Re: [PATCH net v3] nfc: llcp: prevent resource leak on repeated connect after DM
From: Simon Horman
Date: Thu Oct 01 2026 - 08:09:42 EST
On Mon, Sep 28, 2026 at 12:57:49AM -0300, Aldo Ariel Panzardo wrote:
> A rejected asynchronous connect leaves a local reference, SAP allocation,
> service name and device reference on a closed socket. Release them before
> retrying connect.
>
> The device pointer alone does not prove ownership: bind() puts its
> temporary device reference while retaining the pointer. When device
> teardown closes a bound socket, the retry cleanup would put that device
> again. Clear the pointer when a bound or listening socket becomes closed,
> and after a connected socket's device reference is put. Do the same when
> DM closes a bound or listening socket. A DM rejected connect keeps its
> device reference until the retry cleanup, so retain that put there.
>
> Fixes: d646960f7986 ("NFC: Initial LLCP support")
> Reported-by: Sashiko <sashiko-bot@xxxxxxxxxx>
> Link: https://ci.syzbot.org/findings/64002827-5231-4183-bfca-0d91bded8543/syz_repro
> Cc: stable@xxxxxxxxxxxxxxx
> Signed-off-by: Aldo Ariel Panzardo <qwe.aldo@xxxxxxxxx>
> ---
> v3: Clear non-owning or already released device pointers on close, while
> preserving the device put for rejected asynchronous connects.
Hi Aldo,
It looks like an AI-generated review of v2 of this patchset was
posted not long after you posted v3. And that review does seem
to raise issues that warrant a response:
- Re: [PATCH net v2] nfc: llcp: prevent resource leak on repeated connect after DM
https://lore.kernel.org/all/179058922656.3145.17540746696102333949@xxxxxxxxxx/
Also, please do not post updated patches as responses to earlier revisions.
Rather, please start a new email thread for each new revision.
Thanks!