Re: [PATCH net-next 2/2] net: annotate lockless writes to sk->sk_err
From: Eric Dumazet
Date: Fri Oct 02 2026 - 04:51:31 EST
On Fri, Oct 2, 2026 at 9:29 AM Quanye Yang via B4 Relay
<devnull+quanyeyang.proton.me@xxxxxxxxxx> wrote:
>
> From: Quanye Yang <quanyeyang@xxxxxxxxx>
>
> do_recvmmsg() and getsockopt(SO_ERROR) clear sk_err with xchg()
> without the socket lock. TCP, MPTCP and kTLS already peek the same
> field with READ_ONCE() or consume it via sock_error().
>
> sock_dequeue_err_skb() still uses plain stores. tcp_recvmsg() can
> call it via MSG_ERRQUEUE before lock_sock(), so those writes race
> with the annotated readers and with sock_error(). The same unmarked
> stores exist in strp_abort_strp() and sk_psock_report_error(), which
> run on the TCP/TLS socket.
>
> Annotate those writers with WRITE_ONCE(). No extra ordering is
> needed; this does not change who wins when ICMP error-queue entries
> overwrite sk_err.
>
> Link: https://lore.kernel.org/netdev/3d9d442f-f168-43da-87b0-010ad5a78365@xxxxxxxxxx/
> Signed-off-by: Quanye Yang <quanyeyang@xxxxxxxxx>
Reviewed-by: Eric Dumazet <edumazet@xxxxxxxxxx>