If listen() fails, fd should be deleted from fdtab, not just closed. Otherwise,
sock_inet_bind_receiver(), which is called in loop for each receiver, will
obtain the same fd via socket() for the next receiver, registered in the
receivers list. Then, it will bind it again and it will try to re-insert it in
fdtab, and fd_insert() will trigger the BUG_ON(fdtab[fd].owner != NULL) check.
When tcp_bind_listener() code was implemented, the use of fd_delete() was
not generalized and this one remained overlooked.
This can be backported to all stable versions.
tcp_close_return:
free_trash_chunk(msg);
msg = NULL;
- close(fd);
+ fd_delete(fd);
tcp_return:
if (msg && errlen && msg->data) {
char pn[INET6_ADDRSTRLEN];