Netdev List
 help / color / mirror / Atom feed
From: Matthieu Baerts <matttbe@kernel.org>
To: Yiming Qian <yimingqian591@gmail.com>, mptcp@lists.linux.dev
Cc: martineau@kernel.org, geliang@kernel.org, netdev@vger.kernel.org,
	stable@vger.kernel.org, Security Officers <security@kernel.org>
Subject: Re: [PATCH net] mptcp: pm: in-kernel: fix C-flag endpoint accounting on family mismatch
Date: Tue, 6 Oct 2026 13:59:02 +0200	[thread overview]
Message-ID: <97c651a1-7647-4f12-8b6b-74b949dce575@kernel.org> (raw)
In-Reply-To: <20261006114409.117190-1-yimingqian591@gmail.com>

Hi Yiming Qian,

On 06/10/2026 13:42, Yiming Qian wrote:
> fill_local_addresses_vec_c_flag() clears the endpoint ID bit in
> id_avail_bitmap before checking whether the endpoint's address family
> matches the remote ADD_ADDR.  If it does not match, the loop skips the
> endpoint without incrementing local_addr_used, leaving id_avail_bitmap
> and local_addr_used inconsistent.
> 
> Removing that SUBFLOW endpoint later calls
> __mark_subflow_endp_available(), which sees the cleared bit, expects
> local_addr_used to be non-zero, and triggers a WARN and, with
> panic_on_warn=1, a panic.
> 
> Keep the endpoints that are skipped during this specific C-flag
> iteration available by tracking them in a local bitmap passed to
> select_local_address(), instead of clearing their IDs in the per-socket
> bitmap.  Only IDs of endpoints actually used for a subflow are now
> cleared and accounted for.

Thank you for the patch.

Please do not Cc security@k.o on patches sent to public ML. Here the
issue is "just" a WARN produced in some conditions when the user has the
rights to delete MPTCP endpoints.

(Please remove it from future replies.)

> diff --git a/net/mptcp/pm_kernel.c b/net/mptcp/pm_kernel.c
> index 1a77508132354..a5952dd0ae125 100644
> --- a/net/mptcp/pm_kernel.c
> +++ b/net/mptcp/pm_kernel.c

(...)

> @@ -574,22 +578,28 @@ fill_local_addresses_vec_c_flag(struct mptcp_sock *msk,
>  	u8 endp_subflow_max = mptcp_pm_get_endp_subflow_max(msk);
>  	struct sock *sk = (struct sock *)msk;
>  	struct mptcp_pm_local *local;
> +	DECLARE_BITMAP(skip, MPTCP_PM_MAX_ADDR_ID + 1);
>  	int i = 0;
>  
> +	bitmap_zero(skip, MPTCP_PM_MAX_ADDR_ID + 1);
> +
>  	while (msk->pm.local_addr_used < endp_subflow_max) {
>  		local = &locals[i];
>  
> -		if (!select_local_address(pernet, msk, local))
> +		if (!select_local_address(pernet, msk, skip, local))
>  			break;
>  
> -		__clear_bit(local->addr.id, msk->pm.id_avail_bitmap);
> -
> -		if (!mptcp_pm_addr_families_match(sk, &local->addr, remote))
> +		if (!mptcp_pm_addr_families_match(sk, &local->addr, remote)) {
> +			__set_bit(local->addr.id, skip);
>  			continue;
> +		}
>  
> -		if (local->addr.id == msk->mpc_endpoint_id)
> +		if (local->addr.id == msk->mpc_endpoint_id) {
> +			__set_bit(local->addr.id, skip);
>  			continue;
> +		}
>  
> +		__clear_bit(local->addr.id, msk->pm.id_avail_bitmap);

Why is it not enough to move __clear_bit() to here? Why do you need to
modify select_local_address(), etc.?

Also, can you also provide a regression test as well, please?
Adding a subtest in tools/testing/selftests/net/mptcp/mptcp_join.sh,
e.g. in deny_join_id0_tests(), adding a new subcase using
"addr_nr_ns2=-1 speed=slow run_tests (...)" to remove the subflow during
the connection.

Cheers,
Matt
-- 
Sponsored by the NGI0 Core fund.


      parent reply	other threads:[~2026-10-06 11:59 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-06 11:42 [PATCH net] mptcp: pm: in-kernel: fix C-flag endpoint accounting on family mismatch Yiming Qian
2026-10-06 11:49 ` netdev-bot+sinfo
2026-10-06 11:59 ` Matthieu Baerts [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=97c651a1-7647-4f12-8b6b-74b949dce575@kernel.org \
    --to=matttbe@kernel.org \
    --cc=geliang@kernel.org \
    --cc=martineau@kernel.org \
    --cc=mptcp@lists.linux.dev \
    --cc=netdev@vger.kernel.org \
    --cc=security@kernel.org \
    --cc=stable@vger.kernel.org \
    --cc=yimingqian591@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox