MPTCP Linux Development
 help / color / mirror / Atom feed
* [PATCH 6.1.y 0/3] mptcp: fix recent failed backports (20260919)
@ 2026-09-19 20:12 Matthieu Baerts (NGI0)
  2026-09-19 20:12 ` [PATCH 6.1.y 1/3] mptcp: consolidate subflow cleanup Matthieu Baerts (NGI0)
                   ` (2 more replies)
  0 siblings, 3 replies; 9+ messages in thread
From: Matthieu Baerts (NGI0) @ 2026-09-19 20:12 UTC (permalink / raw)
  To: mptcp, stable, gregkh; +Cc: Matthieu Baerts (NGI0), sashal

The following patches could not be applied without conflicts in this
tree:

- 2b0f561f21b2 ("mptcp: avoid unneeded actions on subflow reset")
- 42064de57fb8 ("mptcp: close race between scheduler and state change")

I backported the following commit to avoid conflicts:

- c3349a22c200 ("mptcp: consolidate subflow cleanup")

Conflicts (if any) have been resolved, and documented in each patch.

Paolo Abeni (3):
  mptcp: consolidate subflow cleanup
  mptcp: avoid unneeded actions on subflow reset
  mptcp: close race between scheduler and state change

 net/mptcp/protocol.c | 10 ++++++----
 net/mptcp/protocol.h |  3 ++-
 net/mptcp/subflow.c  | 46 ++++++++++++++++++++++++++++----------------
 3 files changed, 37 insertions(+), 22 deletions(-)

-- 
2.55.0


^ permalink raw reply	[flat|nested] 9+ messages in thread

* [PATCH 6.1.y 1/3] mptcp: consolidate subflow cleanup
  2026-09-19 20:12 [PATCH 6.1.y 0/3] mptcp: fix recent failed backports (20260919) Matthieu Baerts (NGI0)
@ 2026-09-19 20:12 ` Matthieu Baerts (NGI0)
  2026-09-19 20:23   ` sashiko-bot
  2026-09-20  7:36   ` Patch "mptcp: consolidate subflow cleanup" has been added to the 6.1-stable tree gregkh
  2026-09-19 20:12 ` [PATCH 6.1.y 2/3] mptcp: avoid unneeded actions on subflow reset Matthieu Baerts (NGI0)
  2026-09-19 20:12 ` [PATCH 6.1.y 3/3] mptcp: close race between scheduler and state change Matthieu Baerts (NGI0)
  2 siblings, 2 replies; 9+ messages in thread
From: Matthieu Baerts (NGI0) @ 2026-09-19 20:12 UTC (permalink / raw)
  To: mptcp, stable, gregkh
  Cc: Paolo Abeni, sashal, Mat Martineau, Matthieu Baerts (NGI0),
	Jakub Kicinski

From: Paolo Abeni <pabeni@redhat.com>

commit c3349a22c2002947d29a98a77bfb36d97cfbfac1 upstream.

Consolidate all the cleanup actions requiring the worker in a single
helper and ensure the dummy data fin creation for fallback socket is
performed only when the tcp rx queue is empty.

There are no functional changes intended, but this will simplify the
next patch, when the tcp rx queue spooling could be delayed at release_cb
time.

Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Reviewed-by: Mat Martineau <martineau@kernel.org>
Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Link: https://patch.msgid.link/20250218-net-next-mptcp-rx-path-refactor-v1-1-4a47d90d7998@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Stable-dep-of: 2b0f561f21b2 ("mptcp: avoid unneeded actions on subflow reset")
[ Note: also remove struct mptcp_sock *msk from subflow_state_change: it
  is no longer used after this modification. ]
Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
---
 net/mptcp/subflow.c | 35 ++++++++++++++++++-----------------
 1 file changed, 18 insertions(+), 17 deletions(-)

diff --git a/net/mptcp/subflow.c b/net/mptcp/subflow.c
index eed5b90bf5a0..07cdb162b709 100644
--- a/net/mptcp/subflow.c
+++ b/net/mptcp/subflow.c
@@ -1159,7 +1159,12 @@ static void mptcp_subflow_discard_data(struct sock *ssk, struct sk_buff *skb,
 		subflow->map_valid = 0;
 }
 
-/* sched mptcp worker to remove the subflow if no more data is pending */
+static bool subflow_is_done(const struct sock *sk)
+{
+	return sk->sk_shutdown & RCV_SHUTDOWN || sk->sk_state == TCP_CLOSE;
+}
+
+/* sched mptcp worker for subflow cleanup if no more data is pending */
 static void subflow_sched_work_if_closed(struct mptcp_sock *msk, struct sock *ssk)
 {
 	struct sock *sk = (struct sock *)msk;
@@ -1169,8 +1174,18 @@ static void subflow_sched_work_if_closed(struct mptcp_sock *msk, struct sock *ss
 		    inet_sk_state_load(sk) != TCP_ESTABLISHED)))
 		return;
 
-	if (skb_queue_empty(&ssk->sk_receive_queue) &&
-	    !test_and_set_bit(MPTCP_WORK_CLOSE_SUBFLOW, &msk->flags))
+	if (!skb_queue_empty(&ssk->sk_receive_queue))
+		return;
+
+	if (!test_and_set_bit(MPTCP_WORK_CLOSE_SUBFLOW, &msk->flags))
+		mptcp_schedule_work(sk);
+
+	/* when the fallback subflow closes the rx side, trigger a 'dummy'
+	 * ingress data fin, so that the msk state will follow along
+	 */
+	if (__mptcp_check_fallback(msk) && subflow_is_done(ssk) &&
+	    msk->first == ssk &&
+	    mptcp_update_rcv_data_fin(msk, READ_ONCE(msk->ack_seq), true))
 		mptcp_schedule_work(sk);
 }
 
@@ -1688,20 +1703,13 @@ static void __subflow_state_change(struct sock *sk)
 	rcu_read_unlock();
 }
 
-static bool subflow_is_done(const struct sock *sk)
-{
-	return sk->sk_shutdown & RCV_SHUTDOWN || sk->sk_state == TCP_CLOSE;
-}
-
 static void subflow_state_change(struct sock *sk)
 {
 	struct mptcp_subflow_context *subflow = mptcp_subflow_ctx(sk);
 	struct sock *parent = subflow->conn;
-	struct mptcp_sock *msk;
 
 	__subflow_state_change(sk);
 
-	msk = mptcp_sk(parent);
 	/* as recvmsg() does not acquire the subflow socket for ssk selection
 	 * a fin packet carrying a DSS can be unnoticed if we don't trigger
 	 * the data available machinery here.
@@ -1712,13 +1720,6 @@ static void subflow_state_change(struct sock *sk)
 		subflow_error_report(sk);
 
 	subflow_sched_work_if_closed(mptcp_sk(parent), sk);
-
-	/* when the fallback subflow closes the rx side, trigger a 'dummy'
-	 * ingress data fin, so that the msk state will follow along
-	 */
-	if (__mptcp_check_fallback(msk) && subflow_is_done(sk) && msk->first == sk &&
-	    mptcp_update_rcv_data_fin(msk, READ_ONCE(msk->ack_seq), true))
-		mptcp_schedule_work(parent);
 }
 
 void mptcp_subflow_queue_clean(struct sock *listener_sk, struct sock *listener_ssk)
-- 
2.55.0


^ permalink raw reply related	[flat|nested] 9+ messages in thread

* [PATCH 6.1.y 2/3] mptcp: avoid unneeded actions on subflow reset
  2026-09-19 20:12 [PATCH 6.1.y 0/3] mptcp: fix recent failed backports (20260919) Matthieu Baerts (NGI0)
  2026-09-19 20:12 ` [PATCH 6.1.y 1/3] mptcp: consolidate subflow cleanup Matthieu Baerts (NGI0)
@ 2026-09-19 20:12 ` Matthieu Baerts (NGI0)
  2026-09-20  7:36   ` Patch "mptcp: avoid unneeded actions on subflow reset" has been added to the 6.1-stable tree gregkh
  2026-09-19 20:12 ` [PATCH 6.1.y 3/3] mptcp: close race between scheduler and state change Matthieu Baerts (NGI0)
  2 siblings, 1 reply; 9+ messages in thread
From: Matthieu Baerts (NGI0) @ 2026-09-19 20:12 UTC (permalink / raw)
  To: mptcp, stable, gregkh
  Cc: Paolo Abeni, sashal, Xinyang Ge, Matthieu Baerts (NGI0),
	Jakub Kicinski

From: Paolo Abeni <pabeni@redhat.com>

commit 2b0f561f21b27c40c91ea4975268a06092bd7e9c upstream.

Once in a blue moon, the mptcp receive path can recursively call
mptcp_data_ready() via state change under unlucky error conditions, and
then try to hold the data lock again.

Break the recursion loop explicitly checking for the exceptional
condition.

Add a new flag instead of using an existing one like 'closing', to exit
early in subflow_state_change(), and explicitly flush the RX queue at
reset time.

This avoids unneeded processing to check for available data -- calling
get_mapping_status() and more on a dying subflow -- but also in error
reporting and worker scheduling.

Note that we must consume the currently peeked skb before invoking
mptcp_dss_corruption to avoid consuming it again after the eventual
reset has freed it.

Fixes: e32d262c89e2 ("mptcp: handle consistently DSS corruption")
Cc: stable@vger.kernel.org
Reported-by: Xinyang Ge <xinyang@anthropic.com>
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Reviewed-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Link: https://patch.msgid.link/20260917-net-mptcp-misc-fixes-7-3-rc4-v2-1-0cf5c72667c8@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
[ Note: conflict in protocol.c, because commit e0ca4057e0ec ("mptcp:
  micro-optimize __mptcp_move_skb()") is not in this version, and is
  part of a consequent rx path refactor. The conflict is in the context,
  and is easy to resolve, "done = true" can be moved along without
  consequences.
  Also a conflict in protocol.h, because __unused is at a different
  number. Decrement the one from this version and add the new flag
  above. The context is also a bit different with data_avail being an
  enum, but that's without consequences here. ]
Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
---
 net/mptcp/protocol.c |  6 +++---
 net/mptcp/protocol.h |  3 ++-
 net/mptcp/subflow.c  | 11 +++++++++++
 3 files changed, 16 insertions(+), 4 deletions(-)

diff --git a/net/mptcp/protocol.c b/net/mptcp/protocol.c
index 2ce20884d730..ab83cf46a8c3 100644
--- a/net/mptcp/protocol.c
+++ b/net/mptcp/protocol.c
@@ -754,13 +754,13 @@ static bool __mptcp_move_skbs_from_subflow(struct mptcp_sock *msk,
 				mptcp_dss_corruption(msk, ssk);
 			}
 		} else {
+			sk_eat_skb(ssk, skb);
+			done = true;
+
 			if (unlikely(!fin)) {
 				DEBUG_NET_WARN_ON_ONCE(1);
 				mptcp_dss_corruption(msk, ssk);
 			}
-
-			sk_eat_skb(ssk, skb);
-			done = true;
 		}
 
 		WRITE_ONCE(tp->copied_seq, seq);
diff --git a/net/mptcp/protocol.h b/net/mptcp/protocol.h
index e835028fc4e5..1de257b86839 100644
--- a/net/mptcp/protocol.h
+++ b/net/mptcp/protocol.h
@@ -492,7 +492,8 @@ struct mptcp_subflow_context {
 		stale : 1,	    /* unable to snd/rcv data, do not use for xmit */
 		valid_csum_seen : 1,        /* at least one csum validated */
 		close_event_done : 1,       /* has done the post-closed part */
-		__unused : 9;
+		resetting : 1,	    /* subflow is resetting */
+		__unused : 8;
 	enum mptcp_data_avail data_avail;
 	bool	pm_listener;	    /* a listener managed by the kernel PM? */
 	u32	remote_nonce;
diff --git a/net/mptcp/subflow.c b/net/mptcp/subflow.c
index 07cdb162b709..cc62681d6ea8 100644
--- a/net/mptcp/subflow.c
+++ b/net/mptcp/subflow.c
@@ -379,6 +379,10 @@ void mptcp_subflow_reset(struct sock *ssk)
 	/* must hold: tcp_done() could drop last reference on parent */
 	sock_hold(sk);
 
+	subflow->resetting = 1;
+
+	/* No need to delay the actual close for to-be discarded data. */
+	__skb_queue_purge(&ssk->sk_receive_queue);
 	tcp_send_active_reset(ssk, GFP_ATOMIC);
 	tcp_done(ssk);
 	if (!test_and_set_bit(MPTCP_WORK_CLOSE_SUBFLOW, &mptcp_sk(sk)->flags))
@@ -1710,6 +1714,13 @@ static void subflow_state_change(struct sock *sk)
 
 	__subflow_state_change(sk);
 
+	/* Rx queue processing is unneeded, error reporting will take place at
+	 * __mptcp_close_ssk() time and subflow reset can't happen in case of
+	 * fallback: subflow_sched_work_if_closed() would be a no-op.
+	 */
+	if (subflow->resetting)
+		return;
+
 	/* as recvmsg() does not acquire the subflow socket for ssk selection
 	 * a fin packet carrying a DSS can be unnoticed if we don't trigger
 	 * the data available machinery here.
-- 
2.55.0


^ permalink raw reply related	[flat|nested] 9+ messages in thread

* [PATCH 6.1.y 3/3] mptcp: close race between scheduler and state change
  2026-09-19 20:12 [PATCH 6.1.y 0/3] mptcp: fix recent failed backports (20260919) Matthieu Baerts (NGI0)
  2026-09-19 20:12 ` [PATCH 6.1.y 1/3] mptcp: consolidate subflow cleanup Matthieu Baerts (NGI0)
  2026-09-19 20:12 ` [PATCH 6.1.y 2/3] mptcp: avoid unneeded actions on subflow reset Matthieu Baerts (NGI0)
@ 2026-09-19 20:12 ` Matthieu Baerts (NGI0)
  2026-09-20  7:36   ` Patch "mptcp: close race between scheduler and state change" has been added to the 6.1-stable tree gregkh
  2 siblings, 1 reply; 9+ messages in thread
From: Matthieu Baerts (NGI0) @ 2026-09-19 20:12 UTC (permalink / raw)
  To: mptcp, stable, gregkh
  Cc: Paolo Abeni, sashal, Shardul Bankar, Xinyang Ge,
	Matthieu Baerts (NGI0), Jakub Kicinski

From: Paolo Abeni <pabeni@redhat.com>

commit 42064de57fb83231fcc89663a94885f228a1ee53 upstream.

The mptcp scheduler may race with subflow sockets state change: data
transmission on the selected socket may fail and a later release could
try to use mss_now reset to 0 for a divide operation.

Address the issue by explicitly checking for the critical scenario.

Fixes: c886d70286bf ("mptcp: do not queue data on closed subflows")
Cc: stable@vger.kernel.org
Reported-by: Shardul Bankar <shardul.b@mpiricsoftware.com>
Reported-by: Xinyang Ge <xinyang@anthropic.com>
Closes: https://lore.kernel.org/20260525194828.1137119-1-shardul.b@mpiricsoftware.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Reviewed-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Link: https://patch.msgid.link/20260917-net-mptcp-misc-fixes-7-3-rc4-v2-2-0cf5c72667c8@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
---
 net/mptcp/protocol.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/net/mptcp/protocol.c b/net/mptcp/protocol.c
index ab83cf46a8c3..ca78add7670d 100644
--- a/net/mptcp/protocol.c
+++ b/net/mptcp/protocol.c
@@ -1636,7 +1636,9 @@ static struct sock *mptcp_subflow_get_send(struct mptcp_sock *msk)
 
 static void mptcp_push_release(struct sock *ssk, struct mptcp_sendmsg_info *info)
 {
-	tcp_push(ssk, 0, info->mss_now, tcp_sk(ssk)->nonagle, info->size_goal);
+	if (info->mss_now)
+		tcp_push(ssk, 0, info->mss_now, tcp_sk(ssk)->nonagle,
+			 info->size_goal);
 	release_sock(ssk);
 }
 
-- 
2.55.0


^ permalink raw reply related	[flat|nested] 9+ messages in thread

* Re: [PATCH 6.1.y 1/3] mptcp: consolidate subflow cleanup
  2026-09-19 20:12 ` [PATCH 6.1.y 1/3] mptcp: consolidate subflow cleanup Matthieu Baerts (NGI0)
@ 2026-09-19 20:23   ` sashiko-bot
  2026-09-19 20:30     ` Matthieu Baerts
  2026-09-20  7:36   ` Patch "mptcp: consolidate subflow cleanup" has been added to the 6.1-stable tree gregkh
  1 sibling, 1 reply; 9+ messages in thread
From: sashiko-bot @ 2026-09-19 20:23 UTC (permalink / raw)
  To: Matthieu Baerts (NGI0); +Cc: mptcp

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] mptcp: socket hang in fallback teardown due to restrictive state checks
--

commit 56f82de860d8f3b2e8b76eca945e8a61ec848e3a
Author: Paolo Abeni <pabeni@redhat.com>

mptcp: consolidate subflow cleanup

This commit consolidates subflow cleanup actions requiring the worker into a
single helper. It ensures the dummy data FIN creation for fallback sockets is
performed only when the TCP receive queue is empty.

Link: https://patch.msgid.link/20250218-net-next-mptcp-rx-path-refactor-v1-1-4a47d90d7998@kernel.org

> diff --git a/net/mptcp/subflow.c b/net/mptcp/subflow.c
> index d9734bfb7283b..9bbeed6290d7a 100644
> --- a/net/mptcp/subflow.c
> +++ b/net/mptcp/subflow.c

[ ... ]

> @@ -1169,8 +1174,18 @@ static void subflow_sched_work_if_closed(struct mptcp_sock *msk, struct sock *ss
>  		    inet_sk_state_load(sk) != TCP_ESTABLISHED)))
>  		return;
>  
> -	if (skb_queue_empty(&ssk->sk_receive_queue) &&
> -	    !test_and_set_bit(MPTCP_WORK_CLOSE_SUBFLOW, &msk->flags))
> +	if (!skb_queue_empty(&ssk->sk_receive_queue))
> +		return;
> +
> +	if (!test_and_set_bit(MPTCP_WORK_CLOSE_SUBFLOW, &msk->flags))
> +		mptcp_schedule_work(sk);
> +
> +	/* when the fallback subflow closes the rx side, trigger a 'dummy'
> +	 * ingress data fin, so that the msk state will follow along
> +	 */
> +	if (__mptcp_check_fallback(msk) && subflow_is_done(ssk) &&
> +	    msk->first == ssk &&
> +	    mptcp_update_rcv_data_fin(msk, READ_ONCE(msk->ack_seq), true))
>  		mptcp_schedule_work(sk);
>  }

[Severity: High]
Does this new placement of the fallback dummy FIN logic cause a socket hang
during connection teardown?

In the previous implementation, the dummy FIN injection was executed in
subflow_state_change() regardless of the early returns in
subflow_sched_work_if_closed().

By moving it inside subflow_sched_work_if_closed(), it is now gated by the
restrictive state checks at the top of the function:

	if (likely(ssk->sk_state != TCP_CLOSE &&
		   (ssk->sk_state != TCP_CLOSE_WAIT ||
		    inet_sk_state_load(sk) != TCP_ESTABLISHED)))
		return;

When a local application closes a fallback connection, the msk transitions
to TCP_FIN_WAIT1 or TCP_FIN_WAIT2. If the remote peer then sends a FIN, the
underlying TCP subflow (ssk) transitions to TCP_CLOSING or TCP_TIME_WAIT.
Since the ssk is neither in TCP_CLOSE nor TCP_CLOSE_WAIT, the function
returns early.

Will this skip the fallback dummy FIN injection entirely, leaving the msk
state machine stuck without mptcp_update_rcv_data_fin() and causing
fallback MPTCP sockets to hang indefinitely?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260919201252.2025112-5-matttbe@kernel.org?part=1

^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: [PATCH 6.1.y 1/3] mptcp: consolidate subflow cleanup
  2026-09-19 20:23   ` sashiko-bot
@ 2026-09-19 20:30     ` Matthieu Baerts
  0 siblings, 0 replies; 9+ messages in thread
From: Matthieu Baerts @ 2026-09-19 20:30 UTC (permalink / raw)
  To: sashiko-reviews; +Cc: mptcp

On 19/09/2026 22:23, sashiko-bot@kernel.org wrote:
> Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
> - [High] mptcp: socket hang in fallback teardown due to restrictive state checks

I guess I would have quickly seen that in the mptcp_connect*.sh tests.

Cheers,
Matt
-- 
Sponsored by the NGI0 Core fund.


^ permalink raw reply	[flat|nested] 9+ messages in thread

* Patch "mptcp: close race between scheduler and state change" has been added to the 6.1-stable tree
  2026-09-19 20:12 ` [PATCH 6.1.y 3/3] mptcp: close race between scheduler and state change Matthieu Baerts (NGI0)
@ 2026-09-20  7:36   ` gregkh
  0 siblings, 0 replies; 9+ messages in thread
From: gregkh @ 2026-09-20  7:36 UTC (permalink / raw)
  To: gregkh, kuba, matttbe, mptcp, pabeni, sashal, shardul.b, xinyang
  Cc: stable-commits


This is a note to let you know that I've just added the patch titled

    mptcp: close race between scheduler and state change

to the 6.1-stable tree which can be found at:
    http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary

The filename of the patch is:
     mptcp-close-race-between-scheduler-and-state-change.patch
and it can be found in the queue-6.1 subdirectory.

If you, or anyone else, feels it should not be added to the stable tree,
please let <stable@vger.kernel.org> know about it.


From stable+bounces-338610-greg=kroah.com@vger.kernel.org Sat Sep 19 22:13:35 2026
From: "Matthieu Baerts (NGI0)" <matttbe@kernel.org>
Date: Sat, 19 Sep 2026 22:12:56 +0200
Subject: mptcp: close race between scheduler and state change
To: mptcp@lists.linux.dev, stable@vger.kernel.org, gregkh@linuxfoundation.org
Cc: Paolo Abeni <pabeni@redhat.com>, sashal@kernel.org, Shardul Bankar <shardul.b@mpiricsoftware.com>, Xinyang Ge <xinyang@anthropic.com>, "Matthieu Baerts (NGI0)" <matttbe@kernel.org>, Jakub Kicinski <kuba@kernel.org>
Message-ID: <20260919201252.2025112-8-matttbe@kernel.org>

From: Paolo Abeni <pabeni@redhat.com>

commit 42064de57fb83231fcc89663a94885f228a1ee53 upstream.

The mptcp scheduler may race with subflow sockets state change: data
transmission on the selected socket may fail and a later release could
try to use mss_now reset to 0 for a divide operation.

Address the issue by explicitly checking for the critical scenario.

Fixes: c886d70286bf ("mptcp: do not queue data on closed subflows")
Cc: stable@vger.kernel.org
Reported-by: Shardul Bankar <shardul.b@mpiricsoftware.com>
Reported-by: Xinyang Ge <xinyang@anthropic.com>
Closes: https://lore.kernel.org/20260525194828.1137119-1-shardul.b@mpiricsoftware.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Reviewed-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Link: https://patch.msgid.link/20260917-net-mptcp-misc-fixes-7-3-rc4-v2-2-0cf5c72667c8@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 net/mptcp/protocol.c |    4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

--- a/net/mptcp/protocol.c
+++ b/net/mptcp/protocol.c
@@ -1636,7 +1636,9 @@ static struct sock *mptcp_subflow_get_se
 
 static void mptcp_push_release(struct sock *ssk, struct mptcp_sendmsg_info *info)
 {
-	tcp_push(ssk, 0, info->mss_now, tcp_sk(ssk)->nonagle, info->size_goal);
+	if (info->mss_now)
+		tcp_push(ssk, 0, info->mss_now, tcp_sk(ssk)->nonagle,
+			 info->size_goal);
 	release_sock(ssk);
 }
 


Patches currently in stable-queue which might be from matttbe@kernel.org are

queue-6.1/selftests-mptcp-fix-an-uaf-in-mptcp_connect.c.patch
queue-6.1/mptcp-syncookies-remember-the-request-backup-flag.patch
queue-6.1/mptcp-close-race-between-scheduler-and-state-change.patch
queue-6.1/mptcp-avoid-unneeded-actions-on-subflow-reset.patch
queue-6.1/mptcp-options-handle-mpc-data-csum-reqd-no-csum.patch
queue-6.1/mptcp-consolidate-subflow-cleanup.patch
queue-6.1/mptcp-subflow-no-need-to-copy-thmac-during-ulp_clone.patch

^ permalink raw reply	[flat|nested] 9+ messages in thread

* Patch "mptcp: consolidate subflow cleanup" has been added to the 6.1-stable tree
  2026-09-19 20:12 ` [PATCH 6.1.y 1/3] mptcp: consolidate subflow cleanup Matthieu Baerts (NGI0)
  2026-09-19 20:23   ` sashiko-bot
@ 2026-09-20  7:36   ` gregkh
  1 sibling, 0 replies; 9+ messages in thread
From: gregkh @ 2026-09-20  7:36 UTC (permalink / raw)
  To: gregkh, kuba, martineau, matttbe, mptcp, pabeni, sashal; +Cc: stable-commits


This is a note to let you know that I've just added the patch titled

    mptcp: consolidate subflow cleanup

to the 6.1-stable tree which can be found at:
    http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary

The filename of the patch is:
     mptcp-consolidate-subflow-cleanup.patch
and it can be found in the queue-6.1 subdirectory.

If you, or anyone else, feels it should not be added to the stable tree,
please let <stable@vger.kernel.org> know about it.


From stable+bounces-338608-greg=kroah.com@vger.kernel.org Sat Sep 19 22:13:14 2026
From: "Matthieu Baerts (NGI0)" <matttbe@kernel.org>
Date: Sat, 19 Sep 2026 22:12:54 +0200
Subject: mptcp: consolidate subflow cleanup
To: mptcp@lists.linux.dev, stable@vger.kernel.org, gregkh@linuxfoundation.org
Cc: Paolo Abeni <pabeni@redhat.com>, sashal@kernel.org, Mat Martineau <martineau@kernel.org>, "Matthieu Baerts (NGI0)" <matttbe@kernel.org>, Jakub Kicinski <kuba@kernel.org>
Message-ID: <20260919201252.2025112-6-matttbe@kernel.org>

From: Paolo Abeni <pabeni@redhat.com>

commit c3349a22c2002947d29a98a77bfb36d97cfbfac1 upstream.

Consolidate all the cleanup actions requiring the worker in a single
helper and ensure the dummy data fin creation for fallback socket is
performed only when the tcp rx queue is empty.

There are no functional changes intended, but this will simplify the
next patch, when the tcp rx queue spooling could be delayed at release_cb
time.

Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Reviewed-by: Mat Martineau <martineau@kernel.org>
Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Link: https://patch.msgid.link/20250218-net-next-mptcp-rx-path-refactor-v1-1-4a47d90d7998@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Stable-dep-of: 2b0f561f21b2 ("mptcp: avoid unneeded actions on subflow reset")
[ Note: also remove struct mptcp_sock *msk from subflow_state_change: it
  is no longer used after this modification. ]
Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 net/mptcp/subflow.c |   35 ++++++++++++++++++-----------------
 1 file changed, 18 insertions(+), 17 deletions(-)

--- a/net/mptcp/subflow.c
+++ b/net/mptcp/subflow.c
@@ -1159,7 +1159,12 @@ out:
 		subflow->map_valid = 0;
 }
 
-/* sched mptcp worker to remove the subflow if no more data is pending */
+static bool subflow_is_done(const struct sock *sk)
+{
+	return sk->sk_shutdown & RCV_SHUTDOWN || sk->sk_state == TCP_CLOSE;
+}
+
+/* sched mptcp worker for subflow cleanup if no more data is pending */
 static void subflow_sched_work_if_closed(struct mptcp_sock *msk, struct sock *ssk)
 {
 	struct sock *sk = (struct sock *)msk;
@@ -1169,8 +1174,18 @@ static void subflow_sched_work_if_closed
 		    inet_sk_state_load(sk) != TCP_ESTABLISHED)))
 		return;
 
-	if (skb_queue_empty(&ssk->sk_receive_queue) &&
-	    !test_and_set_bit(MPTCP_WORK_CLOSE_SUBFLOW, &msk->flags))
+	if (!skb_queue_empty(&ssk->sk_receive_queue))
+		return;
+
+	if (!test_and_set_bit(MPTCP_WORK_CLOSE_SUBFLOW, &msk->flags))
+		mptcp_schedule_work(sk);
+
+	/* when the fallback subflow closes the rx side, trigger a 'dummy'
+	 * ingress data fin, so that the msk state will follow along
+	 */
+	if (__mptcp_check_fallback(msk) && subflow_is_done(ssk) &&
+	    msk->first == ssk &&
+	    mptcp_update_rcv_data_fin(msk, READ_ONCE(msk->ack_seq), true))
 		mptcp_schedule_work(sk);
 }
 
@@ -1688,20 +1703,13 @@ static void __subflow_state_change(struc
 	rcu_read_unlock();
 }
 
-static bool subflow_is_done(const struct sock *sk)
-{
-	return sk->sk_shutdown & RCV_SHUTDOWN || sk->sk_state == TCP_CLOSE;
-}
-
 static void subflow_state_change(struct sock *sk)
 {
 	struct mptcp_subflow_context *subflow = mptcp_subflow_ctx(sk);
 	struct sock *parent = subflow->conn;
-	struct mptcp_sock *msk;
 
 	__subflow_state_change(sk);
 
-	msk = mptcp_sk(parent);
 	/* as recvmsg() does not acquire the subflow socket for ssk selection
 	 * a fin packet carrying a DSS can be unnoticed if we don't trigger
 	 * the data available machinery here.
@@ -1712,13 +1720,6 @@ static void subflow_state_change(struct
 		subflow_error_report(sk);
 
 	subflow_sched_work_if_closed(mptcp_sk(parent), sk);
-
-	/* when the fallback subflow closes the rx side, trigger a 'dummy'
-	 * ingress data fin, so that the msk state will follow along
-	 */
-	if (__mptcp_check_fallback(msk) && subflow_is_done(sk) && msk->first == sk &&
-	    mptcp_update_rcv_data_fin(msk, READ_ONCE(msk->ack_seq), true))
-		mptcp_schedule_work(parent);
 }
 
 void mptcp_subflow_queue_clean(struct sock *listener_sk, struct sock *listener_ssk)


Patches currently in stable-queue which might be from matttbe@kernel.org are

queue-6.1/selftests-mptcp-fix-an-uaf-in-mptcp_connect.c.patch
queue-6.1/mptcp-syncookies-remember-the-request-backup-flag.patch
queue-6.1/mptcp-close-race-between-scheduler-and-state-change.patch
queue-6.1/mptcp-avoid-unneeded-actions-on-subflow-reset.patch
queue-6.1/mptcp-options-handle-mpc-data-csum-reqd-no-csum.patch
queue-6.1/mptcp-consolidate-subflow-cleanup.patch
queue-6.1/mptcp-subflow-no-need-to-copy-thmac-during-ulp_clone.patch

^ permalink raw reply	[flat|nested] 9+ messages in thread

* Patch "mptcp: avoid unneeded actions on subflow reset" has been added to the 6.1-stable tree
  2026-09-19 20:12 ` [PATCH 6.1.y 2/3] mptcp: avoid unneeded actions on subflow reset Matthieu Baerts (NGI0)
@ 2026-09-20  7:36   ` gregkh
  0 siblings, 0 replies; 9+ messages in thread
From: gregkh @ 2026-09-20  7:36 UTC (permalink / raw)
  To: gregkh, kuba, matttbe, mptcp, pabeni, sashal, xinyang; +Cc: stable-commits


This is a note to let you know that I've just added the patch titled

    mptcp: avoid unneeded actions on subflow reset

to the 6.1-stable tree which can be found at:
    http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary

The filename of the patch is:
     mptcp-avoid-unneeded-actions-on-subflow-reset.patch
and it can be found in the queue-6.1 subdirectory.

If you, or anyone else, feels it should not be added to the stable tree,
please let <stable@vger.kernel.org> know about it.


From stable+bounces-338609-greg=kroah.com@vger.kernel.org Sat Sep 19 22:13:16 2026
From: "Matthieu Baerts (NGI0)" <matttbe@kernel.org>
Date: Sat, 19 Sep 2026 22:12:55 +0200
Subject: mptcp: avoid unneeded actions on subflow reset
To: mptcp@lists.linux.dev, stable@vger.kernel.org, gregkh@linuxfoundation.org
Cc: Paolo Abeni <pabeni@redhat.com>, sashal@kernel.org, Xinyang Ge <xinyang@anthropic.com>, "Matthieu Baerts (NGI0)" <matttbe@kernel.org>, Jakub Kicinski <kuba@kernel.org>
Message-ID: <20260919201252.2025112-7-matttbe@kernel.org>

From: Paolo Abeni <pabeni@redhat.com>

commit 2b0f561f21b27c40c91ea4975268a06092bd7e9c upstream.

Once in a blue moon, the mptcp receive path can recursively call
mptcp_data_ready() via state change under unlucky error conditions, and
then try to hold the data lock again.

Break the recursion loop explicitly checking for the exceptional
condition.

Add a new flag instead of using an existing one like 'closing', to exit
early in subflow_state_change(), and explicitly flush the RX queue at
reset time.

This avoids unneeded processing to check for available data -- calling
get_mapping_status() and more on a dying subflow -- but also in error
reporting and worker scheduling.

Note that we must consume the currently peeked skb before invoking
mptcp_dss_corruption to avoid consuming it again after the eventual
reset has freed it.

Fixes: e32d262c89e2 ("mptcp: handle consistently DSS corruption")
Cc: stable@vger.kernel.org
Reported-by: Xinyang Ge <xinyang@anthropic.com>
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Reviewed-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Link: https://patch.msgid.link/20260917-net-mptcp-misc-fixes-7-3-rc4-v2-1-0cf5c72667c8@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
[ Note: conflict in protocol.c, because commit e0ca4057e0ec ("mptcp:
  micro-optimize __mptcp_move_skb()") is not in this version, and is
  part of a consequent rx path refactor. The conflict is in the context,
  and is easy to resolve, "done = true" can be moved along without
  consequences.
  Also a conflict in protocol.h, because __unused is at a different
  number. Decrement the one from this version and add the new flag
  above. The context is also a bit different with data_avail being an
  enum, but that's without consequences here. ]
Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 net/mptcp/protocol.c |    6 +++---
 net/mptcp/protocol.h |    3 ++-
 net/mptcp/subflow.c  |   11 +++++++++++
 3 files changed, 16 insertions(+), 4 deletions(-)

--- a/net/mptcp/protocol.c
+++ b/net/mptcp/protocol.c
@@ -754,13 +754,13 @@ static bool __mptcp_move_skbs_from_subfl
 				mptcp_dss_corruption(msk, ssk);
 			}
 		} else {
+			sk_eat_skb(ssk, skb);
+			done = true;
+
 			if (unlikely(!fin)) {
 				DEBUG_NET_WARN_ON_ONCE(1);
 				mptcp_dss_corruption(msk, ssk);
 			}
-
-			sk_eat_skb(ssk, skb);
-			done = true;
 		}
 
 		WRITE_ONCE(tp->copied_seq, seq);
--- a/net/mptcp/protocol.h
+++ b/net/mptcp/protocol.h
@@ -492,7 +492,8 @@ struct mptcp_subflow_context {
 		stale : 1,	    /* unable to snd/rcv data, do not use for xmit */
 		valid_csum_seen : 1,        /* at least one csum validated */
 		close_event_done : 1,       /* has done the post-closed part */
-		__unused : 9;
+		resetting : 1,	    /* subflow is resetting */
+		__unused : 8;
 	enum mptcp_data_avail data_avail;
 	bool	pm_listener;	    /* a listener managed by the kernel PM? */
 	u32	remote_nonce;
--- a/net/mptcp/subflow.c
+++ b/net/mptcp/subflow.c
@@ -379,6 +379,10 @@ void mptcp_subflow_reset(struct sock *ss
 	/* must hold: tcp_done() could drop last reference on parent */
 	sock_hold(sk);
 
+	subflow->resetting = 1;
+
+	/* No need to delay the actual close for to-be discarded data. */
+	__skb_queue_purge(&ssk->sk_receive_queue);
 	tcp_send_active_reset(ssk, GFP_ATOMIC);
 	tcp_done(ssk);
 	if (!test_and_set_bit(MPTCP_WORK_CLOSE_SUBFLOW, &mptcp_sk(sk)->flags))
@@ -1710,6 +1714,13 @@ static void subflow_state_change(struct
 
 	__subflow_state_change(sk);
 
+	/* Rx queue processing is unneeded, error reporting will take place at
+	 * __mptcp_close_ssk() time and subflow reset can't happen in case of
+	 * fallback: subflow_sched_work_if_closed() would be a no-op.
+	 */
+	if (subflow->resetting)
+		return;
+
 	/* as recvmsg() does not acquire the subflow socket for ssk selection
 	 * a fin packet carrying a DSS can be unnoticed if we don't trigger
 	 * the data available machinery here.


Patches currently in stable-queue which might be from matttbe@kernel.org are

queue-6.1/selftests-mptcp-fix-an-uaf-in-mptcp_connect.c.patch
queue-6.1/mptcp-syncookies-remember-the-request-backup-flag.patch
queue-6.1/mptcp-close-race-between-scheduler-and-state-change.patch
queue-6.1/mptcp-avoid-unneeded-actions-on-subflow-reset.patch
queue-6.1/mptcp-options-handle-mpc-data-csum-reqd-no-csum.patch
queue-6.1/mptcp-consolidate-subflow-cleanup.patch
queue-6.1/mptcp-subflow-no-need-to-copy-thmac-during-ulp_clone.patch

^ permalink raw reply	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2026-09-20  7:39 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-19 20:12 [PATCH 6.1.y 0/3] mptcp: fix recent failed backports (20260919) Matthieu Baerts (NGI0)
2026-09-19 20:12 ` [PATCH 6.1.y 1/3] mptcp: consolidate subflow cleanup Matthieu Baerts (NGI0)
2026-09-19 20:23   ` sashiko-bot
2026-09-19 20:30     ` Matthieu Baerts
2026-09-20  7:36   ` Patch "mptcp: consolidate subflow cleanup" has been added to the 6.1-stable tree gregkh
2026-09-19 20:12 ` [PATCH 6.1.y 2/3] mptcp: avoid unneeded actions on subflow reset Matthieu Baerts (NGI0)
2026-09-20  7:36   ` Patch "mptcp: avoid unneeded actions on subflow reset" has been added to the 6.1-stable tree gregkh
2026-09-19 20:12 ` [PATCH 6.1.y 3/3] mptcp: close race between scheduler and state change Matthieu Baerts (NGI0)
2026-09-20  7:36   ` Patch "mptcp: close race between scheduler and state change" has been added to the 6.1-stable tree gregkh

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox