* [PATCH 5.10.y 0/3] mptcp: fix recent failed backports (20260919)
@ 2026-09-19 20:40 Matthieu Baerts (NGI0)
2026-09-19 20:40 ` [PATCH 5.10.y 1/3] mptcp: hold mptcp socket before calling tcp_done Matthieu Baerts (NGI0)
` (2 more replies)
0 siblings, 3 replies; 8+ messages in thread
From: Matthieu Baerts (NGI0) @ 2026-09-19 20:40 UTC (permalink / raw)
To: mptcp, stable, gregkh; +Cc: Matthieu Baerts (NGI0), sashal
The following patches could not be applied without conflicts in this
tree:
- 2b0f561f21b2 ("mptcp: avoid unneeded actions on subflow reset")
- 42064de57fb8 ("mptcp: close race between scheduler and state change")
I backported the following commit to avoid conflicts:
- ab82e996a1fa ("mptcp: hold mptcp socket before calling tcp_done")
Conflicts (if any) have been resolved, and documented in each patch.
Florian Westphal (1):
mptcp: hold mptcp socket before calling tcp_done
Paolo Abeni (2):
mptcp: avoid unneeded actions on subflow reset
mptcp: close race between scheduler and state change
net/mptcp/protocol.c | 10 +++++-----
net/mptcp/protocol.h | 3 ++-
net/mptcp/subflow.c | 18 +++++++++++++++++-
3 files changed, 24 insertions(+), 7 deletions(-)
--
2.55.0
^ permalink raw reply [flat|nested] 8+ messages in thread* [PATCH 5.10.y 1/3] mptcp: hold mptcp socket before calling tcp_done 2026-09-19 20:40 [PATCH 5.10.y 0/3] mptcp: fix recent failed backports (20260919) Matthieu Baerts (NGI0) @ 2026-09-19 20:40 ` Matthieu Baerts (NGI0) 2026-09-20 7:36 ` Patch "mptcp: hold mptcp socket before calling tcp_done" has been added to the 5.10-stable tree gregkh 2026-09-19 20:40 ` [PATCH 5.10.y 2/3] mptcp: avoid unneeded actions on subflow reset Matthieu Baerts (NGI0) 2026-09-19 20:40 ` [PATCH 5.10.y 3/3] mptcp: close race between scheduler and state change Matthieu Baerts (NGI0) 2 siblings, 1 reply; 8+ messages in thread From: Matthieu Baerts (NGI0) @ 2026-09-19 20:40 UTC (permalink / raw) To: mptcp, stable, gregkh Cc: Florian Westphal, sashal, Matthieu Baerts, Mat Martineau, Jakub Kicinski, Matthieu Baerts (NGI0) From: Florian Westphal <fw@strlen.de> commit ab82e996a1fa1b9ae514fa357d9ce8df62321157 upstream. When processing options from tcp reset path its possible that tcp_done(ssk) drops the last reference on the mptcp socket which results in use-after-free. Reviewed-by: Matthieu Baerts <matthieu.baerts@tessares.net> Signed-off-by: Florian Westphal <fw@strlen.de> Signed-off-by: Mat Martineau <mathew.j.martineau@linux.intel.com> Signed-off-by: Jakub Kicinski <kuba@kernel.org> Stable-dep-of: 2b0f561f21b2 ("mptcp: avoid unneeded actions on subflow reset") [ Conflicts in subflow.c, because commit 3ba14528684f ("mptcp: avoid setting TCP_CLOSE state twice") has already been backported and also had the same conflict: this commit here should have been backported first. Fixed now! ] Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org> --- net/mptcp/subflow.c | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/net/mptcp/subflow.c b/net/mptcp/subflow.c index c9cf0fdbfbdc..77cc4f585cd8 100644 --- a/net/mptcp/subflow.c +++ b/net/mptcp/subflow.c @@ -279,11 +279,16 @@ void mptcp_subflow_reset(struct sock *ssk) struct mptcp_subflow_context *subflow = mptcp_subflow_ctx(ssk); struct sock *sk = subflow->conn; + /* must hold: tcp_done() could drop last reference on parent */ + sock_hold(sk); + tcp_send_active_reset(ssk, GFP_ATOMIC); tcp_done(ssk); if (!test_and_set_bit(MPTCP_WORK_CLOSE_SUBFLOW, &mptcp_sk(sk)->flags) && schedule_work(&mptcp_sk(sk)->work)) - sock_hold(sk); + return; /* worker will put sk for us */ + + sock_put(sk); } static void subflow_finish_connect(struct sock *sk, const struct sk_buff *skb) -- 2.55.0 ^ permalink raw reply related [flat|nested] 8+ messages in thread
* Patch "mptcp: hold mptcp socket before calling tcp_done" has been added to the 5.10-stable tree 2026-09-19 20:40 ` [PATCH 5.10.y 1/3] mptcp: hold mptcp socket before calling tcp_done Matthieu Baerts (NGI0) @ 2026-09-20 7:36 ` gregkh 0 siblings, 0 replies; 8+ messages in thread From: gregkh @ 2026-09-20 7:36 UTC (permalink / raw) To: fw, gregkh, kuba, mathew.j.martineau, matthieu.baerts, matttbe, mptcp, sashal Cc: stable-commits This is a note to let you know that I've just added the patch titled mptcp: hold mptcp socket before calling tcp_done to the 5.10-stable tree which can be found at: http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary The filename of the patch is: mptcp-hold-mptcp-socket-before-calling-tcp_done.patch and it can be found in the queue-5.10 subdirectory. If you, or anyone else, feels it should not be added to the stable tree, please let <stable@vger.kernel.org> know about it. From stable+bounces-338615-greg=kroah.com@vger.kernel.org Sat Sep 19 22:40:23 2026 From: "Matthieu Baerts (NGI0)" <matttbe@kernel.org> Date: Sat, 19 Sep 2026 22:40:04 +0200 Subject: mptcp: hold mptcp socket before calling tcp_done To: mptcp@lists.linux.dev, stable@vger.kernel.org, gregkh@linuxfoundation.org Cc: Florian Westphal <fw@strlen.de>, sashal@kernel.org, Matthieu Baerts <matthieu.baerts@tessares.net>, Mat Martineau <mathew.j.martineau@linux.intel.com>, Jakub Kicinski <kuba@kernel.org>, "Matthieu Baerts (NGI0)" <matttbe@kernel.org> Message-ID: <20260919204002.2106015-6-matttbe@kernel.org> From: Florian Westphal <fw@strlen.de> commit ab82e996a1fa1b9ae514fa357d9ce8df62321157 upstream. When processing options from tcp reset path its possible that tcp_done(ssk) drops the last reference on the mptcp socket which results in use-after-free. Reviewed-by: Matthieu Baerts <matthieu.baerts@tessares.net> Signed-off-by: Florian Westphal <fw@strlen.de> Signed-off-by: Mat Martineau <mathew.j.martineau@linux.intel.com> Signed-off-by: Jakub Kicinski <kuba@kernel.org> Stable-dep-of: 2b0f561f21b2 ("mptcp: avoid unneeded actions on subflow reset") [ Conflicts in subflow.c, because commit 3ba14528684f ("mptcp: avoid setting TCP_CLOSE state twice") has already been backported and also had the same conflict: this commit here should have been backported first. Fixed now! ] Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> --- net/mptcp/subflow.c | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) --- a/net/mptcp/subflow.c +++ b/net/mptcp/subflow.c @@ -279,11 +279,16 @@ void mptcp_subflow_reset(struct sock *ss struct mptcp_subflow_context *subflow = mptcp_subflow_ctx(ssk); struct sock *sk = subflow->conn; + /* must hold: tcp_done() could drop last reference on parent */ + sock_hold(sk); + tcp_send_active_reset(ssk, GFP_ATOMIC); tcp_done(ssk); if (!test_and_set_bit(MPTCP_WORK_CLOSE_SUBFLOW, &mptcp_sk(sk)->flags) && schedule_work(&mptcp_sk(sk)->work)) - sock_hold(sk); + return; /* worker will put sk for us */ + + sock_put(sk); } static void subflow_finish_connect(struct sock *sk, const struct sk_buff *skb) Patches currently in stable-queue which might be from matttbe@kernel.org are queue-5.10/mptcp-hold-mptcp-socket-before-calling-tcp_done.patch queue-5.10/mptcp-syncookies-remember-the-request-backup-flag.patch queue-5.10/mptcp-close-race-between-scheduler-and-state-change.patch queue-5.10/mptcp-avoid-unneeded-actions-on-subflow-reset.patch ^ permalink raw reply [flat|nested] 8+ messages in thread
* [PATCH 5.10.y 2/3] mptcp: avoid unneeded actions on subflow reset 2026-09-19 20:40 [PATCH 5.10.y 0/3] mptcp: fix recent failed backports (20260919) Matthieu Baerts (NGI0) 2026-09-19 20:40 ` [PATCH 5.10.y 1/3] mptcp: hold mptcp socket before calling tcp_done Matthieu Baerts (NGI0) @ 2026-09-19 20:40 ` Matthieu Baerts (NGI0) 2026-09-20 7:36 ` Patch "mptcp: avoid unneeded actions on subflow reset" has been added to the 5.10-stable tree gregkh 2026-09-19 20:40 ` [PATCH 5.10.y 3/3] mptcp: close race between scheduler and state change Matthieu Baerts (NGI0) 2 siblings, 1 reply; 8+ messages in thread From: Matthieu Baerts (NGI0) @ 2026-09-19 20:40 UTC (permalink / raw) To: mptcp, stable, gregkh Cc: Paolo Abeni, sashal, Xinyang Ge, Matthieu Baerts (NGI0), Jakub Kicinski From: Paolo Abeni <pabeni@redhat.com> commit 2b0f561f21b27c40c91ea4975268a06092bd7e9c upstream. Once in a blue moon, the mptcp receive path can recursively call mptcp_data_ready() via state change under unlucky error conditions, and then try to hold the data lock again. Break the recursion loop explicitly checking for the exceptional condition. Add a new flag instead of using an existing one like 'closing', to exit early in subflow_state_change(), and explicitly flush the RX queue at reset time. This avoids unneeded processing to check for available data -- calling get_mapping_status() and more on a dying subflow -- but also in error reporting and worker scheduling. Note that we must consume the currently peeked skb before invoking mptcp_dss_corruption to avoid consuming it again after the eventual reset has freed it. Fixes: e32d262c89e2 ("mptcp: handle consistently DSS corruption") Cc: stable@vger.kernel.org Reported-by: Xinyang Ge <xinyang@anthropic.com> Signed-off-by: Paolo Abeni <pabeni@redhat.com> Reviewed-by: Matthieu Baerts (NGI0) <matttbe@kernel.org> Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org> Link: https://patch.msgid.link/20260917-net-mptcp-misc-fixes-7-3-rc4-v2-1-0cf5c72667c8@kernel.org Signed-off-by: Jakub Kicinski <kuba@kernel.org> [ Note: conflict in protocol.c, because commit e0ca4057e0ec ("mptcp: micro-optimize __mptcp_move_skb()") is not in this version, and is part of a consequent rx path refactor. The conflict is in the context, and is easy to resolve, "done = true" can be moved along without consequences. Also, the context is slightly different because there is no DEBUG_NET_WARN_ON_ONCE in this version, see the backport commit 12c1676d598e ("mptcp: handle consistently DSS corruption"). Also a conflict in protocol.h, because __unused is at a different number. Decrement the one from this version and add the new flag above. The context is also a bit different with data_avail being an enum, but that's without consequences here. Also a conflict in subflow.c, because commit 71154bbe4942 ("mptcp: fallback earlier on simult connection") was not needed in this version, and cause conflicts in the context, but that's without consequences here. Also, a conflict in the context, because commit 81c1d0290160 ("mptcp: consolidate fallback and non fallback state machine") was not needed in this version. ] Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org> --- net/mptcp/protocol.c | 6 +++--- net/mptcp/protocol.h | 3 ++- net/mptcp/subflow.c | 11 +++++++++++ 3 files changed, 16 insertions(+), 4 deletions(-) diff --git a/net/mptcp/protocol.c b/net/mptcp/protocol.c index 2c6aef813473..292c21713eb7 100644 --- a/net/mptcp/protocol.c +++ b/net/mptcp/protocol.c @@ -581,11 +581,11 @@ static bool __mptcp_move_skbs_from_subflow(struct mptcp_sock *msk, if (unlikely(map_remaining < len)) mptcp_dss_corruption(msk, ssk); } else { - if (unlikely(!fin)) - mptcp_dss_corruption(msk, ssk); - sk_eat_skb(ssk, skb); done = true; + + if (unlikely(!fin)) + mptcp_dss_corruption(msk, ssk); } WRITE_ONCE(tp->copied_seq, seq); diff --git a/net/mptcp/protocol.h b/net/mptcp/protocol.h index ac064c44079d..b64a50b22d62 100644 --- a/net/mptcp/protocol.h +++ b/net/mptcp/protocol.h @@ -314,7 +314,8 @@ struct mptcp_subflow_context { mpc_map : 1, backup : 1, rx_eof : 1, - can_ack : 1; /* only after processing the remote a key */ + can_ack : 1, /* only after processing the remote a key */ + resetting : 1; /* subflow is resetting */ enum mptcp_data_avail data_avail; u32 remote_nonce; u64 thmac; diff --git a/net/mptcp/subflow.c b/net/mptcp/subflow.c index 77cc4f585cd8..fff70a5b06db 100644 --- a/net/mptcp/subflow.c +++ b/net/mptcp/subflow.c @@ -282,6 +282,10 @@ void mptcp_subflow_reset(struct sock *ssk) /* must hold: tcp_done() could drop last reference on parent */ sock_hold(sk); + subflow->resetting = 1; + + /* No need to delay the actual close for to-be discarded data. */ + __skb_queue_purge(&ssk->sk_receive_queue); tcp_send_active_reset(ssk, GFP_ATOMIC); tcp_done(ssk); if (!test_and_set_bit(MPTCP_WORK_CLOSE_SUBFLOW, &mptcp_sk(sk)->flags) && @@ -1302,6 +1306,13 @@ static void subflow_state_change(struct sock *sk) __subflow_state_change(sk); + /* Rx queue processing is unneeded, error reporting will take place at + * __mptcp_close_ssk() time and subflow reset can't happen in case of + * fallback: subflow_sched_work_if_closed() would be a no-op. + */ + if (subflow->resetting) + return; + if (subflow_simultaneous_connect(sk)) { mptcp_do_fallback(sk); mptcp_rcv_space_init(mptcp_sk(parent), sk); -- 2.55.0 ^ permalink raw reply related [flat|nested] 8+ messages in thread
* Patch "mptcp: avoid unneeded actions on subflow reset" has been added to the 5.10-stable tree 2026-09-19 20:40 ` [PATCH 5.10.y 2/3] mptcp: avoid unneeded actions on subflow reset Matthieu Baerts (NGI0) @ 2026-09-20 7:36 ` gregkh 0 siblings, 0 replies; 8+ messages in thread From: gregkh @ 2026-09-20 7:36 UTC (permalink / raw) To: gregkh, kuba, matttbe, mptcp, pabeni, sashal, xinyang; +Cc: stable-commits This is a note to let you know that I've just added the patch titled mptcp: avoid unneeded actions on subflow reset to the 5.10-stable tree which can be found at: http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary The filename of the patch is: mptcp-avoid-unneeded-actions-on-subflow-reset.patch and it can be found in the queue-5.10 subdirectory. If you, or anyone else, feels it should not be added to the stable tree, please let <stable@vger.kernel.org> know about it. From stable+bounces-338616-greg=kroah.com@vger.kernel.org Sat Sep 19 22:40:25 2026 From: "Matthieu Baerts (NGI0)" <matttbe@kernel.org> Date: Sat, 19 Sep 2026 22:40:05 +0200 Subject: mptcp: avoid unneeded actions on subflow reset To: mptcp@lists.linux.dev, stable@vger.kernel.org, gregkh@linuxfoundation.org Cc: Paolo Abeni <pabeni@redhat.com>, sashal@kernel.org, Xinyang Ge <xinyang@anthropic.com>, "Matthieu Baerts (NGI0)" <matttbe@kernel.org>, Jakub Kicinski <kuba@kernel.org> Message-ID: <20260919204002.2106015-7-matttbe@kernel.org> From: Paolo Abeni <pabeni@redhat.com> commit 2b0f561f21b27c40c91ea4975268a06092bd7e9c upstream. Once in a blue moon, the mptcp receive path can recursively call mptcp_data_ready() via state change under unlucky error conditions, and then try to hold the data lock again. Break the recursion loop explicitly checking for the exceptional condition. Add a new flag instead of using an existing one like 'closing', to exit early in subflow_state_change(), and explicitly flush the RX queue at reset time. This avoids unneeded processing to check for available data -- calling get_mapping_status() and more on a dying subflow -- but also in error reporting and worker scheduling. Note that we must consume the currently peeked skb before invoking mptcp_dss_corruption to avoid consuming it again after the eventual reset has freed it. Fixes: e32d262c89e2 ("mptcp: handle consistently DSS corruption") Cc: stable@vger.kernel.org Reported-by: Xinyang Ge <xinyang@anthropic.com> Signed-off-by: Paolo Abeni <pabeni@redhat.com> Reviewed-by: Matthieu Baerts (NGI0) <matttbe@kernel.org> Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org> Link: https://patch.msgid.link/20260917-net-mptcp-misc-fixes-7-3-rc4-v2-1-0cf5c72667c8@kernel.org Signed-off-by: Jakub Kicinski <kuba@kernel.org> [ Note: conflict in protocol.c, because commit e0ca4057e0ec ("mptcp: micro-optimize __mptcp_move_skb()") is not in this version, and is part of a consequent rx path refactor. The conflict is in the context, and is easy to resolve, "done = true" can be moved along without consequences. Also, the context is slightly different because there is no DEBUG_NET_WARN_ON_ONCE in this version, see the backport commit 12c1676d598e ("mptcp: handle consistently DSS corruption"). Also a conflict in protocol.h, because __unused is at a different number. Decrement the one from this version and add the new flag above. The context is also a bit different with data_avail being an enum, but that's without consequences here. Also a conflict in subflow.c, because commit 71154bbe4942 ("mptcp: fallback earlier on simult connection") was not needed in this version, and cause conflicts in the context, but that's without consequences here. Also, a conflict in the context, because commit 81c1d0290160 ("mptcp: consolidate fallback and non fallback state machine") was not needed in this version. ] Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> --- net/mptcp/protocol.c | 6 +++--- net/mptcp/protocol.h | 3 ++- net/mptcp/subflow.c | 11 +++++++++++ 3 files changed, 16 insertions(+), 4 deletions(-) --- a/net/mptcp/protocol.c +++ b/net/mptcp/protocol.c @@ -581,11 +581,11 @@ static bool __mptcp_move_skbs_from_subfl if (unlikely(map_remaining < len)) mptcp_dss_corruption(msk, ssk); } else { - if (unlikely(!fin)) - mptcp_dss_corruption(msk, ssk); - sk_eat_skb(ssk, skb); done = true; + + if (unlikely(!fin)) + mptcp_dss_corruption(msk, ssk); } WRITE_ONCE(tp->copied_seq, seq); --- a/net/mptcp/protocol.h +++ b/net/mptcp/protocol.h @@ -314,7 +314,8 @@ struct mptcp_subflow_context { mpc_map : 1, backup : 1, rx_eof : 1, - can_ack : 1; /* only after processing the remote a key */ + can_ack : 1, /* only after processing the remote a key */ + resetting : 1; /* subflow is resetting */ enum mptcp_data_avail data_avail; u32 remote_nonce; u64 thmac; --- a/net/mptcp/subflow.c +++ b/net/mptcp/subflow.c @@ -282,6 +282,10 @@ void mptcp_subflow_reset(struct sock *ss /* must hold: tcp_done() could drop last reference on parent */ sock_hold(sk); + subflow->resetting = 1; + + /* No need to delay the actual close for to-be discarded data. */ + __skb_queue_purge(&ssk->sk_receive_queue); tcp_send_active_reset(ssk, GFP_ATOMIC); tcp_done(ssk); if (!test_and_set_bit(MPTCP_WORK_CLOSE_SUBFLOW, &mptcp_sk(sk)->flags) && @@ -1302,6 +1306,13 @@ static void subflow_state_change(struct __subflow_state_change(sk); + /* Rx queue processing is unneeded, error reporting will take place at + * __mptcp_close_ssk() time and subflow reset can't happen in case of + * fallback: subflow_sched_work_if_closed() would be a no-op. + */ + if (subflow->resetting) + return; + if (subflow_simultaneous_connect(sk)) { mptcp_do_fallback(sk); mptcp_rcv_space_init(mptcp_sk(parent), sk); Patches currently in stable-queue which might be from matttbe@kernel.org are queue-5.10/mptcp-hold-mptcp-socket-before-calling-tcp_done.patch queue-5.10/mptcp-syncookies-remember-the-request-backup-flag.patch queue-5.10/mptcp-close-race-between-scheduler-and-state-change.patch queue-5.10/mptcp-avoid-unneeded-actions-on-subflow-reset.patch ^ permalink raw reply [flat|nested] 8+ messages in thread
* [PATCH 5.10.y 3/3] mptcp: close race between scheduler and state change 2026-09-19 20:40 [PATCH 5.10.y 0/3] mptcp: fix recent failed backports (20260919) Matthieu Baerts (NGI0) 2026-09-19 20:40 ` [PATCH 5.10.y 1/3] mptcp: hold mptcp socket before calling tcp_done Matthieu Baerts (NGI0) 2026-09-19 20:40 ` [PATCH 5.10.y 2/3] mptcp: avoid unneeded actions on subflow reset Matthieu Baerts (NGI0) @ 2026-09-19 20:40 ` Matthieu Baerts (NGI0) 2026-09-19 20:53 ` sashiko-bot 2026-09-20 7:36 ` Patch "mptcp: close race between scheduler and state change" has been added to the 5.10-stable tree gregkh 2 siblings, 2 replies; 8+ messages in thread From: Matthieu Baerts (NGI0) @ 2026-09-19 20:40 UTC (permalink / raw) To: mptcp, stable, gregkh Cc: Paolo Abeni, sashal, Shardul Bankar, Xinyang Ge, Matthieu Baerts (NGI0), Jakub Kicinski From: Paolo Abeni <pabeni@redhat.com> commit 42064de57fb83231fcc89663a94885f228a1ee53 upstream. The mptcp scheduler may race with subflow sockets state change: data transmission on the selected socket may fail and a later release could try to use mss_now reset to 0 for a divide operation. Address the issue by explicitly checking for the critical scenario. Fixes: c886d70286bf ("mptcp: do not queue data on closed subflows") Cc: stable@vger.kernel.org Reported-by: Shardul Bankar <shardul.b@mpiricsoftware.com> Reported-by: Xinyang Ge <xinyang@anthropic.com> Closes: https://lore.kernel.org/20260525194828.1137119-1-shardul.b@mpiricsoftware.com Signed-off-by: Paolo Abeni <pabeni@redhat.com> Reviewed-by: Matthieu Baerts (NGI0) <matttbe@kernel.org> Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org> Link: https://patch.msgid.link/20260917-net-mptcp-misc-fixes-7-3-rc4-v2-2-0cf5c72667c8@kernel.org Signed-off-by: Jakub Kicinski <kuba@kernel.org> [ Note: moved the mss_now check in previous places before commit d9ca1de8c0cd ("mptcp: move page frag allocation in mptcp_sendmsg()") which is not in this version. ] Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org> --- net/mptcp/protocol.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/net/mptcp/protocol.c b/net/mptcp/protocol.c index 292c21713eb7..fdebc451e23a 100644 --- a/net/mptcp/protocol.c +++ b/net/mptcp/protocol.c @@ -1381,7 +1381,7 @@ static int mptcp_sendmsg(struct sock *sk, struct msghdr *msg, size_t len) } mptcp_set_timeout(sk, ssk); - if (copied) { + if (copied && mss_now) { tcp_push(ssk, msg->msg_flags, mss_now, tcp_sk(ssk)->nonagle, size_goal); @@ -1891,7 +1891,7 @@ static void mptcp_worker(struct work_struct *work) if (!mptcp_ext_cache_refill(msk)) break; } - if (copied) { + if (copied && mss_now) { tcp_push(ssk, msg.msg_flags, mss_now, tcp_sk(ssk)->nonagle, size_goal); WRITE_ONCE(msk->allow_infinite_fallback, false); -- 2.55.0 ^ permalink raw reply related [flat|nested] 8+ messages in thread
* Re: [PATCH 5.10.y 3/3] mptcp: close race between scheduler and state change 2026-09-19 20:40 ` [PATCH 5.10.y 3/3] mptcp: close race between scheduler and state change Matthieu Baerts (NGI0) @ 2026-09-19 20:53 ` sashiko-bot 2026-09-20 7:36 ` Patch "mptcp: close race between scheduler and state change" has been added to the 5.10-stable tree gregkh 1 sibling, 0 replies; 8+ messages in thread From: sashiko-bot @ 2026-09-19 20:53 UTC (permalink / raw) To: Matthieu Baerts (NGI0); +Cc: mptcp Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider: - [High] mptcp: skipped timer reset when mss_now is 0 leads to connection stall - [High] mptcp: allow_infinite_fallback state corruption when mss_now is 0 -- commit 4c31a1df5ba815467dd012d7f0c9b7bc2457aca9 Author: Paolo Abeni <pabeni@redhat.com> mptcp: close race between scheduler and state change This commit adds a check for mss_now being 0 to prevent a divide by zero operation when selecting a subflow socket. It modifies mptcp_sendmsg and mptcp_worker to only trigger tcp_push if both copied and mss_now are non-zero. Link: https://patch.msgid.link/20260917-net-mptcp-misc-fixes-7-3-rc4-v2-2-0cf5c72667c8@kernel.org > diff --git a/net/mptcp/protocol.c b/net/mptcp/protocol.c > index 292c21713eb7f..fdebc451e23aa 100644 > --- a/net/mptcp/protocol.c > +++ b/net/mptcp/protocol.c > @@ -1381,7 +1381,7 @@ static int mptcp_sendmsg(struct sock *sk, struct msghdr *msg, size_t len) > } > > mptcp_set_timeout(sk, ssk); > - if (copied) { > + if (copied && mss_now) { > tcp_push(ssk, msg->msg_flags, mss_now, tcp_sk(ssk)->nonagle, > size_goal); > > /* start the timer, if it's not pending */ > if (!mptcp_timer_pending(sk)) > mptcp_reset_timer(sk); > } [Severity: High] Does this unintentionally skip resetting the retransmit timer when mss_now is 0? If multiple fragments are sent and a subsequent fragment fails, it can leave copied > 0 but mss_now == 0. By bundling the timer initialization with the mss_now check, this might prevent data queued to the MPTCP socket from being retransmitted if the current subflow fails, potentially stalling the connection. [ ... ] > @@ -1891,7 +1891,7 @@ static void mptcp_worker(struct work_struct *work) > if (!mptcp_ext_cache_refill(msk)) > break; > } > - if (copied) { > + if (copied && mss_now) { > tcp_push(ssk, msg.msg_flags, mss_now, tcp_sk(ssk)->nonagle, > size_goal); > WRITE_ONCE(msk->allow_infinite_fallback, false); > } [Severity: High] Could skipping this block when mss_now is 0 cause allow_infinite_fallback state corruption? In mptcp_worker(), if a subflow failure occurs during retransmission causing mss_now == 0, copied might still be > 0. Skipping the update to msk->allow_infinite_fallback could leave it as true even after MPTCP data was successfully queued. A subsequent error might then trigger an invalid fallback to plain TCP, corrupting the connection state and stream data. -- Sashiko AI review · https://sashiko.dev/#/patchset/20260919204002.2106015-5-matttbe@kernel.org?part=3 ^ permalink raw reply [flat|nested] 8+ messages in thread
* Patch "mptcp: close race between scheduler and state change" has been added to the 5.10-stable tree 2026-09-19 20:40 ` [PATCH 5.10.y 3/3] mptcp: close race between scheduler and state change Matthieu Baerts (NGI0) 2026-09-19 20:53 ` sashiko-bot @ 2026-09-20 7:36 ` gregkh 1 sibling, 0 replies; 8+ messages in thread From: gregkh @ 2026-09-20 7:36 UTC (permalink / raw) To: gregkh, kuba, matttbe, mptcp, pabeni, sashal, shardul.b, xinyang Cc: stable-commits This is a note to let you know that I've just added the patch titled mptcp: close race between scheduler and state change to the 5.10-stable tree which can be found at: http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary The filename of the patch is: mptcp-close-race-between-scheduler-and-state-change.patch and it can be found in the queue-5.10 subdirectory. If you, or anyone else, feels it should not be added to the stable tree, please let <stable@vger.kernel.org> know about it. From stable+bounces-338617-greg=kroah.com@vger.kernel.org Sat Sep 19 22:40:32 2026 From: "Matthieu Baerts (NGI0)" <matttbe@kernel.org> Date: Sat, 19 Sep 2026 22:40:06 +0200 Subject: mptcp: close race between scheduler and state change To: mptcp@lists.linux.dev, stable@vger.kernel.org, gregkh@linuxfoundation.org Cc: Paolo Abeni <pabeni@redhat.com>, sashal@kernel.org, Shardul Bankar <shardul.b@mpiricsoftware.com>, Xinyang Ge <xinyang@anthropic.com>, "Matthieu Baerts (NGI0)" <matttbe@kernel.org>, Jakub Kicinski <kuba@kernel.org> Message-ID: <20260919204002.2106015-8-matttbe@kernel.org> From: Paolo Abeni <pabeni@redhat.com> commit 42064de57fb83231fcc89663a94885f228a1ee53 upstream. The mptcp scheduler may race with subflow sockets state change: data transmission on the selected socket may fail and a later release could try to use mss_now reset to 0 for a divide operation. Address the issue by explicitly checking for the critical scenario. Fixes: c886d70286bf ("mptcp: do not queue data on closed subflows") Cc: stable@vger.kernel.org Reported-by: Shardul Bankar <shardul.b@mpiricsoftware.com> Reported-by: Xinyang Ge <xinyang@anthropic.com> Closes: https://lore.kernel.org/20260525194828.1137119-1-shardul.b@mpiricsoftware.com Signed-off-by: Paolo Abeni <pabeni@redhat.com> Reviewed-by: Matthieu Baerts (NGI0) <matttbe@kernel.org> Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org> Link: https://patch.msgid.link/20260917-net-mptcp-misc-fixes-7-3-rc4-v2-2-0cf5c72667c8@kernel.org Signed-off-by: Jakub Kicinski <kuba@kernel.org> [ Note: moved the mss_now check in previous places before commit d9ca1de8c0cd ("mptcp: move page frag allocation in mptcp_sendmsg()") which is not in this version. ] Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> --- net/mptcp/protocol.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) --- a/net/mptcp/protocol.c +++ b/net/mptcp/protocol.c @@ -1381,7 +1381,7 @@ restart: } mptcp_set_timeout(sk, ssk); - if (copied) { + if (copied && mss_now) { tcp_push(ssk, msg->msg_flags, mss_now, tcp_sk(ssk)->nonagle, size_goal); @@ -1891,7 +1891,7 @@ static void mptcp_worker(struct work_str if (!mptcp_ext_cache_refill(msk)) break; } - if (copied) { + if (copied && mss_now) { tcp_push(ssk, msg.msg_flags, mss_now, tcp_sk(ssk)->nonagle, size_goal); WRITE_ONCE(msk->allow_infinite_fallback, false); Patches currently in stable-queue which might be from matttbe@kernel.org are queue-5.10/mptcp-hold-mptcp-socket-before-calling-tcp_done.patch queue-5.10/mptcp-syncookies-remember-the-request-backup-flag.patch queue-5.10/mptcp-close-race-between-scheduler-and-state-change.patch queue-5.10/mptcp-avoid-unneeded-actions-on-subflow-reset.patch ^ permalink raw reply [flat|nested] 8+ messages in thread
end of thread, other threads:[~2026-09-20 7:39 UTC | newest] Thread overview: 8+ messages (download: mbox.gz follow: Atom feed -- links below jump to the message on this page -- 2026-09-19 20:40 [PATCH 5.10.y 0/3] mptcp: fix recent failed backports (20260919) Matthieu Baerts (NGI0) 2026-09-19 20:40 ` [PATCH 5.10.y 1/3] mptcp: hold mptcp socket before calling tcp_done Matthieu Baerts (NGI0) 2026-09-20 7:36 ` Patch "mptcp: hold mptcp socket before calling tcp_done" has been added to the 5.10-stable tree gregkh 2026-09-19 20:40 ` [PATCH 5.10.y 2/3] mptcp: avoid unneeded actions on subflow reset Matthieu Baerts (NGI0) 2026-09-20 7:36 ` Patch "mptcp: avoid unneeded actions on subflow reset" has been added to the 5.10-stable tree gregkh 2026-09-19 20:40 ` [PATCH 5.10.y 3/3] mptcp: close race between scheduler and state change Matthieu Baerts (NGI0) 2026-09-19 20:53 ` sashiko-bot 2026-09-20 7:36 ` Patch "mptcp: close race between scheduler and state change" has been added to the 5.10-stable tree gregkh
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox