From mboxrd@z Thu Jan 1 00:00:00 1970 Authentication-Results: mail.toke.dk; dkim=none; arc=none (Message is not ARC signed); dmarc=fail (Used From Domain Record) header.from=toke.dk policy.dmarc=none From: Toke =?utf-8?Q?H=C3=B8iland-J=C3=B8rgensen?= To: Yuchao Zhang , "David S . Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni Cc: Simon Horman , Jamal Hadi Salim , Jiri Pirko , cake@lists.bufferbloat.net, netdev@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org, Yuchao Zhang In-Reply-To: <20260927131009.24250-2-ndaugoing@gmail.com> References: <20260927131009.24250-1-ndaugoing@gmail.com> <20260927131009.24250-2-ndaugoing@gmail.com> Date: Mon, 28 Sep 2026 14:30:39 +0200 X-Clacks-Overhead: GNU Terry Pratchett Message-ID: <877bk5lfrk.fsf@toke.dk> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Message-ID-Hash: SF6LAZRHDH4SSZTVBI4GDXAYZDDB3K44 X-Message-ID-Hash: SF6LAZRHDH4SSZTVBI4GDXAYZDDB3K44 X-MailFrom: toke@toke.dk X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list Subject: [Cake] Re: [PATCH net v3 1/2] net/sched: sch_cake: fix shaper stall on segs == 0 in cake_overhead() List-Id: Cake - FQ_codel the next generation Archived-At: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: Yuchao Zhang writes: > In cake_overhead(), packets with a single segment bypass multi-segment > overhead calculations: > > if (segs =3D=3D 1) > return cake_calc_overhead(q, len, off); > > Commit c5d34f4583ea ("net_sched: cake: use qdisc_pkt_segs()") switched > cake to retrieve the cached segmentation count via qdisc_pkt_segs(skb) > instead of calculating it locally for dodgy GSO packets. If an skb with > segs =3D=3D 0 reaches cake_overhead(), it skips the segs =3D=3D 1 early r= eturn > and enters the multi-segment arithmetic: > > len =3D shinfo->gso_size + hdr_len; > last_len =3D skb->len - shinfo->gso_size * (segs - 1); > > return (cake_calc_overhead(q, len, off) * (segs - 1) + > cake_calc_overhead(q, last_len, off)); > > Because segs is an unsigned 16-bit integer, (segs - 1) underflows to > 65535 (and is promoted to 4294967295 in the 32-bit unsigned arithmetic > above). This multiplies the per-segment overhead by UINT32_MAX, so > cake_overhead() returns a length close to 4.29 GB. cake_advance_shaper() > then charges that length to the shaper, stalling the CAKE dequeue path > for tens of seconds at 1 Gbit/s, and for minutes to hours at lower rates. > > Fix this by returning early with cake_calc_overhead(q, len, off) whenever > segs <=3D 1. > > Fixes: c5d34f4583ea ("net_sched: cake: use qdisc_pkt_segs()") > Cc: stable@vger.kernel.org > Signed-off-by: Yuchao Zhang Acked-by: Toke H=C3=B8iland-J=C3=B8rgensen