All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Matthieu Baerts (NGI0)" <matttbe@kernel.org>
Cc: mptcp@lists.linux.dev
Subject: Re: [PATCH net v2 08/15] mptcp: pm: userspace: fix address ID overflow
Date: Wed, 09 Sep 2026 14:15:05 +0000	[thread overview]
Message-ID: <20260909141505.840EE1F00A3D@smtp.kernel.org> (raw)
In-Reply-To: <20260908-net-mptcp-misc-fixes-7-3-rc1-v2-8-df1de70348b6@kernel.org>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [High] Incorrect ID collision check permanently breaks ID allocation if an entry with ID 0 exists.
--

commit 0ac6c6a2ecc7912387ac1b8203c8c6f77120a794
Author: Qing Luo <luoqing@kylinos.cn>
mptcp: pm: userspace: fix address ID overflow

This commit fixes an address ID overflow in the userspace PM when all
IDs (1-255) are exhausted. By returning -ENOSPC when the next available ID
exceeds the maximum, it prevents ID 0 from being incorrectly allocated.
The ID allocation check is also moved before memory allocation to simplify
the error path.

> diff --git a/net/mptcp/pm_userspace.c b/net/mptcp/pm_userspace.c
> index b94fbb483bf94..fab16d953dbfe 100644
> --- a/net/mptcp/pm_userspace.c
> +++ b/net/mptcp/pm_userspace.c
> @@ -69,6 +69,19 @@ static int mptcp_userspace_pm_append_new_local_addr(struct mptcp_sock *msk,
>  	}
>  
>  	if (!addr_match && !id_match) {

[Severity: High]
This isn't a bug introduced by this patch, but does the loop preceding this
block permanently break ID allocation if an entry with ID 0 exists?

If needs_id is true and no address match is found, entry->addr.id remains 0.
The check in the loop:

    id_match = (e->addr.id == entry->addr.id);
    if (addr_match || id_match)
        break;

evaluates to true if an existing entry has ID 0. This breaks the loop early
and causes the function to return -EINVAL instead of allocating a new ID.

A privileged user (CAP_NET_ADMIN) can configure the userspace PM to create a
subflow using the initial connection address (omitting the ID or specifying
ID 0) via mptcp_pm_nl_subflow_create_doit(). This legitimately adds an entry
with ID 0 to the userspace_pm_local_addr_list. Later, when an event requires
a new implicit ID allocation (e.g., calling
mptcp_userspace_pm_get_local_id()), needs_id is true and entry->addr.id is
initially 0.

Could this incorrectly match the unassigned ID against the existing entry
with ID 0, permanently breaking MPTCP connection management for the socket?

> +		unsigned int id;
> +
> +		if (!entry->addr.id && needs_id) {
> +			id = find_next_zero_bit(id_bitmap,
> +						MPTCP_PM_MAX_ADDR_ID + 1, 1);
> +			if (id > MPTCP_PM_MAX_ADDR_ID) {
> +				ret = -ENOSPC;
> +				goto append_err;
> +			}
> +		} else {
> +			id = entry->addr.id;
> +		}
> +

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260908-net-mptcp-misc-fixes-7-3-rc1-v2-0-df1de70348b6@kernel.org?part=8

  reply	other threads:[~2026-09-09 14:15 UTC|newest]

Thread overview: 33+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-08 14:07 [PATCH net v2 00/15] mptcp: misc fixes for v7.3-rc1 Matthieu Baerts (NGI0)
2026-09-08 14:07 ` [PATCH net v2 01/15] mptcp: do not reschedule the RTX timer for fallback sockets Matthieu Baerts (NGI0)
2026-09-09 14:49   ` netdev-bot+sashiko
2026-09-09 15:32     ` Paolo Abeni
2026-09-08 14:07 ` [PATCH net v2 02/15] mptcp: subflow: no need to copy thmac during ulp_clone Matthieu Baerts (NGI0)
2026-09-08 14:07 ` [PATCH net v2 03/15] mptcp: syncookies: remember the request backup flag Matthieu Baerts (NGI0)
2026-09-08 14:07 ` [PATCH net v2 04/15] mptcp: pm: kernel: drop pending ADD_ADDR when removing ID0 Matthieu Baerts (NGI0)
2026-09-09 14:49   ` netdev-bot+sashiko
2026-09-09 17:57     ` Matthieu Baerts
2026-09-08 14:07 ` [PATCH net v2 05/15] mptcp: options: handle MPC data + csum reqd + no csum Matthieu Baerts (NGI0)
2026-09-09 14:49   ` netdev-bot+sashiko
2026-09-09 18:03     ` Matthieu Baerts
2026-09-08 14:07 ` [PATCH net v2 06/15] mptcp: prevent race between disconnect() and rtx Matthieu Baerts (NGI0)
2026-09-09 14:49   ` netdev-bot+sashiko
2026-09-09 15:54     ` Paolo Abeni
2026-09-09 18:05   ` Matthieu Baerts
2026-09-08 14:07 ` [PATCH net v2 07/15] selftests: mptcp: fix an UAF in mptcp_connect.c Matthieu Baerts (NGI0)
2026-09-08 14:07 ` [PATCH net v2 08/15] mptcp: pm: userspace: fix address ID overflow Matthieu Baerts (NGI0)
2026-09-09 14:15   ` sashiko-bot [this message]
2026-09-08 14:07 ` [PATCH net v2 09/15] mptcp: pm: reset retrans_time when ADD_ADDR entry is reused Matthieu Baerts (NGI0)
2026-09-08 14:07 ` [PATCH net v2 10/15] mptcp: remove unneeded READ_ONCE() annotation Matthieu Baerts (NGI0)
2026-09-08 14:07 ` [PATCH net v2 11/15] selftests: mptcp: lib: dump nstat for the right test Matthieu Baerts (NGI0)
2026-09-08 14:07 ` [PATCH net v2 12/15] selftests: mptcp: lib: get counters " Matthieu Baerts (NGI0)
2026-09-09 14:15   ` sashiko-bot
2026-09-09 16:17     ` Matthieu Baerts
2026-09-08 14:07 ` [PATCH net v2 13/15] mptcp: options: fix uninit-value in mptcp_write_data_fin Matthieu Baerts (NGI0)
2026-09-08 14:07 ` [PATCH net v2 14/15] mptcp: being below memory limit is a likely() condition Matthieu Baerts (NGI0)
2026-09-08 14:07 ` [PATCH net v2 15/15] mptcp: avoid pruning for OoW data Matthieu Baerts (NGI0)
2026-09-09 14:49   ` netdev-bot+sashiko
2026-09-09 15:50     ` Paolo Abeni
2026-09-09 18:07       ` Matthieu Baerts
2026-09-09 18:09 ` [PATCH net v2 00/15] mptcp: misc fixes for v7.3-rc1 Matthieu Baerts
2026-09-09 20:40 ` patchwork-bot+netdevbpf

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260909141505.840EE1F00A3D@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=matttbe@kernel.org \
    --cc=mptcp@lists.linux.dev \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.