From: Matthieu Baerts <matttbe@kernel.org>
To: Quanye Yang <quanyeyang@proton.me>
Cc: MPTCP Linux <mptcp@lists.linux.dev>, Tao Cui <cui.tao@linux.dev>
Subject: Re: [PATCH mptcp-net] mptcp: pm: cap userspace extra_subflows at U8_MAX
Date: Wed, 2 Sep 2026 18:52:14 +0200 [thread overview]
Message-ID: <67a2bdd2-6936-4d1d-8d38-18be961d35c4@kernel.org> (raw)
In-Reply-To: <20260902-mptcp-pm-extra-subflows-v1-1-68540a866e5a@proton.me>
Hi Quanye,
+ Cc: Tao Cui
On 02/09/2026 17:39, Quanye Yang via B4 Relay wrote:
> From: Quanye Yang <quanyeyang@proton.me>
>
> The userspace PM increments extra_subflows with no upper bound. The
> field is a u8, so the 256th extra subflow wraps the counter to 0 and
> the next close hits WARN_ON_ONCE().
>
> Refuse admission at U8_MAX for incoming MP_JOIN and for the Netlink
> create path.
>
> Fixes: 77e4b94a3de6 ("mptcp: update userspace pm infos")
> Cc: stable@vger.kernel.org
(No need to add stable on patches sent to the MPTCP ML, that will be
added later when sending these patches to netdev)
> Link: https://github.com/multipath-tcp/mptcp_net-next/issues/629
"Closes:" can be used here.
(...)
> diff --git a/net/mptcp/pm_userspace.c b/net/mptcp/pm_userspace.c
> index fab16d953dbf..6d798dd96702 100644
> --- a/net/mptcp/pm_userspace.c
> +++ b/net/mptcp/pm_userspace.c
> @@ -427,16 +427,22 @@ int mptcp_pm_nl_subflow_create_doit(struct sk_buff *skb, struct genl_info *info)
> local.ifindex = entry.ifindex;
>
> spin_lock_bh(&msk->pm.lock);
> - msk->pm.extra_subflows++;
> - spin_unlock_bh(&msk->pm.lock);
> + if (msk->pm.extra_subflows == U8_MAX) {
> + spin_unlock_bh(&msk->pm.lock);
> + GENL_SET_ERR_MSG(info, "too many extra subflows");
> + err = -ENOSPC;
Maybe a goto could be used here ...
> + } else {
> + msk->pm.extra_subflows++;
> + spin_unlock_bh(&msk->pm.lock);
>
> - lock_sock(sk);
> - err = __mptcp_subflow_connect(sk, &local, &addr_r);
> - release_sock(sk);
> + lock_sock(sk);
> + err = __mptcp_subflow_connect(sk, &local, &addr_r);
> + release_sock(sk);
> + if (err)
> + GENL_SET_ERR_MSG_FMT(info, "connect error: %d", err);
> + }
>
> if (err) {
> - GENL_SET_ERR_MSG_FMT(info, "connect error: %d", err);
> -
... to here, not to modify the rest of the code?
> spin_lock_bh(&msk->pm.lock);
> mptcp_userspace_pm_delete_local_addr(msk, &entry);
> spin_unlock_bh(&msk->pm.lock);
This part hasn't been fixed on Tao's series [1]. Would it be OK for both
of you if this part of Quanye's patch is added to Tao's v2 series with
Quanye as author?
[1] https://lore.kernel.org/20260831093206.689827-1-cui.tao@linux.dev
Cheers,
Matt
--
Sponsored by the NGI0 Core fund.
next prev parent reply other threads:[~2026-09-02 16:52 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-02 15:39 [PATCH mptcp-net] mptcp: pm: cap userspace extra_subflows at U8_MAX Quanye Yang
2026-09-02 15:39 ` Quanye Yang via B4 Relay
2026-09-02 15:49 ` sashiko-bot
2026-09-02 16:36 ` Matthieu Baerts
2026-09-02 16:52 ` Matthieu Baerts [this message]
2026-09-02 17:02 ` MPTCP CI
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=67a2bdd2-6936-4d1d-8d38-18be961d35c4@kernel.org \
--to=matttbe@kernel.org \
--cc=cui.tao@linux.dev \
--cc=mptcp@lists.linux.dev \
--cc=quanyeyang@proton.me \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.