Skip to content

Commit efbb6ba

Browse files
Qing Luogregkh
authored andcommitted
mptcp: pm: fix data race in add_addr timer callback
[ Upstream commit a7aad5b ] The timer callback reads entry->retrans_times outside pm.lock to decide whether to call mptcp_pm_subflow_established(). Since mptcp_pm_announced_del_timer() can concurrently set retrans_times = ADD_ADDR_RETRANS_MAX under pm.lock, a race condition exists. I discovered this issue while studying the code. AI tools helped me to verify the issue can potentially happen under race conditions. Use a local 'retransmit' flag set inside pm.lock to capture whether retransmission is still possible when the lock is taken. This allows to call mptcp_pm_subflow_established() accordingly, and not depending on the situation that can be different when checked outside the pm.lock. Fixes: 348d5c1 ("mptcp: move to next addr when timeout") Cc: stable@vger.kernel.org Signed-off-by: Qing Luo <luoqing@kylinos.cn> Reviewed-by: Matthieu Baerts (NGI0) <matttbe@kernel.org> Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org> Link: https://patch.msgid.link/20260803-net-mptcp-misc-fixes-7-2-rc6-v2-4-b8f496d71664@kernel.org Signed-off-by: Jakub Kicinski <kuba@kernel.org> [ applied hunk to mptcp_pm_add_timer() in net/mptcp/pm_netlink.c instead of pm.c, dropping the absent adaptive-timeout shift line ] Signed-off-by: Sasha Levin <sashal@kernel.org> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
1 parent 1f26487 commit efbb6ba

1 file changed

Lines changed: 4 additions & 2 deletions

File tree

‎net/mptcp/pm_netlink.c‎

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -318,6 +318,7 @@ static void mptcp_pm_add_timer(struct timer_list *timer)
318318
struct mptcp_sock *msk = entry->sock;
319319
struct sock *sk = (struct sock *)msk;
320320
unsigned int timeout = 0;
321+
bool retransmit;
321322

322323
pr_debug("msk=%p\n", msk);
323324

@@ -355,12 +356,13 @@ static void mptcp_pm_add_timer(struct timer_list *timer)
355356
entry->retrans_times++;
356357
}
357358

358-
if (entry->retrans_times >= ADD_ADDR_RETRANS_MAX)
359+
retransmit = entry->retrans_times < ADD_ADDR_RETRANS_MAX;
360+
if (!retransmit)
359361
timeout = 0;
360362

361363
spin_unlock_bh(&msk->pm.lock);
362364

363-
if (entry->retrans_times == ADD_ADDR_RETRANS_MAX)
365+
if (!retransmit)
364366
mptcp_pm_subflow_established(msk);
365367

366368
out:

0 commit comments

Comments
 (0)