Re: [PATCH v3 0/2] taskstats: fix cross-netns exit listener delivery

From: Greg KH

Date: Fri Oct 02 2026 - 07:06:40 EST


On Fri, Oct 02, 2026 at 07:56:12PM +0900, tjdqudcks0424@xxxxxxxxx wrote:
> From: 성병찬 <tjdqudcks0424@xxxxxxxxx>
>
> CPU-mask taskstats listeners are currently identified only by a numeric
> Generic Netlink port ID and exit records are sent through init_net. Since
> port IDs are namespace-local, an unprivileged init_net socket can bind the
> same number as a listener in another network namespace and receive that
> listener's cross-UID exit record.
>
> Patch 1 associates listener entries with the registering Generic Netlink
> socket's namespace and port ID and cleans them up when that socket closes.
> Patch 2 adds an acct kselftest which constructs the collision and checks the
> normal listener, explicit deregistration, and unrelated-port controls.
>
> The test was built with GCC using -Wall -Wextra and run in disposable QEMU
> guests with the same userspace binary. On the unmodified baseline it reports
> 3 passes and 1 failure: the child-netns listener misses the victim record and
> the colliding unprivileged init_net socket receives it. On the fixed kernel,
> three independent clean boots each report 4 passes and no failures. No
> KASAN, UBSAN, BUG, WARNING, Oops, panic, lockdep, refcount, use-after-free,
> out-of-bounds, or kmemleak diagnostic was emitted during the final runs.
>
> The exact Message-ID and lore URL of the previous public posting were not
> present in the available local sent-mail or raw-mail artifacts:
>
> Link: https://lore.kernel.org/r/20261002075842.146026-1-tjdqudcks0424@xxxxxxxxx/

Please slow down, there's no rush here and you aren't giving people a
chance to test or review any of this.

thanks,

greg k-h