[PATCH net-next v2 2/7] net: cap sockopt_expand_out() at MAX_RW_COUNT

From: Breno Leitao

Date: Fri Oct 09 2026 - 05:14:17 EST


sockopt_expand_out() grows the output iterator up to INT_MAX, but its
callers rewind it with iov_iter_revert() once they know the real reply
size. iov_iter_revert() refuses to unroll past MAX_RW_COUNT:

if (WARN_ON(unroll > MAX_RW_COUNT))
return;

MAX_RW_COUNT is INT_MAX rounded down to a page boundary, so a caller
that expands into the (MAX_RW_COUNT, INT_MAX] range and then reverts
hits that WARN_ON, and the iterator is left where it was instead of
rewound. So does a caller whose optlen already covers such a size.

Cap the size at MAX_RW_COUNT instead, before the early return for an
optlen that already covers it, so a size that could never be reverted
later is rejected up front.

This was detected by sashiko, and I fits in this patchset/net-next,
given this doesn't seem to be a big deal.

Fixes: 0093f7db9c47 ("net: add sockopt_expand_out()")
Signed-off-by: Breno Leitao <leitao@xxxxxxxxxx>
---
include/linux/net.h | 10 +++++++---
1 file changed, 7 insertions(+), 3 deletions(-)

diff --git a/include/linux/net.h b/include/linux/net.h
index e2a866fbcfa5ea..461137bdc8817e 100644
--- a/include/linux/net.h
+++ b/include/linux/net.h
@@ -84,12 +84,16 @@ static inline int sockopt_init_user(sockopt_t *opt, char __user *optval,
*/
static inline int sockopt_expand_out(sockopt_t *opt, size_t size)
{
+ /* iov_iter_revert() refuses to unroll past MAX_RW_COUNT, so a size
+ * beyond that could never be reverted back to the fixed part later,
+ * even when optlen already covers it.
+ */
+ if (size > MAX_RW_COUNT)
+ return -EINVAL;
+
if (size <= (size_t)opt->optlen)
return 0;

- if (size > INT_MAX)
- return -EINVAL;
-
/* Re-anchoring reads iter_out.ubuf, so the iterator has to be a user
* buffer that nothing has written through yet.
*/

--
2.53.0-Meta