* [syzbot] [wireless?] INFO: rcu detected stall in sock_close (5)
@ 2025-07-16 17:01 syzbot
2026-07-22 15:42 ` [syzbot] [bpf?] [sctp?] [tipc?] " syzbot
2026-07-23 6:08 ` Forwarded: " syzbot
0 siblings, 2 replies; 5+ messages in thread
From: syzbot @ 2025-07-16 17:01 UTC (permalink / raw)
To: davem, edumazet, horms, jmaloy, kuba, linux-kernel,
linux-wireless, netdev, pabeni, syzkaller-bugs, tipc-discussion
Hello,
syzbot found the following issue on:
HEAD commit: 379f604cc3dc Merge tag 'pci-v6.16-fixes-3' of git://git.ke..
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=1690fe8c580000
kernel config: https://syzkaller.appspot.com/x/.config?x=b309c907eaab29da
dashboard link: https://syzkaller.appspot.com/bug?extid=9a29e1dba699b6f46a03
compiler: Debian clang version 20.1.7 (++20250616065708+6146a88f6049-1~exp1~20250616065826.132), Debian LLD 20.1.7
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1190fe8c580000
Downloadable assets:
disk image (non-bootable): https://storage.googleapis.com/syzbot-assets/d900f083ada3/non_bootable_disk-379f604c.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/355475904f2c/vmlinux-379f604c.xz
kernel image: https://storage.googleapis.com/syzbot-assets/c247a5b19c2d/bzImage-379f604c.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+9a29e1dba699b6f46a03@syzkaller.appspotmail.com
watchdog: BUG: soft lockup - CPU#0 stuck for 123s! [syz.0.2011:11811]
Modules linked in:
irq event stamp: 337922703
hardirqs last enabled at (337922702): [<ffffffff8185b0dd>] __local_bh_enable_ip+0x12d/0x1c0 kernel/softirq.c:412
hardirqs last disabled at (337922703): [<ffffffff8b6f3f4e>] sysvec_apic_timer_interrupt+0xe/0xc0 arch/x86/kernel/apic/apic.c:1050
softirqs last enabled at (584): [<ffffffff8b0f4de9>] spin_unlock_bh include/linux/spinlock.h:396 [inline]
softirqs last enabled at (584): [<ffffffff8b0f4de9>] tipc_skb_peek_port net/tipc/msg.h:1235 [inline]
softirqs last enabled at (584): [<ffffffff8b0f4de9>] tipc_sk_rcv+0x3e9/0x2ba0 net/tipc/socket.c:2489
softirqs last disabled at (586): [<ffffffff8b0f4e21>] spin_trylock_bh include/linux/spinlock.h:411 [inline]
softirqs last disabled at (586): [<ffffffff8b0f4e21>] tipc_sk_rcv+0x421/0x2ba0 net/tipc/socket.c:2494
CPU: 0 UID: 0 PID: 11811 Comm: syz.0.2011 Not tainted 6.16.0-rc5-syzkaller-00224-g379f604cc3dc #0 PREEMPT(full)
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014
RIP: 0010:should_resched arch/x86/include/asm/preempt.h:104 [inline]
RIP: 0010:__local_bh_enable_ip+0x135/0x1c0 kernel/softirq.c:414
Code: 8b e8 6f b2 e9 09 65 66 8b 05 6f 9f 1a 11 66 85 c0 75 5a bf 01 00 00 00 e8 a8 32 0b 00 e8 b3 11 42 00 fb 65 8b 05 4b 9f 1a 11 <85> c0 75 05 e8 82 f5 ad ff 48 c7 04 24 0e 36 e0 45 4b c7 04 37 00
RSP: 0018:ffffc9000e456540 EFLAGS: 00000286
RAX: 0000000000000201 RBX: 0000000000000201 RCX: 1216cf3644652a00
RDX: 0000000000000002 RSI: ffffffff8d998e51 RDI: ffffffff8be29e00
RBP: ffffc9000e4565d0 R08: ffffffff8fa1f5f7 R09: 1ffffffff1f43ebe
R10: dffffc0000000000 R11: fffffbfff1f43ebf R12: ffffffff8b0f4de9
R13: dffffc0000000000 R14: dffffc0000000000 R15: 1ffff92001c8aca8
FS: 00007fa71c0906c0(0000) GS:ffff88808d21b000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000200000009000 CR3: 0000000043757000 CR4: 0000000000352ef0
Call Trace:
<TASK>
spin_unlock_bh include/linux/spinlock.h:396 [inline]
tipc_skb_peek_port net/tipc/msg.h:1235 [inline]
tipc_sk_rcv+0x3e9/0x2ba0 net/tipc/socket.c:2489
tipc_node_xmit+0x1c9/0xe90 net/tipc/node.c:1701
tipc_node_xmit_skb+0xf4/0x150 net/tipc/node.c:1766
tipc_sk_rcv+0x29c4/0x2ba0 net/tipc/socket.c:2520
tipc_node_xmit+0x1c9/0xe90 net/tipc/node.c:1701
tipc_sk_push_backlog net/tipc/socket.c:1312 [inline]
tipc_sk_filter_connect net/tipc/socket.c:2253 [inline]
tipc_sk_filter_rcv+0x12a0/0x30b0 net/tipc/socket.c:2362
tipc_sk_enqueue net/tipc/socket.c:2443 [inline]
tipc_sk_rcv+0x8a5/0x2ba0 net/tipc/socket.c:2495
tipc_node_xmit+0x1c9/0xe90 net/tipc/node.c:1701
tipc_node_xmit_skb net/tipc/node.c:1766 [inline]
tipc_node_distr_xmit+0x2a0/0x3b0 net/tipc/node.c:1781
tipc_sk_backlog_rcv+0x1a1/0x230 net/tipc/socket.c:2410
sk_backlog_rcv include/net/sock.h:1148 [inline]
__release_sock+0x249/0x350 net/core/sock.c:3213
release_sock+0x5f/0x1f0 net/core/sock.c:3767
tipc_release+0x16e2/0x2160 net/tipc/socket.c:650
__sock_release net/socket.c:647 [inline]
sock_close+0xc3/0x240 net/socket.c:1391
__fput+0x449/0xa70 fs/file_table.c:465
task_work_run+0x1d1/0x260 kernel/task_work.c:227
resume_user_mode_work include/linux/resume_user_mode.h:50 [inline]
exit_to_user_mode_loop+0xec/0x110 kernel/entry/common.c:114
exit_to_user_mode_prepare include/linux/entry-common.h:330 [inline]
syscall_exit_to_user_mode_work include/linux/entry-common.h:414 [inline]
syscall_exit_to_user_mode include/linux/entry-common.h:449 [inline]
do_syscall_64+0x2bd/0x3b0 arch/x86/entry/syscall_64.c:100
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7fa71b18e929
Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007fa71c090038 EFLAGS: 00000246 ORIG_RAX: 000000000000002e
RAX: 00000000000203a0 RBX: 00007fa71b3b5fa0 RCX: 00007fa71b18e929
RDX: 0000000000000000 RSI: 00002000000003c0 RDI: 0000000000000003
RBP: 00007fa71b210b39 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 0000000000000000 R14: 00007fa71b3b5fa0 R15: 00007fffdf037f88
</TASK>
---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzkaller@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [syzbot] [bpf?] [sctp?] [tipc?] INFO: rcu detected stall in sock_close (5)
2025-07-16 17:01 [syzbot] [wireless?] INFO: rcu detected stall in sock_close (5) syzbot
@ 2026-07-22 15:42 ` syzbot
2026-07-23 2:31 ` Hillf Danton
2026-07-23 6:08 ` Forwarded: " syzbot
1 sibling, 1 reply; 5+ messages in thread
From: syzbot @ 2026-07-22 15:42 UTC (permalink / raw)
To: andrii, ast, bpf, daniel, davem, edumazet, horms, jmaloy, kuba,
linux-kernel, linux-sctp, linux-wireless, lucien.xin,
marcelo.leitner, netdev, pabeni, syzkaller-bugs, tipc-discussion
syzbot has found a reproducer for the following issue on:
HEAD commit: 248951ddc14d Merge tag 'hwmon-for-v7.2-rc5' of git://git.k..
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=15080ab9580000
kernel config: https://syzkaller.appspot.com/x/.config?x=98da55a882774dfe
dashboard link: https://syzkaller.appspot.com/bug?extid=9a29e1dba699b6f46a03
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=165d9746580000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=15ba2ab9580000
Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/cbba9d9c5929/disk-248951dd.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/84360c1cd7aa/vmlinux-248951dd.xz
kernel image: https://storage.googleapis.com/syzbot-assets/c128dc7a62e1/bzImage-248951dd.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+9a29e1dba699b6f46a03@syzkaller.appspotmail.com
rcu: INFO: rcu_preempt detected stalls on CPUs/tasks:
rcu: Tasks blocked on level-0 rcu_node (CPUs 0-1): P5985
rcu: (detected by 0, t=10502 jiffies, g=18453, q=4003 ncpus=2)
task:syz.0.20 state:R running task stack:22176 pid:5985 tgid:5984 ppid:5819 task_flags:0x400040 flags:0x00080002
Call Trace:
<IRQ>
sched_show_task+0x4aa/0x5f0 kernel/sched/core.c:8184
rcu_print_detail_task_stall_rnp kernel/rcu/tree_stall.h:292 [inline]
print_other_cpu_stall+0xf7b/0x1310 kernel/rcu/tree_stall.h:680
check_cpu_stall kernel/rcu/tree_stall.h:855 [inline]
rcu_pending kernel/rcu/tree.c:3708 [inline]
rcu_sched_clock_irq+0x93d/0x1050 kernel/rcu/tree.c:2744
update_process_times+0x234/0x2d0 kernel/time/timer.c:2475
tick_sched_handle kernel/time/tick-sched.c:296 [inline]
tick_nohz_handler+0x38f/0x6b0 kernel/time/tick-sched.c:317
__run_hrtimer kernel/time/hrtimer.c:2032 [inline]
__hrtimer_run_queues+0x3a0/0xaf0 kernel/time/hrtimer.c:2096
hrtimer_interrupt+0x44a/0x900 kernel/time/hrtimer.c:2215
local_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1051 [inline]
__sysvec_apic_timer_interrupt+0x102/0x430 arch/x86/kernel/apic/apic.c:1068
instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1062 [inline]
sysvec_apic_timer_interrupt+0xa1/0xc0 arch/x86/kernel/apic/apic.c:1062
</IRQ>
<TASK>
asm_sysvec_apic_timer_interrupt+0x1a/0x20 arch/x86/include/asm/idtentry.h:674
RIP: 0010:__local_bh_enable_ip+0x1c2/0x2b0 kernel/softirq.c:307
Code: f7 89 df e8 60 01 00 00 41 f7 c4 00 02 00 00 74 05 e8 c2 9e 45 00 9c 58 a9 00 02 00 00 75 23 41 f7 c4 00 02 00 00 74 01 fb 5b <41> 5c 41 5d 41 5e 41 5f 5d e9 00 97 be 09 cc 90 0f 0b 90 e9 66 fe
RSP: 0018:ffffc900040ee0f0 EFLAGS: 00000206
RAX: 0000000000000006 RBX: dffffc0000000000 RCX: 0000000000000046
RDX: 0000000000000002 RSI: ffffffff8d883356 RDI: ffffffff8bca6680
RBP: 1ffff11005252d1e R08: ffffffff8faf8df7 R09: 1ffffffff1f5f1be
R10: dffffc0000000000 R11: fffffbfff1f5f1bf R12: 0000000000000282
R13: dffffc0000000000 R14: ffff8880292968f4 R15: 0000000000000001
local_bh_enable include/linux/bottom_half.h:33 [inline]
spin_unlock_bh include/linux/spinlock_rt.h:116 [inline]
tipc_skb_peek_port net/tipc/msg.h:1235 [inline]
tipc_sk_rcv+0x44d/0x2b30 net/tipc/socket.c:2495
tipc_node_xmit+0x218/0xf10 net/tipc/node.c:1701
tipc_node_xmit_skb+0x139/0x1b0 net/tipc/node.c:1766
tipc_sk_rcv+0x2926/0x2b30 net/tipc/socket.c:2526
tipc_node_xmit+0x218/0xf10 net/tipc/node.c:1701
tipc_sk_push_backlog net/tipc/socket.c:1313 [inline]
tipc_sk_filter_connect net/tipc/socket.c:2259 [inline]
tipc_sk_filter_rcv+0x1811/0x3240 net/tipc/socket.c:2368
tipc_sk_enqueue net/tipc/socket.c:2449 [inline]
tipc_sk_rcv+0x8c4/0x2b30 net/tipc/socket.c:2501
tipc_node_xmit+0x218/0xf10 net/tipc/node.c:1701
tipc_node_xmit_skb net/tipc/node.c:1766 [inline]
tipc_node_distr_xmit+0x2da/0x420 net/tipc/node.c:1781
tipc_sk_backlog_rcv+0x1b6/0x280 net/tipc/socket.c:2416
sk_backlog_rcv include/net/sock.h:1190 [inline]
__release_sock+0x2b2/0x3d0 net/core/sock.c:3261
release_sock+0x1be/0x290 net/core/sock.c:3860
tipc_release+0x1abe/0x2500 net/tipc/socket.c:651
__sock_release net/socket.c:710 [inline]
sock_close+0xad/0x220 net/socket.c:1501
__fput+0x42a/0xa80 fs/file_table.c:512
task_work_run+0x1d9/0x270 kernel/task_work.c:233
resume_user_mode_work include/linux/resume_user_mode.h:50 [inline]
__exit_to_user_mode_loop kernel/entry/common.c:70 [inline]
exit_to_user_mode_loop+0x1fa/0x730 kernel/entry/common.c:101
__exit_to_user_mode_prepare include/linux/irq-entry-common.h:207 [inline]
syscall_exit_to_user_mode_prepare include/linux/irq-entry-common.h:230 [inline]
syscall_exit_to_user_mode include/linux/entry-common.h:318 [inline]
do_syscall_64+0x353/0x580 arch/x86/entry/syscall_64.c:100
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f7460e5de99
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007f74604be028 EFLAGS: 00000246 ORIG_RAX: 000000000000002e
RAX: 00000000000203a0 RBX: 00007f74610e5fa0 RCX: 00007f7460e5de99
RDX: 0000000000000000 RSI: 00002000000003c0 RDI: 0000000000000003
RBP: 00007f7460ef3eaf R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007f74610e6038 R14: 00007f74610e5fa0 R15: 00007ffc753a57c8
</TASK>
---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [syzbot] [bpf?] [sctp?] [tipc?] INFO: rcu detected stall in sock_close (5)
2026-07-22 15:42 ` [syzbot] [bpf?] [sctp?] [tipc?] " syzbot
@ 2026-07-23 2:31 ` Hillf Danton
2026-07-23 3:25 ` syzbot
0 siblings, 1 reply; 5+ messages in thread
From: Hillf Danton @ 2026-07-23 2:31 UTC (permalink / raw)
To: syzbot; +Cc: linux-kernel, syzkaller-bugs
> Date: Wed, 22 Jul 2026 08:42:25 -0700
> syzbot has found a reproducer for the following issue on:
>
> HEAD commit: 248951ddc14d Merge tag 'hwmon-for-v7.2-rc5' of git://git.k..
> git tree: upstream
> console output: https://syzkaller.appspot.com/x/log.txt?x=15080ab9580000
> kernel config: https://syzkaller.appspot.com/x/.config?x=98da55a882774dfe
> dashboard link: https://syzkaller.appspot.com/bug?extid=9a29e1dba699b6f46a03
> syz repro: https://syzkaller.appspot.com/x/repro.syz?x=165d9746580000
> C reproducer: https://syzkaller.appspot.com/x/repro.c?x=15ba2ab9580000
#syz test
--- x/net/tipc/socket.c
+++ y/net/tipc/socket.c
@@ -2489,7 +2489,10 @@ void tipc_sk_rcv(struct net *net, struct
struct tipc_sock *tsk;
struct sock *sk;
struct sk_buff *skb;
+ static int nogo = 0;
+ if (nogo)
+ return;
__skb_queue_head_init(&xmitq);
while (skb_queue_len(inputq)) {
dport = tipc_skb_peek_port(inputq, dport);
@@ -2498,7 +2501,9 @@ void tipc_sk_rcv(struct net *net, struct
if (likely(tsk)) {
sk = &tsk->sk;
if (likely(spin_trylock_bh(&sk->sk_lock.slock))) {
+ nogo = 1;
tipc_sk_enqueue(inputq, sk, dport, &xmitq);
+ nogo = 0;
spin_unlock_bh(&sk->sk_lock.slock);
}
/* Send pending response/rejected messages, if any */
--
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [syzbot] [bpf?] [sctp?] [tipc?] INFO: rcu detected stall in sock_close (5)
2026-07-23 2:31 ` Hillf Danton
@ 2026-07-23 3:25 ` syzbot
0 siblings, 0 replies; 5+ messages in thread
From: syzbot @ 2026-07-23 3:25 UTC (permalink / raw)
To: hdanton, linux-kernel, syzkaller-bugs
Hello,
syzbot has tested the proposed patch but the reproducer is still triggering an issue:
lost connection to test machine
Tested on:
commit: 4539944e Merge tag 'liveupdate-fixes-2026-07-22' of gi..
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=10b0eab9580000
kernel config: https://syzkaller.appspot.com/x/.config?x=98da55a882774dfe
dashboard link: https://syzkaller.appspot.com/bug?extid=9a29e1dba699b6f46a03
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
patch: https://syzkaller.appspot.com/x/patch.diff?x=154e5746580000
^ permalink raw reply [flat|nested] 5+ messages in thread
* Forwarded: Re: [syzbot] [bpf?] [sctp?] [tipc?] INFO: rcu detected stall in sock_close (5)
2025-07-16 17:01 [syzbot] [wireless?] INFO: rcu detected stall in sock_close (5) syzbot
2026-07-22 15:42 ` [syzbot] [bpf?] [sctp?] [tipc?] " syzbot
@ 2026-07-23 6:08 ` syzbot
1 sibling, 0 replies; 5+ messages in thread
From: syzbot @ 2026-07-23 6:08 UTC (permalink / raw)
To: linux-kernel, syzkaller-bugs
For archival purposes, forwarding an incoming command email to
linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com.
***
Subject: Re: [syzbot] [bpf?] [sctp?] [tipc?] INFO: rcu detected stall in sock_close (5)
Author: xuanqiang.luo@linux.dev
From: luoxuanqiang <luoxuanqiang@kylinos.cn>
tipc_sk_rcv() holds the destination socket spinlock while filtering
incoming messages. The filter may flush the Nagle write backlog, and
tipc_sk_push_backlog() currently transmits it immediately.
For local delivery, that transmission re-enters tipc_sk_rcv(). A
returned message can then target the socket locked by the outer receive
call. Its spin_trylock_bh() never succeeds, the input skb is never
dequeued, and the receive loop spins until an RCU stall is reported.
Detach a pending write backlog while the socket lock is held and
transmit it immediately after releasing the lock. Temporarily mark the
socket congested while the queue is detached so concurrent senders
cannot overtake it. Preserve real link congestion on -ELINKCONG;
otherwise clear the temporary state and wake writers.
Fixes: c0bceb97db9e ("tipc: add smart nagle feature")
Reported-by: syzbot+9a29e1dba699b6f46a03@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=9a29e1dba699b6f46a03
Signed-off-by: luoxuanqiang <luoxuanqiang@kylinos.cn>
#syz test: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git 248951ddc14de84de3910f9b13f51491a8cd91df
---
net/tipc/socket.c | 69 +++++++++++++++++++++++++++++++++++------------
1 file changed, 52 insertions(+), 17 deletions(-)
diff --git a/net/tipc/socket.c b/net/tipc/socket.c
index e564341e0216..73c7c966c98c 100644
--- a/net/tipc/socket.c
+++ b/net/tipc/socket.c
@@ -156,7 +156,8 @@ static int tipc_sk_insert(struct tipc_sock *tsk);
static void tipc_sk_remove(struct tipc_sock *tsk);
static int __tipc_sendstream(struct socket *sock, struct msghdr *m, size_t dsz);
static int __tipc_sendmsg(struct socket *sock, struct msghdr *m, size_t dsz);
-static void tipc_sk_push_backlog(struct tipc_sock *tsk, bool nagle_ack);
+static void tipc_sk_push_backlog(struct tipc_sock *tsk, bool nagle_ack,
+ struct sk_buff_head *deferq);
static int tipc_wait_for_connect(struct socket *sock, long *timeo_p);
static const struct proto_ops packet_ops;
@@ -560,7 +561,7 @@ static void __tipc_shutdown(struct socket *sock, int error)
!tsk_conn_cong(tsk)));
/* Push out delayed messages if in Nagle mode */
- tipc_sk_push_backlog(tsk, false);
+ tipc_sk_push_backlog(tsk, false, NULL);
/* Remove pending SYN */
__skb_queue_purge(&sk->sk_write_queue);
@@ -1268,7 +1269,8 @@ void tipc_sk_mcast_rcv(struct net *net, struct sk_buff_head *arrvq,
/* tipc_sk_push_backlog(): send accumulated buffers in socket write queue
* when socket is in Nagle mode
*/
-static void tipc_sk_push_backlog(struct tipc_sock *tsk, bool nagle_ack)
+static void tipc_sk_push_backlog(struct tipc_sock *tsk, bool nagle_ack,
+ struct sk_buff_head *deferq)
{
struct sk_buff_head *txq = &tsk->sk.sk_write_queue;
struct sk_buff *skb = skb_peek_tail(txq);
@@ -1310,6 +1312,12 @@ static void tipc_sk_push_backlog(struct tipc_sock *tsk, bool nagle_ack)
tsk->pkt_cnt += skb_queue_len(txq);
tsk->snt_unacked += tsk->snd_backlog;
tsk->snd_backlog = 0;
+ if (deferq) {
+ /* Block concurrent senders until the detached queue is sent. */
+ tsk->cong_link_cnt = 1;
+ skb_queue_splice_tail_init(txq, deferq);
+ return;
+ }
rc = tipc_node_xmit(net, txq, dnode, tsk->portid);
if (rc == -ELINKCONG)
tsk->cong_link_cnt = 1;
@@ -1321,10 +1329,12 @@ static void tipc_sk_push_backlog(struct tipc_sock *tsk, bool nagle_ack)
* @skb: pointer to message buffer.
* @inputq: buffer list containing the buffers
* @xmitq: output message area
+ * @deferq: socket write queue to transmit after releasing the socket lock
*/
static void tipc_sk_conn_proto_rcv(struct tipc_sock *tsk, struct sk_buff *skb,
struct sk_buff_head *inputq,
- struct sk_buff_head *xmitq)
+ struct sk_buff_head *xmitq,
+ struct sk_buff_head *deferq)
{
struct tipc_msg *hdr = buf_msg(skb);
u32 onode = tsk_own_node(tsk);
@@ -1367,7 +1377,7 @@ static void tipc_sk_conn_proto_rcv(struct tipc_sock *tsk, struct sk_buff *skb,
goto exit;
was_cong = tsk_conn_cong(tsk);
- tipc_sk_push_backlog(tsk, msg_nagle_ack(hdr));
+ tipc_sk_push_backlog(tsk, msg_nagle_ack(hdr), deferq);
tsk->snt_unacked -= msg_conn_ack(hdr);
if (tsk->peer_caps & TIPC_BLOCK_FLOWCTL)
tsk->snd_win = msg_adv_win(hdr);
@@ -2147,7 +2157,8 @@ static void tipc_sock_destruct(struct sock *sk)
static void tipc_sk_proto_rcv(struct sock *sk,
struct sk_buff_head *inputq,
- struct sk_buff_head *xmitq)
+ struct sk_buff_head *xmitq,
+ struct sk_buff_head *deferq)
{
struct sk_buff *skb = __skb_dequeue(inputq);
struct tipc_sock *tsk = tipc_sk(sk);
@@ -2157,7 +2168,7 @@ static void tipc_sk_proto_rcv(struct sock *sk,
switch (msg_user(hdr)) {
case CONN_MANAGER:
- tipc_sk_conn_proto_rcv(tsk, skb, inputq, xmitq);
+ tipc_sk_conn_proto_rcv(tsk, skb, inputq, xmitq, deferq);
return;
case SOCK_WAKEUP:
tipc_dest_del(&tsk->cong_links, msg_orignode(hdr), 0);
@@ -2165,7 +2176,7 @@ static void tipc_sk_proto_rcv(struct sock *sk,
smp_wmb();
tsk->cong_link_cnt--;
wakeup = true;
- tipc_sk_push_backlog(tsk, false);
+ tipc_sk_push_backlog(tsk, false, deferq);
break;
case GROUP_PROTOCOL:
tipc_group_proto_rcv(grp, &wakeup, hdr, inputq, xmitq);
@@ -2189,10 +2200,12 @@ static void tipc_sk_proto_rcv(struct sock *sk,
* @tsk: TIPC socket
* @skb: pointer to message buffer.
* @xmitq: for Nagle ACK if any
+ * @deferq: socket write queue to transmit after releasing the socket lock
* Return: true if message should be added to receive queue, false otherwise
*/
static bool tipc_sk_filter_connect(struct tipc_sock *tsk, struct sk_buff *skb,
- struct sk_buff_head *xmitq)
+ struct sk_buff_head *xmitq,
+ struct sk_buff_head *deferq)
{
struct sock *sk = &tsk->sk;
struct net *net = sock_net(sk);
@@ -2256,7 +2269,7 @@ static bool tipc_sk_filter_connect(struct tipc_sock *tsk, struct sk_buff *skb,
return false;
case TIPC_ESTABLISHED:
if (!skb_queue_empty(&sk->sk_write_queue))
- tipc_sk_push_backlog(tsk, false);
+ tipc_sk_push_backlog(tsk, false, deferq);
/* Accept only connection-based messages sent by peer */
if (likely(con_msg && !err && pport == oport &&
pnode == onode)) {
@@ -2329,6 +2342,7 @@ static unsigned int rcvbuf_limit(struct sock *sk, struct sk_buff *skb)
* @sk: socket
* @skb: pointer to message.
* @xmitq: output message area (FIXME)
+ * @deferq: socket write queue to transmit after releasing the socket lock
*
* Enqueues message on receive queue if acceptable; optionally handles
* disconnect indication for a connected socket.
@@ -2336,7 +2350,8 @@ static unsigned int rcvbuf_limit(struct sock *sk, struct sk_buff *skb)
* Called with socket lock already taken
*/
static void tipc_sk_filter_rcv(struct sock *sk, struct sk_buff *skb,
- struct sk_buff_head *xmitq)
+ struct sk_buff_head *xmitq,
+ struct sk_buff_head *deferq)
{
bool sk_conn = !tipc_sk_type_connectionless(sk);
struct tipc_sock *tsk = tipc_sk(sk);
@@ -2353,7 +2368,7 @@ static void tipc_sk_filter_rcv(struct sock *sk, struct sk_buff *skb,
__skb_queue_tail(&inputq, skb);
if (unlikely(!msg_isdata(hdr)))
- tipc_sk_proto_rcv(sk, &inputq, xmitq);
+ tipc_sk_proto_rcv(sk, &inputq, xmitq, deferq);
if (unlikely(grp))
tipc_group_filter_msg(grp, &inputq, xmitq);
@@ -2365,7 +2380,8 @@ static void tipc_sk_filter_rcv(struct sock *sk, struct sk_buff *skb,
while ((skb = __skb_dequeue(&inputq))) {
hdr = buf_msg(skb);
limit = rcvbuf_limit(sk, skb);
- if ((sk_conn && !tipc_sk_filter_connect(tsk, skb, xmitq)) ||
+ if ((sk_conn &&
+ !tipc_sk_filter_connect(tsk, skb, xmitq, deferq)) ||
(!sk_conn && msg_connected(hdr)) ||
(!grp && msg_in_group(hdr)))
err = TIPC_ERR_NO_PORT;
@@ -2408,7 +2424,7 @@ static int tipc_sk_backlog_rcv(struct sock *sk, struct sk_buff *skb)
__skb_queue_head_init(&xmitq);
- tipc_sk_filter_rcv(sk, skb, &xmitq);
+ tipc_sk_filter_rcv(sk, skb, &xmitq, NULL);
added = sk_rmem_alloc_get(sk) - before;
atomic_add(added, &tipc_sk(sk)->dupl_rcvcnt);
@@ -2424,11 +2440,13 @@ static int tipc_sk_backlog_rcv(struct sock *sk, struct sk_buff *skb)
* @sk: socket where the buffers should be enqueued
* @dport: port number for the socket
* @xmitq: output queue
+ * @deferq: socket write queue to transmit after releasing the socket lock
*
* Caller must hold socket lock
*/
static void tipc_sk_enqueue(struct sk_buff_head *inputq, struct sock *sk,
- u32 dport, struct sk_buff_head *xmitq)
+ u32 dport, struct sk_buff_head *xmitq,
+ struct sk_buff_head *deferq)
{
unsigned long time_limit = jiffies + usecs_to_jiffies(20000);
struct sk_buff *skb;
@@ -2446,7 +2464,9 @@ static void tipc_sk_enqueue(struct sk_buff_head *inputq, struct sock *sk,
/* Add message directly to receive queue if possible */
if (!sock_owned_by_user(sk)) {
- tipc_sk_filter_rcv(sk, skb, xmitq);
+ tipc_sk_filter_rcv(sk, skb, xmitq, deferq);
+ if (deferq && !skb_queue_empty(deferq))
+ return;
continue;
}
@@ -2483,6 +2503,7 @@ static void tipc_sk_enqueue(struct sk_buff_head *inputq, struct sock *sk,
*/
void tipc_sk_rcv(struct net *net, struct sk_buff_head *inputq)
{
+ struct sk_buff_head deferq;
struct sk_buff_head xmitq;
u32 dnode, dport = 0;
int err;
@@ -2490,6 +2511,7 @@ void tipc_sk_rcv(struct net *net, struct sk_buff_head *inputq)
struct sock *sk;
struct sk_buff *skb;
+ __skb_queue_head_init(&deferq);
__skb_queue_head_init(&xmitq);
while (skb_queue_len(inputq)) {
dport = tipc_skb_peek_port(inputq, dport);
@@ -2498,9 +2520,22 @@ void tipc_sk_rcv(struct net *net, struct sk_buff_head *inputq)
if (likely(tsk)) {
sk = &tsk->sk;
if (likely(spin_trylock_bh(&sk->sk_lock.slock))) {
- tipc_sk_enqueue(inputq, sk, dport, &xmitq);
+ tipc_sk_enqueue(inputq, sk, dport, &xmitq,
+ &deferq);
+ if (!skb_queue_empty(&deferq))
+ dnode = tsk_peer_node(tsk);
spin_unlock_bh(&sk->sk_lock.slock);
}
+ if (!skb_queue_empty(&deferq)) {
+ err = tipc_node_xmit(sock_net(sk), &deferq,
+ dnode, dport);
+ if (err != -ELINKCONG) {
+ spin_lock_bh(&sk->sk_lock.slock);
+ tsk->cong_link_cnt = 0;
+ sk->sk_write_space(sk);
+ spin_unlock_bh(&sk->sk_lock.slock);
+ }
+ }
/* Send pending response/rejected messages, if any */
tipc_node_distr_xmit(sock_net(sk), &xmitq);
sock_put(sk);
--
2.39.3 (Apple Git-145)
^ permalink raw reply related [flat|nested] 5+ messages in thread
end of thread, other threads:[~2026-07-23 6:08 UTC | newest]
Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2025-07-16 17:01 [syzbot] [wireless?] INFO: rcu detected stall in sock_close (5) syzbot
2026-07-22 15:42 ` [syzbot] [bpf?] [sctp?] [tipc?] " syzbot
2026-07-23 2:31 ` Hillf Danton
2026-07-23 3:25 ` syzbot
2026-07-23 6:08 ` Forwarded: " syzbot
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.