From: 성병찬 <[email protected]> CPU-mask taskstats listeners are currently identified only by a numeric Generic Netlink port ID and exit records are sent through init_net. Since port IDs are namespace-local, an unprivileged init_net socket can bind the same number as a listener in another network namespace and receive that listener's cross-UID exit record.
Patch 1 associates listener entries with the registering Generic Netlink socket's namespace and port ID and cleans them up when that socket closes. Patch 2 adds an acct kselftest which constructs the collision and checks the normal listener, explicit deregistration, and unrelated-port controls. The test was built with GCC using -Wall -Wextra and run in disposable QEMU guests with the same userspace binary. On the unmodified baseline it reports 3 passes and 1 failure: the child-netns listener misses the victim record and the colliding unprivileged init_net socket receives it. On the fixed kernel, three independent clean boots each report 4 passes and no failures. No KASAN, UBSAN, BUG, WARNING, Oops, panic, lockdep, refcount, use-after-free, out-of-bounds, or kmemleak diagnostic was emitted during the final runs. The exact Message-ID and lore URL of the previous public posting were not present in the available local sent-mail or raw-mail artifacts: Link: https://lore.kernel.org/r/[email protected]/ Changes in v3: - remove wording that called a private draft "v1" - add an in-tree taskstats CPU-listener network-namespace regression test - send the fix and selftest as a two-patch series 성병찬 (2): taskstats: route exit listener records through their netns selftests: acct: test taskstats listener netns routing kernel/taskstats.c | 135 ++- tools/testing/selftests/acct/Makefile | 1 + .../selftests/acct/taskstats_netns_listener.c | 945 ++++++++++++++++++ 3 files changed, 1037 insertions(+), 44 deletions(-) create mode 100644 tools/testing/selftests/acct/taskstats_netns_listener.c base-commit: ce1e0223d8ad4211275c82a17ed6d43ab81e13d9 -- 2.43.0

