All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH mptcp-next v4] mptcp: drop skb_ext from tx clone in fallback mode
@ 2026-09-11 14:05 Geliang Tang
  2026-09-11 15:13 ` MPTCP CI
  0 siblings, 1 reply; 2+ messages in thread
From: Geliang Tang @ 2026-09-11 14:05 UTC (permalink / raw)
  To: mptcp; +Cc: Geliang Tang

From: Geliang Tang <tanggeliang@kylinos.cn>

In fallback mode, mptcp_established_options() returns 0 and no DSS options
are generated, but __skb_clone() has already shared the skb_ext with the
transmit clone via __skb_ext_copy(), bumping its refcount. The clone holds
the reference until the peer reads data, so the ext is not freed when the
original skb is released from the rtx queue. This causes a kmemleak when
TLS ULP pushes pending records during close, as the ext lifecycle cannot
complete before kmemleak scans. Drop the ext from the clone in the fallback
path of mptcp_established_options() to eliminate the unnecessary shared
reference.

Signed-off-by: Geliang Tang <tanggeliang@kylinos.cn>
---
v4:
 - drop skb_ext in mptcp_established_options in fallback mode

v3:
 - Free extensions before early returns (fixes memory leak)
 - Use fallback label to skip mpext operations (fixes NULL deref)
 - Allow TCP coalescing when mpext NULL in fallback mode
 - Remove cached fb variable to avoid race conditions (fixes NULL deref)
 - Pass fallback state to mptcp_skb_can_collapse_to() for correct behavior
 - https://patchwork.kernel.org/project/mptcp/patch/6e4266b0dc3eb7e68f0064e16fa9921f46b85319.1788338252.git.tanggeliang@kylinos.cn/

v2:
 - Free extensions before early returns
 - Added fallback label to skip mpext operations
 - Allow TCP coalescing when mpext NULL
 - Cache fallback state in bool fb
 - https://patchwork.kernel.org/project/mptcp/patch/b67dec47d321886d45fdd2bca1c303314fcdb229.1788252583.git.tanggeliang@kylinos.cn/

v1:
 - https://patchwork.kernel.org/project/mptcp/patch/70a7e7e05337faa0547c3759e5d9829763f2bcc5.1788244452.git.tanggeliang@kylinos.cn/
---
 net/mptcp/options.c | 6 +++++-
 1 file changed, 5 insertions(+), 1 deletion(-)

diff --git a/net/mptcp/options.c b/net/mptcp/options.c
index 2bf3686709de..3b52e9f971f0 100644
--- a/net/mptcp/options.c
+++ b/net/mptcp/options.c
@@ -885,8 +885,12 @@ int mptcp_established_options(struct sock *sk, struct sk_buff *skb,
 	/* Force later mptcp_write_options(), but do not use any actual
 	 * option space.
 	 */
-	if (unlikely(__mptcp_check_fallback(msk) && !mptcp_check_infinite_map(skb)))
+	if (unlikely(__mptcp_check_fallback(msk) &&
+		     !mptcp_check_infinite_map(skb))) {
+		if (skb)
+			skb_ext_del(skb, SKB_EXT_MPTCP);
 		return 0;
+	}
 
 	if (unlikely(skb && TCP_SKB_CB(skb)->tcp_flags & TCPHDR_RST)) {
 		if (mptcp_established_options_fastclose(sk, &opt_size, remaining, opts) ||
-- 
2.53.0


^ permalink raw reply related	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-09-11 15:13 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-11 14:05 [PATCH mptcp-next v4] mptcp: drop skb_ext from tx clone in fallback mode Geliang Tang
2026-09-11 15:13 ` MPTCP CI

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.