[PATCH net-next v5 0/2] tcp: annotate lockless access to sk->sk_err

From: Quanye Yang via B4 Relay

Date: Fri Sep 25 2026 - 08:53:52 EST


do_recvmmsg() and getsockopt(SO_ERROR) call sock_error() without the
socket lock and clear sk_err with xchg().

Patch 1 covers TCP. Peek-only sites use READ_ONCE(). On the no-data
recv and splice paths, call sock_error() once and only stop when it
returns a non-zero error. tcp_bpf_sendmsg() folds two unmarked loads
into one READ_ONCE() and uses that value as the returned errno.

Patch 2 does the same for MPTCP and annotates the remaining subflow
error-report peeks.

---
Changes in v5:
- recv/splice: call sock_error() once instead of peek-then-consume
- mention the tcp_bpf_sendmsg() READ_ONCE fold in the TCP commit
- Link to v4: https://patch.msgid.link/20260917-mptcp-sk-err-net-v4-0-1f04f52f2561@xxxxxxxxx

Changes in v4:
- split the annotation change, one points to tcp and another points to
mptcp.
- annotate the remaining unmarked MPTCP sk_err peeks on the
subflow error-report path.
- Link to v3: https://patch.msgid.link/20260912-mptcp-sk-err-net-v3-1-c41383878bde@xxxxxxxxx

Changes in v3:
- drop the Fixes tag and retarget to net-next
- annotate the remaining unmarked sk_err peeks on the TCP/MPTCP
send, recv and splice paths
- Link to v2: https://patch.msgid.link/20260909-mptcp-sk-err-net-v2-1-5044abecac90@xxxxxxxxx

Changes in v2:
- add Reported-by and Closes for the MPTCP syzkaller report
- Link to v1: https://patch.msgid.link/20260908-mptcp-sk-err-net-v1-1-da71aaec9afd@xxxxxxxxx

---
Quanye Yang (2):
tcp: annotate lockless access to sk->sk_err
mptcp: annotate lockless access to sk->sk_err

include/net/tcp.h | 2 +-
net/core/stream.c | 2 +-
net/ipv4/tcp.c | 12 +++++-------
net/ipv4/tcp_bpf.c | 10 ++++------
net/mptcp/protocol.c | 14 ++++++--------
net/mptcp/subflow.c | 4 ++--
6 files changed, 19 insertions(+), 25 deletions(-)
---
base-commit: 211f2a875f6f447745d80d5762d6d614503ac84a
change-id: 20260908-mptcp-sk-err-net-7ff88ef05044

Best regards,
--
Quanye Yang <quanyeyang@xxxxxxxxx>