From: <gregkh@linuxfoundation.org>
To: gregkh@linuxfoundation.org,kuba@kernel.org,martineau@kernel.org,matttbe@kernel.org,mptcp@lists.linux.dev,pabeni@redhat.com,sashal@kernel.org
Cc: <stable-commits@vger.kernel.org>
Subject: Patch "mptcp: consolidate subflow cleanup" has been added to the 6.1-stable tree
Date: Sun, 20 Sep 2026 09:36:34 +0200 [thread overview]
Message-ID: <2026092034-agreeably-parachute-6afb@gregkh> (raw)
In-Reply-To: <20260919201252.2025112-6-matttbe@kernel.org>
This is a note to let you know that I've just added the patch titled
mptcp: consolidate subflow cleanup
to the 6.1-stable tree which can be found at:
http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary
The filename of the patch is:
mptcp-consolidate-subflow-cleanup.patch
and it can be found in the queue-6.1 subdirectory.
If you, or anyone else, feels it should not be added to the stable tree,
please let <stable@vger.kernel.org> know about it.
From stable+bounces-338608-greg=kroah.com@vger.kernel.org Sat Sep 19 22:13:14 2026
From: "Matthieu Baerts (NGI0)" <matttbe@kernel.org>
Date: Sat, 19 Sep 2026 22:12:54 +0200
Subject: mptcp: consolidate subflow cleanup
To: mptcp@lists.linux.dev, stable@vger.kernel.org, gregkh@linuxfoundation.org
Cc: Paolo Abeni <pabeni@redhat.com>, sashal@kernel.org, Mat Martineau <martineau@kernel.org>, "Matthieu Baerts (NGI0)" <matttbe@kernel.org>, Jakub Kicinski <kuba@kernel.org>
Message-ID: <20260919201252.2025112-6-matttbe@kernel.org>
From: Paolo Abeni <pabeni@redhat.com>
commit c3349a22c2002947d29a98a77bfb36d97cfbfac1 upstream.
Consolidate all the cleanup actions requiring the worker in a single
helper and ensure the dummy data fin creation for fallback socket is
performed only when the tcp rx queue is empty.
There are no functional changes intended, but this will simplify the
next patch, when the tcp rx queue spooling could be delayed at release_cb
time.
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Reviewed-by: Mat Martineau <martineau@kernel.org>
Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Link: https://patch.msgid.link/20250218-net-next-mptcp-rx-path-refactor-v1-1-4a47d90d7998@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Stable-dep-of: 2b0f561f21b2 ("mptcp: avoid unneeded actions on subflow reset")
[ Note: also remove struct mptcp_sock *msk from subflow_state_change: it
is no longer used after this modification. ]
Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/mptcp/subflow.c | 35 ++++++++++++++++++-----------------
1 file changed, 18 insertions(+), 17 deletions(-)
--- a/net/mptcp/subflow.c
+++ b/net/mptcp/subflow.c
@@ -1159,7 +1159,12 @@ out:
subflow->map_valid = 0;
}
-/* sched mptcp worker to remove the subflow if no more data is pending */
+static bool subflow_is_done(const struct sock *sk)
+{
+ return sk->sk_shutdown & RCV_SHUTDOWN || sk->sk_state == TCP_CLOSE;
+}
+
+/* sched mptcp worker for subflow cleanup if no more data is pending */
static void subflow_sched_work_if_closed(struct mptcp_sock *msk, struct sock *ssk)
{
struct sock *sk = (struct sock *)msk;
@@ -1169,8 +1174,18 @@ static void subflow_sched_work_if_closed
inet_sk_state_load(sk) != TCP_ESTABLISHED)))
return;
- if (skb_queue_empty(&ssk->sk_receive_queue) &&
- !test_and_set_bit(MPTCP_WORK_CLOSE_SUBFLOW, &msk->flags))
+ if (!skb_queue_empty(&ssk->sk_receive_queue))
+ return;
+
+ if (!test_and_set_bit(MPTCP_WORK_CLOSE_SUBFLOW, &msk->flags))
+ mptcp_schedule_work(sk);
+
+ /* when the fallback subflow closes the rx side, trigger a 'dummy'
+ * ingress data fin, so that the msk state will follow along
+ */
+ if (__mptcp_check_fallback(msk) && subflow_is_done(ssk) &&
+ msk->first == ssk &&
+ mptcp_update_rcv_data_fin(msk, READ_ONCE(msk->ack_seq), true))
mptcp_schedule_work(sk);
}
@@ -1688,20 +1703,13 @@ static void __subflow_state_change(struc
rcu_read_unlock();
}
-static bool subflow_is_done(const struct sock *sk)
-{
- return sk->sk_shutdown & RCV_SHUTDOWN || sk->sk_state == TCP_CLOSE;
-}
-
static void subflow_state_change(struct sock *sk)
{
struct mptcp_subflow_context *subflow = mptcp_subflow_ctx(sk);
struct sock *parent = subflow->conn;
- struct mptcp_sock *msk;
__subflow_state_change(sk);
- msk = mptcp_sk(parent);
/* as recvmsg() does not acquire the subflow socket for ssk selection
* a fin packet carrying a DSS can be unnoticed if we don't trigger
* the data available machinery here.
@@ -1712,13 +1720,6 @@ static void subflow_state_change(struct
subflow_error_report(sk);
subflow_sched_work_if_closed(mptcp_sk(parent), sk);
-
- /* when the fallback subflow closes the rx side, trigger a 'dummy'
- * ingress data fin, so that the msk state will follow along
- */
- if (__mptcp_check_fallback(msk) && subflow_is_done(sk) && msk->first == sk &&
- mptcp_update_rcv_data_fin(msk, READ_ONCE(msk->ack_seq), true))
- mptcp_schedule_work(parent);
}
void mptcp_subflow_queue_clean(struct sock *listener_sk, struct sock *listener_ssk)
Patches currently in stable-queue which might be from matttbe@kernel.org are
queue-6.1/selftests-mptcp-fix-an-uaf-in-mptcp_connect.c.patch
queue-6.1/mptcp-syncookies-remember-the-request-backup-flag.patch
queue-6.1/mptcp-close-race-between-scheduler-and-state-change.patch
queue-6.1/mptcp-avoid-unneeded-actions-on-subflow-reset.patch
queue-6.1/mptcp-options-handle-mpc-data-csum-reqd-no-csum.patch
queue-6.1/mptcp-consolidate-subflow-cleanup.patch
queue-6.1/mptcp-subflow-no-need-to-copy-thmac-during-ulp_clone.patch
next prev parent reply other threads:[~2026-09-20 7:39 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-19 20:12 [PATCH 6.1.y 0/3] mptcp: fix recent failed backports (20260919) Matthieu Baerts (NGI0)
2026-09-19 20:12 ` [PATCH 6.1.y 1/3] mptcp: consolidate subflow cleanup Matthieu Baerts (NGI0)
2026-09-19 20:23 ` sashiko-bot
2026-09-19 20:30 ` Matthieu Baerts
2026-09-20 7:36 ` gregkh [this message]
2026-09-19 20:12 ` [PATCH 6.1.y 2/3] mptcp: avoid unneeded actions on subflow reset Matthieu Baerts (NGI0)
2026-09-20 7:36 ` Patch "mptcp: avoid unneeded actions on subflow reset" has been added to the 6.1-stable tree gregkh
2026-09-19 20:12 ` [PATCH 6.1.y 3/3] mptcp: close race between scheduler and state change Matthieu Baerts (NGI0)
2026-09-20 7:36 ` Patch "mptcp: close race between scheduler and state change" has been added to the 6.1-stable tree gregkh
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=2026092034-agreeably-parachute-6afb@gregkh \
--to=gregkh@linuxfoundation.org \
--cc=kuba@kernel.org \
--cc=martineau@kernel.org \
--cc=matttbe@kernel.org \
--cc=mptcp@lists.linux.dev \
--cc=pabeni@redhat.com \
--cc=sashal@kernel.org \
--cc=stable-commits@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox