linux/include
Willem de Bruijn fc6d80eb50 tcp: prevent collapsing skbs across boundary in rtx queue
tcp_write_collapse_fence() sets TCP_SKB_CB(skb)->eor = 1 on
tcp_write_queue_tail(sk) to prevent skbs queued after a switch to
device encryption from being collapsed into earlier skbs.

The fence is a no-op if all earlier data has already been transmitted
when the switch happens: sk->sk_write_queue is empty. The not yet
acknowledged earlier skbs wait in sk->tcp_rtx_queue with eor 0.

On a subsequent retransmit or SACK shift, tcp_retrans_try_collapse() or
tcp_shift_skb_data() can then merge an skb queued after the switch into
one queued before it.

Both users of the fence are affected:

- psp: devices only encrypt skbs with skb->decrypted set. The merged skb
  keeps decrypted = 0 from the earlier skb, so merged data sent after
  psp_sock_assoc_set_tx() is retransmitted in cleartext.

- tls device offload: the merged skb straddles the start marker set in
  tls_set_device_offload(). The software fallback (fill_sg_in() returns
  -EINVAL) and the mlx5, nfp and funeth drivers cannot handle such an
  skb and drop it. Every retransmit rebuilds the same skb, so the
  connection stalls.

Fix this in two places, for defense in depth:

1. Fall back to tcp_rtx_queue_tail(sk) in tcp_write_collapse_fence()
   when tcp_write_queue_tail(sk) is NULL.

2. Check !skb_cmp_decrypted(to, from) in tcp_skb_can_collapse(), as
   tcp_skb_can_collapse_rx() does on receive. skb_shift(), which both
   collapse paths call, already has a DEBUG_NET_WARN_ON_ONCE() for this
   condition.

Fixes: e8f6979981 ("net/tls: Add generic NIC offload infrastructure")
Cc: stable@vger.kernel.org
Signed-off-by: Willem de Bruijn <willemb@google.com>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Daniel Zahka <daniel.zahka@gmail.com>
Link: https://patch.msgid.link/20260924154427.953800-1-willemdebruijn.kernel@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
2026-09-24 11:03:42 -07:00
..
acpi ACPI: bus: Drop two fields from struct acpi_device_pnp 2026-09-01 21:45:50 +02:00
asm-generic kho: make boot time huge page allocation work nicely with KHO 2026-08-23 09:17:38 -07:00
clocksource hyperv-next for v7.3-rc1 2026-08-26 16:47:40 -07:00
crypto This update includes the following changes: 2026-08-19 17:25:42 -07:00
cxl
drm Merge drm/drm-fixes into drm-misc-fixes 2026-09-01 09:38:51 +02:00
dt-bindings sound fixes for 7.3-rc1 2026-08-28 10:01:02 -07:00
hyperv
keys tpm: Initial step to reorganize TPM public headers 2026-08-25 18:13:35 +03:00
kunit gpio updates for v7.3-rc1 2026-08-19 09:10:07 -07:00
kvm KVM/arm64 changes for 7.3 2026-08-24 12:42:07 -04:00
linux packet: use ubuf_info completion for TX_RING packets 2026-09-22 18:32:57 -07:00
math-emu
media media: hevc: add bounded tile-count helpers 2026-09-07 09:01:05 +02:00
memory
misc
net tcp: prevent collapsing skbs across boundary in rtx queue 2026-09-24 11:03:42 -07:00
pcmcia
ras
rdma RDMA/uverbs: Fix mmap_lock/disassociation_lock circular dependency 2026-09-01 10:03:08 -04:00
rv mm.git review status for linus..mm-stable 2026-08-27 09:17:06 -07:00
scsi SCSI updates for 7.3 2026-08-29 11:55:36 -07:00
soc Mostly the usual clk driver updates and new SoC additions plus non-critical 2026-08-26 11:14:30 -07:00
sound ASoC: sdw_utils: cs_amp: Delete bogus and incorrect capture channel fixup 2026-09-14 00:37:41 +01:00
target
trace dma-mapping fixes for Linux 7.3 2026-09-17 08:03:37 -07:00
uapi RDMA v7.3 first rc pull 2026-09-14 09:58:12 -07:00
ufs
vdso
video fbdev: maxine: fix 64-bit build error 2026-08-20 23:45:07 +02:00
xen
Kbuild