Re: [PATCH bpf 2/3] bpf: Extract shared reqsk-to-listener upgrade
From: Emil Tsalapatis
Date: Wed Jul 29 2026 - 16:32:38 EST
On Thu Jul 23, 2026 at 7:33 AM EDT, Michal Luczaj wrote:
> __bpf_sk_lookup() and bpf_sk_lookup() duplicate the same sk_to_full_sk()
> reqsk-to-listener upgrade. Extract it into a helper.
>
> Leave the currently unreachable WARN_ONCE as a defensive assert.
>
> No functional change.
Reviewed-by: Emil Tsalapatis <emil@xxxxxxxxxxxxxxx>
>
> Signed-off-by: Michal Luczaj <mhal@xxxxxxx>
> ---
> net/core/filter.c | 57 ++++++++++++++++++++++++-------------------------------
> 1 file changed, 25 insertions(+), 32 deletions(-)
>
> diff --git a/net/core/filter.c b/net/core/filter.c
> index b446aa8be5c3..403aba3ce891 100644
> --- a/net/core/filter.c
> +++ b/net/core/filter.c
> @@ -7074,6 +7074,27 @@ __bpf_skc_lookup(struct sk_buff *skb, struct bpf_sock_tuple *tuple, u32 len,
> return sk;
> }
>
> +static struct sock *
> +bpf_sk_lookup_full_sk(struct sock *sk)
> +{
> + struct sock *sk2 = sk_to_full_sk(sk);
> +
> + /* sk_to_full_sk() may return sk->rsk_listener, make sure the original
> + * sk sock refcnt is decremented to prevent a request_sock leak.
> + */
> + if (sk2 != sk) {
> + sock_gen_put(sk);
> + /* Ensure there is no need to bump sk2 refcnt. */
> + if (unlikely(sk2 && !sock_flag(sk2, SOCK_RCU_FREE))) {
> + WARN_ONCE(1, "Found non-RCU, unreferenced socket!");
> + return NULL;
> + }
> + sk = sk2;
> + }
> +
> + return sk;
> +}
> +
> static struct sock *
> __bpf_sk_lookup(struct sk_buff *skb, struct bpf_sock_tuple *tuple, u32 len,
> struct net *caller_net, u32 ifindex, u8 proto, u64 netns_id,
> @@ -7083,22 +7104,8 @@ __bpf_sk_lookup(struct sk_buff *skb, struct bpf_sock_tuple *tuple, u32 len,
> ifindex, proto, netns_id, flags,
> sdif);
>
> - if (sk) {
> - struct sock *sk2 = sk_to_full_sk(sk);
> -
> - /* sk_to_full_sk() may return (sk)->rsk_listener, so make sure the original sk
> - * sock refcnt is decremented to prevent a request_sock leak.
> - */
> - if (sk2 != sk) {
> - sock_gen_put(sk);
> - /* Ensure there is no need to bump sk2 refcnt */
> - if (unlikely(sk2 && !sock_flag(sk2, SOCK_RCU_FREE))) {
> - WARN_ONCE(1, "Found non-RCU, unreferenced socket!");
> - return NULL;
> - }
> - sk = sk2;
> - }
> - }
> + if (sk)
> + sk = bpf_sk_lookup_full_sk(sk);
>
> return sk;
> }
> @@ -7129,22 +7136,8 @@ bpf_sk_lookup(struct sk_buff *skb, struct bpf_sock_tuple *tuple, u32 len,
> struct sock *sk = bpf_skc_lookup(skb, tuple, len, proto, netns_id,
> flags);
>
> - if (sk) {
> - struct sock *sk2 = sk_to_full_sk(sk);
> -
> - /* sk_to_full_sk() may return (sk)->rsk_listener, so make sure the original sk
> - * sock refcnt is decremented to prevent a request_sock leak.
> - */
> - if (sk2 != sk) {
> - sock_gen_put(sk);
> - /* Ensure there is no need to bump sk2 refcnt */
> - if (unlikely(sk2 && !sock_flag(sk2, SOCK_RCU_FREE))) {
> - WARN_ONCE(1, "Found non-RCU, unreferenced socket!");
> - return NULL;
> - }
> - sk = sk2;
> - }
> - }
> + if (sk)
> + sk = bpf_sk_lookup_full_sk(sk);
>
> return sk;
> }