From nobody Mon Sep 28 13:18:10 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 16F60366061; Fri, 21 Aug 2026 11:17:31 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787311052; cv=none; b=tTEGzrHL4fM6zLjdRKBir6wySCCnnaBmcYy9xp5GuH9AzOkMUJf3iR3pV8uXY1jzOBQSqGl+jQLVsAk4GwRG3WlwJqUgvVu4pX8L+CVM8ryChdFdfl8A0pZUtw4QT0e/UW83WrF/ZkDnRBsZ/VauKwMIhM2qt8DIWDTjdiu1dk8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787311052; c=relaxed/simple; bh=rAjTQEtLsLV9kFA7GO/RMTn5HEOTkBpQ/dZay1kXX58=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=KWDizvVXfcly9bWrF5ywFnzATx0OyZ0Spd62Dk0DRzKMvVJ3yZjDmykTGDfNaVThMSZ5zYJb4iWQI/YjgHnyNLV8eLb0JABO72GtldvI9DNpHO5xEc6Pbbxy3FDEGauvGDPYd3lRkhxUA8Vx7FeFOcEciNC88BmSW9LgF+e5QWU= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=uel5cNk9; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="uel5cNk9" Received: by smtp.kernel.org (Postfix) with ESMTPS id AC45AC2BCF7; Fri, 21 Aug 2026 11:17:31 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1787311051; bh=rAjTQEtLsLV9kFA7GO/RMTn5HEOTkBpQ/dZay1kXX58=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=uel5cNk9QGdQl3mIBL6FAQIAWDNSYRPJgeDj1FrLqIuxz92/UlegvcLiKEawiwaO8 PNHkjEIbSbP/OKi+GQOr7/Q3hDmraE7yQn5u9FZK/DypTHC6qMU/0XdGoDsXE6oVYF J0N12mcnnk3cABvIbUe4APxKz1BF+OXgJ0jiPYW3n1tdJvKO606N00pVUo6GWZJx1K 2BSFWKqCxCT9cjKiABTpM3zqlwG/mSmvde2Ks9nZ19UgoQWmexZ9W4yQImPL2g14/c RUlIfQMzspVFi4/N/Mjba/CmpXy2HF3thlG3IdnW8jGxXTsJJLLez9HRMZurNEserB ZPKPGpwheYOog== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 8A7B9C5DF7D; Fri, 21 Aug 2026 11:17:31 +0000 (UTC) From: Bryam Vargas via B4 Relay Date: Fri, 21 Aug 2026 06:17:31 -0500 Subject: [PATCH net v2 1/3] net/iucv: only send the window update on HiperSockets sockets Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260821-b4-disp-3a6e8695-v2-1-37597ff723a8@proton.me> References: <20260821-b4-disp-3a6e8695-v2-0-37597ff723a8@proton.me> In-Reply-To: <20260821-b4-disp-3a6e8695-v2-0-37597ff723a8@proton.me> To: Eric Dumazet , Paolo Abeni , Jakub Kicinski , Alexandra Winter , Thorsten Winkler , "David S. Miller" Cc: Hidayath Khan , Simon Horman , linux-kernel@vger.kernel.org, netdev@vger.kernel.org, linux-s390@vger.kernel.org, Ursula Braun X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1787311050; l=1571; i=hexlabsecurity@proton.me; s=default; h=from:subject:message-id; bh=UV3NZoQuo/NUMIXZzEpsfVb35DP1P1HpuhR4s+1zr/s=; b=nRbIFg0Vj+2He+x6Njfa7xtOheMIN5cIuHP7k6WwIHI0wPSs5mir5dLB3ha5chqfh4C3g//YY 08Z9Bs6RQPGCySJCrvoQlABTgdD/zITernQUTM2qDRFFMwQIAa1/Zt7 X-Developer-Key: i=hexlabsecurity@proton.me; a=ed25519; pk=xw1AhCtQdvuoQc+bOQIYy9o8G++cp4/VniI2G/tc3G8= X-Endpoint-Received: by B4 Relay for hexlabsecurity@proton.me/default with auth_id=893 X-Original-From: Bryam Vargas Reply-To: hexlabsecurity@proton.me From: Bryam Vargas iucv_sock_recvmsg() sends AF_IUCV_FLAG_WIN without testing the transport, but that flag exists only on HiperSockets. On a classic z/VM socket iucv->hs_dev is NULL and iucv_send_ctrl() sizes the skb from LL_RESERVED_SPACE(iucv->hs_dev), so the read goes through NULL. It is one recvmsg() away for an unprivileged process on a socket of its own: SO_MSGLIMIT accepts 1, so msglimit / 2 is 0 and msg_recv never leaves 0 on a classic socket. The read lands in mapped lowcore on a default kernel and the socket takes a spurious disconnect; with relocate_lowcore it faults. Test the transport. The unconditional send is older than that, but stayed harmless while iucv_send_ctrl() used a constant ETH_HLEN. Fixes: 238965b71b96 ("net/af_iucv: build proper skbs for HiperTransport") Cc: stable@vger.kernel.org Signed-off-by: Bryam Vargas Tested-by: Aswin Karuvally --- net/iucv/af_iucv.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/net/iucv/af_iucv.c b/net/iucv/af_iucv.c index ea047bab65e7..0bc4a15f4b56 100644 --- a/net/iucv/af_iucv.c +++ b/net/iucv/af_iucv.c @@ -1331,7 +1331,8 @@ static int iucv_sock_recvmsg(struct socket *sock, str= uct msghdr *msg, if (skb_queue_empty(&iucv->backlog_skb_q)) { if (!list_empty(&iucv->message_q.list)) iucv_process_message_q(sk); - if (atomic_read(&iucv->msg_recv) >=3D + if (iucv->transport =3D=3D AF_IUCV_TRANS_HIPER && + atomic_read(&iucv->msg_recv) >=3D iucv->msglimit / 2) { err =3D iucv_send_ctrl(sk, AF_IUCV_FLAG_WIN); if (err) { --=20 2.55.0 From nobody Mon Sep 28 13:18:10 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 16E2023AE87; Fri, 21 Aug 2026 11:17:31 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787311052; cv=none; b=dGE85BVXh6piXmtJV6x4/925XyGSr1nM6eK6xd/fv7nZ5iukJl9MAZk9ImwzVOZNH9oaAmdGn0smwIcvZUvvW3cu3ORysYrz0gwmAJMUEEaRzqQZpsH/EYCPCRIp6nv80bZbwde9PxgKyO+b/+lF3cesJ1RMGWCSDrJcJwxtlvI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787311052; c=relaxed/simple; bh=Z2qkCOW6uOoE4Tcm2xkjLfssvPh/evtQRuReVm29Y1s=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=W1FwKZhxYPGJVvUAbVBWu9h336SGOSADWE8f+ZiemnUX8seIqgXSAefhCUAQ+3WYPJK1LBCRp0tNiIjS4K0buXMqxUy78JwXAL85sa6e2deq6ulZLngBBtpaSKvRMEtcXNCjQvjTTcZgmnLXAhkHcvtf8PJPErb/49L/5nNKvkU= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=T2EQMrOW; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="T2EQMrOW" Received: by smtp.kernel.org (Postfix) with ESMTPS id C12D6C2BCF6; Fri, 21 Aug 2026 11:17:31 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1787311051; bh=Z2qkCOW6uOoE4Tcm2xkjLfssvPh/evtQRuReVm29Y1s=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=T2EQMrOWrgXqTt3S7iNddF3R1H0t/Tt/l2N7LOxdV6S3pUZzR2mc6FWd9mu4kOc3Y 4tLvVRgB4WLPj8pwOKIsqUSjzQIRDgplzw2U/QFXt8R1IGB2MR7u3gczqUGKc7KDNx nPfgUL/JvIMhhP7cs70ENhhOO93vthbFKhpsYAcELbg7wl6g8u1a/DwlyKt5ogzw5p AvSfsIKEKh9mW3tWihc8UH5s+AHYRSg6sA09ntUkVfklSzJhPf89ZUnO+igxzcs/YR mBm/jTxOsuXHlVeDQTAeYZAZMEf+XfyLXr8nvds3D6Oy+CxYa9lKJNsRUKiAci1sCQ fQP+HfzAkWuoQ== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id A04C6C5DF87; Fri, 21 Aug 2026 11:17:31 +0000 (UTC) From: Bryam Vargas via B4 Relay Date: Fri, 21 Aug 2026 06:17:32 -0500 Subject: [PATCH net v2 2/3] net/iucv: claim the receive credit atomically Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260821-b4-disp-3a6e8695-v2-2-37597ff723a8@proton.me> References: <20260821-b4-disp-3a6e8695-v2-0-37597ff723a8@proton.me> In-Reply-To: <20260821-b4-disp-3a6e8695-v2-0-37597ff723a8@proton.me> To: Eric Dumazet , Paolo Abeni , Jakub Kicinski , Alexandra Winter , Thorsten Winkler , "David S. Miller" Cc: Hidayath Khan , Simon Horman , linux-kernel@vger.kernel.org, netdev@vger.kernel.org, linux-s390@vger.kernel.org, Ursula Braun X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1787311050; l=2680; i=hexlabsecurity@proton.me; s=default; h=from:subject:message-id; bh=gdWnKR2zta/pTzLbRUr1dcaH2AxxQQj7YNfOq5qNvR4=; b=zqGOlGCSiF/k0bUYBWLokM3x49KYfuMD+pmlbvhvcEII4VXlHTl0qCJo0NIbd5XnvkfOp8YJ/ EFnXIm3r+q4AZxHrn3GA3SNQsI59sg8NHDGkBTGUKAUY5qtboegyOn1 X-Developer-Key: i=hexlabsecurity@proton.me; a=ed25519; pk=xw1AhCtQdvuoQc+bOQIYy9o8G++cp4/VniI2G/tc3G8= X-Endpoint-Received: by B4 Relay for hexlabsecurity@proton.me/default with auth_id=893 X-Original-From: Bryam Vargas Reply-To: hexlabsecurity@proton.me From: Bryam Vargas afiucv_hs_send() samples msg_recv, advertises it to the peer as the window, and subtracts it once dev_queue_xmit() has returned. Nothing owns the counter across the two: iucv_sock_sendmsg() reaches it under lock_sock() and iucv_sock_recvmsg() reaches it under no socket lock, so an unprivileged process running both on one socket can have them subtract the same value. msg_recv goes negative and trips the WARN_ON(); the same interleaving puts that credit on the wire twice, and the peer's afiucv_hs_callback_win() subtracts the wire value from msg_sent unchecked. Claim it with atomic_xchg(), after the last error exit so the counter reads zero only while the transmit is in flight, and hand it back if that fails. Nothing subtracts now, so the WARN_ON() goes too. Fixes: 3881ac441f64 ("af_iucv: add HiperSockets transport") Cc: stable@vger.kernel.org Signed-off-by: Bryam Vargas Tested-by: Aswin Karuvally --- net/iucv/af_iucv.c | 21 ++++++++++++--------- 1 file changed, 12 insertions(+), 9 deletions(-) diff --git a/net/iucv/af_iucv.c b/net/iucv/af_iucv.c index 0bc4a15f4b56..492a45bb2bba 100644 --- a/net/iucv/af_iucv.c +++ b/net/iucv/af_iucv.c @@ -210,12 +210,6 @@ static int afiucv_hs_send(struct iucv_message *imsg, s= truct sock *sock, phs_hdr->flags =3D flags; if (flags =3D=3D AF_IUCV_FLAG_SYN) phs_hdr->window =3D iucv->msglimit; - else if ((flags =3D=3D AF_IUCV_FLAG_WIN) || !flags) { - confirm_recv =3D atomic_read(&iucv->msg_recv); - phs_hdr->window =3D confirm_recv; - if (confirm_recv) - phs_hdr->flags =3D phs_hdr->flags | AF_IUCV_FLAG_WIN; - } memcpy(phs_hdr->destUserID, iucv->dst_user_id, 8); memcpy(phs_hdr->destAppName, iucv->dst_name, 8); memcpy(phs_hdr->srcUserID, iucv->src_user_id, 8); @@ -250,13 +244,22 @@ static int afiucv_hs_send(struct iucv_message *imsg, = struct sock *sock, } skb->protocol =3D cpu_to_be16(ETH_P_AF_IUCV); =20 + /* Claim the receive credit here, not while building the header: every + * way this frame can be dropped has now been ruled out, so the window + * is zeroed only for as long as the transmit itself takes. + */ + if (flags =3D=3D AF_IUCV_FLAG_WIN || !flags) { + confirm_recv =3D atomic_xchg(&iucv->msg_recv, 0); + phs_hdr->window =3D confirm_recv; + if (confirm_recv) + phs_hdr->flags =3D phs_hdr->flags | AF_IUCV_FLAG_WIN; + } + atomic_inc(&iucv->skbs_in_xmit); err =3D dev_queue_xmit(skb); if (net_xmit_eval(err)) { atomic_dec(&iucv->skbs_in_xmit); - } else { - atomic_sub(confirm_recv, &iucv->msg_recv); - WARN_ON(atomic_read(&iucv->msg_recv) < 0); + atomic_add(confirm_recv, &iucv->msg_recv); } return net_xmit_eval(err); =20 --=20 2.55.0 From nobody Mon Sep 28 13:18:10 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 23B8D38DC5F; Fri, 21 Aug 2026 11:17:32 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787311052; cv=none; b=oGZjdMwLzPGQNAdenoogiDO5XDwi2n5U9fNAA+JWOXOwJ6zweTft0Gn0ZFqiYYb1cAZve8rYnHXT+EgPu/VLIHr9xMS4Bde82v073NBIyeBjZfyr9GuR85/fd7ynOY+ZoAGHNWkQ106Y99Ypb6gA6IoUrVbsXITnz7oc0+hOgp4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787311052; c=relaxed/simple; bh=NiWBE4yx44puwWourTxNjWuihHkf6cPGspOXQsKtJwM=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=aXnd75qo+1vWVaAzE/khbZ7a2QDhPjjq6E+EqtIKPj5ZXlvbDDIhwLXGfzZUrQyIm8DeQ2ajz0I6HhSOJU4l8A6lzjUoZQVyKUzo+pJrRhAD7b0vsen1FlQztJVM+0O/zmpiI1aypQmqB12CR7wUeGbNav43iyhpQq1pZgMf4/A= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=Jo6l07MU; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="Jo6l07MU" Received: by smtp.kernel.org (Postfix) with ESMTPS id CEDCDC2BCFA; Fri, 21 Aug 2026 11:17:31 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1787311051; bh=NiWBE4yx44puwWourTxNjWuihHkf6cPGspOXQsKtJwM=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=Jo6l07MUB6A6dW2p5jHvmodbDiFdtx5NyayhEDzKavDJH1gWphm4kv0llzulEE51s 5GVzsas13bIw0qmGNE4erH9fvZcU0EPCeNzscoWDIMY/Zw3V0kE6ZfB1+ULZvFOUUr xrt45/XNXe8GxWaNrh2Gmldiv6RLOalkF0sE9CO+mIdkNPlTS0BBd4ntrAmKlySB5O BCFXzocyjBWKtO0sQ4D3aqBWjZxAKElj/EPkOoz4UN1V0fDGnxDRYJHH702rbrcSXH OYCW+XyUKCXAmpBJrMgq/dcrSq3MHo8DnDhaPQajURcU8X0qjqHQD0w2UupFAxKKpI etjw/ewYf1m8Q== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id B7B1DC5DF91; Fri, 21 Aug 2026 11:17:31 +0000 (UTC) From: Bryam Vargas via B4 Relay Date: Fri, 21 Aug 2026 06:17:33 -0500 Subject: [PATCH net v2 3/3] net/iucv: send the window update outside message_q.lock Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260821-b4-disp-3a6e8695-v2-3-37597ff723a8@proton.me> References: <20260821-b4-disp-3a6e8695-v2-0-37597ff723a8@proton.me> In-Reply-To: <20260821-b4-disp-3a6e8695-v2-0-37597ff723a8@proton.me> To: Eric Dumazet , Paolo Abeni , Jakub Kicinski , Alexandra Winter , Thorsten Winkler , "David S. Miller" Cc: Hidayath Khan , Simon Horman , linux-kernel@vger.kernel.org, netdev@vger.kernel.org, linux-s390@vger.kernel.org, Ursula Braun X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1787311050; l=1987; i=hexlabsecurity@proton.me; s=default; h=from:subject:message-id; bh=EWiW3Q06PiBKk4QOZ/RVbzwZ2pT/eM2TGSityU6WPw0=; b=X9RlmlLOvvGwqBAvQgiE+Xzah8fMZJkCoUV4zOd7BiKwfb1FAPYx0Cv8NLpJpHCUm9vQUIz5C eK46Z1Eu3/WBBRLhhNiwGqkWES0Bigm9XjJTKs7Us/2ZuaiSBJITdJW X-Developer-Key: i=hexlabsecurity@proton.me; a=ed25519; pk=xw1AhCtQdvuoQc+bOQIYy9o8G++cp4/VniI2G/tc3G8= X-Endpoint-Received: by B4 Relay for hexlabsecurity@proton.me/default with auth_id=893 X-Original-From: Bryam Vargas Reply-To: hexlabsecurity@proton.me From: Bryam Vargas iucv_sock_recvmsg() calls iucv_send_ctrl() with message_q.lock held, and iucv_send_ctrl() allocates through sock_alloc_send_skb() with sk->sk_allocation -- GFP_KERNEL here -- so the allocation may sleep inside the spin_lock_bh() section; noblock suppresses only the wait for send buffer space, not the allocation flags. CONFIG_DEBUG_ATOMIC_SLEEP reports it. Note that the update is due and send it once the lock is dropped. That leaves two recvmsg() able to reach afiucv_hs_send() concurrently, which message_q.lock used to prevent; the preceding patch is what makes that safe, so do not apply this one without it. Fixes: 3881ac441f64 ("af_iucv: add HiperSockets transport") Cc: stable@vger.kernel.org Signed-off-by: Bryam Vargas Tested-by: Aswin Karuvally --- net/iucv/af_iucv.c | 18 +++++++++++------- 1 file changed, 11 insertions(+), 7 deletions(-) diff --git a/net/iucv/af_iucv.c b/net/iucv/af_iucv.c index 492a45bb2bba..a7c0f60bb5bf 100644 --- a/net/iucv/af_iucv.c +++ b/net/iucv/af_iucv.c @@ -1244,6 +1244,7 @@ static int iucv_sock_recvmsg(struct socket *sock, str= uct msghdr *msg, struct iucv_sock *iucv =3D iucv_sk(sk); unsigned int copied, rlen; struct sk_buff *skb, *rskb, *cskb; + bool send_win =3D false; int err =3D 0; u32 offset; =20 @@ -1336,15 +1337,18 @@ static int iucv_sock_recvmsg(struct socket *sock, s= truct msghdr *msg, iucv_process_message_q(sk); if (iucv->transport =3D=3D AF_IUCV_TRANS_HIPER && atomic_read(&iucv->msg_recv) >=3D - iucv->msglimit / 2) { - err =3D iucv_send_ctrl(sk, AF_IUCV_FLAG_WIN); - if (err) { - sk->sk_state =3D IUCV_DISCONN; - sk->sk_state_change(sk); - } - } + iucv->msglimit / 2) + send_win =3D true; } spin_unlock_bh(&iucv->message_q.lock); + + if (send_win) { + err =3D iucv_send_ctrl(sk, AF_IUCV_FLAG_WIN); + if (err) { + sk->sk_state =3D IUCV_DISCONN; + sk->sk_state_change(sk); + } + } } =20 done: --=20 2.55.0