MPTCP Linux Development
 help / color / mirror / Atom feed
* [PATCH 5.15.y 0/2] mptcp: fix recent failed backports (20260919)
@ 2026-09-19 20:29 Matthieu Baerts (NGI0)
  2026-09-19 20:29 ` [PATCH 5.15.y 1/2] mptcp: avoid unneeded actions on subflow reset Matthieu Baerts (NGI0)
  2026-09-19 20:29 ` [PATCH 5.15.y 2/2] mptcp: close race between scheduler and state change Matthieu Baerts (NGI0)
  0 siblings, 2 replies; 6+ messages in thread
From: Matthieu Baerts (NGI0) @ 2026-09-19 20:29 UTC (permalink / raw)
  To: mptcp, stable, gregkh; +Cc: Matthieu Baerts (NGI0), sashal

The following patches could not be applied without conflicts in this
tree:

- 2b0f561f21b2 ("mptcp: avoid unneeded actions on subflow reset")
- 42064de57fb8 ("mptcp: close race between scheduler and state change")

Conflicts (if any) have been resolved, and documented in each patch.

Paolo Abeni (2):
  mptcp: avoid unneeded actions on subflow reset
  mptcp: close race between scheduler and state change

 net/mptcp/protocol.c | 10 ++++++----
 net/mptcp/protocol.h |  3 ++-
 net/mptcp/subflow.c  | 11 +++++++++++
 3 files changed, 19 insertions(+), 5 deletions(-)

-- 
2.55.0


^ permalink raw reply	[flat|nested] 6+ messages in thread

* [PATCH 5.15.y 1/2] mptcp: avoid unneeded actions on subflow reset
  2026-09-19 20:29 [PATCH 5.15.y 0/2] mptcp: fix recent failed backports (20260919) Matthieu Baerts (NGI0)
@ 2026-09-19 20:29 ` Matthieu Baerts (NGI0)
  2026-09-19 20:42   ` sashiko-bot
  2026-09-20  7:36   ` Patch "mptcp: avoid unneeded actions on subflow reset" has been added to the 5.15-stable tree gregkh
  2026-09-19 20:29 ` [PATCH 5.15.y 2/2] mptcp: close race between scheduler and state change Matthieu Baerts (NGI0)
  1 sibling, 2 replies; 6+ messages in thread
From: Matthieu Baerts (NGI0) @ 2026-09-19 20:29 UTC (permalink / raw)
  To: mptcp, stable, gregkh
  Cc: Paolo Abeni, sashal, Xinyang Ge, Matthieu Baerts (NGI0),
	Jakub Kicinski

From: Paolo Abeni <pabeni@redhat.com>

commit 2b0f561f21b27c40c91ea4975268a06092bd7e9c upstream.

Once in a blue moon, the mptcp receive path can recursively call
mptcp_data_ready() via state change under unlucky error conditions, and
then try to hold the data lock again.

Break the recursion loop explicitly checking for the exceptional
condition.

Add a new flag instead of using an existing one like 'closing', to exit
early in subflow_state_change(), and explicitly flush the RX queue at
reset time.

This avoids unneeded processing to check for available data -- calling
get_mapping_status() and more on a dying subflow -- but also in error
reporting and worker scheduling.

Note that we must consume the currently peeked skb before invoking
mptcp_dss_corruption to avoid consuming it again after the eventual
reset has freed it.

Fixes: e32d262c89e2 ("mptcp: handle consistently DSS corruption")
Cc: stable@vger.kernel.org
Reported-by: Xinyang Ge <xinyang@anthropic.com>
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Reviewed-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Link: https://patch.msgid.link/20260917-net-mptcp-misc-fixes-7-3-rc4-v2-1-0cf5c72667c8@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
[ Note: conflict in protocol.c, because commit e0ca4057e0ec ("mptcp:
  micro-optimize __mptcp_move_skb()") is not in this version, and is
  part of a consequent rx path refactor. The conflict is in the context,
  and is easy to resolve, "done = true" can be moved along without
  consequences. Also, the context is slightly different because there is
  no DEBUG_NET_WARN_ON_ONCE in this version, see the backport commit
  12c1676d598e ("mptcp: handle consistently DSS corruption").
  Also a conflict in protocol.h, because __unused is at a different
  number. Decrement the one from this version and add the new flag
  above. The context is also a bit different with data_avail being an
  enum, but that's without consequences here.
  Also a conflict in subflow.c, because commit 71154bbe4942 ("mptcp:
  fallback earlier on simult connection") was not needed in this
  version, and cause conflicts in the context, but that's without
  consequences here. ]
Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
---
 net/mptcp/protocol.c |  6 +++---
 net/mptcp/protocol.h |  3 ++-
 net/mptcp/subflow.c  | 11 +++++++++++
 3 files changed, 16 insertions(+), 4 deletions(-)

diff --git a/net/mptcp/protocol.c b/net/mptcp/protocol.c
index 522d8740a0f3..42190efadb11 100644
--- a/net/mptcp/protocol.c
+++ b/net/mptcp/protocol.c
@@ -687,11 +687,11 @@ static bool __mptcp_move_skbs_from_subflow(struct mptcp_sock *msk,
 			if (unlikely(map_remaining < len))
 				mptcp_dss_corruption(msk, ssk);
 		} else {
-			if (unlikely(!fin))
-				mptcp_dss_corruption(msk, ssk);
-
 			sk_eat_skb(ssk, skb);
 			done = true;
+
+			if (unlikely(!fin))
+				mptcp_dss_corruption(msk, ssk);
 		}
 
 		WRITE_ONCE(tp->copied_seq, seq);
diff --git a/net/mptcp/protocol.h b/net/mptcp/protocol.h
index 609e7768fab3..913d9b1474b0 100644
--- a/net/mptcp/protocol.h
+++ b/net/mptcp/protocol.h
@@ -447,7 +447,8 @@ struct mptcp_subflow_context {
 		stale : 1,	    /* unable to snd/rcv data, do not use for xmit */
 		valid_csum_seen : 1,        /* at least one csum validated */
 		close_event_done : 1,       /* has done the post-closed part */
-		__unused : 11;
+		resetting : 1,	    /* subflow is resetting */
+		__unused : 10;
 	enum mptcp_data_avail data_avail;
 	bool	pm_listener;	    /* a listener managed by the kernel PM? */
 	u32	remote_nonce;
diff --git a/net/mptcp/subflow.c b/net/mptcp/subflow.c
index 33b16ea7ae5b..5ee090b74fa4 100644
--- a/net/mptcp/subflow.c
+++ b/net/mptcp/subflow.c
@@ -373,6 +373,10 @@ void mptcp_subflow_reset(struct sock *ssk)
 	/* must hold: tcp_done() could drop last reference on parent */
 	sock_hold(sk);
 
+	subflow->resetting = 1;
+
+	/* No need to delay the actual close for to-be discarded data. */
+	__skb_queue_purge(&ssk->sk_receive_queue);
 	tcp_send_active_reset(ssk, GFP_ATOMIC);
 	tcp_done(ssk);
 	if (!test_and_set_bit(MPTCP_WORK_CLOSE_SUBFLOW, &mptcp_sk(sk)->flags))
@@ -1667,6 +1671,13 @@ static void subflow_state_change(struct sock *sk)
 
 	__subflow_state_change(sk);
 
+	/* Rx queue processing is unneeded, error reporting will take place at
+	 * __mptcp_close_ssk() time and subflow reset can't happen in case of
+	 * fallback: subflow_sched_work_if_closed() would be a no-op.
+	 */
+	if (subflow->resetting)
+		return;
+
 	msk = mptcp_sk(parent);
 	if (subflow_simultaneous_connect(sk)) {
 		mptcp_propagate_sndbuf(parent, sk);
-- 
2.55.0


^ permalink raw reply related	[flat|nested] 6+ messages in thread

* [PATCH 5.15.y 2/2] mptcp: close race between scheduler and state change
  2026-09-19 20:29 [PATCH 5.15.y 0/2] mptcp: fix recent failed backports (20260919) Matthieu Baerts (NGI0)
  2026-09-19 20:29 ` [PATCH 5.15.y 1/2] mptcp: avoid unneeded actions on subflow reset Matthieu Baerts (NGI0)
@ 2026-09-19 20:29 ` Matthieu Baerts (NGI0)
  2026-09-20  7:36   ` Patch "mptcp: close race between scheduler and state change" has been added to the 5.15-stable tree gregkh
  1 sibling, 1 reply; 6+ messages in thread
From: Matthieu Baerts (NGI0) @ 2026-09-19 20:29 UTC (permalink / raw)
  To: mptcp, stable, gregkh
  Cc: Paolo Abeni, sashal, Shardul Bankar, Xinyang Ge,
	Matthieu Baerts (NGI0), Jakub Kicinski

From: Paolo Abeni <pabeni@redhat.com>

commit 42064de57fb83231fcc89663a94885f228a1ee53 upstream.

The mptcp scheduler may race with subflow sockets state change: data
transmission on the selected socket may fail and a later release could
try to use mss_now reset to 0 for a divide operation.

Address the issue by explicitly checking for the critical scenario.

Fixes: c886d70286bf ("mptcp: do not queue data on closed subflows")
Cc: stable@vger.kernel.org
Reported-by: Shardul Bankar <shardul.b@mpiricsoftware.com>
Reported-by: Xinyang Ge <xinyang@anthropic.com>
Closes: https://lore.kernel.org/20260525194828.1137119-1-shardul.b@mpiricsoftware.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Reviewed-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Link: https://patch.msgid.link/20260917-net-mptcp-misc-fixes-7-3-rc4-v2-2-0cf5c72667c8@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
---
 net/mptcp/protocol.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/net/mptcp/protocol.c b/net/mptcp/protocol.c
index 42190efadb11..2f18dcb8d034 100644
--- a/net/mptcp/protocol.c
+++ b/net/mptcp/protocol.c
@@ -1621,7 +1621,9 @@ static struct sock *mptcp_subflow_get_send(struct mptcp_sock *msk)
 
 static void mptcp_push_release(struct sock *ssk, struct mptcp_sendmsg_info *info)
 {
-	tcp_push(ssk, 0, info->mss_now, tcp_sk(ssk)->nonagle, info->size_goal);
+	if (info->mss_now)
+		tcp_push(ssk, 0, info->mss_now, tcp_sk(ssk)->nonagle,
+			 info->size_goal);
 	release_sock(ssk);
 }
 
-- 
2.55.0


^ permalink raw reply related	[flat|nested] 6+ messages in thread

* Re: [PATCH 5.15.y 1/2] mptcp: avoid unneeded actions on subflow reset
  2026-09-19 20:29 ` [PATCH 5.15.y 1/2] mptcp: avoid unneeded actions on subflow reset Matthieu Baerts (NGI0)
@ 2026-09-19 20:42   ` sashiko-bot
  2026-09-20  7:36   ` Patch "mptcp: avoid unneeded actions on subflow reset" has been added to the 5.15-stable tree gregkh
  1 sibling, 0 replies; 6+ messages in thread
From: sashiko-bot @ 2026-09-19 20:42 UTC (permalink / raw)
  To: Matthieu Baerts (NGI0); +Cc: mptcp

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] mptcp: data race in subflow bitfield leads to deadlock
--

commit 748ca2aef871b6b237079df0a200a9001209199e
Author: Paolo Abeni <pabeni@redhat.com>
Subject: mptcp: avoid unneeded actions on subflow reset

This commit introduces a new flag, resetting, to exit early in
subflow_state_change(), preventing recursive calls to mptcp_data_ready()
and recursive spinlock acquisition. It also explicitly flushes the RX queue
at reset time.

Link: https://patch.msgid.link/20260917-net-mptcp-misc-fixes-7-3-rc4-v2-1-0cf5c72667c8@kernel.org

> diff --git a/net/mptcp/protocol.h b/net/mptcp/protocol.h
> index 609e7768fab31..913d9b1474b05 100644
> --- a/net/mptcp/protocol.h
> +++ b/net/mptcp/protocol.h
> @@ -447,7 +447,8 @@ struct mptcp_subflow_context {
>  		stale : 1,	    /* unable to snd/rcv data, do not use for xmit */
>  		valid_csum_seen : 1,        /* at least one csum validated */
>  		close_event_done : 1,       /* has done the post-closed part */
> -		__unused : 11;
> +		resetting : 1,	    /* subflow is resetting */
> +		__unused : 10;
>  	enum mptcp_data_avail data_avail;
>  	bool	pm_listener;	    /* a listener managed by the kernel PM? */
>  	u32	remote_nonce;
> diff --git a/net/mptcp/subflow.c b/net/mptcp/subflow.c
> index 33b16ea7ae5bc..5ee090b74fa45 100644
> --- a/net/mptcp/subflow.c
> +++ b/net/mptcp/subflow.c
> @@ -373,6 +373,10 @@ void mptcp_subflow_reset(struct sock *ssk)
>  	/* must hold: tcp_done() could drop last reference on parent */
>  	sock_hold(sk);
>  
> +	subflow->resetting = 1;

[Severity: High]
Does this bitfield assignment introduce a data race that could clear the new
flag and cause a deadlock?

The C compiler implements bitfield modifications as non-atomic read-modify-write
operations on the containing 32-bit word. 

Here in mptcp_subflow_reset(), subflow->resetting = 1 is set while holding the
subflow ssk lock and the mptcp_data_lock, but the msk socket lock is not held.

Concurrently, a PM event like mptcp_pm_nl_mp_prio_send_ack() can modify
send_mp_prio in the same bitfield word:

net/mptcp/pm_netlink.c:mptcp_pm_nl_mp_prio_send_ack() {
    ...
    subflow->send_mp_prio = 1;
    subflow->request_bkup = bkup;
    ...
}

This PM path holds the msk socket lock and pm.lock, but critically does not
hold the ssk lock.

If the concurrent unguarded writes race, could the PM thread's update silently
overwrite and clear the resetting flag?

If the resetting flag is lost, the fix introduced in this commit would be
bypassed. subflow_state_change() would fail to return early and instead
recursively call mptcp_data_ready(), which tries to re-acquire the already held
mptcp_data_lock spinlock, leading to an immediate deadlock.

[ ... ]

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260919202918.2074632-4-matttbe@kernel.org?part=1

^ permalink raw reply	[flat|nested] 6+ messages in thread

* Patch "mptcp: avoid unneeded actions on subflow reset" has been added to the 5.15-stable tree
  2026-09-19 20:29 ` [PATCH 5.15.y 1/2] mptcp: avoid unneeded actions on subflow reset Matthieu Baerts (NGI0)
  2026-09-19 20:42   ` sashiko-bot
@ 2026-09-20  7:36   ` gregkh
  1 sibling, 0 replies; 6+ messages in thread
From: gregkh @ 2026-09-20  7:36 UTC (permalink / raw)
  To: gregkh, kuba, matttbe, mptcp, pabeni, sashal, xinyang; +Cc: stable-commits


This is a note to let you know that I've just added the patch titled

    mptcp: avoid unneeded actions on subflow reset

to the 5.15-stable tree which can be found at:
    http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary

The filename of the patch is:
     mptcp-avoid-unneeded-actions-on-subflow-reset.patch
and it can be found in the queue-5.15 subdirectory.

If you, or anyone else, feels it should not be added to the stable tree,
please let <stable@vger.kernel.org> know about it.


From stable+bounces-338612-greg=kroah.com@vger.kernel.org Sat Sep 19 22:29:39 2026
From: "Matthieu Baerts (NGI0)" <matttbe@kernel.org>
Date: Sat, 19 Sep 2026 22:29:20 +0200
Subject: mptcp: avoid unneeded actions on subflow reset
To: mptcp@lists.linux.dev, stable@vger.kernel.org, gregkh@linuxfoundation.org
Cc: Paolo Abeni <pabeni@redhat.com>, sashal@kernel.org, Xinyang Ge <xinyang@anthropic.com>, "Matthieu Baerts (NGI0)" <matttbe@kernel.org>, Jakub Kicinski <kuba@kernel.org>
Message-ID: <20260919202918.2074632-5-matttbe@kernel.org>

From: Paolo Abeni <pabeni@redhat.com>

commit 2b0f561f21b27c40c91ea4975268a06092bd7e9c upstream.

Once in a blue moon, the mptcp receive path can recursively call
mptcp_data_ready() via state change under unlucky error conditions, and
then try to hold the data lock again.

Break the recursion loop explicitly checking for the exceptional
condition.

Add a new flag instead of using an existing one like 'closing', to exit
early in subflow_state_change(), and explicitly flush the RX queue at
reset time.

This avoids unneeded processing to check for available data -- calling
get_mapping_status() and more on a dying subflow -- but also in error
reporting and worker scheduling.

Note that we must consume the currently peeked skb before invoking
mptcp_dss_corruption to avoid consuming it again after the eventual
reset has freed it.

Fixes: e32d262c89e2 ("mptcp: handle consistently DSS corruption")
Cc: stable@vger.kernel.org
Reported-by: Xinyang Ge <xinyang@anthropic.com>
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Reviewed-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Link: https://patch.msgid.link/20260917-net-mptcp-misc-fixes-7-3-rc4-v2-1-0cf5c72667c8@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
[ Note: conflict in protocol.c, because commit e0ca4057e0ec ("mptcp:
  micro-optimize __mptcp_move_skb()") is not in this version, and is
  part of a consequent rx path refactor. The conflict is in the context,
  and is easy to resolve, "done = true" can be moved along without
  consequences. Also, the context is slightly different because there is
  no DEBUG_NET_WARN_ON_ONCE in this version, see the backport commit
  12c1676d598e ("mptcp: handle consistently DSS corruption").
  Also a conflict in protocol.h, because __unused is at a different
  number. Decrement the one from this version and add the new flag
  above. The context is also a bit different with data_avail being an
  enum, but that's without consequences here.
  Also a conflict in subflow.c, because commit 71154bbe4942 ("mptcp:
  fallback earlier on simult connection") was not needed in this
  version, and cause conflicts in the context, but that's without
  consequences here. ]
Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 net/mptcp/protocol.c |    6 +++---
 net/mptcp/protocol.h |    3 ++-
 net/mptcp/subflow.c  |   11 +++++++++++
 3 files changed, 16 insertions(+), 4 deletions(-)

--- a/net/mptcp/protocol.c
+++ b/net/mptcp/protocol.c
@@ -687,11 +687,11 @@ static bool __mptcp_move_skbs_from_subfl
 			if (unlikely(map_remaining < len))
 				mptcp_dss_corruption(msk, ssk);
 		} else {
-			if (unlikely(!fin))
-				mptcp_dss_corruption(msk, ssk);
-
 			sk_eat_skb(ssk, skb);
 			done = true;
+
+			if (unlikely(!fin))
+				mptcp_dss_corruption(msk, ssk);
 		}
 
 		WRITE_ONCE(tp->copied_seq, seq);
--- a/net/mptcp/protocol.h
+++ b/net/mptcp/protocol.h
@@ -447,7 +447,8 @@ struct mptcp_subflow_context {
 		stale : 1,	    /* unable to snd/rcv data, do not use for xmit */
 		valid_csum_seen : 1,        /* at least one csum validated */
 		close_event_done : 1,       /* has done the post-closed part */
-		__unused : 11;
+		resetting : 1,	    /* subflow is resetting */
+		__unused : 10;
 	enum mptcp_data_avail data_avail;
 	bool	pm_listener;	    /* a listener managed by the kernel PM? */
 	u32	remote_nonce;
--- a/net/mptcp/subflow.c
+++ b/net/mptcp/subflow.c
@@ -373,6 +373,10 @@ void mptcp_subflow_reset(struct sock *ss
 	/* must hold: tcp_done() could drop last reference on parent */
 	sock_hold(sk);
 
+	subflow->resetting = 1;
+
+	/* No need to delay the actual close for to-be discarded data. */
+	__skb_queue_purge(&ssk->sk_receive_queue);
 	tcp_send_active_reset(ssk, GFP_ATOMIC);
 	tcp_done(ssk);
 	if (!test_and_set_bit(MPTCP_WORK_CLOSE_SUBFLOW, &mptcp_sk(sk)->flags))
@@ -1667,6 +1671,13 @@ static void subflow_state_change(struct
 
 	__subflow_state_change(sk);
 
+	/* Rx queue processing is unneeded, error reporting will take place at
+	 * __mptcp_close_ssk() time and subflow reset can't happen in case of
+	 * fallback: subflow_sched_work_if_closed() would be a no-op.
+	 */
+	if (subflow->resetting)
+		return;
+
 	msk = mptcp_sk(parent);
 	if (subflow_simultaneous_connect(sk)) {
 		mptcp_propagate_sndbuf(parent, sk);


Patches currently in stable-queue which might be from matttbe@kernel.org are

queue-5.15/mptcp-syncookies-remember-the-request-backup-flag.patch
queue-5.15/mptcp-close-race-between-scheduler-and-state-change.patch
queue-5.15/mptcp-avoid-unneeded-actions-on-subflow-reset.patch
queue-5.15/mptcp-options-handle-mpc-data-csum-reqd-no-csum.patch

^ permalink raw reply	[flat|nested] 6+ messages in thread

* Patch "mptcp: close race between scheduler and state change" has been added to the 5.15-stable tree
  2026-09-19 20:29 ` [PATCH 5.15.y 2/2] mptcp: close race between scheduler and state change Matthieu Baerts (NGI0)
@ 2026-09-20  7:36   ` gregkh
  0 siblings, 0 replies; 6+ messages in thread
From: gregkh @ 2026-09-20  7:36 UTC (permalink / raw)
  To: gregkh, kuba, matttbe, mptcp, pabeni, sashal, shardul.b, xinyang
  Cc: stable-commits


This is a note to let you know that I've just added the patch titled

    mptcp: close race between scheduler and state change

to the 5.15-stable tree which can be found at:
    http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary

The filename of the patch is:
     mptcp-close-race-between-scheduler-and-state-change.patch
and it can be found in the queue-5.15 subdirectory.

If you, or anyone else, feels it should not be added to the stable tree,
please let <stable@vger.kernel.org> know about it.


From stable+bounces-338613-greg=kroah.com@vger.kernel.org Sat Sep 19 22:29:43 2026
From: "Matthieu Baerts (NGI0)" <matttbe@kernel.org>
Date: Sat, 19 Sep 2026 22:29:21 +0200
Subject: mptcp: close race between scheduler and state change
To: mptcp@lists.linux.dev, stable@vger.kernel.org, gregkh@linuxfoundation.org
Cc: Paolo Abeni <pabeni@redhat.com>, sashal@kernel.org, Shardul Bankar <shardul.b@mpiricsoftware.com>, Xinyang Ge <xinyang@anthropic.com>, "Matthieu Baerts (NGI0)" <matttbe@kernel.org>, Jakub Kicinski <kuba@kernel.org>
Message-ID: <20260919202918.2074632-6-matttbe@kernel.org>

From: Paolo Abeni <pabeni@redhat.com>

commit 42064de57fb83231fcc89663a94885f228a1ee53 upstream.

The mptcp scheduler may race with subflow sockets state change: data
transmission on the selected socket may fail and a later release could
try to use mss_now reset to 0 for a divide operation.

Address the issue by explicitly checking for the critical scenario.

Fixes: c886d70286bf ("mptcp: do not queue data on closed subflows")
Cc: stable@vger.kernel.org
Reported-by: Shardul Bankar <shardul.b@mpiricsoftware.com>
Reported-by: Xinyang Ge <xinyang@anthropic.com>
Closes: https://lore.kernel.org/20260525194828.1137119-1-shardul.b@mpiricsoftware.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Reviewed-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Link: https://patch.msgid.link/20260917-net-mptcp-misc-fixes-7-3-rc4-v2-2-0cf5c72667c8@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 net/mptcp/protocol.c |    4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

--- a/net/mptcp/protocol.c
+++ b/net/mptcp/protocol.c
@@ -1621,7 +1621,9 @@ static struct sock *mptcp_subflow_get_se
 
 static void mptcp_push_release(struct sock *ssk, struct mptcp_sendmsg_info *info)
 {
-	tcp_push(ssk, 0, info->mss_now, tcp_sk(ssk)->nonagle, info->size_goal);
+	if (info->mss_now)
+		tcp_push(ssk, 0, info->mss_now, tcp_sk(ssk)->nonagle,
+			 info->size_goal);
 	release_sock(ssk);
 }
 


Patches currently in stable-queue which might be from matttbe@kernel.org are

queue-5.15/mptcp-syncookies-remember-the-request-backup-flag.patch
queue-5.15/mptcp-close-race-between-scheduler-and-state-change.patch
queue-5.15/mptcp-avoid-unneeded-actions-on-subflow-reset.patch
queue-5.15/mptcp-options-handle-mpc-data-csum-reqd-no-csum.patch

^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2026-09-20  7:39 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-19 20:29 [PATCH 5.15.y 0/2] mptcp: fix recent failed backports (20260919) Matthieu Baerts (NGI0)
2026-09-19 20:29 ` [PATCH 5.15.y 1/2] mptcp: avoid unneeded actions on subflow reset Matthieu Baerts (NGI0)
2026-09-19 20:42   ` sashiko-bot
2026-09-20  7:36   ` Patch "mptcp: avoid unneeded actions on subflow reset" has been added to the 5.15-stable tree gregkh
2026-09-19 20:29 ` [PATCH 5.15.y 2/2] mptcp: close race between scheduler and state change Matthieu Baerts (NGI0)
2026-09-20  7:36   ` Patch "mptcp: close race between scheduler and state change" has been added to the 5.15-stable tree gregkh

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox