]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
mptcp: prevent excessive coalescing on receive
authorPaolo Abeni <pabeni@redhat.com>
Sun, 9 Feb 2025 17:48:31 +0000 (18:48 +0100)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Fri, 21 Feb 2025 12:49:54 +0000 (13:49 +0100)
commit 56b824eb49d6258aa0bad09a406ceac3f643cdae upstream.

Currently the skb size after coalescing is only limited by the skb
layout (the skb must not carry frag_list). A single coalesced skb
covering several MSS can potentially fill completely the receive
buffer. In such a case, the snd win will zero until the receive buffer
will be empty again, affecting tput badly.

Fixes: 8268ed4c9d19 ("mptcp: introduce and use mptcp_try_coalesce()")
Cc: stable@vger.kernel.org # please delay 2 weeks after 6.13-final release
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Reviewed-by: Mat Martineau <martineau@kernel.org>
Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Link: https://patch.msgid.link/20241230-net-mptcp-rbuf-fixes-v1-3-8608af434ceb@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
net/mptcp/protocol.c

index 1cec2be7db55d6d77fe8cd0903d3d0fc9a02e8ec..e975693b8fa9797ef6a5311c01ed5d11b811c9fe 100644 (file)
@@ -149,6 +149,7 @@ static bool mptcp_try_coalesce(struct sock *sk, struct sk_buff *to,
        int delta;
 
        if (MPTCP_SKB_CB(from)->offset ||
+           ((to->len + from->len) > (sk->sk_rcvbuf >> 3)) ||
            !skb_try_coalesce(to, from, &fragstolen, &delta))
                return false;