mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH net-next v5 0/2] tcp: annotate lockless access to sk->sk_err
@ 2026-09-25 12:47 Quanye Yang via B4 Relay
  2026-09-25 12:47 ` [PATCH net-next v5 1/2] " Quanye Yang via B4 Relay
                   ` (3 more replies)
  0 siblings, 4 replies; 9+ messages in thread
From: Quanye Yang via B4 Relay @ 2026-09-25 12:47 UTC (permalink / raw)
  To: Eric Dumazet, Neal Cardwell, Kuniyuki Iwashima, David S. Miller,
	Jakub Kicinski, Paolo Abeni, Simon Horman, Matthieu Baerts (NGI0),
	Geliang Tang, Mat Martineau, Jiayuan Chen
  Cc: netdev, linux-kernel

do_recvmmsg() and getsockopt(SO_ERROR) call sock_error() without the
socket lock and clear sk_err with xchg().

Patch 1 covers TCP. Peek-only sites use READ_ONCE(). On the no-data
recv and splice paths, call sock_error() once and only stop when it
returns a non-zero error. tcp_bpf_sendmsg() folds two unmarked loads
into one READ_ONCE() and uses that value as the returned errno.

Patch 2 does the same for MPTCP and annotates the remaining subflow
error-report peeks.

---
Changes in v5:
- recv/splice: call sock_error() once instead of peek-then-consume
- mention the tcp_bpf_sendmsg() READ_ONCE fold in the TCP commit
- Link to v4: https://patch.msgid.link/20260917-mptcp-sk-err-net-v4-0-1f04f52f2561@proton.me

Changes in v4:
- split the annotation change, one points to tcp and another points to
  mptcp.
- annotate the remaining unmarked MPTCP sk_err peeks on the
  subflow error-report path.
- Link to v3: https://patch.msgid.link/20260912-mptcp-sk-err-net-v3-1-c41383878bde@proton.me

Changes in v3:
- drop the Fixes tag and retarget to net-next
- annotate the remaining unmarked sk_err peeks on the TCP/MPTCP
  send, recv and splice paths
- Link to v2: https://patch.msgid.link/20260909-mptcp-sk-err-net-v2-1-5044abecac90@proton.me

Changes in v2:
- add Reported-by and Closes for the MPTCP syzkaller report
- Link to v1: https://patch.msgid.link/20260908-mptcp-sk-err-net-v1-1-da71aaec9afd@proton.me

---
Quanye Yang (2):
      tcp: annotate lockless access to sk->sk_err
      mptcp: annotate lockless access to sk->sk_err

 include/net/tcp.h    |  2 +-
 net/core/stream.c    |  2 +-
 net/ipv4/tcp.c       | 12 +++++-------
 net/ipv4/tcp_bpf.c   | 10 ++++------
 net/mptcp/protocol.c | 14 ++++++--------
 net/mptcp/subflow.c  |  4 ++--
 6 files changed, 19 insertions(+), 25 deletions(-)
---
base-commit: 211f2a875f6f447745d80d5762d6d614503ac84a
change-id: 20260908-mptcp-sk-err-net-7ff88ef05044

Best regards,
--  
Quanye Yang <quanyeyang@proton.me>



^ permalink raw reply	[flat|nested] 9+ messages in thread

* [PATCH net-next v5 1/2] tcp: annotate lockless access to sk->sk_err
  2026-09-25 12:47 [PATCH net-next v5 0/2] tcp: annotate lockless access to sk->sk_err Quanye Yang via B4 Relay
@ 2026-09-25 12:47 ` Quanye Yang via B4 Relay
  2026-10-01  0:21   ` Jakub Kicinski
  2026-09-25 12:47 ` [PATCH net-next v5 2/2] mptcp: " Quanye Yang via B4 Relay
                   ` (2 subsequent siblings)
  3 siblings, 1 reply; 9+ messages in thread
From: Quanye Yang via B4 Relay @ 2026-09-25 12:47 UTC (permalink / raw)
  To: Eric Dumazet, Neal Cardwell, Kuniyuki Iwashima, David S. Miller,
	Jakub Kicinski, Paolo Abeni, Simon Horman, Matthieu Baerts (NGI0),
	Geliang Tang, Mat Martineau, Jiayuan Chen
  Cc: netdev, linux-kernel

From: Quanye Yang <quanyeyang@proton.me>

BUG: KCSAN: data-race in do_recvmmsg / mptcp_recvmsg

read-write (marked) to 0xffff8880134d391c of 4 bytes by task 2619 on cpu 1:
 instrument_atomic_read_write include/linux/instrumented.h:113 [inline]
 sock_error include/net/sock.h:2565 [inline]
 do_recvmmsg+0x50c/0x580 net/socket.c:3049
 __sys_recvmmsg net/socket.c:3144 [inline]
 __do_sys_recvmmsg net/socket.c:3167 [inline]
 __se_sys_recvmmsg net/socket.c:3160 [inline]
 __x64_sys_recvmmsg+0x161/0x180 net/socket.c:3160
 x64_sys_call+0x19c7/0x1ca0 arch/x86/include/generated/asm/syscalls_64.h:300
 do_syscall_x64 arch/x86/entry/syscall_64.c:61 [inline]
 do_syscall_64+0xde/0x3d0 arch/x86/entry/syscall_64.c:84
 entry_SYSCALL_64_after_hwframe+0x77/0x7f

read to 0xffff8880134d391c of 4 bytes by task 2620 on cpu 0:
 tcp_recv_should_stop include/net/tcp.h:3086 [inline]
 mptcp_recvmsg+0x54d/0xd50 net/mptcp/protocol.c:2466
 inet_recvmsg+0x204/0x210 net/ipv4/af_inet.c:894
 sock_recvmsg_nosec net/socket.c:1151 [inline]
 sock_recvmsg+0x11a/0x140 net/socket.c:1173
 ____sys_recvmsg+0x14b/0x3c0 net/socket.c:2933
 ___sys_recvmsg+0x116/0x160 net/socket.c:2975
 __sys_recvmsg net/socket.c:3008 [inline]
 __do_sys_recvmsg net/socket.c:3014 [inline]
 __se_sys_recvmsg net/socket.c:3011 [inline]
 __x64_sys_recvmsg+0xeb/0x160 net/socket.c:3011
 x64_sys_call+0x1319/0x1ca0 arch/x86/include/generated/asm/syscalls_64.h:48
 do_syscall_x64 arch/x86/entry/syscall_64.c:61 [inline]
 do_syscall_64+0xde/0x3d0 arch/x86/entry/syscall_64.c:84
 entry_SYSCALL_64_after_hwframe+0x77/0x7f

value changed: 0x0000006b -> 0x00000000

Reported by Kernel Concurrency Sanitizer on:
CPU: 0 UID: 0 PID: 2620 Comm: syz.2.33 Not tainted 7.2.0-g39d4f32c5d53 #76 PREEMPT(full)
Hardware name: QEMU Ubuntu 26.04 PC (i440FX + PIIX, 1996), BIOS 1.17.0-debian-1.17.0-1ubuntu1 04/01/2014

do_recvmmsg() and getsockopt(SO_ERROR) call sock_error() without the
socket lock. sock_error() clears sk_err with xchg(), which races with
unmarked loads of the same field.

KCSAN reported the unmarked peek in tcp_recv_should_stop(). Annotate
that helper and the other send-side peeks with READ_ONCE().

On the no-data recv and splice paths, if (sk_err) followed by
sock_error() and an unconditional break can return 0 after another
thread consumes the error. Call sock_error() once and only stop when
it returns a non-zero error.

tcp_bpf_sendmsg() read sk_err twice; fold those unmarked loads into
one READ_ONCE() and use that value as the returned errno. The field
is still not consumed.

MPTCP is handled in the next patch.

Suggested-by: Jiayuan Chen <jiayuan.chen@linux.dev>
Link: https://lore.kernel.org/netdev/8bbee583-6f21-4817-bfeb-2d60057380a3@linux.dev/
Reported-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Closes: https://github.com/multipath-tcp/mptcp_net-next/issues/632
Signed-off-by: Quanye Yang <quanyeyang@proton.me>
---
 include/net/tcp.h  |  2 +-
 net/core/stream.c  |  2 +-
 net/ipv4/tcp.c     | 12 +++++-------
 net/ipv4/tcp_bpf.c | 10 ++++------
 4 files changed, 11 insertions(+), 15 deletions(-)

diff --git a/include/net/tcp.h b/include/net/tcp.h
index 5e5f5f9b89a3..8b1e1f0070a3 100644
--- a/include/net/tcp.h
+++ b/include/net/tcp.h
@@ -3093,7 +3093,7 @@ enum skb_drop_reason tcp_inbound_hash(struct sock *sk,
 
 static inline int tcp_recv_should_stop(struct sock *sk)
 {
-	return sk->sk_err ||
+	return READ_ONCE(sk->sk_err) ||
 	       sk->sk_state == TCP_CLOSE ||
 	       (sk->sk_shutdown & RCV_SHUTDOWN) ||
 	       signal_pending(current);
diff --git a/net/core/stream.c b/net/core/stream.c
index 2d748581862d..5c0adc3077f0 100644
--- a/net/core/stream.c
+++ b/net/core/stream.c
@@ -133,7 +133,7 @@ int sk_stream_wait_memory(struct sock *sk, long *timeo_p)
 	while (1) {
 		sk_set_bit(SOCKWQ_ASYNC_NOSPACE, sk);
 
-		if (sk->sk_err || (sk->sk_shutdown & SEND_SHUTDOWN))
+		if (READ_ONCE(sk->sk_err) || (sk->sk_shutdown & SEND_SHUTDOWN))
 			goto do_error;
 		if (!*timeo_p)
 			goto do_eagain;
diff --git a/net/ipv4/tcp.c b/net/ipv4/tcp.c
index 1c867a302444..35036e532275 100644
--- a/net/ipv4/tcp.c
+++ b/net/ipv4/tcp.c
@@ -843,10 +843,9 @@ ssize_t tcp_splice_read(struct socket *sock, loff_t *ppos,
 				break;
 			if (sock_flag(sk, SOCK_DONE))
 				break;
-			if (sk->sk_err) {
-				ret = sock_error(sk);
+			ret = sock_error(sk);
+			if (ret)
 				break;
-			}
 			if (sk->sk_shutdown & RCV_SHUTDOWN)
 				break;
 			if (sk->sk_state == TCP_CLOSE) {
@@ -1228,7 +1227,7 @@ int tcp_sendmsg_locked(struct sock *sk, struct msghdr *msg, size_t size)
 	mss_now = tcp_send_mss(sk, &size_goal, flags);
 
 	err = -EPIPE;
-	if (sk->sk_err || (sk->sk_shutdown & SEND_SHUTDOWN))
+	if (READ_ONCE(sk->sk_err) || (sk->sk_shutdown & SEND_SHUTDOWN))
 		goto do_error;
 
 	while (msg_data_left(msg)) {
@@ -2760,10 +2759,9 @@ static int tcp_recvmsg_locked(struct sock *sk, struct msghdr *msg, size_t len,
 			if (sock_flag(sk, SOCK_DONE))
 				break;
 
-			if (sk->sk_err) {
-				copied = sock_error(sk);
+			copied = sock_error(sk);
+			if (copied)
 				break;
-			}
 
 			if (sk->sk_shutdown & RCV_SHUTDOWN)
 				break;
diff --git a/net/ipv4/tcp_bpf.c b/net/ipv4/tcp_bpf.c
index 2e234d155b5e..338c5d90e550 100644
--- a/net/ipv4/tcp_bpf.c
+++ b/net/ipv4/tcp_bpf.c
@@ -286,10 +286,9 @@ static int tcp_bpf_recvmsg_parser(struct sock *sk,
 		if (sock_flag(sk, SOCK_DONE))
 			goto out;
 
-		if (sk->sk_err) {
-			copied = sock_error(sk);
+		copied = sock_error(sk);
+		if (copied)
 			goto out;
-		}
 
 		if (sk->sk_shutdown & RCV_SHUTDOWN)
 			goto out;
@@ -553,10 +552,9 @@ static int tcp_bpf_sendmsg(struct sock *sk, struct msghdr *msg, size_t size)
 		bool enospc = false;
 		u32 copy, osize;
 
-		if (sk->sk_err) {
-			err = -sk->sk_err;
+		err = -READ_ONCE(sk->sk_err);
+		if (err)
 			goto out_err;
-		}
 
 		copy = msg_data_left(msg);
 		if (!sk_stream_memory_free(sk))

-- 
2.55.0



^ permalink raw reply	[flat|nested] 9+ messages in thread

* [PATCH net-next v5 2/2] mptcp: annotate lockless access to sk->sk_err
  2026-09-25 12:47 [PATCH net-next v5 0/2] tcp: annotate lockless access to sk->sk_err Quanye Yang via B4 Relay
  2026-09-25 12:47 ` [PATCH net-next v5 1/2] " Quanye Yang via B4 Relay
@ 2026-09-25 12:47 ` Quanye Yang via B4 Relay
  2026-10-01  7:32   ` Matthieu Baerts
  2026-10-01  9:10 ` [PATCH net-next v5 0/2] tcp: " patchwork-bot+netdevbpf
  2026-10-01  9:10 ` Paolo Abeni
  3 siblings, 1 reply; 9+ messages in thread
From: Quanye Yang via B4 Relay @ 2026-09-25 12:47 UTC (permalink / raw)
  To: Eric Dumazet, Neal Cardwell, Kuniyuki Iwashima, David S. Miller,
	Jakub Kicinski, Paolo Abeni, Simon Horman, Matthieu Baerts (NGI0),
	Geliang Tang, Mat Martineau, Jiayuan Chen
  Cc: netdev, linux-kernel

From: Quanye Yang <quanyeyang@proton.me>

sock_error() can clear sk_err with xchg() without the socket lock.

On the no-data msk recv and splice paths, call sock_error() once and
only stop when it returns a non-zero error. Annotate the remaining
msk send and subflow error-report peeks with READ_ONCE().

Signed-off-by: Quanye Yang <quanyeyang@proton.me>
---
 net/mptcp/protocol.c | 14 ++++++--------
 net/mptcp/subflow.c  |  4 ++--
 2 files changed, 8 insertions(+), 10 deletions(-)

diff --git a/net/mptcp/protocol.c b/net/mptcp/protocol.c
index e1f08f71cdb1..e37a8642a4b0 100644
--- a/net/mptcp/protocol.c
+++ b/net/mptcp/protocol.c
@@ -969,7 +969,7 @@ static bool move_skbs_to_msk(struct mptcp_sock *msk, struct sock *ssk)
 
 	moved = __mptcp_move_skbs_from_subflow(msk, ssk, true);
 	__mptcp_ofo_queue(msk);
-	if (unlikely(ssk->sk_err))
+	if (unlikely(READ_ONCE(ssk->sk_err)))
 		__mptcp_subflow_error_report(sk, ssk);
 
 	/* If the moves have caught up with the DATA_FIN sequence number
@@ -2028,7 +2028,7 @@ static int mptcp_sendmsg(struct sock *sk, struct msghdr *msg, size_t len)
 	}
 
 	ret = -EPIPE;
-	if (unlikely(sk->sk_err || (sk->sk_shutdown & SEND_SHUTDOWN)))
+	if (unlikely(READ_ONCE(sk->sk_err) || (sk->sk_shutdown & SEND_SHUTDOWN)))
 		goto do_error;
 
 	pfrag = sk_page_frag(sk);
@@ -2429,10 +2429,9 @@ static int mptcp_recvmsg(struct sock *sk, struct msghdr *msg, size_t len,
 			    !timeo)
 				break;
 		} else {
-			if (sk->sk_err) {
-				copied = sock_error(sk);
+			copied = sock_error(sk);
+			if (copied)
 				break;
-			}
 
 			if (sk->sk_shutdown & RCV_SHUTDOWN)
 				break;
@@ -4655,10 +4654,9 @@ static ssize_t mptcp_splice_read(struct socket *sock, loff_t *ppos,
 				break;
 			if (sock_flag(sk, SOCK_DONE))
 				break;
-			if (sk->sk_err) {
-				ret = sock_error(sk);
+			ret = sock_error(sk);
+			if (ret)
 				break;
-			}
 			if (sk->sk_shutdown & RCV_SHUTDOWN)
 				break;
 			if (sk->sk_state == TCP_CLOSE) {
diff --git a/net/mptcp/subflow.c b/net/mptcp/subflow.c
index af81ad5e699d..ec9668fe8d5b 100644
--- a/net/mptcp/subflow.c
+++ b/net/mptcp/subflow.c
@@ -1541,7 +1541,7 @@ static void subflow_data_ready(struct sock *sk)
 		if (mptcp_data_avail(msk) < parent->sk_rcvlowat &&
 		    (tcp_sk(sk)->rcv_nxt - tcp_sk(sk)->rcv_wup) > inet_csk(sk)->icsk_ack.rcv_mss)
 			inet_csk(sk)->icsk_ack.pending |= ICSK_ACK_NOW;
-	} else if (unlikely(sk->sk_err)) {
+	} else if (unlikely(READ_ONCE(sk->sk_err))) {
 		subflow_error_report(sk);
 	}
 }
@@ -1889,7 +1889,7 @@ static void subflow_state_change(struct sock *sk)
 	 */
 	if (mptcp_subflow_data_available(sk))
 		mptcp_data_ready(parent, sk);
-	else if (unlikely(sk->sk_err))
+	else if (unlikely(READ_ONCE(sk->sk_err)))
 		subflow_error_report(sk);
 
 	subflow_sched_work_if_closed(mptcp_sk(parent), sk);

-- 
2.55.0



^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: [PATCH net-next v5 1/2] tcp: annotate lockless access to sk->sk_err
  2026-09-25 12:47 ` [PATCH net-next v5 1/2] " Quanye Yang via B4 Relay
@ 2026-10-01  0:21   ` Jakub Kicinski
  2026-10-01  7:24     ` Eric Dumazet
  0 siblings, 1 reply; 9+ messages in thread
From: Jakub Kicinski @ 2026-10-01  0:21 UTC (permalink / raw)
  To: edumazet
  Cc: Quanye Yang via B4 Relay, quanyeyang, Eric Dumazet,
	Neal Cardwell, Kuniyuki Iwashima, David S. Miller, Paolo Abeni,
	Simon Horman, Matthieu Baerts (NGI0),
	Geliang Tang, Mat Martineau, Jiayuan Chen, netdev, linux-kernel

On Fri, 25 Sep 2026 05:47:56 -0700 Quanye Yang via B4 Relay wrote:
> Subject: [PATCH net-next v5 1/2] tcp: annotate lockless access to sk->sk_err

Updating Eric's email just in case this isn't ignored intentionally :)
https://lore.kernel.org/all/20260925-mptcp-sk-err-net-v5-1-0cac04d6ea48@proton.me/

^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: [PATCH net-next v5 1/2] tcp: annotate lockless access to sk->sk_err
  2026-10-01  0:21   ` Jakub Kicinski
@ 2026-10-01  7:24     ` Eric Dumazet
  0 siblings, 0 replies; 9+ messages in thread
From: Eric Dumazet @ 2026-10-01  7:24 UTC (permalink / raw)
  To: Jakub Kicinski
  Cc: Quanye Yang via B4 Relay, quanyeyang, Eric Dumazet,
	Neal Cardwell, Kuniyuki Iwashima, David S. Miller, Paolo Abeni,
	Simon Horman, Matthieu Baerts (NGI0),
	Geliang Tang, Mat Martineau, Jiayuan Chen, netdev, linux-kernel

On Thu, Oct 1, 2026 at 2:21 AM Jakub Kicinski <kuba@kernel.org> wrote:
>
> On Fri, 25 Sep 2026 05:47:56 -0700 Quanye Yang via B4 Relay wrote:
> > Subject: [PATCH net-next v5 1/2] tcp: annotate lockless access to sk->sk_err
>
> Updating Eric's email just in case this isn't ignored intentionally :)
> https://lore.kernel.org/all/20260925-mptcp-sk-err-net-v5-1-0cac04d6ea48@proton.me/

Reviewed-by: Eric Dumazet <edumazet@kernel.org>

Thanks!

^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: [PATCH net-next v5 2/2] mptcp: annotate lockless access to sk->sk_err
  2026-09-25 12:47 ` [PATCH net-next v5 2/2] mptcp: " Quanye Yang via B4 Relay
@ 2026-10-01  7:32   ` Matthieu Baerts
  0 siblings, 0 replies; 9+ messages in thread
From: Matthieu Baerts @ 2026-10-01  7:32 UTC (permalink / raw)
  To: quanyeyang, Eric Dumazet, Neal Cardwell, Kuniyuki Iwashima,
	David S. Miller, Jakub Kicinski, Paolo Abeni, Simon Horman,
	Geliang Tang, Mat Martineau, Jiayuan Chen
  Cc: netdev, linux-kernel

Hi Quanye,

On 25/09/2026 14:47, Quanye Yang via B4 Relay wrote:
> From: Quanye Yang <quanyeyang@proton.me>
> 
> sock_error() can clear sk_err with xchg() without the socket lock.
> 
> On the no-data msk recv and splice paths, call sock_error() once and
> only stop when it returns a non-zero error. Annotate the remaining
> msk send and subflow error-report peeks with READ_ONCE().

Thanks!

Reviewed-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>

Cheers,
Matt
-- 
Sponsored by the NGI0 Core fund.


^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: [PATCH net-next v5 0/2] tcp: annotate lockless access to sk->sk_err
  2026-09-25 12:47 [PATCH net-next v5 0/2] tcp: annotate lockless access to sk->sk_err Quanye Yang via B4 Relay
  2026-09-25 12:47 ` [PATCH net-next v5 1/2] " Quanye Yang via B4 Relay
  2026-09-25 12:47 ` [PATCH net-next v5 2/2] mptcp: " Quanye Yang via B4 Relay
@ 2026-10-01  9:10 ` patchwork-bot+netdevbpf
  2026-10-01  9:10 ` Paolo Abeni
  3 siblings, 0 replies; 9+ messages in thread
From: patchwork-bot+netdevbpf @ 2026-10-01  9:10 UTC (permalink / raw)
  To: Quanye Yang
  Cc: edumazet, ncardwell, kuniyu, davem, kuba, pabeni, horms, matttbe,
	geliang, martineau, jiayuan.chen, netdev, linux-kernel

Hello:

This series was applied to netdev/net-next.git (main)
by Paolo Abeni <pabeni@redhat.com>:

On Fri, 25 Sep 2026 05:47:55 -0700 you wrote:
> do_recvmmsg() and getsockopt(SO_ERROR) call sock_error() without the
> socket lock and clear sk_err with xchg().
> 
> Patch 1 covers TCP. Peek-only sites use READ_ONCE(). On the no-data
> recv and splice paths, call sock_error() once and only stop when it
> returns a non-zero error. tcp_bpf_sendmsg() folds two unmarked loads
> into one READ_ONCE() and uses that value as the returned errno.
> 
> [...]

Here is the summary with links:
  - [net-next,v5,1/2] tcp: annotate lockless access to sk->sk_err
    https://git.kernel.org/netdev/net-next/c/3b49f11cc92d
  - [net-next,v5,2/2] mptcp: annotate lockless access to sk->sk_err
    https://git.kernel.org/netdev/net-next/c/97870870b7dd

You are awesome, thank you!
-- 
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html



^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: [PATCH net-next v5 0/2] tcp: annotate lockless access to sk->sk_err
  2026-09-25 12:47 [PATCH net-next v5 0/2] tcp: annotate lockless access to sk->sk_err Quanye Yang via B4 Relay
                   ` (2 preceding siblings ...)
  2026-10-01  9:10 ` [PATCH net-next v5 0/2] tcp: " patchwork-bot+netdevbpf
@ 2026-10-01  9:10 ` Paolo Abeni
  2026-10-01 12:44   ` quanyeyang
  3 siblings, 1 reply; 9+ messages in thread
From: Paolo Abeni @ 2026-10-01  9:10 UTC (permalink / raw)
  To: quanyeyang, Eric Dumazet, Neal Cardwell, Kuniyuki Iwashima,
	David S. Miller, Jakub Kicinski, Simon Horman,
	Matthieu Baerts (NGI0),
	Geliang Tang, Mat Martineau, Jiayuan Chen
  Cc: netdev, linux-kernel

On 9/25/26 14:47, Quanye Yang via B4 Relay wrote:
> do_recvmmsg() and getsockopt(SO_ERROR) call sock_error() without the
> socket lock and clear sk_err with xchg().
> 
> Patch 1 covers TCP. Peek-only sites use READ_ONCE(). On the no-data
> recv and splice paths, call sock_error() once and only stop when it
> returns a non-zero error. tcp_bpf_sendmsg() folds two unmarked loads
> into one READ_ONCE() and uses that value as the returned errno.
> 
> Patch 2 does the same for MPTCP and annotates the remaining subflow
> error-report peeks.
Note that there are more possible follow-ups in tls and on the write side:

https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260925-mptcp-sk-err-net-v5-0-0cac04d6ea48@proton.me

/P


^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: [PATCH net-next v5 0/2] tcp: annotate lockless access to sk->sk_err
  2026-10-01  9:10 ` Paolo Abeni
@ 2026-10-01 12:44   ` quanyeyang
  0 siblings, 0 replies; 9+ messages in thread
From: quanyeyang @ 2026-10-01 12:44 UTC (permalink / raw)
  To: Paolo Abeni
  Cc: Eric Dumazet, Neal Cardwell, Kuniyuki Iwashima, David S. Miller,
	Jakub Kicinski, Simon Horman, Matthieu Baerts (NGI0),
	Geliang Tang, Mat Martineau, Jiayuan Chen, netdev, linux-kernel

> Note that there are more possible follow-ups in tls and on the write side:
> 
Thanks for pointing this out.

I'll continue looking into the remaining sk_err accesses in TLS and on the write side, and follow up with patches where appropriate.

Thanks,
Quanye
> https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260925-mptcp-sk-err-net-v5-0-0cac04d6ea48@proton.me
> 
> /P
> 
>

^ permalink raw reply	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2026-10-01 12:45 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-25 12:47 [PATCH net-next v5 0/2] tcp: annotate lockless access to sk->sk_err Quanye Yang via B4 Relay
2026-09-25 12:47 ` [PATCH net-next v5 1/2] " Quanye Yang via B4 Relay
2026-10-01  0:21   ` Jakub Kicinski
2026-10-01  7:24     ` Eric Dumazet
2026-09-25 12:47 ` [PATCH net-next v5 2/2] mptcp: " Quanye Yang via B4 Relay
2026-10-01  7:32   ` Matthieu Baerts
2026-10-01  9:10 ` [PATCH net-next v5 0/2] tcp: " patchwork-bot+netdevbpf
2026-10-01  9:10 ` Paolo Abeni
2026-10-01 12:44   ` quanyeyang

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®