From nobody Fri Sep 25 05:29:21 2026 Received: from mail-pj2-f13.google.com (mail-pj2-f13.google.com [74.125.227.141]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 62DEB4E66DA for ; Wed, 16 Sep 2026 11:37:22 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.227.141 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789558647; cv=none; b=O/6dSvjtGEfVzvSo1KvEKEYeF5UHsbEB8GwoPBLEofclaoj1jCnctXs0ELahSCCN/ojl3YzPQR/SnGGAHzMk5zta6YrH/JsVjVYzQRZI0mj7O1cXdZsRhH7atBRhh65q2NgKGvk0c7xGJ17GVzPRV7uIdDRrzLF7W/7iXMxwIUE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789558647; c=relaxed/simple; bh=3uaObKhY36qkdLUb4pvRy/Y7taGooeBUyJJlfhXMPyU=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=PPoqs2oDqrsdYX/+eXvNS4v6wEAzyD0NmxljX+a7eX/IaTvpgSBBgFeRJYoI9gYuqWBGB+V2uMbCOykHFH5px7UOjw5LqPEFBuZUSqUslAQMaGtr13O7DXoiGQJvuyn54b7LQ6M7Xj85a2ThmcprIfPyCb+3gkbvaMpgp6mc4RQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=X8N5Jcs3; arc=none smtp.client-ip=74.125.227.141 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="X8N5Jcs3" Received: by mail-pj2-f13.google.com with SMTP id d9443c01a7336-2d91ede8035so9284045ad.3 for ; Wed, 16 Sep 2026 04:37:21 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789558638; x=1790163438; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=oOQF8lSD7wdJvBSJlzI6UX4BPG3ivMWDQsQe23mQk7c=; b=X8N5Jcs3hPDyXmeaSlRypDxXcs9LPre+NLB/t6soDQBJyMteLrs00qojbyXgS3gjIQ 353omtc5s0xw4Tg/EKD9jPpIkoPccKwqDzAqnrVjPGOexvVO1Lkufq5V9XzL7FEMKjCc up5//J5YvW1fYOW71km9urGjABEhVqvK5NGzpwwU+mMpKJxJ/6l2hbLPOLX6iCAMzGQ5 PiF7m+8vUcopxDQV2qjQNhZNxEu9M6DCgs2vmWfh2E3M2DWda3+Lo9B0oSqVIjgD5p9c c2IWu6S6/aIHMDXzJlylkMCI7Op2QMY2/7u8Rs+Ur35ZE4vY86Rskasa0W2iazpydER1 dk3Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789558638; x=1790163438; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=oOQF8lSD7wdJvBSJlzI6UX4BPG3ivMWDQsQe23mQk7c=; b=NCiL7xNH/AR4Xi+8OMM/6gkAXrd0J0qP9PBerNR0p3wn/AzutXEWOGhGWoGkJZT0+e wOfrmbJOD/vdEu3+iSleAcad26yTgNRMT6JU4iUCckmZ8D4NdqSPIo08gwoyImYwQG7P vXAkls5D+9aCHEBdsgG/XE2Xm6jxmm+/y6TJC9x/8Ux3vWmk1rZUrWApI0IyJ0Mz0Vvr 6EvdM1YHhSTeoFf5G1so/fVbTg8Z3OXlI0oiREIRUc/GfSVFXgl/iY7tosEeVynQ4SwH P3aCjqkphk64eAmE66KhfvotMbGduSC5+nK8HDGuW17XVu86VST9MHlWOzDaOcDOcJih AUbQ== X-Forwarded-Encrypted: i=1; AKwUvBybj6fOa/E7sqd0Z8/Av1SUKEF/3hmuUI1HUcJA9rQVGU4/t55q9nohUVaiI2gt3Posim3JgXxLR5mizH0=@vger.kernel.org X-Gm-Message-State: AFuF++kI3Lbo0wIGpDn4r/mD5CdIXHhRe67s8HXHVzxgKwzzUqE5oghQ AbrPSxp2m6VU6Q8Bm/9ltGYV0AQ9VKLmNANLKumlCFSLgyAaBn+asSTY X-Gm-Gg: AYBFou2N1fSkLgxjulG8P+eSD1noLJDKovFuLAFk2FEZOw46ADsxa0mj3YasBiZRZal sbv/pQHRQu56o1fuWIDZkDt0BwVCtERKRwZ4aeyqwzAsLLjHXQi4mwwNywLX/WHhjO/cLqs0OM+ 38qY7SCk0K1W9xB/7ZQ4hju39b+tdzmDhjv3GHJpqZx2+Qqrh1amjWRRc4P/2m5E+PSaV3fYnAS h4sYFBK4sswHQ+9MMmygVoVriD4DZVjV/q9phnLOp4+IGc4X3BDudU+pl6k6uk6OHWGLFg0Z3Av LUskuLM0NVM5tzsolYJqUi/+Opuls87UbDpHwce9APTUWqHLDKAB3K/lZxSAKLjmj/6KF+AyO/7 0ShX+I3KszYRloj1x3Cclg3asOp7n346xKIGPkhvsPZYGGAfiYaHntPUvno59FwX10PpuDZSPoc 0DhMPFf9wHoeyLVBAKT9H3EyazF10JdEek7ZHClZdzxxKKKbIWASLEOH10/8N0KmXkOPKFl2PSC zaU5L4RwhHnvahm6AF5KPYln5Qngo+nLw== X-Received: by 2002:a17:903:46c7:b0:2db:8ae7:a5d2 with SMTP id d9443c01a7336-2dd8e026db9mr44702525ad.9.1789558638056; Wed, 16 Sep 2026 04:37:18 -0700 (PDT) Received: from KRHW1CJW23.bytedance.net ([139.177.225.247]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2dd89f02fc2sm9927045ad.59.2026.09.16.04.37.11 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Wed, 16 Sep 2026 04:37:17 -0700 (PDT) From: Zhao Li To: Johannes Berg Cc: Bob Copeland , linux-wireless@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org Subject: [PATCH 1/2] wifi: mac80211: release mesh path quota on failed additions Date: Wed, 16 Sep 2026 19:36:48 +0800 Message-ID: <20260916113649.28315-2-enderaoelyther@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260916113649.28315-1-enderaoelyther@gmail.com> References: <20260916113649.28315-1-enderaoelyther@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Repeated failed or duplicate mesh path additions can exhaust MESH_MAX_MPATHS while the path table holds fewer paths, which stops new paths to reachable destinations from being created. mesh_path_add() reserves a slot before allocating and inserting a path. If allocation fails, the function returns without releasing the slot. If the rhashtable insertion reports an error or an existing destination, the function discards its candidate but retains the reservation. No new path is installed in any of these cases. Release the reservation whenever the candidate is not installed. Fixes: ae76eef027f7 ("mac80211: return new mpath from mesh_path_add()") Fixes: 60854fd94573 ("mac80211: mesh: convert path table to rhashtable") Cc: stable@vger.kernel.org Assisted-by: LLM sparse kasan Signed-off-by: Zhao Li --- Validation: - GCC W=3D1 and Sparse C=3D2 produced no diagnostics. - A controlled production-helper matrix reproduced the allocation, insertion, and duplicate reservation leaks. Allocation and insertion errors used test-only fault injection; 24/24 concurrent same-destination trials leaked a reservation before the fix and 0/24 after. That case used no forced-failure hook. - A two-point hwsim 802.11s run reached production mesh_path_add() from mesh_nexthop_resolve() and hwmp_route_info_get() during PREQ/PREP processing. No physical-radio or layer-3 success is claimed. net/mac80211/mesh_pathtbl.c | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/net/mac80211/mesh_pathtbl.c b/net/mac80211/mesh_pathtbl.c index 03171cf00855..770fc16b439b 100644 --- a/net/mac80211/mesh_pathtbl.c +++ b/net/mac80211/mesh_pathtbl.c @@ -694,8 +694,10 @@ struct mesh_path *mesh_path_add(struct ieee80211_sub_i= f_data *sdata, return ERR_PTR(-ENOSPC); =20 new_mpath =3D mesh_path_new(sdata, dst, GFP_ATOMIC); - if (!new_mpath) + if (!new_mpath) { + atomic_dec(&sdata->u.mesh.mpaths); return ERR_PTR(-ENOMEM); + } =20 tbl =3D &sdata->u.mesh.mesh_paths; spin_lock_bh(&tbl->walk_lock); @@ -708,6 +710,7 @@ struct mesh_path *mesh_path_add(struct ieee80211_sub_if= _data *sdata, =20 if (mpath) { kfree(new_mpath); + atomic_dec(&sdata->u.mesh.mpaths); =20 if (IS_ERR(mpath)) return mpath; --=20 2.55.0 From nobody Fri Sep 25 05:29:21 2026 Received: from mail-pj2-f13.google.com (mail-pj2-f13.google.com [74.125.227.141]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6FE734F054A for ; Wed, 16 Sep 2026 11:37:28 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.227.141 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789558673; cv=none; b=rRal4WPMcOtRn/0sk558ZoNZjT6eBAQxHkr3uPgz80LYYSzpRqWjU0XiGuAgrUXOdIbaVUagHvYMnN8Zq7GDo3onqgIwFfalBoZaRthTxfJ0FyxLX16uLhkPgwj2NtFA/4vzEsSP2QLhp9k7UKpqx8DBIb4FzSI2wklSh6wHDLY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789558673; c=relaxed/simple; bh=/Hc8uJtTDrUeU5cVZdc1ZyUkvgdb77Y94Nbtto9GWOk=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=We8BrQyVesp3bnncljn8ThvtS4furvUWzAPAZkX7UWYt8xAIy3fW4V4LvmLw8ewmbRTZKRTU+EVpQIxE05KNfLWLpWOJ5Oyv4OxcWCmJxCuuGuKYLClAphKcYxu0wloCXMklms9WV2tOtDk5bRU971jrfNg2QL+jUAY127pMiO4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=TqbZiUiE; arc=none smtp.client-ip=74.125.227.141 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="TqbZiUiE" Received: by mail-pj2-f13.google.com with SMTP id d9443c01a7336-2dd53691be5so8006185ad.1 for ; Wed, 16 Sep 2026 04:37:27 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789558643; x=1790163443; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=u71SukOk/uWqGG5KqXUmklLOaVffKeGeaoghUb9DD4k=; b=TqbZiUiEA+CMSix0qtFQKpx40D5mN8jlve96C1PqxDGY+d6GYO8iLxFXjeurGRkyW6 b+sxAOZb21sPCeM35/2kNOpL3bbCbBMgyVOR4xpbRiZaMU292mcnMLEsbe1eqqtQ9qgw 33kEn9KnAfzL3zwGhUVRM+atXUu7tkhIKfV6Fu/hy8dK7//TMVak8mOLH22gA35rFB0x KeiZ8kOoxsPPYFZXKlNhEhK7PoRTZ0szUCEaHp5X6b0vblxkLYeaDp3gYhu+lWx283R4 9GIHlyueTiBghsTGtaZ1NLzRnNcvBFc7Z9Z+FtTEnif/ma7zlS1+LOakFJBLMJthUIBI pcxg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789558643; x=1790163443; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=u71SukOk/uWqGG5KqXUmklLOaVffKeGeaoghUb9DD4k=; b=DguuxUPA3AlV2OFTMlWYf3/u12kgZ5RsuHTUc0sAiQLNTLWUc24Abc9U/JVY28pyO6 k+/3KrwaqkOfdcKBAPu+XBsortIh7yKFwQAhcgUaVaEUF+BnspkaogWE6TIiznggfQ9q P6+mh5YpOTBWF3tN7kfwA0wUgGLbQPyhcvVRLrvUTxz9c/3f2DzhCfMot+XEbCNHfC6s LtpOS1qJBATkyl6Th30V5VFglI3cxulT7Bk+4Nq9vE7ff1CjPiKCVm5hKWd1LxZbrSJK 90ziA2WgrABu5hsdjuj9fCFbfJPqlOH5+aQ4hcLjJ+oIOJCEtZttKcBQKq4uBWvBH97f f7hA== X-Forwarded-Encrypted: i=1; AKwUvBz+QQAwo9BE5IwpIm11BUDWDNNSoENm/AvjhcB9pURrBVyrNLfIAqV9uiHiNzkO91T+o1/rNv7OUhHfwpE=@vger.kernel.org X-Gm-Message-State: AFuF++lWujm7GF3ULIHMJAGeCdC3qDXfn9pqKEMv/6vJsBbQp/EKT7c/ AR54risKq9BzZfpzH1dCE65Mmf6aYL6V164mvtNVOpoRMR/TZnTYwEM4 X-Gm-Gg: AYBFou1R+4qIrY9Gtw9QgE5oUfrD8J4neDQCvzvg//y1jFJpjMoNnNTcuJpQGOh4bW/ uMVsfMgP891Ge2vGhP8y1emeAFtpyteSf+iXBaSorRmNEKqC9OAOOj+L7/AjH/dC+ipWOFe4zXr 9wH/guXKLTQEFQrXY/LU1TpD4mXV3KBgPai/JSbE7v8RbIFeWFHEKk4G2q/7SK8P0n4ceanbC8B YL64RtzdAGN3O2Mkp6w091a9R8lNYkxargw6d2eRniDhBCuh0t/m/rinM6scr0xvA5q+DFVDA1w kD2XKrj6EU6WAJPGzhynF4552UtiHzgc/G296Joc1anP75CiIT8qTS3yLYUHiO7AUgZJZD6SYdL 4NakXZv+52BujU8exIhCNmMZiJXgDvCadjuGKrpKJ6WgBWM9UoMINI+gpbDxYL4EyVQtfkKbsKw GqVmTr7FkBmgNbQlPFiDPZ5wfbBK3ysOmk7jViLFkyEmsPYWddzsiAz9+cn2x2micyDRVRQsGKj bqPOwbArSU1PHMvOhoKawKi5kbwjV088w== X-Received: by 2002:a17:903:1b67:b0:2cc:6018:f030 with SMTP id d9443c01a7336-2dd8e51df8amr47363745ad.14.1789558642410; Wed, 16 Sep 2026 04:37:22 -0700 (PDT) Received: from KRHW1CJW23.bytedance.net ([139.177.225.247]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2dd89f02fc2sm9927045ad.59.2026.09.16.04.37.18 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Wed, 16 Sep 2026 04:37:21 -0700 (PDT) From: Zhao Li To: Johannes Berg Cc: Bob Copeland , linux-wireless@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org Subject: [PATCH 2/2] wifi: mac80211: account proxy paths against the mesh path limit Date: Wed, 16 Sep 2026 19:36:49 +0800 Message-ID: <20260916113649.28315-3-enderaoelyther@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260916113649.28315-1-enderaoelyther@gmail.com> References: <20260916113649.28315-1-enderaoelyther@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Proxy-path churn can drive the interface path counter negative and let later mesh path additions exceed MESH_MAX_MPATHS. mesh_path_free_rcu() decrements the interface mpaths counter for entries from both the mesh and proxy path tables, but mpp_path_add() never reserves a slot in that counter. Removing or expiring a proxy path therefore returns a slot that was never charged. mesh_path_add() uses the same counter to enforce MESH_MAX_MPATHS, so once it falls below the number of installed paths the limit no longer holds. Reserve the shared quota before allocating a proxy path and release it on every unsuccessful addition. Mesh and proxy paths now share one 1024-entry budget, so mpp_path_add() can return -ENOSPC at that limit. Fixes: ece1a2e7e860 ("mac80211: Remove mesh paths when an interface is remo= ved") Cc: stable@vger.kernel.org Assisted-by: LLM sparse kasan Signed-off-by: Zhao Li --- Validation: - GCC W=3D1 and Sparse C=3D2 produced no diagnostics. - A controlled production-helper matrix drove the counter to -10 through proxy-path churn before the fix and kept it at zero after it. With 1023 mesh paths and one proxy path installed, one further mesh addition exceeded the combined cap before the fix and returned -ENOSPC afterward. - A two-point hwsim 802.11s run reached production mpp_path_add() from received address-extension mesh data. After one proxy install, the pre-patch counter was 2 and the fixed counter was 3 for the same three walk-list entries. No physical-radio or layer-3 success is claimed. net/mac80211/mesh_pathtbl.c | 13 ++++++++++--- 1 file changed, 10 insertions(+), 3 deletions(-) diff --git a/net/mac80211/mesh_pathtbl.c b/net/mac80211/mesh_pathtbl.c index 770fc16b439b..1c55b14c2ac0 100644 --- a/net/mac80211/mesh_pathtbl.c +++ b/net/mac80211/mesh_pathtbl.c @@ -736,10 +736,15 @@ int mpp_path_add(struct ieee80211_sub_if_data *sdata, if (is_multicast_ether_addr(dst)) return -EOPNOTSUPP; =20 + if (!atomic_add_unless(&sdata->u.mesh.mpaths, 1, MESH_MAX_MPATHS)) + return -ENOSPC; + new_mpath =3D mesh_path_new(sdata, dst, GFP_ATOMIC); =20 - if (!new_mpath) + if (!new_mpath) { + atomic_dec(&sdata->u.mesh.mpaths); return -ENOMEM; + } =20 memcpy(new_mpath->mpp, mpp, ETH_ALEN); tbl =3D &sdata->u.mesh.mpp_paths; @@ -752,10 +757,12 @@ int mpp_path_add(struct ieee80211_sub_if_data *sdata, hlist_add_head_rcu(&new_mpath->walk_list, &tbl->walk_head); spin_unlock_bh(&tbl->walk_lock); =20 - if (ret) + if (ret) { kfree(new_mpath); - else + atomic_dec(&sdata->u.mesh.mpaths); + } else { mesh_fast_tx_flush_addr(sdata, dst); + } =20 sdata->u.mesh.mpp_paths_generation++; return ret; --=20 2.55.0