* [PATCH 6.1.y 0/3] mptcp: fix recent failed backports (20260919)
@ 2026-09-19 20:12 Matthieu Baerts (NGI0)
2026-09-19 20:12 ` [PATCH 6.1.y 1/3] mptcp: consolidate subflow cleanup Matthieu Baerts (NGI0)
` (2 more replies)
0 siblings, 3 replies; 9+ messages in thread
From: Matthieu Baerts (NGI0) @ 2026-09-19 20:12 UTC (permalink / raw)
To: mptcp, stable, gregkh; +Cc: Matthieu Baerts (NGI0), sashal
The following patches could not be applied without conflicts in this
tree:
- 2b0f561f21b2 ("mptcp: avoid unneeded actions on subflow reset")
- 42064de57fb8 ("mptcp: close race between scheduler and state change")
I backported the following commit to avoid conflicts:
- c3349a22c200 ("mptcp: consolidate subflow cleanup")
Conflicts (if any) have been resolved, and documented in each patch.
Paolo Abeni (3):
mptcp: consolidate subflow cleanup
mptcp: avoid unneeded actions on subflow reset
mptcp: close race between scheduler and state change
net/mptcp/protocol.c | 10 ++++++----
net/mptcp/protocol.h | 3 ++-
net/mptcp/subflow.c | 46 ++++++++++++++++++++++++++++----------------
3 files changed, 37 insertions(+), 22 deletions(-)
--
2.55.0
^ permalink raw reply [flat|nested] 9+ messages in thread* [PATCH 6.1.y 1/3] mptcp: consolidate subflow cleanup 2026-09-19 20:12 [PATCH 6.1.y 0/3] mptcp: fix recent failed backports (20260919) Matthieu Baerts (NGI0) @ 2026-09-19 20:12 ` Matthieu Baerts (NGI0) 2026-09-19 20:23 ` sashiko-bot 2026-09-20 7:36 ` Patch "mptcp: consolidate subflow cleanup" has been added to the 6.1-stable tree gregkh 2026-09-19 20:12 ` [PATCH 6.1.y 2/3] mptcp: avoid unneeded actions on subflow reset Matthieu Baerts (NGI0) 2026-09-19 20:12 ` [PATCH 6.1.y 3/3] mptcp: close race between scheduler and state change Matthieu Baerts (NGI0) 2 siblings, 2 replies; 9+ messages in thread From: Matthieu Baerts (NGI0) @ 2026-09-19 20:12 UTC (permalink / raw) To: mptcp, stable, gregkh Cc: Paolo Abeni, sashal, Mat Martineau, Matthieu Baerts (NGI0), Jakub Kicinski From: Paolo Abeni <pabeni@redhat.com> commit c3349a22c2002947d29a98a77bfb36d97cfbfac1 upstream. Consolidate all the cleanup actions requiring the worker in a single helper and ensure the dummy data fin creation for fallback socket is performed only when the tcp rx queue is empty. There are no functional changes intended, but this will simplify the next patch, when the tcp rx queue spooling could be delayed at release_cb time. Signed-off-by: Paolo Abeni <pabeni@redhat.com> Reviewed-by: Mat Martineau <martineau@kernel.org> Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org> Link: https://patch.msgid.link/20250218-net-next-mptcp-rx-path-refactor-v1-1-4a47d90d7998@kernel.org Signed-off-by: Jakub Kicinski <kuba@kernel.org> Stable-dep-of: 2b0f561f21b2 ("mptcp: avoid unneeded actions on subflow reset") [ Note: also remove struct mptcp_sock *msk from subflow_state_change: it is no longer used after this modification. ] Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org> --- net/mptcp/subflow.c | 35 ++++++++++++++++++----------------- 1 file changed, 18 insertions(+), 17 deletions(-) diff --git a/net/mptcp/subflow.c b/net/mptcp/subflow.c index eed5b90bf5a0..07cdb162b709 100644 --- a/net/mptcp/subflow.c +++ b/net/mptcp/subflow.c @@ -1159,7 +1159,12 @@ static void mptcp_subflow_discard_data(struct sock *ssk, struct sk_buff *skb, subflow->map_valid = 0; } -/* sched mptcp worker to remove the subflow if no more data is pending */ +static bool subflow_is_done(const struct sock *sk) +{ + return sk->sk_shutdown & RCV_SHUTDOWN || sk->sk_state == TCP_CLOSE; +} + +/* sched mptcp worker for subflow cleanup if no more data is pending */ static void subflow_sched_work_if_closed(struct mptcp_sock *msk, struct sock *ssk) { struct sock *sk = (struct sock *)msk; @@ -1169,8 +1174,18 @@ static void subflow_sched_work_if_closed(struct mptcp_sock *msk, struct sock *ss inet_sk_state_load(sk) != TCP_ESTABLISHED))) return; - if (skb_queue_empty(&ssk->sk_receive_queue) && - !test_and_set_bit(MPTCP_WORK_CLOSE_SUBFLOW, &msk->flags)) + if (!skb_queue_empty(&ssk->sk_receive_queue)) + return; + + if (!test_and_set_bit(MPTCP_WORK_CLOSE_SUBFLOW, &msk->flags)) + mptcp_schedule_work(sk); + + /* when the fallback subflow closes the rx side, trigger a 'dummy' + * ingress data fin, so that the msk state will follow along + */ + if (__mptcp_check_fallback(msk) && subflow_is_done(ssk) && + msk->first == ssk && + mptcp_update_rcv_data_fin(msk, READ_ONCE(msk->ack_seq), true)) mptcp_schedule_work(sk); } @@ -1688,20 +1703,13 @@ static void __subflow_state_change(struct sock *sk) rcu_read_unlock(); } -static bool subflow_is_done(const struct sock *sk) -{ - return sk->sk_shutdown & RCV_SHUTDOWN || sk->sk_state == TCP_CLOSE; -} - static void subflow_state_change(struct sock *sk) { struct mptcp_subflow_context *subflow = mptcp_subflow_ctx(sk); struct sock *parent = subflow->conn; - struct mptcp_sock *msk; __subflow_state_change(sk); - msk = mptcp_sk(parent); /* as recvmsg() does not acquire the subflow socket for ssk selection * a fin packet carrying a DSS can be unnoticed if we don't trigger * the data available machinery here. @@ -1712,13 +1720,6 @@ static void subflow_state_change(struct sock *sk) subflow_error_report(sk); subflow_sched_work_if_closed(mptcp_sk(parent), sk); - - /* when the fallback subflow closes the rx side, trigger a 'dummy' - * ingress data fin, so that the msk state will follow along - */ - if (__mptcp_check_fallback(msk) && subflow_is_done(sk) && msk->first == sk && - mptcp_update_rcv_data_fin(msk, READ_ONCE(msk->ack_seq), true)) - mptcp_schedule_work(parent); } void mptcp_subflow_queue_clean(struct sock *listener_sk, struct sock *listener_ssk) -- 2.55.0 ^ permalink raw reply related [flat|nested] 9+ messages in thread
* Re: [PATCH 6.1.y 1/3] mptcp: consolidate subflow cleanup 2026-09-19 20:12 ` [PATCH 6.1.y 1/3] mptcp: consolidate subflow cleanup Matthieu Baerts (NGI0) @ 2026-09-19 20:23 ` sashiko-bot 2026-09-19 20:30 ` Matthieu Baerts 2026-09-20 7:36 ` Patch "mptcp: consolidate subflow cleanup" has been added to the 6.1-stable tree gregkh 1 sibling, 1 reply; 9+ messages in thread From: sashiko-bot @ 2026-09-19 20:23 UTC (permalink / raw) To: Matthieu Baerts (NGI0); +Cc: mptcp Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider: - [High] mptcp: socket hang in fallback teardown due to restrictive state checks -- commit 56f82de860d8f3b2e8b76eca945e8a61ec848e3a Author: Paolo Abeni <pabeni@redhat.com> mptcp: consolidate subflow cleanup This commit consolidates subflow cleanup actions requiring the worker into a single helper. It ensures the dummy data FIN creation for fallback sockets is performed only when the TCP receive queue is empty. Link: https://patch.msgid.link/20250218-net-next-mptcp-rx-path-refactor-v1-1-4a47d90d7998@kernel.org > diff --git a/net/mptcp/subflow.c b/net/mptcp/subflow.c > index d9734bfb7283b..9bbeed6290d7a 100644 > --- a/net/mptcp/subflow.c > +++ b/net/mptcp/subflow.c [ ... ] > @@ -1169,8 +1174,18 @@ static void subflow_sched_work_if_closed(struct mptcp_sock *msk, struct sock *ss > inet_sk_state_load(sk) != TCP_ESTABLISHED))) > return; > > - if (skb_queue_empty(&ssk->sk_receive_queue) && > - !test_and_set_bit(MPTCP_WORK_CLOSE_SUBFLOW, &msk->flags)) > + if (!skb_queue_empty(&ssk->sk_receive_queue)) > + return; > + > + if (!test_and_set_bit(MPTCP_WORK_CLOSE_SUBFLOW, &msk->flags)) > + mptcp_schedule_work(sk); > + > + /* when the fallback subflow closes the rx side, trigger a 'dummy' > + * ingress data fin, so that the msk state will follow along > + */ > + if (__mptcp_check_fallback(msk) && subflow_is_done(ssk) && > + msk->first == ssk && > + mptcp_update_rcv_data_fin(msk, READ_ONCE(msk->ack_seq), true)) > mptcp_schedule_work(sk); > } [Severity: High] Does this new placement of the fallback dummy FIN logic cause a socket hang during connection teardown? In the previous implementation, the dummy FIN injection was executed in subflow_state_change() regardless of the early returns in subflow_sched_work_if_closed(). By moving it inside subflow_sched_work_if_closed(), it is now gated by the restrictive state checks at the top of the function: if (likely(ssk->sk_state != TCP_CLOSE && (ssk->sk_state != TCP_CLOSE_WAIT || inet_sk_state_load(sk) != TCP_ESTABLISHED))) return; When a local application closes a fallback connection, the msk transitions to TCP_FIN_WAIT1 or TCP_FIN_WAIT2. If the remote peer then sends a FIN, the underlying TCP subflow (ssk) transitions to TCP_CLOSING or TCP_TIME_WAIT. Since the ssk is neither in TCP_CLOSE nor TCP_CLOSE_WAIT, the function returns early. Will this skip the fallback dummy FIN injection entirely, leaving the msk state machine stuck without mptcp_update_rcv_data_fin() and causing fallback MPTCP sockets to hang indefinitely? -- Sashiko AI review · https://sashiko.dev/#/patchset/20260919201252.2025112-5-matttbe@kernel.org?part=1 ^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: [PATCH 6.1.y 1/3] mptcp: consolidate subflow cleanup 2026-09-19 20:23 ` sashiko-bot @ 2026-09-19 20:30 ` Matthieu Baerts 0 siblings, 0 replies; 9+ messages in thread From: Matthieu Baerts @ 2026-09-19 20:30 UTC (permalink / raw) To: sashiko-reviews; +Cc: mptcp On 19/09/2026 22:23, sashiko-bot@kernel.org wrote: > Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider: > - [High] mptcp: socket hang in fallback teardown due to restrictive state checks I guess I would have quickly seen that in the mptcp_connect*.sh tests. Cheers, Matt -- Sponsored by the NGI0 Core fund. ^ permalink raw reply [flat|nested] 9+ messages in thread
* Patch "mptcp: consolidate subflow cleanup" has been added to the 6.1-stable tree 2026-09-19 20:12 ` [PATCH 6.1.y 1/3] mptcp: consolidate subflow cleanup Matthieu Baerts (NGI0) 2026-09-19 20:23 ` sashiko-bot @ 2026-09-20 7:36 ` gregkh 1 sibling, 0 replies; 9+ messages in thread From: gregkh @ 2026-09-20 7:36 UTC (permalink / raw) To: gregkh, kuba, martineau, matttbe, mptcp, pabeni, sashal; +Cc: stable-commits This is a note to let you know that I've just added the patch titled mptcp: consolidate subflow cleanup to the 6.1-stable tree which can be found at: http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary The filename of the patch is: mptcp-consolidate-subflow-cleanup.patch and it can be found in the queue-6.1 subdirectory. If you, or anyone else, feels it should not be added to the stable tree, please let <stable@vger.kernel.org> know about it. From stable+bounces-338608-greg=kroah.com@vger.kernel.org Sat Sep 19 22:13:14 2026 From: "Matthieu Baerts (NGI0)" <matttbe@kernel.org> Date: Sat, 19 Sep 2026 22:12:54 +0200 Subject: mptcp: consolidate subflow cleanup To: mptcp@lists.linux.dev, stable@vger.kernel.org, gregkh@linuxfoundation.org Cc: Paolo Abeni <pabeni@redhat.com>, sashal@kernel.org, Mat Martineau <martineau@kernel.org>, "Matthieu Baerts (NGI0)" <matttbe@kernel.org>, Jakub Kicinski <kuba@kernel.org> Message-ID: <20260919201252.2025112-6-matttbe@kernel.org> From: Paolo Abeni <pabeni@redhat.com> commit c3349a22c2002947d29a98a77bfb36d97cfbfac1 upstream. Consolidate all the cleanup actions requiring the worker in a single helper and ensure the dummy data fin creation for fallback socket is performed only when the tcp rx queue is empty. There are no functional changes intended, but this will simplify the next patch, when the tcp rx queue spooling could be delayed at release_cb time. Signed-off-by: Paolo Abeni <pabeni@redhat.com> Reviewed-by: Mat Martineau <martineau@kernel.org> Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org> Link: https://patch.msgid.link/20250218-net-next-mptcp-rx-path-refactor-v1-1-4a47d90d7998@kernel.org Signed-off-by: Jakub Kicinski <kuba@kernel.org> Stable-dep-of: 2b0f561f21b2 ("mptcp: avoid unneeded actions on subflow reset") [ Note: also remove struct mptcp_sock *msk from subflow_state_change: it is no longer used after this modification. ] Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> --- net/mptcp/subflow.c | 35 ++++++++++++++++++----------------- 1 file changed, 18 insertions(+), 17 deletions(-) --- a/net/mptcp/subflow.c +++ b/net/mptcp/subflow.c @@ -1159,7 +1159,12 @@ out: subflow->map_valid = 0; } -/* sched mptcp worker to remove the subflow if no more data is pending */ +static bool subflow_is_done(const struct sock *sk) +{ + return sk->sk_shutdown & RCV_SHUTDOWN || sk->sk_state == TCP_CLOSE; +} + +/* sched mptcp worker for subflow cleanup if no more data is pending */ static void subflow_sched_work_if_closed(struct mptcp_sock *msk, struct sock *ssk) { struct sock *sk = (struct sock *)msk; @@ -1169,8 +1174,18 @@ static void subflow_sched_work_if_closed inet_sk_state_load(sk) != TCP_ESTABLISHED))) return; - if (skb_queue_empty(&ssk->sk_receive_queue) && - !test_and_set_bit(MPTCP_WORK_CLOSE_SUBFLOW, &msk->flags)) + if (!skb_queue_empty(&ssk->sk_receive_queue)) + return; + + if (!test_and_set_bit(MPTCP_WORK_CLOSE_SUBFLOW, &msk->flags)) + mptcp_schedule_work(sk); + + /* when the fallback subflow closes the rx side, trigger a 'dummy' + * ingress data fin, so that the msk state will follow along + */ + if (__mptcp_check_fallback(msk) && subflow_is_done(ssk) && + msk->first == ssk && + mptcp_update_rcv_data_fin(msk, READ_ONCE(msk->ack_seq), true)) mptcp_schedule_work(sk); } @@ -1688,20 +1703,13 @@ static void __subflow_state_change(struc rcu_read_unlock(); } -static bool subflow_is_done(const struct sock *sk) -{ - return sk->sk_shutdown & RCV_SHUTDOWN || sk->sk_state == TCP_CLOSE; -} - static void subflow_state_change(struct sock *sk) { struct mptcp_subflow_context *subflow = mptcp_subflow_ctx(sk); struct sock *parent = subflow->conn; - struct mptcp_sock *msk; __subflow_state_change(sk); - msk = mptcp_sk(parent); /* as recvmsg() does not acquire the subflow socket for ssk selection * a fin packet carrying a DSS can be unnoticed if we don't trigger * the data available machinery here. @@ -1712,13 +1720,6 @@ static void subflow_state_change(struct subflow_error_report(sk); subflow_sched_work_if_closed(mptcp_sk(parent), sk); - - /* when the fallback subflow closes the rx side, trigger a 'dummy' - * ingress data fin, so that the msk state will follow along - */ - if (__mptcp_check_fallback(msk) && subflow_is_done(sk) && msk->first == sk && - mptcp_update_rcv_data_fin(msk, READ_ONCE(msk->ack_seq), true)) - mptcp_schedule_work(parent); } void mptcp_subflow_queue_clean(struct sock *listener_sk, struct sock *listener_ssk) Patches currently in stable-queue which might be from matttbe@kernel.org are queue-6.1/selftests-mptcp-fix-an-uaf-in-mptcp_connect.c.patch queue-6.1/mptcp-syncookies-remember-the-request-backup-flag.patch queue-6.1/mptcp-close-race-between-scheduler-and-state-change.patch queue-6.1/mptcp-avoid-unneeded-actions-on-subflow-reset.patch queue-6.1/mptcp-options-handle-mpc-data-csum-reqd-no-csum.patch queue-6.1/mptcp-consolidate-subflow-cleanup.patch queue-6.1/mptcp-subflow-no-need-to-copy-thmac-during-ulp_clone.patch ^ permalink raw reply [flat|nested] 9+ messages in thread
* [PATCH 6.1.y 2/3] mptcp: avoid unneeded actions on subflow reset 2026-09-19 20:12 [PATCH 6.1.y 0/3] mptcp: fix recent failed backports (20260919) Matthieu Baerts (NGI0) 2026-09-19 20:12 ` [PATCH 6.1.y 1/3] mptcp: consolidate subflow cleanup Matthieu Baerts (NGI0) @ 2026-09-19 20:12 ` Matthieu Baerts (NGI0) 2026-09-20 7:36 ` Patch "mptcp: avoid unneeded actions on subflow reset" has been added to the 6.1-stable tree gregkh 2026-09-19 20:12 ` [PATCH 6.1.y 3/3] mptcp: close race between scheduler and state change Matthieu Baerts (NGI0) 2 siblings, 1 reply; 9+ messages in thread From: Matthieu Baerts (NGI0) @ 2026-09-19 20:12 UTC (permalink / raw) To: mptcp, stable, gregkh Cc: Paolo Abeni, sashal, Xinyang Ge, Matthieu Baerts (NGI0), Jakub Kicinski From: Paolo Abeni <pabeni@redhat.com> commit 2b0f561f21b27c40c91ea4975268a06092bd7e9c upstream. Once in a blue moon, the mptcp receive path can recursively call mptcp_data_ready() via state change under unlucky error conditions, and then try to hold the data lock again. Break the recursion loop explicitly checking for the exceptional condition. Add a new flag instead of using an existing one like 'closing', to exit early in subflow_state_change(), and explicitly flush the RX queue at reset time. This avoids unneeded processing to check for available data -- calling get_mapping_status() and more on a dying subflow -- but also in error reporting and worker scheduling. Note that we must consume the currently peeked skb before invoking mptcp_dss_corruption to avoid consuming it again after the eventual reset has freed it. Fixes: e32d262c89e2 ("mptcp: handle consistently DSS corruption") Cc: stable@vger.kernel.org Reported-by: Xinyang Ge <xinyang@anthropic.com> Signed-off-by: Paolo Abeni <pabeni@redhat.com> Reviewed-by: Matthieu Baerts (NGI0) <matttbe@kernel.org> Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org> Link: https://patch.msgid.link/20260917-net-mptcp-misc-fixes-7-3-rc4-v2-1-0cf5c72667c8@kernel.org Signed-off-by: Jakub Kicinski <kuba@kernel.org> [ Note: conflict in protocol.c, because commit e0ca4057e0ec ("mptcp: micro-optimize __mptcp_move_skb()") is not in this version, and is part of a consequent rx path refactor. The conflict is in the context, and is easy to resolve, "done = true" can be moved along without consequences. Also a conflict in protocol.h, because __unused is at a different number. Decrement the one from this version and add the new flag above. The context is also a bit different with data_avail being an enum, but that's without consequences here. ] Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org> --- net/mptcp/protocol.c | 6 +++--- net/mptcp/protocol.h | 3 ++- net/mptcp/subflow.c | 11 +++++++++++ 3 files changed, 16 insertions(+), 4 deletions(-) diff --git a/net/mptcp/protocol.c b/net/mptcp/protocol.c index 2ce20884d730..ab83cf46a8c3 100644 --- a/net/mptcp/protocol.c +++ b/net/mptcp/protocol.c @@ -754,13 +754,13 @@ static bool __mptcp_move_skbs_from_subflow(struct mptcp_sock *msk, mptcp_dss_corruption(msk, ssk); } } else { + sk_eat_skb(ssk, skb); + done = true; + if (unlikely(!fin)) { DEBUG_NET_WARN_ON_ONCE(1); mptcp_dss_corruption(msk, ssk); } - - sk_eat_skb(ssk, skb); - done = true; } WRITE_ONCE(tp->copied_seq, seq); diff --git a/net/mptcp/protocol.h b/net/mptcp/protocol.h index e835028fc4e5..1de257b86839 100644 --- a/net/mptcp/protocol.h +++ b/net/mptcp/protocol.h @@ -492,7 +492,8 @@ struct mptcp_subflow_context { stale : 1, /* unable to snd/rcv data, do not use for xmit */ valid_csum_seen : 1, /* at least one csum validated */ close_event_done : 1, /* has done the post-closed part */ - __unused : 9; + resetting : 1, /* subflow is resetting */ + __unused : 8; enum mptcp_data_avail data_avail; bool pm_listener; /* a listener managed by the kernel PM? */ u32 remote_nonce; diff --git a/net/mptcp/subflow.c b/net/mptcp/subflow.c index 07cdb162b709..cc62681d6ea8 100644 --- a/net/mptcp/subflow.c +++ b/net/mptcp/subflow.c @@ -379,6 +379,10 @@ void mptcp_subflow_reset(struct sock *ssk) /* must hold: tcp_done() could drop last reference on parent */ sock_hold(sk); + subflow->resetting = 1; + + /* No need to delay the actual close for to-be discarded data. */ + __skb_queue_purge(&ssk->sk_receive_queue); tcp_send_active_reset(ssk, GFP_ATOMIC); tcp_done(ssk); if (!test_and_set_bit(MPTCP_WORK_CLOSE_SUBFLOW, &mptcp_sk(sk)->flags)) @@ -1710,6 +1714,13 @@ static void subflow_state_change(struct sock *sk) __subflow_state_change(sk); + /* Rx queue processing is unneeded, error reporting will take place at + * __mptcp_close_ssk() time and subflow reset can't happen in case of + * fallback: subflow_sched_work_if_closed() would be a no-op. + */ + if (subflow->resetting) + return; + /* as recvmsg() does not acquire the subflow socket for ssk selection * a fin packet carrying a DSS can be unnoticed if we don't trigger * the data available machinery here. -- 2.55.0 ^ permalink raw reply related [flat|nested] 9+ messages in thread
* Patch "mptcp: avoid unneeded actions on subflow reset" has been added to the 6.1-stable tree 2026-09-19 20:12 ` [PATCH 6.1.y 2/3] mptcp: avoid unneeded actions on subflow reset Matthieu Baerts (NGI0) @ 2026-09-20 7:36 ` gregkh 0 siblings, 0 replies; 9+ messages in thread From: gregkh @ 2026-09-20 7:36 UTC (permalink / raw) To: gregkh, kuba, matttbe, mptcp, pabeni, sashal, xinyang; +Cc: stable-commits This is a note to let you know that I've just added the patch titled mptcp: avoid unneeded actions on subflow reset to the 6.1-stable tree which can be found at: http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary The filename of the patch is: mptcp-avoid-unneeded-actions-on-subflow-reset.patch and it can be found in the queue-6.1 subdirectory. If you, or anyone else, feels it should not be added to the stable tree, please let <stable@vger.kernel.org> know about it. From stable+bounces-338609-greg=kroah.com@vger.kernel.org Sat Sep 19 22:13:16 2026 From: "Matthieu Baerts (NGI0)" <matttbe@kernel.org> Date: Sat, 19 Sep 2026 22:12:55 +0200 Subject: mptcp: avoid unneeded actions on subflow reset To: mptcp@lists.linux.dev, stable@vger.kernel.org, gregkh@linuxfoundation.org Cc: Paolo Abeni <pabeni@redhat.com>, sashal@kernel.org, Xinyang Ge <xinyang@anthropic.com>, "Matthieu Baerts (NGI0)" <matttbe@kernel.org>, Jakub Kicinski <kuba@kernel.org> Message-ID: <20260919201252.2025112-7-matttbe@kernel.org> From: Paolo Abeni <pabeni@redhat.com> commit 2b0f561f21b27c40c91ea4975268a06092bd7e9c upstream. Once in a blue moon, the mptcp receive path can recursively call mptcp_data_ready() via state change under unlucky error conditions, and then try to hold the data lock again. Break the recursion loop explicitly checking for the exceptional condition. Add a new flag instead of using an existing one like 'closing', to exit early in subflow_state_change(), and explicitly flush the RX queue at reset time. This avoids unneeded processing to check for available data -- calling get_mapping_status() and more on a dying subflow -- but also in error reporting and worker scheduling. Note that we must consume the currently peeked skb before invoking mptcp_dss_corruption to avoid consuming it again after the eventual reset has freed it. Fixes: e32d262c89e2 ("mptcp: handle consistently DSS corruption") Cc: stable@vger.kernel.org Reported-by: Xinyang Ge <xinyang@anthropic.com> Signed-off-by: Paolo Abeni <pabeni@redhat.com> Reviewed-by: Matthieu Baerts (NGI0) <matttbe@kernel.org> Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org> Link: https://patch.msgid.link/20260917-net-mptcp-misc-fixes-7-3-rc4-v2-1-0cf5c72667c8@kernel.org Signed-off-by: Jakub Kicinski <kuba@kernel.org> [ Note: conflict in protocol.c, because commit e0ca4057e0ec ("mptcp: micro-optimize __mptcp_move_skb()") is not in this version, and is part of a consequent rx path refactor. The conflict is in the context, and is easy to resolve, "done = true" can be moved along without consequences. Also a conflict in protocol.h, because __unused is at a different number. Decrement the one from this version and add the new flag above. The context is also a bit different with data_avail being an enum, but that's without consequences here. ] Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> --- net/mptcp/protocol.c | 6 +++--- net/mptcp/protocol.h | 3 ++- net/mptcp/subflow.c | 11 +++++++++++ 3 files changed, 16 insertions(+), 4 deletions(-) --- a/net/mptcp/protocol.c +++ b/net/mptcp/protocol.c @@ -754,13 +754,13 @@ static bool __mptcp_move_skbs_from_subfl mptcp_dss_corruption(msk, ssk); } } else { + sk_eat_skb(ssk, skb); + done = true; + if (unlikely(!fin)) { DEBUG_NET_WARN_ON_ONCE(1); mptcp_dss_corruption(msk, ssk); } - - sk_eat_skb(ssk, skb); - done = true; } WRITE_ONCE(tp->copied_seq, seq); --- a/net/mptcp/protocol.h +++ b/net/mptcp/protocol.h @@ -492,7 +492,8 @@ struct mptcp_subflow_context { stale : 1, /* unable to snd/rcv data, do not use for xmit */ valid_csum_seen : 1, /* at least one csum validated */ close_event_done : 1, /* has done the post-closed part */ - __unused : 9; + resetting : 1, /* subflow is resetting */ + __unused : 8; enum mptcp_data_avail data_avail; bool pm_listener; /* a listener managed by the kernel PM? */ u32 remote_nonce; --- a/net/mptcp/subflow.c +++ b/net/mptcp/subflow.c @@ -379,6 +379,10 @@ void mptcp_subflow_reset(struct sock *ss /* must hold: tcp_done() could drop last reference on parent */ sock_hold(sk); + subflow->resetting = 1; + + /* No need to delay the actual close for to-be discarded data. */ + __skb_queue_purge(&ssk->sk_receive_queue); tcp_send_active_reset(ssk, GFP_ATOMIC); tcp_done(ssk); if (!test_and_set_bit(MPTCP_WORK_CLOSE_SUBFLOW, &mptcp_sk(sk)->flags)) @@ -1710,6 +1714,13 @@ static void subflow_state_change(struct __subflow_state_change(sk); + /* Rx queue processing is unneeded, error reporting will take place at + * __mptcp_close_ssk() time and subflow reset can't happen in case of + * fallback: subflow_sched_work_if_closed() would be a no-op. + */ + if (subflow->resetting) + return; + /* as recvmsg() does not acquire the subflow socket for ssk selection * a fin packet carrying a DSS can be unnoticed if we don't trigger * the data available machinery here. Patches currently in stable-queue which might be from matttbe@kernel.org are queue-6.1/selftests-mptcp-fix-an-uaf-in-mptcp_connect.c.patch queue-6.1/mptcp-syncookies-remember-the-request-backup-flag.patch queue-6.1/mptcp-close-race-between-scheduler-and-state-change.patch queue-6.1/mptcp-avoid-unneeded-actions-on-subflow-reset.patch queue-6.1/mptcp-options-handle-mpc-data-csum-reqd-no-csum.patch queue-6.1/mptcp-consolidate-subflow-cleanup.patch queue-6.1/mptcp-subflow-no-need-to-copy-thmac-during-ulp_clone.patch ^ permalink raw reply [flat|nested] 9+ messages in thread
* [PATCH 6.1.y 3/3] mptcp: close race between scheduler and state change 2026-09-19 20:12 [PATCH 6.1.y 0/3] mptcp: fix recent failed backports (20260919) Matthieu Baerts (NGI0) 2026-09-19 20:12 ` [PATCH 6.1.y 1/3] mptcp: consolidate subflow cleanup Matthieu Baerts (NGI0) 2026-09-19 20:12 ` [PATCH 6.1.y 2/3] mptcp: avoid unneeded actions on subflow reset Matthieu Baerts (NGI0) @ 2026-09-19 20:12 ` Matthieu Baerts (NGI0) 2026-09-20 7:36 ` Patch "mptcp: close race between scheduler and state change" has been added to the 6.1-stable tree gregkh 2 siblings, 1 reply; 9+ messages in thread From: Matthieu Baerts (NGI0) @ 2026-09-19 20:12 UTC (permalink / raw) To: mptcp, stable, gregkh Cc: Paolo Abeni, sashal, Shardul Bankar, Xinyang Ge, Matthieu Baerts (NGI0), Jakub Kicinski From: Paolo Abeni <pabeni@redhat.com> commit 42064de57fb83231fcc89663a94885f228a1ee53 upstream. The mptcp scheduler may race with subflow sockets state change: data transmission on the selected socket may fail and a later release could try to use mss_now reset to 0 for a divide operation. Address the issue by explicitly checking for the critical scenario. Fixes: c886d70286bf ("mptcp: do not queue data on closed subflows") Cc: stable@vger.kernel.org Reported-by: Shardul Bankar <shardul.b@mpiricsoftware.com> Reported-by: Xinyang Ge <xinyang@anthropic.com> Closes: https://lore.kernel.org/20260525194828.1137119-1-shardul.b@mpiricsoftware.com Signed-off-by: Paolo Abeni <pabeni@redhat.com> Reviewed-by: Matthieu Baerts (NGI0) <matttbe@kernel.org> Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org> Link: https://patch.msgid.link/20260917-net-mptcp-misc-fixes-7-3-rc4-v2-2-0cf5c72667c8@kernel.org Signed-off-by: Jakub Kicinski <kuba@kernel.org> Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org> --- net/mptcp/protocol.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/net/mptcp/protocol.c b/net/mptcp/protocol.c index ab83cf46a8c3..ca78add7670d 100644 --- a/net/mptcp/protocol.c +++ b/net/mptcp/protocol.c @@ -1636,7 +1636,9 @@ static struct sock *mptcp_subflow_get_send(struct mptcp_sock *msk) static void mptcp_push_release(struct sock *ssk, struct mptcp_sendmsg_info *info) { - tcp_push(ssk, 0, info->mss_now, tcp_sk(ssk)->nonagle, info->size_goal); + if (info->mss_now) + tcp_push(ssk, 0, info->mss_now, tcp_sk(ssk)->nonagle, + info->size_goal); release_sock(ssk); } -- 2.55.0 ^ permalink raw reply related [flat|nested] 9+ messages in thread
* Patch "mptcp: close race between scheduler and state change" has been added to the 6.1-stable tree 2026-09-19 20:12 ` [PATCH 6.1.y 3/3] mptcp: close race between scheduler and state change Matthieu Baerts (NGI0) @ 2026-09-20 7:36 ` gregkh 0 siblings, 0 replies; 9+ messages in thread From: gregkh @ 2026-09-20 7:36 UTC (permalink / raw) To: gregkh, kuba, matttbe, mptcp, pabeni, sashal, shardul.b, xinyang Cc: stable-commits This is a note to let you know that I've just added the patch titled mptcp: close race between scheduler and state change to the 6.1-stable tree which can be found at: http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary The filename of the patch is: mptcp-close-race-between-scheduler-and-state-change.patch and it can be found in the queue-6.1 subdirectory. If you, or anyone else, feels it should not be added to the stable tree, please let <stable@vger.kernel.org> know about it. From stable+bounces-338610-greg=kroah.com@vger.kernel.org Sat Sep 19 22:13:35 2026 From: "Matthieu Baerts (NGI0)" <matttbe@kernel.org> Date: Sat, 19 Sep 2026 22:12:56 +0200 Subject: mptcp: close race between scheduler and state change To: mptcp@lists.linux.dev, stable@vger.kernel.org, gregkh@linuxfoundation.org Cc: Paolo Abeni <pabeni@redhat.com>, sashal@kernel.org, Shardul Bankar <shardul.b@mpiricsoftware.com>, Xinyang Ge <xinyang@anthropic.com>, "Matthieu Baerts (NGI0)" <matttbe@kernel.org>, Jakub Kicinski <kuba@kernel.org> Message-ID: <20260919201252.2025112-8-matttbe@kernel.org> From: Paolo Abeni <pabeni@redhat.com> commit 42064de57fb83231fcc89663a94885f228a1ee53 upstream. The mptcp scheduler may race with subflow sockets state change: data transmission on the selected socket may fail and a later release could try to use mss_now reset to 0 for a divide operation. Address the issue by explicitly checking for the critical scenario. Fixes: c886d70286bf ("mptcp: do not queue data on closed subflows") Cc: stable@vger.kernel.org Reported-by: Shardul Bankar <shardul.b@mpiricsoftware.com> Reported-by: Xinyang Ge <xinyang@anthropic.com> Closes: https://lore.kernel.org/20260525194828.1137119-1-shardul.b@mpiricsoftware.com Signed-off-by: Paolo Abeni <pabeni@redhat.com> Reviewed-by: Matthieu Baerts (NGI0) <matttbe@kernel.org> Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org> Link: https://patch.msgid.link/20260917-net-mptcp-misc-fixes-7-3-rc4-v2-2-0cf5c72667c8@kernel.org Signed-off-by: Jakub Kicinski <kuba@kernel.org> Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> --- net/mptcp/protocol.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) --- a/net/mptcp/protocol.c +++ b/net/mptcp/protocol.c @@ -1636,7 +1636,9 @@ static struct sock *mptcp_subflow_get_se static void mptcp_push_release(struct sock *ssk, struct mptcp_sendmsg_info *info) { - tcp_push(ssk, 0, info->mss_now, tcp_sk(ssk)->nonagle, info->size_goal); + if (info->mss_now) + tcp_push(ssk, 0, info->mss_now, tcp_sk(ssk)->nonagle, + info->size_goal); release_sock(ssk); } Patches currently in stable-queue which might be from matttbe@kernel.org are queue-6.1/selftests-mptcp-fix-an-uaf-in-mptcp_connect.c.patch queue-6.1/mptcp-syncookies-remember-the-request-backup-flag.patch queue-6.1/mptcp-close-race-between-scheduler-and-state-change.patch queue-6.1/mptcp-avoid-unneeded-actions-on-subflow-reset.patch queue-6.1/mptcp-options-handle-mpc-data-csum-reqd-no-csum.patch queue-6.1/mptcp-consolidate-subflow-cleanup.patch queue-6.1/mptcp-subflow-no-need-to-copy-thmac-during-ulp_clone.patch ^ permalink raw reply [flat|nested] 9+ messages in thread
end of thread, other threads:[~2026-09-20 7:39 UTC | newest] Thread overview: 9+ messages (download: mbox.gz follow: Atom feed -- links below jump to the message on this page -- 2026-09-19 20:12 [PATCH 6.1.y 0/3] mptcp: fix recent failed backports (20260919) Matthieu Baerts (NGI0) 2026-09-19 20:12 ` [PATCH 6.1.y 1/3] mptcp: consolidate subflow cleanup Matthieu Baerts (NGI0) 2026-09-19 20:23 ` sashiko-bot 2026-09-19 20:30 ` Matthieu Baerts 2026-09-20 7:36 ` Patch "mptcp: consolidate subflow cleanup" has been added to the 6.1-stable tree gregkh 2026-09-19 20:12 ` [PATCH 6.1.y 2/3] mptcp: avoid unneeded actions on subflow reset Matthieu Baerts (NGI0) 2026-09-20 7:36 ` Patch "mptcp: avoid unneeded actions on subflow reset" has been added to the 6.1-stable tree gregkh 2026-09-19 20:12 ` [PATCH 6.1.y 3/3] mptcp: close race between scheduler and state change Matthieu Baerts (NGI0) 2026-09-20 7:36 ` Patch "mptcp: close race between scheduler and state change" has been added to the 6.1-stable tree gregkh
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox