MPTCP Linux Development
 help / color / mirror / Atom feed
From: Chenguang Zhao <chenguang.zhao@linux.dev>
To: Matthieu Baerts <matttbe@kernel.org>, mptcp@lists.linux.dev
Cc: Chenguang Zhao <zhaochenguang@kylinos.cn>
Subject: Re: [PATCH mptcp-next RFC v4 2/2] mptcp: send MP_FAIL and infinite mapping on the same ACK
Date: Tue, 25 Aug 2026 14:33:20 +0800	[thread overview]
Message-ID: <8223f1d4-5050-439e-8c00-707ac6b51c5f@linux.dev> (raw)
In-Reply-To: <2ab65503-c388-43f8-90f2-ef676205043b@kernel.org>


在 2026/8/20 00:06, Matthieu Baerts 写道:
> Hi Chenguang,
>
> On 19/08/2026 13:16, Chenguang Zhao wrote:
>> 在 2026/8/19 00:19, Matthieu Baerts 写道:
>>> Hi Chenguang,
>>>
>>> On 18/08/2026 11:14, Chenguang Zhao wrote:
>>>> From: Chenguang Zhao <zhaochenguang@kylinos.cn>
>>>>
>>>> On a single subflow, accepting MP_FAIL must leave MPTCP mode at once
>>>> (RFC8684 §3.7). Emit the infinite mapping on the MP_FAIL reply ACK,
>>>> then call mptcp_try_fallback() immediately after.
>>> I think Sashiko is right about the issue of lacking option space to have
>>> both the MP_FAIL and the infinite mapping sent together.
>> Yes, Sashiko is right, I did not consider all the aspects.
>>> Please also note this from RFC 8684 §3.7.11 [1]:
>>>
>>>> This infinite mapping will be a DSS option (Section 3.3) on the first
>>>> new packet, containing a Data Sequence Mapping that acts retroactively
>>> The "on the first new packet" seems to suggest the infinite mapping
>>> shouldn't be attached to the MP_FAIL.
>>>
>>> [1] https://datatracker.ietf.org/doc/html/rfc8684#section-3.7-11
>>>
>>>
>>> Maybe a fallback for the single subflow without csum is enough? Or maybe
>>> nothing needs to be done? Or maybe this fallback is just an
>>> optimisation, and can be done in net-next (and both commits can be
>>> combined)? WDYT?
>> Hi Matthieu
>>
>> I am getting a bit confused, so let me summarize my current understanding to verify if I got this right.
>> In the existing kernel code, fallback will be triggered upon receiving MP_FAIL. However, the FALLBACK_DONE
>> flag is currently set inside mptcp_update_infinite_map(), which only gets invoked when transmitting a data packet.
>> This creates a timing window between receiving MP_FAIL and sending the first subsequent packet, resulting in this minor bug.
>> Our goal is to close this timing window: set the FALLBACK_DONE flag immediately after MP_FAIL is received.
>> Besides, add a __mptcp_check_fallback() check within mptcp_can_accept_new_subflow() to reject MP_JOIN requests ahead of time.
>>
>> Is my understanding correct? I will send out a v5 RFC based on the above ideas.      
> I'm not sure that it can work: if there is a fallback, no MPTCP options
> are supposed to be sent after that point. That's why the fallback should
> be done after having sent the infinite mapping.
>
> I didn't check in the details: *maybe* the fully_established bit could
> be reset earlier in some cases, but it feels like it can only be done
> when a fallback can be done, so never had extra subflows or reinjection,
> and no checksum. But then again, in this case, we are not supposed to
> receive an MP_FAIL. Then why bother and not simply fallback, and that's
> it, no?
>
> Cheers,
> Matt

Hi Matt,

Thanks for your feedback. I'd like to share some thoughts on the

practical impact of the extra_subflow window.While looking into this, 

I realized that the window where the leak can occur is actually quite

narrow in practice:

	1. MP_FAIL itself is rare — it requires a checksum validation failure,

	   which typically only happens when a middlebox corrupts in-flight

	   data.

	2. It only applies to single-subflow connections — for multi-subflow

	   connections, allow_infinite_fallback is cleared by

	   mptcp_subflow_joined() when the second subflow joins, so the

	   fallback path in mptcp_pm_mp_fail_received() is never reached.

	3. The window is very short — it spans from the MP_FAIL ACK to the

	   first data packet carrying the infinite mapping, which is on the

	   order of microseconds under normal conditions.
	
	4. Even deferring the fallback to the first data packet (as the
	   original code does) does not appear to cause issues in practice,
	   since the infinite mapping is still sent correctly and the
	   connection eventually transitions to TCP.

Given the above, I'm inclined to put this issue on hold for now and

revisit it if a concrete need arises. I'd appreciate your thoughts on

whether that makes sense.

Best regards,

Chenguang


  reply	other threads:[~2026-08-25  6:33 UTC|newest]

Thread overview: 11+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-18  9:14 [PATCH mptcp-next RFC v4 0/2] mptcp: fallback to TCP on MP_FAIL with a single subflow Chenguang Zhao
2026-08-18  9:14 ` [PATCH mptcp-next RFC v4 1/2] mptcp: add MPFailFallback MIB Chenguang Zhao
2026-08-18  9:24   ` sashiko-bot
2026-08-18  9:14 ` [PATCH mptcp-next RFC v4 2/2] mptcp: send MP_FAIL and infinite mapping on the same ACK Chenguang Zhao
2026-08-18  9:30   ` sashiko-bot
2026-08-18 16:19   ` Matthieu Baerts
2026-08-19 11:16     ` Chenguang Zhao
2026-08-19 16:06       ` Matthieu Baerts
2026-08-25  6:33         ` Chenguang Zhao [this message]
2026-08-25  7:19           ` Matthieu Baerts
2026-08-18 10:21 ` [PATCH mptcp-next RFC v4 0/2] mptcp: fallback to TCP on MP_FAIL with a single subflow MPTCP CI

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=8223f1d4-5050-439e-8c00-707ac6b51c5f@linux.dev \
    --to=chenguang.zhao@linux.dev \
    --cc=matttbe@kernel.org \
    --cc=mptcp@lists.linux.dev \
    --cc=zhaochenguang@kylinos.cn \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox