Commit e00b63056fb4 for kernel

commit e00b63056fb4f261455b3e5df5268a1f8ce47a87
Author: Wyatt Feng <bronzed_45_vested@icloud.com>
Date:   Mon Aug 3 18:16:39 2026 +0200

    mptcp: fastopen: only mark MPTFO subflows with SYN data

    Passive TCP Fast Open accepts a valid-cookie SYN even when it carries
    no data. In that case the child socket's receive queue is intentionally
    left empty.

    mptcp_fastopen_subflow_synack_set_params() set is_mptfo before checking
    for queued SYN data. That made data-less TFO SYNs hit a WARN and, if
    the warning was non-fatal, left stale MPTFO state behind. The stale
    flag could later trigger a state-confusion bug in
    check_fully_established().

    Only mark the subflow as MPTFO after confirming that an SKB was queued.
    Return quietly when the receive queue is empty.

    Note that mptcp_subflow_context's is_mptfo field is now not just about
    subflows where the TFO was present, but about MPTFO subflow that
    consumed SYN data. Only having a valid cookie but not carrying data is
    not really "doing TFO".

    Fixes: 36b122baf6a8 ("mptcp: add subflow_v(4,6)_send_synack()")
    Cc: stable@vger.kernel.org
    Reported-by: Yuan Tan <yuantan098@gmail.com>
    Reported-by: Yifan Wu <yifanwucs@gmail.com>
    Reported-by: Juefei Pu <tomapufckgml@gmail.com>
    Reported-by: Zhengchuan Liang <zcliangcn@gmail.com>
    Reported-by: Xin Liu <bird@lzu.edu.cn>
    Signed-off-by: Wyatt Feng <bronzed_45_vested@icloud.com>
    Signed-off-by: Ren Wei <n05ec@lzu.edu.cn>
    Reviewed-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
    Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
    Link: https://patch.msgid.link/20260803-net-mptcp-misc-fixes-7-2-rc6-v2-7-b8f496d71664@kernel.org
    Signed-off-by: Jakub Kicinski <kuba@kernel.org>

diff --git a/net/mptcp/fastopen.c b/net/mptcp/fastopen.c
index 082c46c0f50e..f717750906ff 100644
--- a/net/mptcp/fastopen.c
+++ b/net/mptcp/fastopen.c
@@ -24,12 +24,13 @@ void mptcp_fastopen_subflow_synack_set_params(struct mptcp_subflow_context *subf
 	sk = subflow->conn;
 	tp = tcp_sk(ssk);

-	subflow->is_mptfo = 1;
-
+	/* A valid TFO cookie does not guarantee SYN data. */
 	skb = skb_peek(&ssk->sk_receive_queue);
-	if (WARN_ON_ONCE(!skb))
+	if (!skb)
 		return;

+	subflow->is_mptfo = 1;
+
 	/* dequeue the skb from sk receive queue */
 	__skb_unlink(skb, &ssk->sk_receive_queue);
 	skb_ext_reset(skb);