All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH mptcp-net] mptcp: fix skb_ext leak in fallback mode
@ 2026-09-01  6:34 Geliang Tang
  2026-09-01  6:54 ` sashiko-bot
  2026-09-01  8:52 ` MPTCP CI
  0 siblings, 2 replies; 3+ messages in thread
From: Geliang Tang @ 2026-09-01  6:34 UTC (permalink / raw)
  To: mptcp; +Cc: Geliang Tang

From: Geliang Tang <tanggeliang@kylinos.cn>

In fallback mode, MPTCP sockets behave as plain TCP and should not allocate
SKB_EXT_MPTCP for transmitted skbs, since DSS mappings are never decoded by
the receiver. However, the current sendmsg path unconditionally allocates
the extension, leading to a leak when the skb is freed without properly
releasing the extension.

This latent bug will be exposed once TLS ULP support is added to fallback
MPTCP sockets, as each sendmsg via the TLS path would leak one skb_ext
object.

Fix this by short-circuiting __mptcp_add_ext() in __mptcp_do_alloc_tx_skb()
when the msk is in fallback mode. In mptcp_sendmsg_frag(), skip all DSS
bookkeeping (memset, data_len updates, frozen flag, csum, infinite_map)
when fallback is set, allowing the subflow to behave like a plain TCP
socket.

Fixes: 3a54a74a3c5b ("mptcp: allocate TX skbs in msk context")
Signed-off-by: Geliang Tang <tanggeliang@kylinos.cn>
---
 net/mptcp/protocol.c | 9 ++++++++-
 1 file changed, 8 insertions(+), 1 deletion(-)

diff --git a/net/mptcp/protocol.c b/net/mptcp/protocol.c
index 0b24e0afedfb..96933a221eff 100644
--- a/net/mptcp/protocol.c
+++ b/net/mptcp/protocol.c
@@ -1361,7 +1361,8 @@ static struct sk_buff *__mptcp_do_alloc_tx_skb(struct sock *sk, gfp_t gfp)
 
 	skb = alloc_skb_fclone(MAX_TCP_HEADER, gfp);
 	if (likely(skb)) {
-		if (likely(__mptcp_add_ext(skb, gfp))) {
+		if (unlikely(__mptcp_check_fallback(mptcp_sk(sk))) ||
+		    likely(__mptcp_add_ext(skb, gfp))) {
 			skb_reserve(skb, MAX_TCP_HEADER);
 			skb->ip_summed = CHECKSUM_PARTIAL;
 			INIT_LIST_HEAD(&skb->tcp_tsorted_anchor);
@@ -1538,6 +1539,12 @@ static int mptcp_sendmsg_frag(struct sock *sk, struct sock *ssk,
 	TCP_SKB_CB(skb)->end_seq += copy;
 	tcp_skb_pcount_set(skb, 0);
 
+	/* in fallback the msk ext is not allocated; skip DSS bookkeeping
+	 * entirely and let the subflow behave like a plain TCP socket
+	 */
+	if (__mptcp_check_fallback(msk))
+		goto out;
+
 	/* on skb reuse we just need to update the DSS len */
 	if (reuse_skb) {
 		TCP_SKB_CB(skb)->tcp_flags &= ~TCPHDR_PSH;
-- 
2.53.0


^ permalink raw reply related	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-09-01  8:52 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-01  6:34 [PATCH mptcp-net] mptcp: fix skb_ext leak in fallback mode Geliang Tang
2026-09-01  6:54 ` sashiko-bot
2026-09-01  8:52 ` MPTCP CI

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.