Re: [PATCH] sctp: hold transport reference across connect wait
From: Xin Long
Date: Thu Oct 01 2026 - 14:53:26 EST
On Mon, Sep 28, 2026 at 11:21 AM Seung Min Shin <guncraft2000@xxxxxxxxx> wrote:
>
> sctp_sendmsg_to_asoc() selects a transport before waiting for a new
> interleaved association to become established. sctp_wait_for_connect()
> drops the socket lock while sleeping.
>
> While the lock is dropped, backlog processing can handle a COOKIE ACK and
> an ASCONF DEL-IP that removes the selected transport. sctp_assoc_rm_peer()
> then marks the transport dead and drops its association-owned reference.
> The transport can be freed through RCU before the send path resumes.
>
> After the wait, the stale pointer is assigned to newly created DATA or
> I-DATA chunks and later dereferenced by sctp_outq_select_transport().
>
> Hold a reference to the selected transport across
> sctp_wait_for_connect(). After the socket lock is reacquired, abort the
> send if the transport was marked dead. Callers without a selected
> transport pass NULL and retain their existing behavior.
>
> Cc: stable@xxxxxxxxxx
> Fixes: 668c9beb9020 ("sctp: implement assign_number for sctp_stream_interleave")
> Assisted-by: LLM
> Signed-off-by: Seung Min Shin <guncraft2000@xxxxxxxxx>
Acked-by: Xin Long <lucien.xin@xxxxxxxxx>