From: Yiming Qian <yimingqian591@gmail.com>
To: security@kernel.org, mptcp@lists.linux.dev
Cc: matttbe@kernel.org, martineau@kernel.org, geliang@kernel.org,
netdev@vger.kernel.org, stable@vger.kernel.org,
yimingqian591@gmail.com
Subject: [PATCH net] mptcp: pm: in-kernel: fix C-flag endpoint accounting on family mismatch
Date: Tue, 6 Oct 2026 11:42:27 +0000 [thread overview]
Message-ID: <20261006114409.117190-1-yimingqian591@gmail.com> (raw)
fill_local_addresses_vec_c_flag() clears the endpoint ID bit in
id_avail_bitmap before checking whether the endpoint's address family
matches the remote ADD_ADDR. If it does not match, the loop skips the
endpoint without incrementing local_addr_used, leaving id_avail_bitmap
and local_addr_used inconsistent.
Removing that SUBFLOW endpoint later calls
__mark_subflow_endp_available(), which sees the cleared bit, expects
local_addr_used to be non-zero, and triggers a WARN and, with
panic_on_warn=1, a panic.
Keep the endpoints that are skipped during this specific C-flag
iteration available by tracking them in a local bitmap passed to
select_local_address(), instead of clearing their IDs in the per-socket
bitmap. Only IDs of endpoints actually used for a subflow are now
cleared and accounted for.
Fixes: 4b1ff850e0c1 ("mptcp: pm: in-kernel: usable client side with C-flag")
Cc: stable@vger.kernel.org
Signed-off-by: Yiming Qian <yimingqian591@gmail.com>
---
net/mptcp/pm_kernel.c | 22 ++++++++++++++++------
1 file changed, 16 insertions(+), 6 deletions(-)
diff --git a/net/mptcp/pm_kernel.c b/net/mptcp/pm_kernel.c
index 1a77508132354..a5952dd0ae125 100644
--- a/net/mptcp/pm_kernel.c
+++ b/net/mptcp/pm_kernel.c
@@ -120,6 +120,7 @@ static bool has_subflow_daddr(const struct mptcp_sock *msk,
static bool
select_local_address(const struct pm_nl_pernet *pernet,
const struct mptcp_sock *msk,
+ const unsigned long *skip,
struct mptcp_pm_local *new_local)
{
struct mptcp_pm_addr_entry *entry;
@@ -135,6 +136,9 @@ select_local_address(const struct pm_nl_pernet *pernet,
if (!test_bit(entry->addr.id, msk->pm.id_avail_bitmap))
continue;
+ if (skip && test_bit(entry->addr.id, skip))
+ continue;
+
new_local->addr = entry->addr;
new_local->flags = entry->flags;
new_local->ifindex = entry->ifindex;
@@ -401,7 +405,7 @@ static void mptcp_pm_create_subflow_or_signal_addr(struct mptcp_sock *msk)
if (signal_and_subflow)
signal_and_subflow = false;
- else if (!select_local_address(pernet, msk, &local))
+ else if (!select_local_address(pernet, msk, NULL, &local))
break;
fullmesh = !!(local.flags & MPTCP_PM_ADDR_FLAG_FULLMESH);
@@ -574,22 +578,28 @@ fill_local_addresses_vec_c_flag(struct mptcp_sock *msk,
u8 endp_subflow_max = mptcp_pm_get_endp_subflow_max(msk);
struct sock *sk = (struct sock *)msk;
struct mptcp_pm_local *local;
+ DECLARE_BITMAP(skip, MPTCP_PM_MAX_ADDR_ID + 1);
int i = 0;
+ bitmap_zero(skip, MPTCP_PM_MAX_ADDR_ID + 1);
+
while (msk->pm.local_addr_used < endp_subflow_max) {
local = &locals[i];
- if (!select_local_address(pernet, msk, local))
+ if (!select_local_address(pernet, msk, skip, local))
break;
- __clear_bit(local->addr.id, msk->pm.id_avail_bitmap);
-
- if (!mptcp_pm_addr_families_match(sk, &local->addr, remote))
+ if (!mptcp_pm_addr_families_match(sk, &local->addr, remote)) {
+ __set_bit(local->addr.id, skip);
continue;
+ }
- if (local->addr.id == msk->mpc_endpoint_id)
+ if (local->addr.id == msk->mpc_endpoint_id) {
+ __set_bit(local->addr.id, skip);
continue;
+ }
+ __clear_bit(local->addr.id, msk->pm.id_avail_bitmap);
msk->pm.local_addr_used++;
msk->pm.extra_subflows++;
i++;
--
2.34.1
next reply other threads:[~2026-10-06 11:44 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-06 11:42 Yiming Qian [this message]
2026-10-06 11:49 ` [PATCH net] mptcp: pm: in-kernel: fix C-flag endpoint accounting on family mismatch netdev-bot+sinfo
2026-10-06 11:59 ` Matthieu Baerts
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261006114409.117190-1-yimingqian591@gmail.com \
--to=yimingqian591@gmail.com \
--cc=geliang@kernel.org \
--cc=martineau@kernel.org \
--cc=matttbe@kernel.org \
--cc=mptcp@lists.linux.dev \
--cc=netdev@vger.kernel.org \
--cc=security@kernel.org \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox