]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
mptcp: prevent excessive coalescing on receive
authorPaolo Abeni <pabeni@redhat.com>
Mon, 30 Dec 2024 18:12:32 +0000 (19:12 +0100)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Thu, 13 Mar 2025 11:47:13 +0000 (12:47 +0100)
commit 56b824eb49d6258aa0bad09a406ceac3f643cdae upstream.

Currently the skb size after coalescing is only limited by the skb
layout (the skb must not carry frag_list). A single coalesced skb
covering several MSS can potentially fill completely the receive
buffer. In such a case, the snd win will zero until the receive buffer
will be empty again, affecting tput badly.

Fixes: 8268ed4c9d19 ("mptcp: introduce and use mptcp_try_coalesce()")
Cc: stable@vger.kernel.org # please delay 2 weeks after 6.13-final release
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Reviewed-by: Mat Martineau <martineau@kernel.org>
Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Link: https://patch.msgid.link/20241230-net-mptcp-rbuf-fixes-v1-3-8608af434ceb@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
net/mptcp/protocol.c

index 8558309a2d3fd3685d3968322199956a2e3de377..51b552fa392a5f2f01fe8ad44660fbc61dab3d06 100644 (file)
@@ -125,6 +125,7 @@ static bool mptcp_try_coalesce(struct sock *sk, struct sk_buff *to,
        int delta;
 
        if (MPTCP_SKB_CB(from)->offset ||
+           ((to->len + from->len) > (sk->sk_rcvbuf >> 3)) ||
            !skb_try_coalesce(to, from, &fragstolen, &delta))
                return false;