The sock counting (sock_update_netprioidx() and sock_update_classid()) was missing from pidfd's implementation of received fd installation. Replace the open-coded version with a call to the new receive_fd() helper. Thanks to Vamshi K Sthambamkadi <vamshi.k.sthambamkadi@xxxxxxxxx> for catching a missed fput() in an earlier version of this patch. Fixes: 8649c322f75c ("pid: Implement pidfd_getfd syscall") Reviewed-by: Sargun Dhillon <sargun@xxxxxxxxx> Signed-off-by: Kees Cook <keescook@xxxxxxxxxxxx> --- kernel/pid.c | 13 ++----------- 1 file changed, 2 insertions(+), 11 deletions(-) diff --git a/kernel/pid.c b/kernel/pid.c index f1496b757162..a31c102f4c87 100644 --- a/kernel/pid.c +++ b/kernel/pid.c @@ -635,17 +635,8 @@ static int pidfd_getfd(struct pid *pid, int fd) if (IS_ERR(file)) return PTR_ERR(file); - ret = security_file_receive(file); - if (ret) { - fput(file); - return ret; - } - - ret = get_unused_fd_flags(O_CLOEXEC); - if (ret < 0) - fput(file); - else - fd_install(ret, file); + ret = receive_fd(file, O_CLOEXEC); + fput(file); return ret; } -- 2.25.1 _______________________________________________ Containers mailing list Containers@xxxxxxxxxxxxxxxxxxxxxxxxxx https://lists.linuxfoundation.org/mailman/listinfo/containers