Re: [PATCH net v2] sctp: drop a chunk if its transport was removed
| Newsgroups | org.kernel.vger.linux-sctp,org.kernel.vger.netdev |
|---|---|
| Message-ID | <178725841213.473641.18430300045813272256.git-patchwork-notify@kernel.org> |
Hello: This patch was applied to netdev/net.git (main) by Jakub Kicinski <[email protected]>: On Wed, 19 Aug 2026 10:38:37 +0900 you wrote: > sctp_rcv() resolves the transport once per packet and leaves it in > chunk->transport. The lookup reference, or the one sctp_add_backlog() takes > if the socket is owned by userspace, keeps it around until the chunk has > been processed. > > An authenticated ASCONF DEL-IP can remove it in the meantime. > sctp_assoc_rm_peer() takes the transport out of the association and calls > sctp_transport_free(), which tags it dead and drops the reference the > association held. There is a window on both paths: the packet can sit on > the socket backlog, and on the direct path the lookup completes before > bh_lock_sock(). > > [...] Here is the summary with links: - [net,v2] sctp: drop a chunk if its transport was removed https://git.kernel.org/netdev/net/c/03a9d10ecf71 You are awesome, thank you! -- Deet-doot-dot, I am a bot. https://korg.docs.kernel.org/patchwork/pwbot.html