From: Tao Cui <cui.tao@linux.dev>
To: mptcp@lists.linux.dev
Cc: matttbe@kernel.org, geliang@kernel.org, cuitao@kylinos.cn,
cui.tao@linux.dev
Subject: [PATCH mptcp-next 1/2] mptcp: pm: bound extra_subflows admission on userspace PM
Date: Mon, 31 Aug 2026 17:32:05 +0800 [thread overview]
Message-ID: <20260831093206.689827-2-cui.tao@linux.dev> (raw)
In-Reply-To: <20260831093206.689827-1-cui.tao@linux.dev>
From: Tao Cui <cuitao@kylinos.cn>
mptcp_pm_allow_new_subflow() increments the u8 extra_subflows counter
for every accepted MP_JOIN on sockets using the userspace PM, without
any limit. A peer establishing more than 255 live subflows wraps the
counter back to 0, which then makes the underflow guards warn on the
next subflow close, and permanently corrupts mptcpi_subflows_total
reported to userspace.
Refuse new MP_JOINs once the counter has reached U8_MAX, so that it
cannot wrap anymore.
Fixes: e99c1ca89071 ("mptcp: pm: add WARN_ON_ONCE guards on extra_subflows underflow")
Link: https://github.com/multipath-tcp/mptcp_net-next/issues/629
Signed-off-by: Tao Cui <cuitao@kylinos.cn>
---
net/mptcp/pm.c | 11 +++++++++--
1 file changed, 9 insertions(+), 2 deletions(-)
diff --git a/net/mptcp/pm.c b/net/mptcp/pm.c
index 8b68868255c5..3990f6775723 100644
--- a/net/mptcp/pm.c
+++ b/net/mptcp/pm.c
@@ -562,10 +562,17 @@ bool mptcp_pm_allow_new_subflow(struct mptcp_sock *msk)
if (mptcp_pm_is_userspace(msk)) {
if (mptcp_userspace_pm_active(msk)) {
+ bool allow;
+
+ /* extra_subflows is a u8: don't let a peer wrap it
+ * with more than U8_MAX accepted MP_JOINs
+ */
spin_lock_bh(&pm->lock);
- pm->extra_subflows++;
+ allow = pm->extra_subflows < U8_MAX;
+ if (allow)
+ pm->extra_subflows++;
spin_unlock_bh(&pm->lock);
- return true;
+ return allow;
}
return false;
}
--
2.43.0
next prev parent reply other threads:[~2026-08-31 9:32 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-31 9:32 [PATCH mptcp-next 0/2] mptcp: pm: fix reachable extra_subflows guards Tao Cui
2026-08-31 9:32 ` Tao Cui [this message]
2026-09-02 16:39 ` [PATCH mptcp-next 1/2] mptcp: pm: bound extra_subflows admission on userspace PM Matthieu Baerts
2026-09-03 3:42 ` quanyeyang
2026-09-03 8:57 ` Tao Cui
2026-09-03 8:55 ` Tao Cui
2026-09-03 9:13 ` Matthieu Baerts
2026-08-31 9:32 ` [PATCH mptcp-next 2/2] mptcp: pm: skip extra_subflows accounting on disconnected msk Tao Cui
2026-08-31 10:11 ` sashiko-bot
2026-08-31 13:00 ` Tao Cui
2026-09-02 16:32 ` Matthieu Baerts
2026-09-02 16:56 ` Matthieu Baerts
2026-08-31 10:25 ` [PATCH mptcp-next 0/2] mptcp: pm: fix reachable extra_subflows guards MPTCP CI
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260831093206.689827-2-cui.tao@linux.dev \
--to=cui.tao@linux.dev \
--cc=cuitao@kylinos.cn \
--cc=geliang@kernel.org \
--cc=matttbe@kernel.org \
--cc=mptcp@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.