From: netdev-bot+sashiko@kernel.org
To: leitao@debian.org
Cc: dsahern@kernel.org, idosch@nvidia.com, davem@davemloft.net,
kuba@kernel.org, pabeni@redhat.com, horms@kernel.org,
ast@kernel.org, daniel@iogearbox.net, andrii@kernel.org,
eddyz87@gmail.com, memxor@gmail.com, martin.lau@linux.dev,
song@kernel.org, yonghong.song@linux.dev, jolsa@kernel.org,
emil@etsalapatis.com, ihor.solodrai@linux.dev,
john.fastabend@gmail.com, sdf@fomichev.me, shuah@kernel.org,
edumazet@kernel.org, netdev@vger.kernel.org,
linux-kernel@vger.kernel.org, bpf@vger.kernel.org,
linux-kselftest@vger.kernel.org, david.laight.linux@gmail.com,
kernel-team@meta.com
Subject: Re: [PATCH net-next v2 2/7] net: cap sockopt_expand_out() at MAX_RW_COUNT
Date: Sat, 10 Oct 2026 09:12:51 +0000 [thread overview]
Message-ID: <179162357191.434549.9383804148666639080@kernel.org> (raw)
In-Reply-To: <20261009-sockopt_expand_out_v2-v2-2-8ac08c469ecb@debian.org>
Thank you for your contribution! Sashiko AI review found more severe
issue(s) in other patches of this series. This mail is only an FYI, in case
you want to address the nit picks below when you respin.
Low priority / nit picks for your consideration:
- [Low] Most of this concern does not hold once the whole series is
applied.
--
net: cap sockopt_expand_out() at MAX_RW_COUNT
This patch moves the size check in sockopt_expand_out() so it runs before
the optlen early return. It also lowers the limit from INT_MAX to
MAX_RW_COUNT. Any size that iov_iter_revert() could not unroll later is
now rejected up front.
> sockopt_expand_out() grows the output iterator up to INT_MAX, but its
> callers rewind it with iov_iter_revert() once they know the real reply
> size. iov_iter_revert() refuses to unroll past MAX_RW_COUNT:
[ ... ]
> Fixes: 0093f7db9c47 ("net: add sockopt_expand_out()")
[Severity: Low]
Is the present tense accurate at this point in the series?
At this commit, ip_mc_msfget() in net/ipv4/igmp.c is the only caller of
sockopt_expand_out(). It writes forward through opt->iter_out and never
calls iov_iter_revert(). The same holds at 0093f7db9c47, so neither
commit can reach the WARN_ON in iov_iter_revert().
The callers that rewind come from later patches in this series: "ipv6:
mcast: convert ip6_mc_msfget() to sockopt_t" and "ipv4: igmp: convert
ip_mc_gsfget() to sockopt_t". For example:
ip_get_mcast_msfilter()
iov_iter_revert(&opt->iter_out, gsf_size);
ipv6_get_msfilter()
iov_iter_revert(&opt->iter_out, len);
The same applies to compat_ip_get_mcast_msfilter() and
compat_ipv6_get_msfilter(). Once those patches land, the new cap does
protect these callers.
Would it be more accurate to say the cap is for callers converted later
in the series? Another option is to move this patch next to those
conversions. The Fixes: tag pointing at 0093f7db9c47 has the same
problem.
Also, the header comment above sockopt_expand_out() in include/linux/net.h
still only describes the kernel-backed -EINVAL case:
* the head of optval. Only a user buffer can be longer than the optlen the
* caller declared, so a kernel-backed optval is refused with -EINVAL.
Could it mention the MAX_RW_COUNT rejection as well? The new comment
inside the function already explains it.
--
Sashiko AI review · https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20261009-sockopt_expand_out_v2-v2-0-8ac08c469ecb%40debian.org
next prev parent reply other threads:[~2026-10-10 9:12 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-09 8:53 [PATCH net-next v2 0/7] ipv4,ipv6: convert the getsockopt switches to sockopt_t Breno Leitao
2026-10-09 8:53 ` [PATCH net-next v2 1/7] ipv6: treat a negative optlen as 4 in do_ipv6_getsockopt() Breno Leitao
2026-10-10 9:12 ` netdev-bot+sashiko
2026-10-09 8:53 ` [PATCH net-next v2 2/7] net: cap sockopt_expand_out() at MAX_RW_COUNT Breno Leitao
2026-10-10 9:12 ` netdev-bot+sashiko [this message]
2026-10-09 8:53 ` [PATCH net-next v2 3/7] ipv6: mcast: convert ip6_mc_msfget() to sockopt_t Breno Leitao
2026-10-09 8:53 ` [PATCH net-next v2 4/7] ipv4: igmp: convert ip_mc_gsfget() " Breno Leitao
2026-10-09 8:53 ` [PATCH net-next v2 5/7] ipv4: convert do_ip_getsockopt() " Breno Leitao
2026-10-10 9:12 ` netdev-bot+sashiko
2026-10-09 8:53 ` [PATCH net-next v2 6/7] ipv6: convert do_ipv6_getsockopt() " Breno Leitao
2026-10-10 9:12 ` netdev-bot+sashiko
2026-10-09 8:53 ` [PATCH net-next v2 7/7] selftests: net: getsockopt_iter: cover ip and ipv6 Breno Leitao
2026-10-10 9:12 ` netdev-bot+sashiko
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=179162357191.434549.9383804148666639080@kernel.org \
--to=netdev-bot+sashiko@kernel.org \
--cc=andrii@kernel.org \
--cc=ast@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=daniel@iogearbox.net \
--cc=davem@davemloft.net \
--cc=david.laight.linux@gmail.com \
--cc=dsahern@kernel.org \
--cc=eddyz87@gmail.com \
--cc=edumazet@kernel.org \
--cc=emil@etsalapatis.com \
--cc=horms@kernel.org \
--cc=idosch@nvidia.com \
--cc=ihor.solodrai@linux.dev \
--cc=john.fastabend@gmail.com \
--cc=jolsa@kernel.org \
--cc=kernel-team@meta.com \
--cc=kuba@kernel.org \
--cc=leitao@debian.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-kselftest@vger.kernel.org \
--cc=martin.lau@linux.dev \
--cc=memxor@gmail.com \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=sdf@fomichev.me \
--cc=shuah@kernel.org \
--cc=song@kernel.org \
--cc=yonghong.song@linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®