Commit f3ca0ee2cc30 for kernel

commit f3ca0ee2cc308e33896536789cbc5f3a12ca7b30
Author: Chenguang Zhao <zhaochenguang@kylinos.cn>
Date:   Wed Jul 22 00:14:38 2026 +0200

    mptcp: decrement subflows counter on failed passive join

    mptcp_pm_allow_new_subflow() increments extra_subflows before
    __mptcp_finish_join() on the passive MP_JOIN path.

    In case of race conditions, the subflow is dropped without calling
    mptcp_close_ssk(), so the counter is not rolled back.

    Call mptcp_pm_close_subflow() when the join completion fails to
    decrement the subflows counter.

    Fixes: 10f6d46c943d ("mptcp: fix race between MP_JOIN and close")
    Cc: stable@vger.kernel.org
    Signed-off-by: Chenguang Zhao <zhaochenguang@kylinos.cn>
    Reviewed-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
    Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
    Link: https://patch.msgid.link/20260722-net-mptcp-misc-fixes-7-2-rc5-v1-1-6fb595bc86ef@kernel.org
    Signed-off-by: Jakub Kicinski <kuba@kernel.org>

diff --git a/net/mptcp/protocol.c b/net/mptcp/protocol.c
index cb9515f505aa..b32f0cd262a7 100644
--- a/net/mptcp/protocol.c
+++ b/net/mptcp/protocol.c
@@ -3907,6 +3907,7 @@ bool mptcp_finish_join(struct sock *ssk)
 	mptcp_data_unlock(parent);

 	if (!ret) {
+		mptcp_pm_close_subflow(msk);
 err_prohibited:
 		subflow->reset_reason = MPTCP_RST_EPROHIBIT;
 		return false;