Re: [PATCH net] tcp: fix icsk_ack.ato bitfield overflow

Neal Cardwell <[email protected]>
Newsgroups gmane.linux.network,gmane.linux.kernel
Message-ID <CADVnQynLVAzSdOGmrc4NE2dMWsyj_J89_xCqQ-504G6fOa4vXQ@mail.gmail.com>
On Thu, Aug 6, 2026 at 9:45 PM Jiayuan Chen <[email protected]> wrote:
>
> On cross-region connections we observed delayed ACKs suddenly turning
> into immediate ACKs plus a TCP_MAX_QUICKACKS burst, as if the
> connection had just received its first data segment.
>
> Commit 95b9a87c6a6b ("tcp: record last received ipv6 flowlabel")
> squeezed icsk_ack.ato into 8 bits, sized for TCP_DELACK_MAX. But both
> writers still bound ato by icsk_rto, which can be well above 255
> jiffies, so the bitfield assignment silently wraps mod 256: repeated
> delack timer misses double ato up to icsk_rto, storing 320 as 64 and
> 256 as 0, and ato == 0 is the "first data packet" sentinel in
> tcp_event_data_recv().
>
> Clamp both writers to TCP_DELACK_MAX, which the static_assert already
> guarantees to fit and tcp_send_delayed_ack() effectively caps ato at
> anyway.
>
> Fixes: 95b9a87c6a6b ("tcp: record last received ipv6 flowlabel")
> Signed-off-by: Jiayuan Chen <[email protected]>

Reviewed-by: Neal Cardwell <[email protected]>

Thanks for the fix!

neal
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.