]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
net: remove WARN_ON_ONCE() from sk_mc_loop()
authorEric Dumazet <edumazet@google.com>
Tue, 4 Aug 2026 15:20:48 +0000 (15:20 +0000)
committerPaolo Abeni <pabeni@redhat.com>
Thu, 6 Aug 2026 11:10:16 +0000 (13:10 +0200)
sk_mc_loop() can be called for sockets that are neither AF_INET
nor AF_INET6 (e.g. AF_PACKET sockets when sending packets via raw/packet
socket over virtual devices such as VRF or ipvlan).

In such cases, sk_family is not AF_INET/AF_INET6 and sk_mc_loop() falls
through the switch statement and triggers WARN_ON_ONCE(1).

Non-INET sockets do not support IP_MULTICAST_LOOP or IPV6_MULTICAST_LOOP
options, so loopback should default to true without generating a warning.

Fixes: f60e5990d9c1 ("ipv6: protect skb->sk accesses from recursive dereference inside the stack")
Reported-by: syzbot+22c3218a6fa219e47321@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/netdev/6a72024c.13623e66.bdc14.0019.GAE@google.com/T/#u
Signed-off-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260804152048.2134341-1-edumazet@google.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
net/core/sock.c

index ffa73594c13c7557d011730676edc887ec1de5cb..1ad41904db25b48a914640f538760686f40eb100 100644 (file)
@@ -779,7 +779,6 @@ bool sk_mc_loop(const struct sock *sk)
                return inet6_test_bit(MC6_LOOP, sk);
 #endif
        }
-       WARN_ON_ONCE(1);
        return true;
 }
 EXPORT_SYMBOL(sk_mc_loop);