Re: [PATCH net] tcp: fix icsk_ack.ato bitfield overflow
Neal Cardwell <[email protected]>
| Newsgroups | gmane.linux.network,gmane.linux.kernel |
|---|---|
| Message-ID | <CADVnQynLVAzSdOGmrc4NE2dMWsyj_J89_xCqQ-504G6fOa4vXQ@mail.gmail.com> |
On Thu, Aug 6, 2026 at 9:45 PM Jiayuan Chen <[email protected]> wrote: > > On cross-region connections we observed delayed ACKs suddenly turning > into immediate ACKs plus a TCP_MAX_QUICKACKS burst, as if the > connection had just received its first data segment. > > Commit 95b9a87c6a6b ("tcp: record last received ipv6 flowlabel") > squeezed icsk_ack.ato into 8 bits, sized for TCP_DELACK_MAX. But both > writers still bound ato by icsk_rto, which can be well above 255 > jiffies, so the bitfield assignment silently wraps mod 256: repeated > delack timer misses double ato up to icsk_rto, storing 320 as 64 and > 256 as 0, and ato == 0 is the "first data packet" sentinel in > tcp_event_data_recv(). > > Clamp both writers to TCP_DELACK_MAX, which the static_assert already > guarantees to fit and tcp_send_delayed_ack() effectively caps ato at > anyway. > > Fixes: 95b9a87c6a6b ("tcp: record last received ipv6 flowlabel") > Signed-off-by: Jiayuan Chen <[email protected]> Reviewed-by: Neal Cardwell <[email protected]> Thanks for the fix! neal