]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
mptcp: fastopen: only mark MPTFO subflows with SYN data
authorWyatt Feng <bronzed_45_vested@icloud.com>
Mon, 3 Aug 2026 16:16:39 +0000 (18:16 +0200)
committerJakub Kicinski <kuba@kernel.org>
Thu, 6 Aug 2026 15:46:23 +0000 (08:46 -0700)
Passive TCP Fast Open accepts a valid-cookie SYN even when it carries
no data. In that case the child socket's receive queue is intentionally
left empty.

mptcp_fastopen_subflow_synack_set_params() set is_mptfo before checking
for queued SYN data. That made data-less TFO SYNs hit a WARN and, if
the warning was non-fatal, left stale MPTFO state behind. The stale
flag could later trigger a state-confusion bug in
check_fully_established().

Only mark the subflow as MPTFO after confirming that an SKB was queued.
Return quietly when the receive queue is empty.

Note that mptcp_subflow_context's is_mptfo field is now not just about
subflows where the TFO was present, but about MPTFO subflow that
consumed SYN data. Only having a valid cookie but not carrying data is
not really "doing TFO".

Fixes: 36b122baf6a8 ("mptcp: add subflow_v(4,6)_send_synack()")
Cc: stable@vger.kernel.org
Reported-by: Yuan Tan <yuantan098@gmail.com>
Reported-by: Yifan Wu <yifanwucs@gmail.com>
Reported-by: Juefei Pu <tomapufckgml@gmail.com>
Reported-by: Zhengchuan Liang <zcliangcn@gmail.com>
Reported-by: Xin Liu <bird@lzu.edu.cn>
Signed-off-by: Wyatt Feng <bronzed_45_vested@icloud.com>
Signed-off-by: Ren Wei <n05ec@lzu.edu.cn>
Reviewed-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Link: https://patch.msgid.link/20260803-net-mptcp-misc-fixes-7-2-rc6-v2-7-b8f496d71664@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
net/mptcp/fastopen.c

index 082c46c0f50ee7a32f5f703ac44381cf2d5c3b67..f717750906ffaa043986f9d11485182823eb1ac6 100644 (file)
@@ -24,12 +24,13 @@ void mptcp_fastopen_subflow_synack_set_params(struct mptcp_subflow_context *subf
        sk = subflow->conn;
        tp = tcp_sk(ssk);
 
-       subflow->is_mptfo = 1;
-
+       /* A valid TFO cookie does not guarantee SYN data. */
        skb = skb_peek(&ssk->sk_receive_queue);
-       if (WARN_ON_ONCE(!skb))
+       if (!skb)
                return;
 
+       subflow->is_mptfo = 1;
+
        /* dequeue the skb from sk receive queue */
        __skb_unlink(skb, &ssk->sk_receive_queue);
        skb_ext_reset(skb);