mirror of
https://github.com/torvalds/linux.git
synced 2026-07-27 09:36:22 +02:00
net/sched: cake: reject overhead values that underflow length
CAKE accepts signed overhead values and stores them in an s16, but the
adjusted packet length calculation uses unsigned arithmetic. A negative
effective length can therefore wrap to a large value.
Such configurations make rate accounting depend on integer wraparound
rather than on the packet size userspace intended to model. A static
netlink lower bound is not enough because packets reaching CAKE can be
smaller than any reasonable manual-overhead allowance.
Fold the signed overhead adjustment into the existing datapath MPU clamp
so negative adjusted lengths are clamped before link-layer framing
adjustments.
Fixes: a729b7f0bd ("sch_cake: Add overhead compensation support to the rate shaper")
Assisted-by: Codex:gpt-5.5-cyber-preview
Signed-off-by: Samuel Moelius <sam.moelius@trailofbits.com>
Acked-by: Toke Høiland-Jørgensen <toke@toke.dk>
Link: https://patch.msgid.link/20260702000758.297407.e5c888d9d99d.cake-overhead-underflow@trailofbits.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
This commit is contained in:
parent
5258b4fdae
commit
b7f97cae7e
|
|
@ -1389,10 +1389,7 @@ static u32 cake_calc_overhead(struct cake_sched_data *qd, u32 len, u32 off)
|
|||
if (qd->min_netlen > len)
|
||||
WRITE_ONCE(qd->min_netlen, len);
|
||||
|
||||
len += q->rate_overhead;
|
||||
|
||||
if (len < q->rate_mpu)
|
||||
len = q->rate_mpu;
|
||||
len = max((s32)len + q->rate_overhead, (s32)q->rate_mpu);
|
||||
|
||||
if (q->atm_mode == CAKE_ATM_ATM) {
|
||||
len += 47;
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user