mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
synced 2026-09-18 23:19:34 +02:00
tcp: clamp route advmss to TCP_MIN_MSS
tcp_select_initial_window() assumes that callers never pass an MSS
smaller than 1, but route-derived advmss values can violate that
assumption.
A too-small explicit RTAX_ADVMSS is one way to get there, but it is not
the only one. The same divide-by-zero can also be reached through the
"default advmss" path when RTAX_ADVMSS is left at 0 and the effective
advmss is later driven down by route MTU and min_adv_mss.
Introduce a tcp_dst_advmss() helper that clamps route advmss to
TCP_MIN_MSS before TCP consumes it, and use it in the TCP paths that
derive advmss from dst metrics. This keeps the effective MSS from
dropping to zero before tcp_select_initial_window() rounds the receive
window.
Fixes: 1da177e4c3 ("Linux-2.6.12-rc2")
Cc: stable@vger.kernel.org
Reported-by: Vega <vega@nebusec.ai>
Signed-off-by: Yong Wang <edragain@163.com>
Signed-off-by: Ren Wei <weir@nebusec.ai>
Link: https://patch.msgid.link/251eaf8277fa7c66364c9815c5da01662d269181.1787074852.git.edragain@163.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
This commit is contained in:
committed by
Jakub Kicinski
parent
6776efe4a5
commit
870a9e42ec
@@ -1782,6 +1782,11 @@ static inline int tcp_full_space(const struct sock *sk)
|
||||
return tcp_win_from_space(sk, READ_ONCE(sk->sk_rcvbuf));
|
||||
}
|
||||
|
||||
static inline u32 tcp_dst_advmss(const struct dst_entry *dst)
|
||||
{
|
||||
return max_t(u32, dst_metric_advmss(dst), TCP_MIN_MSS);
|
||||
}
|
||||
|
||||
static inline void __tcp_adjust_rcv_ssthresh(struct sock *sk, u32 new_ssthresh)
|
||||
{
|
||||
int unused_mem = sk_unused_reserved_mem(sk);
|
||||
|
||||
+1
-1
@@ -1736,7 +1736,7 @@ struct sock *tcp_v4_syn_recv_sock(const struct sock *sk, struct sk_buff *skb,
|
||||
tcp_ca_openreq_child(newsk, dst);
|
||||
|
||||
tcp_sync_mss(newsk, dst4_mtu(dst));
|
||||
newtp->advmss = tcp_mss_clamp(tcp_sk(sk), dst_metric_advmss(dst));
|
||||
newtp->advmss = tcp_mss_clamp(tcp_sk(sk), tcp_dst_advmss(dst));
|
||||
|
||||
tcp_initialize_rcv_mss(newsk);
|
||||
|
||||
|
||||
@@ -440,7 +440,7 @@ void tcp_openreq_init_rwin(struct request_sock *req,
|
||||
u32 rcv_wnd;
|
||||
int mss;
|
||||
|
||||
mss = tcp_mss_clamp(tp, dst_metric_advmss(dst));
|
||||
mss = tcp_mss_clamp(tp, tcp_dst_advmss(dst));
|
||||
window_clamp = READ_ONCE(tp->window_clamp);
|
||||
/* Set this up on the first call only */
|
||||
req->rsk_window_clamp = window_clamp ? : dst_metric(dst, RTAX_WINDOW);
|
||||
|
||||
@@ -143,7 +143,7 @@ static __u16 tcp_advertise_mss(struct sock *sk)
|
||||
int mss = tp->advmss;
|
||||
|
||||
if (dst) {
|
||||
unsigned int metric = dst_metric_advmss(dst);
|
||||
unsigned int metric = tcp_dst_advmss(dst);
|
||||
|
||||
if (metric < mss) {
|
||||
mss = metric;
|
||||
@@ -3972,7 +3972,7 @@ struct sk_buff *tcp_make_synack(const struct sock *sk, struct dst_entry *dst,
|
||||
}
|
||||
skb_dst_set(skb, dst);
|
||||
|
||||
mss = tcp_mss_clamp(tp, dst_metric_advmss(dst));
|
||||
mss = tcp_mss_clamp(tp, tcp_dst_advmss(dst));
|
||||
|
||||
memset(&opts, 0, sizeof(opts));
|
||||
now = tcp_clock_ns();
|
||||
@@ -4128,7 +4128,7 @@ static void tcp_connect_init(struct sock *sk)
|
||||
|
||||
if (!tp->window_clamp)
|
||||
WRITE_ONCE(tp->window_clamp, dst_metric(dst, RTAX_WINDOW));
|
||||
tp->advmss = tcp_mss_clamp(tp, dst_metric_advmss(dst));
|
||||
tp->advmss = tcp_mss_clamp(tp, tcp_dst_advmss(dst));
|
||||
|
||||
tcp_initialize_rcv_mss(sk);
|
||||
|
||||
|
||||
+1
-1
@@ -1487,7 +1487,7 @@ static struct sock *tcp_v6_syn_recv_sock(const struct sock *sk, struct sk_buff *
|
||||
tcp_ca_openreq_child(newsk, dst);
|
||||
|
||||
tcp_sync_mss(newsk, dst6_mtu(dst));
|
||||
newtp->advmss = tcp_mss_clamp(tcp_sk(sk), dst_metric_advmss(dst));
|
||||
newtp->advmss = tcp_mss_clamp(tcp_sk(sk), tcp_dst_advmss(dst));
|
||||
|
||||
tcp_initialize_rcv_mss(newsk);
|
||||
|
||||
|
||||
Reference in New Issue
Block a user