* [PATCH net v3 0/2] sctp: handle wrapped and duplicate RECONF responses @ 2026-08-21 9:14 Jun Yang 2026-08-21 9:14 ` [PATCH net v3 1/2] sctp: distinguish sequence zero from wildcard in reconf lookup Jun Yang 2026-08-21 9:14 ` [PATCH net v3 2/2] sctp: fix stream->outcnt underflow on duplicate RECONF responses Jun Yang 0 siblings, 2 replies; 5+ messages in thread From: Jun Yang @ 2026-08-21 9:14 UTC (permalink / raw) To: linux-sctp, netdev Cc: marcelo.leitner, lucien.xin, davem, edumazet, kuba, pabeni, horms, Jun Yang Fix response sequence zero lookup first, then make RECONF response handling idempotent with an outstanding-request bitmask. Jun Yang (2): sctp: distinguish sequence zero from wildcard in reconf lookup sctp: fix stream->outcnt underflow on duplicate RECONF responses include/net/sctp/structs.h | 2 +- net/sctp/stream.c | 46 ++++++++++++++++++++++++++------------ 2 files changed, 33 insertions(+), 15 deletions(-) --- Changes since v2: - Split the sequence-zero lookup fix into patch 1 as requested. v2: https://lore.kernel.org/netdev/20260804113100.37840-1-juny24602@gmail.com/ -- 2.55.0 ^ permalink raw reply [flat|nested] 5+ messages in thread
* [PATCH net v3 1/2] sctp: distinguish sequence zero from wildcard in reconf lookup 2026-08-21 9:14 [PATCH net v3 0/2] sctp: handle wrapped and duplicate RECONF responses Jun Yang @ 2026-08-21 9:14 ` Jun Yang 2026-08-23 20:38 ` Xin Long 2026-08-21 9:14 ` [PATCH net v3 2/2] sctp: fix stream->outcnt underflow on duplicate RECONF responses Jun Yang 1 sibling, 1 reply; 5+ messages in thread From: Jun Yang @ 2026-08-21 9:14 UTC (permalink / raw) To: linux-sctp, netdev Cc: marcelo.leitner, lucien.xin, davem, edumazet, kuba, pabeni, horms, Jun Yang, stable Zero is a valid response sequence after strreset_outseq wraps, but sctp_chunk_lookup_strreset_param() currently treats it as a wildcard. Add match_seq so response lookups match zero exactly while the one type-only lookup can still ignore the sequence. Fixes: 50a41591f110 ("sctp: implement receiver-side procedures for the Add Outgoing Streams Request Parameter") Cc: stable@kernel.org Suggested-by: Simon Horman <horms@kernel.org> Signed-off-by: Jun Yang <junvyyang@tencent.com> --- net/sctp/stream.c | 11 ++++++----- 1 file changed, 6 insertions(+), 5 deletions(-) diff --git a/net/sctp/stream.c b/net/sctp/stream.c index 34ffe6c..cfca5aa 100644 --- a/net/sctp/stream.c +++ b/net/sctp/stream.c @@ -482,7 +482,7 @@ out: static struct sctp_paramhdr *sctp_chunk_lookup_strreset_param( struct sctp_association *asoc, __be32 resp_seq, - __be16 type) + __be16 type, bool match_seq) { struct sctp_chunk *chunk = asoc->strreset_chunk; struct sctp_reconf_chunk *hdr; @@ -499,7 +499,7 @@ static struct sctp_paramhdr *sctp_chunk_lookup_strreset_param( */ struct sctp_strreset_tsnreq *req = param.v; - if ((!resp_seq || req->request_seq == resp_seq) && + if ((!match_seq || req->request_seq == resp_seq) && (!type || type == req->param_hdr.type)) return param.v; } @@ -564,7 +564,7 @@ struct sctp_chunk *sctp_process_strreset_outreq( if (asoc->strreset_chunk) { if (!sctp_chunk_lookup_strreset_param( asoc, outreq->response_seq, - SCTP_PARAM_RESET_IN_REQUEST)) { + SCTP_PARAM_RESET_IN_REQUEST, true)) { /* same process with outstanding isn't 0 */ result = SCTP_STRRESET_ERR_IN_PROGRESS; goto out; @@ -816,7 +816,7 @@ struct sctp_chunk *sctp_process_strreset_addstrm_out( if (asoc->strreset_chunk) { if (!sctp_chunk_lookup_strreset_param( - asoc, 0, SCTP_PARAM_RESET_ADD_IN_STREAMS)) { + asoc, 0, SCTP_PARAM_RESET_ADD_IN_STREAMS, false)) { /* same process with outstanding isn't 0 */ result = SCTP_STRRESET_ERR_IN_PROGRESS; goto out; @@ -927,7 +927,8 @@ struct sctp_chunk *sctp_process_strreset_resp( struct sctp_paramhdr *req; __u32 result; - req = sctp_chunk_lookup_strreset_param(asoc, resp->response_seq, 0); + req = sctp_chunk_lookup_strreset_param(asoc, resp->response_seq, 0, + true); if (!req) return NULL; -- 2.55.0 ^ permalink raw reply related [flat|nested] 5+ messages in thread
* Re: [PATCH net v3 1/2] sctp: distinguish sequence zero from wildcard in reconf lookup 2026-08-21 9:14 ` [PATCH net v3 1/2] sctp: distinguish sequence zero from wildcard in reconf lookup Jun Yang @ 2026-08-23 20:38 ` Xin Long 0 siblings, 0 replies; 5+ messages in thread From: Xin Long @ 2026-08-23 20:38 UTC (permalink / raw) To: Jun Yang Cc: linux-sctp, netdev, marcelo.leitner, davem, edumazet, kuba, pabeni, horms, Jun Yang, stable On Fri, Aug 21, 2026 at 5:14 AM Jun Yang <juny24602@gmail.com> wrote: > > Zero is a valid response sequence after strreset_outseq wraps, but > sctp_chunk_lookup_strreset_param() currently treats it as a wildcard. > > Add match_seq so response lookups match zero exactly while the one > type-only lookup can still ignore the sequence. > > Fixes: 50a41591f110 ("sctp: implement receiver-side procedures for the Add Outgoing Streams Request Parameter") > Cc: stable@kernel.org > Suggested-by: Simon Horman <horms@kernel.org> > Signed-off-by: Jun Yang <junvyyang@tencent.com> > --- > net/sctp/stream.c | 11 ++++++----- > 1 file changed, 6 insertions(+), 5 deletions(-) > > diff --git a/net/sctp/stream.c b/net/sctp/stream.c > index 34ffe6c..cfca5aa 100644 > --- a/net/sctp/stream.c > +++ b/net/sctp/stream.c > @@ -482,7 +482,7 @@ out: > > static struct sctp_paramhdr *sctp_chunk_lookup_strreset_param( > struct sctp_association *asoc, __be32 resp_seq, > - __be16 type) > + __be16 type, bool match_seq) > { > struct sctp_chunk *chunk = asoc->strreset_chunk; > struct sctp_reconf_chunk *hdr; > @@ -499,7 +499,7 @@ static struct sctp_paramhdr *sctp_chunk_lookup_strreset_param( > */ > struct sctp_strreset_tsnreq *req = param.v; > > - if ((!resp_seq || req->request_seq == resp_seq) && > + if ((!match_seq || req->request_seq == resp_seq) && > (!type || type == req->param_hdr.type)) > return param.v; > } > @@ -564,7 +564,7 @@ struct sctp_chunk *sctp_process_strreset_outreq( > if (asoc->strreset_chunk) { > if (!sctp_chunk_lookup_strreset_param( > asoc, outreq->response_seq, > - SCTP_PARAM_RESET_IN_REQUEST)) { > + SCTP_PARAM_RESET_IN_REQUEST, true)) { > /* same process with outstanding isn't 0 */ > result = SCTP_STRRESET_ERR_IN_PROGRESS; > goto out; > @@ -816,7 +816,7 @@ struct sctp_chunk *sctp_process_strreset_addstrm_out( > > if (asoc->strreset_chunk) { > if (!sctp_chunk_lookup_strreset_param( > - asoc, 0, SCTP_PARAM_RESET_ADD_IN_STREAMS)) { > + asoc, 0, SCTP_PARAM_RESET_ADD_IN_STREAMS, false)) { > /* same process with outstanding isn't 0 */ > result = SCTP_STRRESET_ERR_IN_PROGRESS; > goto out; > @@ -927,7 +927,8 @@ struct sctp_chunk *sctp_process_strreset_resp( > struct sctp_paramhdr *req; > __u32 result; > > - req = sctp_chunk_lookup_strreset_param(asoc, resp->response_seq, 0); > + req = sctp_chunk_lookup_strreset_param(asoc, resp->response_seq, 0, > + true); > if (!req) > return NULL; > > -- > 2.55.0 > Acked-by: Xin Long <lucien.xin@gmail.com> The issue reported by Sashiko [1] is mainly a changelog improvement. It’s not a big deal to me. [1] https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260821091440.6496-1-junvyyang%40tencent.com ^ permalink raw reply [flat|nested] 5+ messages in thread
* [PATCH net v3 2/2] sctp: fix stream->outcnt underflow on duplicate RECONF responses 2026-08-21 9:14 [PATCH net v3 0/2] sctp: handle wrapped and duplicate RECONF responses Jun Yang 2026-08-21 9:14 ` [PATCH net v3 1/2] sctp: distinguish sequence zero from wildcard in reconf lookup Jun Yang @ 2026-08-21 9:14 ` Jun Yang 2026-08-23 20:47 ` Xin Long 1 sibling, 1 reply; 5+ messages in thread From: Jun Yang @ 2026-08-21 9:14 UTC (permalink / raw) To: linux-sctp, netdev Cc: marcelo.leitner, lucien.xin, davem, edumazet, kuba, pabeni, horms, Jun Yang, stable, TencentOS Corvus AI A cached RECONF chunk may contain more than one request parameter. A duplicate response can therefore find and process the same ADD_OUT request again while another parameter is still outstanding, rolling back outcnt twice and possibly underflowing it. Track outstanding request types as bits and clear each bit after its first response. Later responses for the same request are then ignored. Fixes: 11ae76e67a17 ("sctp: implement receiver-side procedures for the Reconf Response Parameter") Cc: stable@kernel.org Reported-by: TencentOS Corvus AI <corvus@tencent.com> Link: https://lore.kernel.org/netdev/20260730110225.37371-1-juny24602@gmail.com/ Suggested-by: Xin Long <lucien.xin@gmail.com> Assisted-by: tencentos-corvus-ai:kimi-k3 Signed-off-by: Jun Yang <junvyyang@tencent.com> --- v3: - Split the response_seq == 0 lookup fix into patch 1 (Simon Horman). - Keep the request bit helper local to stream.c. v2: - Track outstanding requests by type instead of sequence (Xin Long). - Drop the redundant arithmetic guard (Xin Long). v1: https://lore.kernel.org/netdev/20260730110225.37371-1-juny24602@gmail.com/ include/net/sctp/structs.h | 2 +- net/sctp/stream.c | 39 +++++++++++++++++++++++++++----------- 2 files changed, 29 insertions(+), 12 deletions(-) diff --git a/include/net/sctp/structs.h b/include/net/sctp/structs.h index cccc662..b21f23b 100644 --- a/include/net/sctp/structs.h +++ b/include/net/sctp/structs.h @@ -2057,7 +2057,7 @@ struct sctp_association { force_delay:1; __u8 strreset_enable; - __u8 strreset_outstanding; /* request param count on the fly */ + __u8 strreset_outstanding; /* request param bitmask on the fly */ __u32 strreset_outseq; /* Update after receiving response */ __u32 strreset_inseq; /* Update after receiving request */ diff --git a/net/sctp/stream.c b/net/sctp/stream.c index cfca5aa..e1a215d 100644 --- a/net/sctp/stream.c +++ b/net/sctp/stream.c @@ -22,6 +22,9 @@ #include <net/sctp/sm.h> #include <net/sctp/stream_sched.h> +#define SCTP_STRRESET_BIT(type) \ + BIT(ntohs(type) - ntohs(SCTP_PARAM_RESET_OUT_REQUEST)) + static void sctp_stream_shrink_out(struct sctp_stream *stream, __u16 outcnt) { struct sctp_association *asoc; @@ -372,7 +375,9 @@ int sctp_send_reset_streams(struct sctp_association *asoc, goto out; } - asoc->strreset_outstanding = out + in; + asoc->strreset_outstanding = + (out ? SCTP_STRRESET_BIT(SCTP_PARAM_RESET_OUT_REQUEST) : 0) | + (in ? SCTP_STRRESET_BIT(SCTP_PARAM_RESET_IN_REQUEST) : 0); out: return retval; @@ -417,7 +422,8 @@ int sctp_send_reset_assoc(struct sctp_association *asoc) return retval; } - asoc->strreset_outstanding = 1; + asoc->strreset_outstanding = + SCTP_STRRESET_BIT(SCTP_PARAM_RESET_TSN_REQUEST); return 0; } @@ -474,7 +480,9 @@ int sctp_send_add_streams(struct sctp_association *asoc, goto out; } - asoc->strreset_outstanding = !!out + !!in; + asoc->strreset_outstanding = + (out ? SCTP_STRRESET_BIT(SCTP_PARAM_RESET_ADD_OUT_STREAMS) : 0) | + (in ? SCTP_STRRESET_BIT(SCTP_PARAM_RESET_ADD_IN_STREAMS) : 0); out: return retval; @@ -564,13 +572,16 @@ struct sctp_chunk *sctp_process_strreset_outreq( if (asoc->strreset_chunk) { if (!sctp_chunk_lookup_strreset_param( asoc, outreq->response_seq, - SCTP_PARAM_RESET_IN_REQUEST, true)) { + SCTP_PARAM_RESET_IN_REQUEST, true) || + !(asoc->strreset_outstanding & + SCTP_STRRESET_BIT(SCTP_PARAM_RESET_IN_REQUEST))) { /* same process with outstanding isn't 0 */ result = SCTP_STRRESET_ERR_IN_PROGRESS; goto out; } - asoc->strreset_outstanding--; + asoc->strreset_outstanding &= + ~SCTP_STRRESET_BIT(SCTP_PARAM_RESET_IN_REQUEST); asoc->strreset_outseq++; if (!asoc->strreset_outstanding) { @@ -669,7 +680,8 @@ struct sctp_chunk *sctp_process_strreset_inreq( SCTP_SO(stream, i)->state = SCTP_STREAM_CLOSED; asoc->strreset_chunk = chunk; - asoc->strreset_outstanding = 1; + asoc->strreset_outstanding = + SCTP_STRRESET_BIT(SCTP_PARAM_RESET_OUT_REQUEST); sctp_chunk_hold(asoc->strreset_chunk); result = SCTP_STRRESET_PERFORMED; @@ -816,13 +828,16 @@ struct sctp_chunk *sctp_process_strreset_addstrm_out( if (asoc->strreset_chunk) { if (!sctp_chunk_lookup_strreset_param( - asoc, 0, SCTP_PARAM_RESET_ADD_IN_STREAMS, false)) { + asoc, 0, SCTP_PARAM_RESET_ADD_IN_STREAMS, false) || + !(asoc->strreset_outstanding & + SCTP_STRRESET_BIT(SCTP_PARAM_RESET_ADD_IN_STREAMS))) { /* same process with outstanding isn't 0 */ result = SCTP_STRRESET_ERR_IN_PROGRESS; goto out; } - asoc->strreset_outstanding--; + asoc->strreset_outstanding &= + ~SCTP_STRRESET_BIT(SCTP_PARAM_RESET_ADD_IN_STREAMS); asoc->strreset_outseq++; if (!asoc->strreset_outstanding) { @@ -899,7 +914,8 @@ struct sctp_chunk *sctp_process_strreset_addstrm_in( goto out; asoc->strreset_chunk = chunk; - asoc->strreset_outstanding = 1; + asoc->strreset_outstanding = + SCTP_STRRESET_BIT(SCTP_PARAM_RESET_ADD_OUT_STREAMS); sctp_chunk_hold(asoc->strreset_chunk); stream->outcnt = outcnt; @@ -929,7 +945,8 @@ struct sctp_chunk *sctp_process_strreset_resp( req = sctp_chunk_lookup_strreset_param(asoc, resp->response_seq, 0, true); - if (!req) + if (!req || !(asoc->strreset_outstanding & + SCTP_STRRESET_BIT(req->type))) return NULL; result = ntohl(resp->result); @@ -1079,7 +1096,7 @@ struct sctp_chunk *sctp_process_strreset_resp( nums, 0, GFP_ATOMIC); } - asoc->strreset_outstanding--; + asoc->strreset_outstanding &= ~SCTP_STRRESET_BIT(req->type); asoc->strreset_outseq++; /* remove everything for this reconf request */ -- 2.55.0 ^ permalink raw reply related [flat|nested] 5+ messages in thread
* Re: [PATCH net v3 2/2] sctp: fix stream->outcnt underflow on duplicate RECONF responses 2026-08-21 9:14 ` [PATCH net v3 2/2] sctp: fix stream->outcnt underflow on duplicate RECONF responses Jun Yang @ 2026-08-23 20:47 ` Xin Long 0 siblings, 0 replies; 5+ messages in thread From: Xin Long @ 2026-08-23 20:47 UTC (permalink / raw) To: Jun Yang Cc: linux-sctp, netdev, marcelo.leitner, davem, edumazet, kuba, pabeni, horms, Jun Yang, stable, TencentOS Corvus AI On Fri, Aug 21, 2026 at 5:14 AM Jun Yang <juny24602@gmail.com> wrote: > > A cached RECONF chunk may contain more than one request parameter. A > duplicate response can therefore find and process the same ADD_OUT request > again while another parameter is still outstanding, rolling back outcnt > twice and possibly underflowing it. > > Track outstanding request types as bits and clear each bit after its first > response. Later responses for the same request are then ignored. > > Fixes: 11ae76e67a17 ("sctp: implement receiver-side procedures for the Reconf Response Parameter") > Cc: stable@kernel.org > Reported-by: TencentOS Corvus AI <corvus@tencent.com> > Link: https://lore.kernel.org/netdev/20260730110225.37371-1-juny24602@gmail.com/ > Suggested-by: Xin Long <lucien.xin@gmail.com> > Assisted-by: tencentos-corvus-ai:kimi-k3 > Signed-off-by: Jun Yang <junvyyang@tencent.com> > --- > v3: > - Split the response_seq == 0 lookup fix into patch 1 (Simon Horman). > - Keep the request bit helper local to stream.c. > > v2: > - Track outstanding requests by type instead of sequence (Xin Long). > - Drop the redundant arithmetic guard (Xin Long). > > v1: https://lore.kernel.org/netdev/20260730110225.37371-1-juny24602@gmail.com/ > > include/net/sctp/structs.h | 2 +- > net/sctp/stream.c | 39 +++++++++++++++++++++++++++----------- > 2 files changed, 29 insertions(+), 12 deletions(-) > > diff --git a/include/net/sctp/structs.h b/include/net/sctp/structs.h > index cccc662..b21f23b 100644 > --- a/include/net/sctp/structs.h > +++ b/include/net/sctp/structs.h > @@ -2057,7 +2057,7 @@ struct sctp_association { > force_delay:1; > > __u8 strreset_enable; > - __u8 strreset_outstanding; /* request param count on the fly */ > + __u8 strreset_outstanding; /* request param bitmask on the fly */ > > __u32 strreset_outseq; /* Update after receiving response */ > __u32 strreset_inseq; /* Update after receiving request */ > diff --git a/net/sctp/stream.c b/net/sctp/stream.c > index cfca5aa..e1a215d 100644 > --- a/net/sctp/stream.c > +++ b/net/sctp/stream.c > @@ -22,6 +22,9 @@ > #include <net/sctp/sm.h> > #include <net/sctp/stream_sched.h> > > +#define SCTP_STRRESET_BIT(type) \ > + BIT(ntohs(type) - ntohs(SCTP_PARAM_RESET_OUT_REQUEST)) > + Hi, Jun Yang, Any reason for removing SCTP_STRRESET_RET/CLEAR/TEST()? Each of these macros is used at least twice below, so removing them increases the number of lines of code. Note: The pre-existing issue reported in sashiko [1] is false positive, as a peer can't answers an IN_REQUEST or ADD_IN_STREAMS with SCTP_STRRESET_PERFORMED according to rfc6525. [1] https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260821091440.6496-1-junvyyang%40tencent.com Thanks. > static void sctp_stream_shrink_out(struct sctp_stream *stream, __u16 outcnt) > { > struct sctp_association *asoc; > @@ -372,7 +375,9 @@ int sctp_send_reset_streams(struct sctp_association *asoc, > goto out; > } > > - asoc->strreset_outstanding = out + in; > + asoc->strreset_outstanding = > + (out ? SCTP_STRRESET_BIT(SCTP_PARAM_RESET_OUT_REQUEST) : 0) | > + (in ? SCTP_STRRESET_BIT(SCTP_PARAM_RESET_IN_REQUEST) : 0); > > out: > return retval; > @@ -417,7 +422,8 @@ int sctp_send_reset_assoc(struct sctp_association *asoc) > return retval; > } > > - asoc->strreset_outstanding = 1; > + asoc->strreset_outstanding = > + SCTP_STRRESET_BIT(SCTP_PARAM_RESET_TSN_REQUEST); > > return 0; > } > @@ -474,7 +480,9 @@ int sctp_send_add_streams(struct sctp_association *asoc, > goto out; > } > > - asoc->strreset_outstanding = !!out + !!in; > + asoc->strreset_outstanding = > + (out ? SCTP_STRRESET_BIT(SCTP_PARAM_RESET_ADD_OUT_STREAMS) : 0) | > + (in ? SCTP_STRRESET_BIT(SCTP_PARAM_RESET_ADD_IN_STREAMS) : 0); > > out: > return retval; > @@ -564,13 +572,16 @@ struct sctp_chunk *sctp_process_strreset_outreq( > if (asoc->strreset_chunk) { > if (!sctp_chunk_lookup_strreset_param( > asoc, outreq->response_seq, > - SCTP_PARAM_RESET_IN_REQUEST, true)) { > + SCTP_PARAM_RESET_IN_REQUEST, true) || > + !(asoc->strreset_outstanding & > + SCTP_STRRESET_BIT(SCTP_PARAM_RESET_IN_REQUEST))) { > /* same process with outstanding isn't 0 */ > result = SCTP_STRRESET_ERR_IN_PROGRESS; > goto out; > } > > - asoc->strreset_outstanding--; > + asoc->strreset_outstanding &= > + ~SCTP_STRRESET_BIT(SCTP_PARAM_RESET_IN_REQUEST); > asoc->strreset_outseq++; > > if (!asoc->strreset_outstanding) { > @@ -669,7 +680,8 @@ struct sctp_chunk *sctp_process_strreset_inreq( > SCTP_SO(stream, i)->state = SCTP_STREAM_CLOSED; > > asoc->strreset_chunk = chunk; > - asoc->strreset_outstanding = 1; > + asoc->strreset_outstanding = > + SCTP_STRRESET_BIT(SCTP_PARAM_RESET_OUT_REQUEST); > sctp_chunk_hold(asoc->strreset_chunk); > > result = SCTP_STRRESET_PERFORMED; > @@ -816,13 +828,16 @@ struct sctp_chunk *sctp_process_strreset_addstrm_out( > > if (asoc->strreset_chunk) { > if (!sctp_chunk_lookup_strreset_param( > - asoc, 0, SCTP_PARAM_RESET_ADD_IN_STREAMS, false)) { > + asoc, 0, SCTP_PARAM_RESET_ADD_IN_STREAMS, false) || > + !(asoc->strreset_outstanding & > + SCTP_STRRESET_BIT(SCTP_PARAM_RESET_ADD_IN_STREAMS))) { > /* same process with outstanding isn't 0 */ > result = SCTP_STRRESET_ERR_IN_PROGRESS; > goto out; > } > > - asoc->strreset_outstanding--; > + asoc->strreset_outstanding &= > + ~SCTP_STRRESET_BIT(SCTP_PARAM_RESET_ADD_IN_STREAMS); > asoc->strreset_outseq++; > > if (!asoc->strreset_outstanding) { > @@ -899,7 +914,8 @@ struct sctp_chunk *sctp_process_strreset_addstrm_in( > goto out; > > asoc->strreset_chunk = chunk; > - asoc->strreset_outstanding = 1; > + asoc->strreset_outstanding = > + SCTP_STRRESET_BIT(SCTP_PARAM_RESET_ADD_OUT_STREAMS); > sctp_chunk_hold(asoc->strreset_chunk); > > stream->outcnt = outcnt; > @@ -929,7 +945,8 @@ struct sctp_chunk *sctp_process_strreset_resp( > > req = sctp_chunk_lookup_strreset_param(asoc, resp->response_seq, 0, > true); > - if (!req) > + if (!req || !(asoc->strreset_outstanding & > + SCTP_STRRESET_BIT(req->type))) > return NULL; > > result = ntohl(resp->result); > @@ -1079,7 +1096,7 @@ struct sctp_chunk *sctp_process_strreset_resp( > nums, 0, GFP_ATOMIC); > } > > - asoc->strreset_outstanding--; > + asoc->strreset_outstanding &= ~SCTP_STRRESET_BIT(req->type); > asoc->strreset_outseq++; > > /* remove everything for this reconf request */ > -- > 2.55.0 > ^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2026-08-23 20:47 UTC | newest] Thread overview: 5+ messages (download: mbox.gz follow: Atom feed -- links below jump to the message on this page -- 2026-08-21 9:14 [PATCH net v3 0/2] sctp: handle wrapped and duplicate RECONF responses Jun Yang 2026-08-21 9:14 ` [PATCH net v3 1/2] sctp: distinguish sequence zero from wildcard in reconf lookup Jun Yang 2026-08-23 20:38 ` Xin Long 2026-08-21 9:14 ` [PATCH net v3 2/2] sctp: fix stream->outcnt underflow on duplicate RECONF responses Jun Yang 2026-08-23 20:47 ` Xin Long
This is an external index of several public inboxes, see mirroring instructions on how to clone and mirror all data and code used by this external index.