Re: [PATCH net] net: psp: do not inherit the Rx association on clone

From: Paolo Abeni

Date: Tue Sep 01 2026 - 06:02:44 EST


On 8/29/26 6:56 PM, Norbert Szetei wrote:
> sk->psp_assoc sits past sk_dontcopy_end, so sock_copy() copies it into
> every socket accepted from a listener without taking a reference, while
> inet_sock_destruct() puts for every inet socket. psp_twsk_init() does
> refcount_inc() for the timewait socket, so a child closing through
> TIME_WAIT cancels its own put and leaves the association with one
> reference and N timewait sockets holding the same pointer. Closing the
> listener frees it, and the timewait timers then put freed memory.
>
> Rejecting the association on a listening socket is not sufficient: a socket
> can acquire one while established and then be turned back into a listener,
> because tcp_disconnect() leaves sk->psp_assoc in place.

So rejecting the association on listener, and clearing on disconnect
would be enough, right?

I think that would be preferable: it's a pity to add safeguard code to
the datapath due to a syscall (disconnect) used mostly by fuzzers.

/P