From: "Matthieu Baerts (NGI0)" <matttbe@kernel.org>
To: MPTCP Upstream <mptcp@lists.linux.dev>
Cc: "Matthieu Baerts (NGI0)" <matttbe@kernel.org>
Subject: [PATCH mptcp-net v5 05/20] mptcp: pm: ADD_ADDR rtx: free sk if last
Date: Wed, 15 Apr 2026 11:56:53 +0200 [thread overview]
Message-ID: <20260415-mptcp-inc-limits-v5-5-e54c3bf80e4e@kernel.org> (raw)
In-Reply-To: <20260415-mptcp-inc-limits-v5-0-e54c3bf80e4e@kernel.org>
When an ADD_ADDR is retransmitted, the sk is held in sk_reset_timer(),
and released at the end.
If at that moment, it was the last reference being held, the sk would
not be freed. sock_put() should then be called instead of __sock_put().
But that's not enough: if it is the last reference, sock_put() will call
sk_free(), which will end up calling sk_stop_timer_sync() on the same
timer, and waiting indefinitely to finish. So it is needed to mark that
the timer is done at the end of the timer handler when it has not been
rescheduled, not to call sk_stop_timer_sync() on "itself".
Fixes: 00cfd77b9063 ("mptcp: retransmit ADD_ADDR when timeout")
Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
---
v3: support calling sk_free() from the timer handler. Note: I'm not very
happy with this patch, it looks too big. Did I miss a simpler way?
v4: init timer_done after 'reset_timer' label to handle cases where the
sysctl is changed in between.
v5: only set timer_done to true in the timer handler, safer and easier.
---
net/mptcp/pm.c | 30 +++++++++++++++++++-----------
1 file changed, 19 insertions(+), 11 deletions(-)
diff --git a/net/mptcp/pm.c b/net/mptcp/pm.c
index d3fcf441b208..0ff35f49d451 100644
--- a/net/mptcp/pm.c
+++ b/net/mptcp/pm.c
@@ -16,6 +16,7 @@ struct mptcp_pm_add_entry {
struct list_head list;
struct mptcp_addr_info addr;
u8 retrans_times;
+ bool timer_done;
struct timer_list add_timer;
struct mptcp_sock *sock;
struct rcu_head rcu;
@@ -327,22 +328,22 @@ static void mptcp_pm_add_timer(struct timer_list *timer)
add_timer);
struct mptcp_sock *msk = entry->sock;
struct sock *sk = (struct sock *)msk;
- unsigned int timeout;
+ unsigned int timeout = 0;
pr_debug("msk=%p\n", msk);
- if (unlikely(inet_sk_state_load(sk) == TCP_CLOSE))
- goto exit;
-
bh_lock_sock(sk);
+ if (unlikely(inet_sk_state_load(sk) == TCP_CLOSE))
+ goto out;
+
if (sock_owned_by_user(sk)) {
/* Try again later. */
- sk_reset_timer(sk, timer, jiffies + HZ / 20);
+ timeout = HZ / 20;
goto out;
}
if (mptcp_pm_should_add_signal_addr(msk)) {
- sk_reset_timer(sk, timer, jiffies + TCP_RTO_MAX / 8);
+ timeout = TCP_RTO_MAX / 8;
goto out;
}
@@ -360,8 +361,9 @@ static void mptcp_pm_add_timer(struct timer_list *timer)
}
if (entry->retrans_times < ADD_ADDR_RETRANS_MAX)
- sk_reset_timer(sk, timer,
- jiffies + (timeout << entry->retrans_times));
+ timeout <<= entry->retrans_times;
+ else
+ timeout = 0;
spin_unlock_bh(&msk->pm.lock);
@@ -369,9 +371,13 @@ static void mptcp_pm_add_timer(struct timer_list *timer)
mptcp_pm_subflow_established(msk);
out:
+ if (timeout)
+ sk_reset_timer(sk, timer, jiffies + timeout);
+ else
+ /* if sock_put calls sk_free: avoid waiting for this timer */
+ entry->timer_done = true;
bh_unlock_sock(sk);
-exit:
- __sock_put(sk);
+ sock_put(sk);
}
struct mptcp_pm_add_entry *
@@ -434,6 +440,7 @@ bool mptcp_pm_alloc_anno_list(struct mptcp_sock *msk,
timer_setup(&add_entry->add_timer, mptcp_pm_add_timer, 0);
reset_timer:
+ add_entry->timer_done = false;
timeout = mptcp_adjust_add_addr_timeout(msk);
if (timeout)
sk_reset_timer(sk, &add_entry->add_timer, jiffies + timeout);
@@ -454,7 +461,8 @@ static void mptcp_pm_free_anno_list(struct mptcp_sock *msk)
spin_unlock_bh(&msk->pm.lock);
list_for_each_entry_safe(entry, tmp, &free_list, list) {
- sk_stop_timer_sync(sk, &entry->add_timer);
+ if (!entry->timer_done)
+ sk_stop_timer_sync(sk, &entry->add_timer);
kfree_rcu(entry, rcu);
}
}
--
2.53.0
next prev parent reply other threads:[~2026-04-15 9:58 UTC|newest]
Thread overview: 35+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-04-15 9:56 [PATCH mptcp-net v5 00/20] mptcp: pm: increase limits, and related fixes and cleanup Matthieu Baerts (NGI0)
2026-04-15 9:56 ` [PATCH mptcp-net v5 01/20] mptcp: pm: kernel: correctly retransmit ADD_ADDR ID 0 Matthieu Baerts (NGI0)
2026-04-15 9:56 ` [PATCH mptcp-net v5 02/20] mptcp: pm: ADD_ADDR rtx: fix potential data-race Matthieu Baerts (NGI0)
2026-04-15 9:56 ` [PATCH mptcp-net v5 03/20] mptcp: pm: ADD_ADDR rtx: allow ID 0 Matthieu Baerts (NGI0)
2026-04-15 9:56 ` [PATCH mptcp-net v5 04/20] mptcp: pm: ADD_ADDR rtx: always decrease sk refcount Matthieu Baerts (NGI0)
2026-04-15 17:09 ` Matthieu Baerts
2026-04-15 9:56 ` Matthieu Baerts (NGI0) [this message]
2026-04-18 18:00 ` [PATCH mptcp-net v5 05/20] mptcp: pm: ADD_ADDR rtx: free sk if last Mat Martineau
2026-04-20 17:12 ` Matthieu Baerts
2026-04-20 21:07 ` Mat Martineau
2026-04-15 9:56 ` [PATCH mptcp-net v5 06/20] mptcp: pm: ADD_ADDR rtx: resched blocked ADD_ADDR quicker Matthieu Baerts (NGI0)
2026-04-15 9:56 ` [PATCH mptcp-net v5 07/20] mptcp: pm: ADD_ADDR rtx: skip inactive subflows Matthieu Baerts (NGI0)
2026-04-18 18:09 ` Mat Martineau
2026-04-20 17:18 ` Matthieu Baerts
2026-04-20 21:07 ` Mat Martineau
2026-04-15 9:56 ` [PATCH mptcp-net v5 08/20] mptcp: pm: retrans ADD_ADDR: return early if no retrans Matthieu Baerts (NGI0)
2026-04-15 9:56 ` [PATCH mptcp-net v5 09/20] mptcp: pm: prio: skip closed subflows Matthieu Baerts (NGI0)
2026-04-15 9:56 ` [PATCH mptcp-net v5 10/20] selftests: mptcp: check output: catch cmd errors Matthieu Baerts (NGI0)
2026-04-15 9:56 ` [PATCH mptcp-net v5 11/20] selftests: mptcp: pm: restrict 'unknown' check to pm_nl_ctl Matthieu Baerts (NGI0)
2026-04-15 9:57 ` [PATCH mptcp-net v5 12/20] mptcp: pm: in-kernel: explicitly limit batches to array size Matthieu Baerts (NGI0)
2026-04-15 9:57 ` [PATCH mptcp-net v5 13/20] mptcp: pm: in-kernel: increase all limits to 64 Matthieu Baerts (NGI0)
2026-04-15 9:57 ` [PATCH mptcp-net v5 14/20] mptcp: pm: kernel: allow flushing more than 8 endpoints Matthieu Baerts (NGI0)
2026-04-15 9:57 ` [PATCH mptcp-net v5 15/20] mptcp: pm: in-kernel: increase endpoints limit Matthieu Baerts (NGI0)
2026-04-15 17:10 ` Matthieu Baerts
2026-04-15 9:57 ` [PATCH mptcp-net v5 16/20] selftests: mptcp: join: allow changing ifaces nr per test Matthieu Baerts (NGI0)
2026-04-15 9:57 ` [PATCH mptcp-net v5 17/20] selftests: mptcp: join: validate 8x8 subflows Matthieu Baerts (NGI0)
2026-04-18 18:22 ` Mat Martineau
2026-04-20 17:30 ` Matthieu Baerts
2026-04-20 21:11 ` Mat Martineau
2026-04-15 9:57 ` [PATCH mptcp-net v5 18/20] selftests: mptcp: pm: validate new limits Matthieu Baerts (NGI0)
2026-04-15 9:57 ` [PATCH mptcp-net v5 19/20] selftests: mptcp: pm: use simpler send/recv forms Matthieu Baerts (NGI0)
2026-04-15 9:57 ` [PATCH mptcp-net v5 20/20] mptcp: pm: clearer ADD_ADDR related helpers names Matthieu Baerts (NGI0)
2026-04-18 18:27 ` Mat Martineau
2026-04-20 17:50 ` Matthieu Baerts
2026-04-15 11:32 ` [PATCH mptcp-net v5 00/20] mptcp: pm: increase limits, and related fixes and cleanup MPTCP CI
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260415-mptcp-inc-limits-v5-5-e54c3bf80e4e@kernel.org \
--to=matttbe@kernel.org \
--cc=mptcp@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox