Re: [PATCH net-next v5] sctp: auth: discard auth_chunk when skb_clone fails

Jakub Kicinski <[email protected]> Tue, 28 Jul 2026 18:23:59 -0700
Newsgroups org.kernel.vger.linux-sctp,org.kernel.vger.linux-kernel,org.kernel.vger.netdev
Message-ID <[email protected]>
On Thu, 23 Jul 2026 14:11:07 +0800 luoqing wrote:
> From: Qing Luo <[email protected]>
> 
> When processing AUTH + COOKIE-ECHO packets, if skb_clone() fails
> due to memory pressure, chunk->auth_chunk is NULL. The original
> code still sets chunk->auth = 1 and continues, leaving the
> COOKIE-ECHO to be processed without a valid auth_chunk for
> deferred verification.
> 
> Discard the AUTH chunk early via pdiscard when skb_clone() fails,
> so that the receive loop can continue processing remaining chunks
> in the inqueue instead of stalling the entire packet.

Hi Xin Long, should we apply this or it's no longer worth it after
8e04823c120b ?

> diff --git a/net/sctp/associola.c b/net/sctp/associola.c
> index 62d3cc155809..a5f2835dbe0f 100644
> --- a/net/sctp/associola.c
> +++ b/net/sctp/associola.c
> @@ -999,6 +999,10 @@ static void sctp_assoc_bh_rcv(struct work_struct *work)
>  			if (next_hdr->type == SCTP_CID_COOKIE_ECHO) {
>  				chunk->auth_chunk = skb_clone(chunk->skb,
>  							      GFP_ATOMIC);
> +				if (!chunk->auth_chunk) {
> +					chunk->pdiscard = 1;
> +					continue;
> +				}
>  				chunk->auth = 1;
>  				continue;
>  			}
> diff --git a/net/sctp/endpointola.c b/net/sctp/endpointola.c
> index dfb1719275db..a15b599b20b7 100644
> --- a/net/sctp/endpointola.c
> +++ b/net/sctp/endpointola.c
> @@ -368,6 +368,10 @@ static void sctp_endpoint_bh_rcv(struct work_struct *work)
>  			if (next_hdr->type == SCTP_CID_COOKIE_ECHO) {
>  				chunk->auth_chunk = skb_clone(chunk->skb,
>  								GFP_ATOMIC);
> +				if (!chunk->auth_chunk) {
> +					chunk->pdiscard = 1;
> +					continue;
> +				}
>  				chunk->auth = 1;
>  				continue;
>  			}