137; a=rsa-sha256; cv=none; b=BH09p/7s4VEOKo+qzw4dquVb4p++VTlkCn97pDS+FNRxqTCQaFoYGuSC50BPXevrKcWone efgbFAvC5ZOGdN3EcTG1efzazdDo49FTDAy6q31zbB86xEsU3tNJlz+x5RbLWha4q3iY/y 5K6QiTM8IIRuRwdZppBqE8OYEen9yX6dkf92UN2bViWfUCiTVNtyyiqEH0+hBysjlIU5cY 3fKpYv6X+im0rtroyy5ZNqwjLkM83M31zpSwZpF6Dt5ZOcrWaBsLxz572BgFAC9vOD7z32 s2HjJiO7D14jx8yNbQABQ5whMPdGJydpYuh6biLraxhK7yXGkjZqU3Xe7dbMiw== ARC-Authentication-Results: i=1; mx1.freebsd.org; none Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4dCcvP23KPzvV for ; Fri, 21 Nov 2025 14:25:37 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 2c12f by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Fri, 21 Nov 2025 14:25:37 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-branches@FreeBSD.org From: Mark Johnston Subject: git: f7c3aa281504 - stable/15 - unix: Fix handling of listening sockets during garbage collection List-Id: Commits to the stable branches of the FreeBSD src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-branches List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-branches@freebsd.org Sender: owner-dev-commits-src-branches@FreeBSD.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: markj X-Git-Repository: src X-Git-Refname: refs/heads/stable/15 X-Git-Reftype: branch X-Git-Commit: f7c3aa2815043c6ac22bcbbec970343ab38025c3 Auto-Submitted: auto-generated Date: Fri, 21 Nov 2025 14:25:37 +0000 Message-Id: <69207661.2c12f.600ec01e@gitrepo.freebsd.org> The branch stable/15 has been updated by markj: URL: https://cgit.FreeBSD.org/src/commit/?id=f7c3aa2815043c6ac22bcbbec970343ab38025c3 commit f7c3aa2815043c6ac22bcbbec970343ab38025c3 Author: Mark Johnston AuthorDate: 2025-11-13 22:56:15 +0000 Commit: Mark Johnston CommitDate: 2025-11-21 14:16:00 +0000 unix: Fix handling of listening sockets during garbage collection socantrcvmore() and unp_dispose() assume that the socket's socket buffers are initialized, which isn't the case for listening sockets. Reported by: syzbot+a62883292a5c257703be@syzkaller.appspotmail.com MFC after: 1 week Reviewed by: glebius Differential Revision: https://reviews.freebsd.org/D53743 (cherry picked from commit 9d9fa9a2c22f67d5f8afec18106c9f0072d6b3d4) --- sys/kern/uipc_usrreq.c | 10 ++++++---- tests/sys/kern/unix_passfd_test.c | 29 +++++++++++++++++++++++++++++ 2 files changed, 35 insertions(+), 4 deletions(-) diff --git a/sys/kern/uipc_usrreq.c b/sys/kern/uipc_usrreq.c index 1d0e1c4f8db6..05e267b8ae2b 100644 --- a/sys/kern/uipc_usrreq.c +++ b/sys/kern/uipc_usrreq.c @@ -4202,10 +4202,12 @@ unp_gc(__unused void *arg, int pending) struct socket *so; so = unref[i]->f_data; - CURVNET_SET(so->so_vnet); - socantrcvmore(so); - unp_dispose(so); - CURVNET_RESTORE(); + if (!SOLISTENING(so)) { + CURVNET_SET(so->so_vnet); + socantrcvmore(so); + unp_dispose(so); + CURVNET_RESTORE(); + } } /* diff --git a/tests/sys/kern/unix_passfd_test.c b/tests/sys/kern/unix_passfd_test.c index 7dc4541ad402..66bb406ea14e 100644 --- a/tests/sys/kern/unix_passfd_test.c +++ b/tests/sys/kern/unix_passfd_test.c @@ -1189,6 +1189,34 @@ ATF_TC_CLEANUP(cross_jail_dirfd, tc) err(1, "jail_remove"); } +ATF_TC_WITHOUT_HEAD(listening_socket); +ATF_TC_BODY(listening_socket, tc) +{ + struct sockaddr_un sun; + int error, ls, s[2]; + + ls = socket(AF_UNIX, SOCK_STREAM, 0); + ATF_REQUIRE(ls != -1); + + memset(&sun, 0, sizeof(sun)); + sun.sun_len = sizeof(sun); + sun.sun_family = AF_UNIX; + snprintf(sun.sun_path, sizeof(sun.sun_path), "listen.sock"); + error = bind(ls, (struct sockaddr *)&sun, sizeof(sun)); + ATF_REQUIRE_MSG(error == 0, "bind failed: %s", strerror(errno)); + error = listen(ls, 0); + + error = socketpair(AF_UNIX, SOCK_STREAM, 0, s); + ATF_REQUIRE_MSG(error == 0, "socketpair failed: %s", strerror(errno)); + + sendfd(s[0], ls); + sendfd(s[0], s[0]); + sendfd(s[0], s[1]); + close(ls); + close(s[0]); + close(s[1]); +} + ATF_TP_ADD_TCS(tp) { @@ -1211,6 +1239,7 @@ ATF_TP_ADD_TCS(tp) ATF_TP_ADD_TC(tp, empty_rights_message); ATF_TP_ADD_TC(tp, control_creates_records); ATF_TP_ADD_TC(tp, cross_jail_dirfd); + ATF_TP_ADD_TC(tp, listening_socket); return (atf_no_error()); }