From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pl1-f179.google.com (mail-pl1-f179.google.com [209.85.214.179]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4B2943B637E for ; Wed, 19 Aug 2026 01:15:16 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.179 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787102117; cv=none; b=LbU+xHTab1UeW3dYPK/vn+mJQ+bJfCNKIUoBbusnWmumgNDJLNq1qDN7dQZoVLyO/pLnqi52TC/Ox1R+PUcIzj/t5RLQ0wcG66q5frZjP24x5V4pwNkUxOavBdorioehDqcuu6Kjii+qL5LUkK5u+vrb10znOlanwTKDbn76q4A= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787102117; c=relaxed/simple; bh=NUDv2JcJ7RwZhBTmVl0jXBgtN2f3GYCncPfUY+N2/Ec=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=cEiaQB1HbaMcok8RkkNybpmPR9SdprH8k5xp7rplYB55rIVveIWScOIHLdrHkVKPPkSFrZ+Abe00SNxYt7NhGl5rWdYh2bb+O4KjDwzKm/C5jqN1HXhpPyQzjjjvA+neOk1IsabC8qwkHasRo+A0x1SRdi9YLHMNV6ADF/DxLkE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=XBYhNNng; arc=none smtp.client-ip=209.85.214.179 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="XBYhNNng" Received: by mail-pl1-f179.google.com with SMTP id d9443c01a7336-2cfbbdfa60bso3698295ad.3 for ; Tue, 18 Aug 2026 18:15:16 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787102115; x=1787706915; darn=vger.kernel.org; h=in-reply-to:content-transfer-encoding:content-disposition :content-type:mime-version:references:message-id:subject:cc:to:from :date:from:to:cc:subject:date:message-id:reply-to:content-type; bh=NUDv2JcJ7RwZhBTmVl0jXBgtN2f3GYCncPfUY+N2/Ec=; b=XBYhNNngXOVdKiqFqgl7JKD8RrYX5gphtnTTQu4kb4ARiOQ7N+KML7fj/tED9g0d82 lE8+LDaRmReINL0DKHYDfM8L9qiR9EgWnn4mKypOtuuFfgKbl+J13gDtbyUWWFQ3CT6n IGAldr5YjFRyKc6PMNorGHjrzsDUAhbKXqA1KMYnX04Au6HNgc/e5kqsed8QIIzCvGhw J/n7JIU8AJDbnfxCM8OrtmNlu1dZVOQJ1OoGZchnC41QjQCEhhkFzd4zMt9CjxDsd5fh usyEII4rIbiyirwkOJ75stYpeSCtI0l8LlOHw5kyX32S4rly9VqSIWYUr099TrPnPw9B A0lQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787102115; x=1787706915; h=in-reply-to:content-transfer-encoding:content-disposition :content-type:mime-version:references:message-id:subject:cc:to:from :date:x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to:content-type; bh=NUDv2JcJ7RwZhBTmVl0jXBgtN2f3GYCncPfUY+N2/Ec=; b=d5EOCbkR0+FD0WS2ZBBt36fO7E6LjMPVPHtb21Gvpq1hO8ctOkLWfDYeL/j0wsahvs JiyyPJN/LORDZtJeB9RqK/AtpC6z4FLMq74lq1tMwDu6HTa0YXdql9cBGSyEvcyJQh2U wPQCrIZwiLKDjDc9qWiCCuk2118hOBCfr5J7+8GxXXqJf2uFLiRqUs+jExJoB5He4rlN z0UEV4foXuC5oKbn9SVlPjkxQJwfJsiw79pcXDPztSGJxxRVEOAgB6ki6XJxkS/v6YbM 8z0ebMc6kLe+eBDe1ThgXC53K95N68HG0AbNvzsK4qlWZW79864yYu6CoPf9l0VDEd03 mC6g== X-Forwarded-Encrypted: i=1; AHgh+Rp6cy3s1a3NFNB7ojtfQLq6vEPGLBZ1ycUeKJjS6Rv7JzM9kppVzKvLnxzwUQTMPJ9brUi+Yyo=@vger.kernel.org X-Gm-Message-State: AOJu0Yz4kwapTDwdEXfEJqpqQ/FTTfQ6UJA75eixpfwAfm/anVNBMuCx 9t8/D1YVyWF8YlCKoyvk5rbtCU5kdChEwwZXQrV9+IWOvlOPNeUnAfG+ X-Gm-Gg: AR+sD10KHQmzcMingy9tm6sA+gqRyxTEndh/+hL5aPNyBRgt/AP4srmTcXYQ+WngIDY Dd++oG1gSK12RIhCjIiQz4sLPu49IXRIQj17CYnPcnli7PaAVha8wXvWGzoNpQVyRxXQvP3c7Jn 62dtKIAmr7cs88JWgJpwgyXdROXl4+ZwZjgiMqQ0dkVTNfXrL+zyC6UePzxofDRfPa/ZL/mzXdH Nn1W1tDRcgUAlv5sGeRLePAwOjSWlvgapTbTmR/9S5pWJU7PmCuUd9xAvCRCKzHmFygEGbiCaHO 7/rNe/Hg4QUj5zeRw4ffdO1PY6T5jycXLKyrKKzdusU/fyv7QLZ4ciN3DY4D2yoodNn8ZpmPE0X w/oRrMQwZ2moTkK57ooLvVtqALUMFH46nZLPaxLe0/EO24fnJj64vkuZqz1QZZJqg/6NSPXkJI/ bgwcY8zDEFEu/kb7thnCM+loE7b4hOJxgQmehvSvBY6/Af2mlwZQDd4UG6QXDaJdw/70OwaFvct Nh/JNAb X-Received: by 2002:a17:903:28c:b0:2cc:aa36:c04c with SMTP id d9443c01a7336-2d5fd5b087fmr18298765ad.1.1787102115407; Tue, 18 Aug 2026 18:15:15 -0700 (PDT) Received: from v4bel ([58.123.110.97]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2d5c1ecb2absm18986855ad.71.2026.08.18.18.15.11 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 18 Aug 2026 18:15:13 -0700 (PDT) Date: Wed, 19 Aug 2026 10:15:10 +0900 From: Hyunwoo Kim To: Xin Long Cc: marcelo.leitner@gmail.com, davem@davemloft.net, edumazet@google.com, kuba@kernel.org, pabeni@redhat.com, horms@kernel.org, linux-sctp@vger.kernel.org, netdev@vger.kernel.org, imv4bel@gmail.com Subject: Re: [PATCH net] sctp: drop a backlogged chunk if its transport was removed Message-ID: References: Precedence: bulk X-Mailing-List: netdev@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: On Mon, Aug 17, 2026 at 04:59:39PM -0400, Xin Long wrote: > On Mon, Aug 17, 2026 at 1:48 PM Xin Long wrote: > > > > On Fri, Aug 14, 2026 at 7:43 PM Hyunwoo Kim wrote: > > > > > > sctp_rcv() resolves the transport once per packet and leaves it in > > > chunk->transport. If the socket is owned by userspace the packet goes to > > > the socket backlog, and sctp_add_backlog() takes a reference on that > > > transport. > > > > > > An authenticated ASCONF DEL-IP in an earlier backlogged packet can remove > > > it. sctp_assoc_rm_peer() takes the transport out of the association and > > > calls sctp_transport_free(), which tags it dead and drops the reference > > > the association held. The backlogged packet still holds a reference, so > > > the transport stays around. > > > > > > The DATA chunk in that packet puts the removed transport back into > > > asoc->peer.last_data_from. Once the packet is done that reference goes > > > away and the transport is freed by RCU, so the next delayed SACK carries > > > the pointer into the SACK chunk and sctp_outq_select_transport() reads the > > > freed transport's state. > > > > > > Drop the chunk in sctp_backlog_rcv(), next to the existing rcvr->dead > > > check. The peer retransmits it. Guarding the last_data_from assignment is > > > not enough, sctp_assoc_rm_peer() clears more than that one pointer and > > > letting the packet run fills them in again. sctp_wait_for_sndbuf() already > > > uses the dead flag this way on the send side. > > > > > > Fixes: df132eff4638 ("sctp: clear the transport of some out_chunk_list chunks in sctp_assoc_rm_peer") > Please also double check the 'Fixes' tag, commit df132eff4638 doesn't > seem to cause the issue. Understood. I'll run a few more tests and then submit v2. Best regards, Hyunwoo Kim