[PATCH net v2] mptcp: upgrade network refcount before socket lock

Runyu Xiao <[email protected]>
Newsgroups dev.linux.lists.mptcp
Message-ID <[email protected]>
sk_net_refcnt_upgrade() is called after lock_sock_nested() in
mptcp_subflow_create_socket(), while other callers perform the upgrade
before taking the socket lock.

Move sk_net_refcnt_upgrade() before lock_sock_nested(). The subflow
socket is newly created and unpublished at this point, so sk_net_refcnt
and ns_tracker are not accessed concurrently, and the existing error
path via sock_release() remains unchanged.

Acked-by: Gang Yan <[email protected]>
Reviewed-by: Matthieu Baerts (NGI0) <[email protected]>
Signed-off-by: Runyu Xiao <[email protected]>
---
Changes in v2:
- Shorten the commit message and remove the validation-method details.
- Describe the change in terms of the pre-lock upgrade ordering.
- Add Acked-by from Gang Yan.
- Add Reviewed-by from Matthieu Baerts.

 net/mptcp/subflow.c | 11 ++++++-----
 1 file changed, 6 insertions(+), 5 deletions(-)

diff --git a/net/mptcp/subflow.c b/net/mptcp/subflow.c
index e1f20ff8fdb4..a9f951cc6a0e 100644
--- a/net/mptcp/subflow.c
+++ b/net/mptcp/subflow.c
@@ -1786,6 +1786,12 @@ int mptcp_subflow_create_socket(struct sock *sk, unsigned short family,
 	if (err)
 		return err;
 
+	/* kernel sockets do not by default acquire net ref, but TCP timer
+	 * needs it.
+	 * Update ns_tracker to current stack trace and refcounted tracker.
+	 */
+	sk_net_refcnt_upgrade(sf->sk);
+
 	lock_sock_nested(sf->sk, SINGLE_DEPTH_NESTING);
 
 	err = security_mptcp_add_subflow(sk, sf->sk);
@@ -1795,11 +1801,6 @@ int mptcp_subflow_create_socket(struct sock *sk, unsigned short family,
 	/* the newly created socket has to be in the same cgroup as its parent */
 	mptcp_attach_cgroup(sk, sf->sk);
 
-	/* kernel sockets do not by default acquire net ref, but TCP timer
-	 * needs it.
-	 * Update ns_tracker to current stack trace and refcounted tracker.
-	 */
-	sk_net_refcnt_upgrade(sf->sk);
 	err = tcp_set_ulp(sf->sk, "mptcp");
 	if (err)
 		goto err_free;
-- 
2.34.1
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.