mirror of
https://github.com/torvalds/linux.git
synced 2026-07-28 01:55:51 +02:00
mptcp: pm: fix extra_subflows underflow on userspace PM subflow creation
The userspace PM increments extra_subflows after __mptcp_subflow_connect()
succeeds, but __mptcp_subflow_connect() calls mptcp_pm_close_subflow()
on failure to roll back the pre-increment done by the kernel PM's fill_*()
helpers. Because the userspace PM hasn't incremented yet at that point,
this decrement is spurious and causes extra_subflows to underflow.
Fix it by aligning the userspace PM with the kernel PM: increment
extra_subflows before calling __mptcp_subflow_connect(), so the existing
error path in subflow.c correctly rolls it back on failure. Also simplify
the error handling by taking pm.lock only when needed for cleanup.
Fixes: 77e4b94a3d ("mptcp: update userspace pm infos")
Cc: stable@vger.kernel.org
Signed-off-by: Tao Cui <cuitao@kylinos.cn>
Reviewed-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Link: https://patch.msgid.link/20260602-net-mptcp-misc-fixes-7-1-rc7-v2-5-856831229976@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
This commit is contained in:
parent
da23be77e1
commit
14e9fea30b
|
|
@ -408,19 +408,21 @@ int mptcp_pm_nl_subflow_create_doit(struct sk_buff *skb, struct genl_info *info)
|
|||
local.flags = entry.flags;
|
||||
local.ifindex = entry.ifindex;
|
||||
|
||||
spin_lock_bh(&msk->pm.lock);
|
||||
msk->pm.extra_subflows++;
|
||||
spin_unlock_bh(&msk->pm.lock);
|
||||
|
||||
lock_sock(sk);
|
||||
err = __mptcp_subflow_connect(sk, &local, &addr_r);
|
||||
release_sock(sk);
|
||||
|
||||
if (err)
|
||||
if (err) {
|
||||
GENL_SET_ERR_MSG_FMT(info, "connect error: %d", err);
|
||||
|
||||
spin_lock_bh(&msk->pm.lock);
|
||||
if (err)
|
||||
spin_lock_bh(&msk->pm.lock);
|
||||
mptcp_userspace_pm_delete_local_addr(msk, &entry);
|
||||
else
|
||||
msk->pm.extra_subflows++;
|
||||
spin_unlock_bh(&msk->pm.lock);
|
||||
spin_unlock_bh(&msk->pm.lock);
|
||||
}
|
||||
|
||||
create_err:
|
||||
sock_put(sk);
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user