All of lore.kernel.org
 help / color / mirror / Atom feed
From: Matthieu Baerts <matttbe@kernel.org>
To: Paolo Abeni <pabeni@redhat.com>
Cc: Geliang Tang <geliang@kernel.org>,
	quanyeyang@proton.me, MPTCP Linux <mptcp@lists.linux.dev>
Subject: Re: [PATCH mptcp-net v3 1/3] mptcp: fix data-race in __mptcp_retrans / mptcp_incoming_options
Date: Mon, 7 Sep 2026 15:55:34 +0200	[thread overview]
Message-ID: <f61eb670-8db3-4c97-92fd-b66294ef222e@kernel.org> (raw)
In-Reply-To: <87fb99e7-df73-46b8-97a1-4d6173121ab5@redhat.com>

Hi Paolo,

On 07/09/2026 15:38, Paolo Abeni wrote:
> On 9/7/26 12:15 PM, quanyeyang@proton.me wrote:
>> From: "Matthieu Baerts (NGI0)" <matttbe@kernel.org>
>>
>> SyzKaller found this data-race:
>>
>>   BUG: KCSAN: data-race in __mptcp_retrans / mptcp_incoming_options
>>
>>   write (marked) to 0xffff888015e8e5f0 of 8 bytes by interrupt on cpu 0:
>>    __mptcp_snd_una_update net/mptcp/options.c:1055 [inline]
>>    mptcp_incoming_options+0x6a3/0x1ac0 net/mptcp/options.c:1183
>>    tcp_data_queue+0x101b/0x2440 net/ipv4/tcp_input.c:5583
>>    tcp_rcv_established+0x684/0x1fc0 net/ipv4/tcp_input.c:6654
>>    tcp_v4_do_rcv+0x35c/0x690 net/ipv4/tcp_ipv4.c:1866
>>    tcp_v4_rcv+0x1d91/0x25a0 net/ipv4/tcp_ipv4.c:2263
>>    ip_protocol_deliver_rcu+0x46/0x280 net/ipv4/ip_input.c:207
>>    ip_local_deliver_finish+0x190/0x270 net/ipv4/ip_input.c:241
>>    NF_HOOK include/linux/netfilter.h:318 [inline]
>>    NF_HOOK include/linux/netfilter.h:312 [inline]
>>    ip_local_deliver+0xe3/0x210 net/ipv4/ip_input.c:262
>>    dst_input include/net/dst.h:480 [inline]
>>    ip_rcv_finish net/ipv4/ip_input.c:492 [inline]
>>    NF_HOOK include/linux/netfilter.h:318 [inline]
>>    NF_HOOK include/linux/netfilter.h:312 [inline]
>>    ip_rcv+0x200/0x220 net/ipv4/ip_input.c:612
>>    __netif_receive_skb_one_core+0xeb/0x110 net/core/dev.c:6178
>>    __netif_receive_skb+0x1f/0xc0 net/core/dev.c:6291
>>    process_backlog+0x168/0x360 net/core/dev.c:6642
>>    __napi_poll+0x71/0x460 net/core/dev.c:7706
>>    napi_poll net/core/dev.c:7769 [inline]
>>    net_rx_action+0x6f8/0x810 net/core/dev.c:7926
>>    handle_softirqs+0xc9/0x2e0 kernel/softirq.c:622
>>    run_ksoftirqd kernel/softirq.c:1063 [inline]
>>    run_ksoftirqd+0x20/0x30 kernel/softirq.c:1055
>>    smpboot_thread_fn+0x287/0x520 kernel/smpboot.c:160
>>    kthread+0x1f2/0x240 kernel/kthread.c:436
>>    ret_from_fork+0x321/0x440 arch/x86/kernel/process.c:158
>>    ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
>>
>>   read to 0xffff888015e8e5f0 of 8 bytes by task 24 on cpu 1:
>>    mptcp_rtx_head net/mptcp/protocol.h:487 [inline]
>>    __mptcp_retrans+0x169/0x8f0 net/mptcp/protocol.c:2759
>>    mptcp_worker+0x6a6/0xb30 net/mptcp/protocol.c:2980
>>    process_one_work+0x3ee/0x970 kernel/workqueue.c:3275
>>    process_scheduled_works kernel/workqueue.c:3358 [inline]
>>    worker_thread+0x3c3/0x730 kernel/workqueue.c:3439
>>    kthread+0x1f2/0x240 kernel/kthread.c:436
>>    ret_from_fork+0x321/0x440 arch/x86/kernel/process.c:158
>>    ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
> 
> I think this race is not present in the current tree, after commit
> 96d846e3e2a7 ("mptcp: let the retrans scheduler do its job").
Thank you for having checked. Good point, this old patch is maybe
outdated, I didn't check.

Note that on syzkaller side, the last occurrence I had for this issue
was on the 13th of May, and your patch was in on tree on the 3rd of
June. I guess it is indeed not needed then. (I don't know why I didn't
see it after the 13th of May, but there were no reproducers.)

Cheers,
Matt
-- 
Sponsored by the NGI0 Core fund.


  reply	other threads:[~2026-09-07 13:55 UTC|newest]

Thread overview: 13+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-07 10:15 [PATCH mptcp-net v3 0/3] mptcp: fix reported data-races quanyeyang
2026-09-07 10:15 ` [PATCH mptcp-net v3 1/3] mptcp: fix data-race in __mptcp_retrans / mptcp_incoming_options quanyeyang
2026-09-07 13:38   ` Paolo Abeni
2026-09-07 13:55     ` Matthieu Baerts [this message]
2026-09-07 10:15 ` [PATCH mptcp-net v3 2/3] mptcp: fix data-race in mptcp_subflow_get_send / tcp_ack Quanye Yang via B4 Relay
2026-09-07 10:15   ` Quanye Yang
2026-09-07 10:15 ` [PATCH mptcp-net v3 3/3] tcp: fix data-race in do_recvmmsg / mptcp_recvmsg Quanye Yang via B4 Relay
2026-09-07 10:15   ` Quanye Yang
2026-09-07 10:24   ` sashiko-bot
2026-09-07 13:23     ` quanyeyang
2026-09-07 13:46   ` Paolo Abeni
2026-09-07 14:38     ` quanyeyang
2026-09-07 11:28 ` [PATCH mptcp-net v3 0/3] mptcp: fix reported data-races MPTCP CI

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=f61eb670-8db3-4c97-92fd-b66294ef222e@kernel.org \
    --to=matttbe@kernel.org \
    --cc=geliang@kernel.org \
    --cc=mptcp@lists.linux.dev \
    --cc=pabeni@redhat.com \
    --cc=quanyeyang@proton.me \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.