From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pj1-f45.google.com (mail-pj1-f45.google.com [209.85.216.45]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C889F37E5EF for ; Sun, 23 Aug 2026 17:59:38 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.45 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787507981; cv=none; b=M6Sfj+E0ztWfUo+85fxkZpf0kt/XHG9NB//F2e3jZzBfhbzv+vrZmwyZy7IB6FC08nxP1YEQ4Z/hTh1RbynMule9cLmbj1osfJOhRrqwJKTh9DT+HOUEz/vGVMprrv5hCgZNVwfPB9OoTpC4SqrNPlhKozHWGqaoCQtNMqzqFmM= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787507981; c=relaxed/simple; bh=j+GvspEPFMJKw6+StUj0ft/LLbZU8zbHTx8oX1MMKJI=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=VVsmuLy/kQmD52TfTKFLK34UssxO/CEVY+HMwK8irvJ8H4rb4ygIZaUDkwSvojXDQqkHzv4dMF1509xH7m30pMkcxUq0dnRdgJCLYm0Jz4uD6KrgWtKfjQoSlpAGSiBsFuIJHQd66xPch/PguLD9bwceT5rS8pRwlzCK6Vzx5Vg= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=f4oRtADo; arc=none smtp.client-ip=209.85.216.45 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="f4oRtADo" Received: by mail-pj1-f45.google.com with SMTP id 98e67ed59e1d1-38e07ebd263so1665449a91.1 for ; Sun, 23 Aug 2026 10:59:38 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787507978; x=1788112778; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=oSG6MK2qQTE9wpGTHa2F4jMVfX6350zfMS2a14Bvdsw=; b=f4oRtADoEr14b5rw/5GmI7QM6w8Gw6/ITb4Jd3bc/sYrjzHflzu55LtZE8O00WFNoF NbjGGk/37VnUCCs8SI1FS+5H+YBPL2JzqMFm/oEq1KK/ynyWb6Ji14HVhvazcLThq099 azdtDa9V/iIp0RZAettYkrXgaZxWgDjXZbUySBLg80vsUNi6KfQsJNHMRUJH7JlOPm94 8DI/BP/QmAX6e/EBxZmyfsoPgHiCx9fa84mDfPvaABF5Kv/XIaOqvUdQiYpVvneGEXu0 B20LBI5LmOQ98aEGEvh3l5zQTWlGOY9ojEsxFrym5fPqsqKKZm0GMn7E7i7fmt9EbyuQ Bh6g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787507978; x=1788112778; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=oSG6MK2qQTE9wpGTHa2F4jMVfX6350zfMS2a14Bvdsw=; b=PaSo5LJsSOprhfMKV5bSoffSfkX3TsR6i7OJEotXcB2aojzjHuu7C8n/1YwMvBgLTg /m5Doa3e+B+F4VBdC6hIjCfpEmPLZ8D+DEnhMppfZhuJrF4HZcLSjU5l0mLRTMzbkCve 8riLktBjIQ56hxbGTd1bxNvlWMsjnd5IhRq1jv98MMYhdvYZOcXU1TUaIkyzJ2c0oNfx jHbIqrXkF898nltBZguHh6fMFQ3j6bdmA8IQNsmUR6cvTcjOUX7ai9ZorbkjpTvSKXGF sJo5lz580M+/NhsdC2Yug5HGHPYHjm7vfW+sGhr4bh5bufZtB382c3sddviUROOUyq5z EJJA== X-Forwarded-Encrypted: i=1; AHgh+RoNC3BinEFEyTOqnmnn/YfnGTBzggLg56RG0WNKWlXgQ7TpukNS4wYp2RQLWpNZkYrtlDjBxVE7Im6lGrg=@vger.kernel.org X-Gm-Message-State: AFuF++k4Hc36n0JCd8pti/qfHI86EsgAYfMxCHzmfdQpSatHtHinXkXq lbkhNvZy/fNRiay95zndhamRQbyRrUYS9K4I6q6owJeJs6pSPnc9gg2k X-Gm-Gg: AR+sD11J9ReqUT4chRgAx8DTkh3JNi9g7qTOivHquHMVLefgxoCwMsajmxZoWw7qn+z qUMpo4gXEU+Rp/3f+BiPkfFIxN/2FA5PdqI7B9IOSzWML1YOwJVL+PQrbw5gk0ADvz9yQ8GOVNC U9jzUJN9FbMgcaE+3U4rpWcX1Ijk4hYvrKrGbYSJqtyT7HCDju94xsq2yjX4Xd5Lw9h1XZyXXU2 VCPsrfs6GPZidMxXC+cRpNrFG0aAk9+894o67qLT1lFrbIbjBblPf3uoz8/5FeFIrNTP183mh7l ktbv/f6cFKElvZVW79cE91kMS0FIeg+V2JqyuAssnNwoaj7KwROyUYy7hvJM3HitNXK9dWZ0oRj kzILoa1KLeyNb/8UWW3ey20IhW5uD9ypCCeGvQMsOUbyDX3jXWuTDH5I9Cp6hqBItyNDLnYdO/6 uuJ/F6JFUlZ7TuN9/P6rK+afpnM4YcDpUuDeRVMvQMKGAbNCSKC/8JxnU0RdL5H5s04dJ5ENQi X-Received: by 2002:a17:90b:4a0d:b0:38e:5b59:c2ff with SMTP id 98e67ed59e1d1-395c3376963mr33466205a91.3.1787507977903; Sun, 23 Aug 2026 10:59:37 -0700 (PDT) Received: from ancienth-X870E-Nova-WiFi ([125.186.72.2]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-395c8fd34d9sm3722818a91.1.2026.08.23.10.59.33 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 23 Aug 2026 10:59:37 -0700 (PDT) From: Daehyeon Ko <4ncienth@gmail.com> To: netdev@vger.kernel.org Cc: sgarzare@redhat.com, stefanha@redhat.com, bobbyeshleman@gmail.com, davem@davemloft.net, edumazet@google.com, kuba@kernel.org, pabeni@redhat.com, horms@kernel.org, mst@redhat.com, jasowangio@gmail.com, xuanzhuo@linux.alibaba.com, eperezma@redhat.com, bryan-bt.tan@broadcom.com, vishnu.dasa@broadcom.com, bcm-kernel-feedback-list@broadcom.com, virtualization@lists.linux.dev, kvm@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH net v3 0/2] vsock: validate packet sources after bound lookup fallback Date: Mon, 24 Aug 2026 02:58:56 +0900 Message-ID: <20260823175858.351431-1-4ncienth@gmail.com> X-Mailer: git-send-email 2.54.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Both virtio and VMCI look up connected sockets by the full tuple before falling back to a destination-only bound lookup. The fallback can select a non-listening socket without validating the packet source. V2 covered only the virtio path. Following Stefano's review, this series moves the source and transport validation into a documented AF_VSOCK helper and uses it for both virtio and VMCI. The VMCI patch checks both its bottom-half and deferred workqueue receive paths. The combined series was tested on x86_64 KASAN kernels. The original cross-UID virtio injection remained blocked in three boots, CID_LOCAL and CID_HOST loopback aliases passed, selected VSOCK selftests passed, and VMCI accepted a matched RST while rejecting a mismatched-context RST in three boots. All changed objects built without warnings under allmodconfig and allyesconfig with W=1. The current-tree guest-CID vhost probe could not be rerun because the test user lacks access to /dev/vhost-vsock. Changes in v3: - Move transport and source validation into vsock_check_source(). - Trust the internally generated source CID for the local transport. - Add VMCI validation in the bottom-half and workqueue receive paths. - Send the related virtio and VMCI fixes in one series. - Do not carry Bobby's v2 Reviewed-by because the helper and loopback logic changed; renewed review is requested. v2: https://lore.kernel.org/netdev/20260820001517.2148196-1-4ncienth@gmail.com/ v1: https://lore.kernel.org/netdev/20260813121236.2328599-1-4ncienth@gmail.com/ Daehyeon Ko (2): vsock/virtio: validate packet source for connected sockets vsock/vmci: validate packet source for connected sockets include/net/af_vsock.h | 3 +++ net/vmw_vsock/af_vsock.c | 32 +++++++++++++++++++++++++ net/vmw_vsock/virtio_transport_common.c | 3 ++- net/vmw_vsock/vmci_transport.c | 29 +++++++++++++++++----- 4 files changed, 60 insertions(+), 7 deletions(-) base-commit: 7cbfb180945ce529608e4d4e24a6d483699fab1e -- 2.54.0