]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
af_unix: fix listen() succeeding on sockets in the wrong state
authorJohn Ericson <mail@johnericson.me>
Sat, 18 Jul 2026 18:29:01 +0000 (14:29 -0400)
committerJakub Kicinski <kuba@kernel.org>
Fri, 24 Jul 2026 22:10:05 +0000 (15:10 -0700)
Commit fd0a109a0f6b ("net, pidfs: prepare for handing out pidfds for
reaped sk->sk_peer_pid") inserted a prepare_peercred() call between err
= -EINVAL and the socket-state check in unix_listen(). Since
prepare_peercred() leaves err at 0 on success, listen() on an AF_UNIX
socket that is not in TCP_CLOSE or TCP_LISTEN state (e.g. one that is
already connected) now silently returns success without doing anything,
instead of failing with EINVAL as it did before.

Fixes: fd0a109a0f6b ("net, pidfs: prepare for handing out pidfds for reaped sk->sk_peer_pid")
Signed-off-by: John Ericson <mail@johnericson.me>
Link: https://patch.msgid.link/20260718182903.2295560-1-John.Ericson@Obsidian.Systems
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
net/unix/af_unix.c

index f7a9d55eee8a12349728323307d027e96a44dace..10ed9421e43aa58776fdd8bc17b67b016b649d0b 100644 (file)
@@ -823,6 +823,7 @@ static int unix_listen(struct socket *sock, int backlog)
        if (err)
                goto out;
        unix_state_lock(sk);
+       err = -EINVAL;
        if (sk->sk_state != TCP_CLOSE && sk->sk_state != TCP_LISTEN)
                goto out_unlock;
        if (backlog > sk->sk_max_ack_backlog)