From mboxrd@z Thu Jan 1 00:00:00 1970 Authentication-Results: mail.toke.dk; dkim=pass header.d=google.com header.i=@google.com header.a=rsa-sha256 header.s=20251104 header.b=smKHattQ; arc=pass; dmarc=pass (Used From Domain Record) header.from=google.com policy.dmarc=reject Received: from mail-qk2-x11.google.com (mail-qk2-x11.google.com [IPv6:2607:f8b0:4864:34::11]) by mail.toke.dk (Postfix) with ESMTPS id 5BEC116F84DD for ; Fri, 25 Sep 2026 11:13:07 +0200 (CEST) Received: by mail-qk2-x11.google.com with SMTP id d75a77b69052e-52fb766bfd6so6687841cf.1 for ; Fri, 25 Sep 2026 02:13:07 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1790327585; cv=none; d=google.com; s=arc-20260327; b=GDDTTvMmv0uyzXdWYqR8C0zdx1PeqTPlWl6m+40nlAcqLelMF4CoiyhD4FxIillqGg aa6HqiJSnhmIpW+U3VIiAiWJYgaHU4AO5Exw8+ztsgS0a5BJg3PrwRrbz3Bw8I2jN+aQ 9GHBpJDmBDgSQrVSUHmEHePq2s40W+OZ3lwojNmKVUbfUgoieLxShk2shr5HXUbrNIUV 0y225NW7YAvrApXp1AOF8KJksD4PdxgYyoAmCuZXr1uDrxHzoHZE02qTifHKif0rN6RM qAKcqKo0tnzTL8V+r52WGOB3l40WeVHKXM3HgdOYthUSRDGV7PO5wwwsSBRA3mSq7CRl D1mA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:dkim-signature; bh=bz9SxP4paTpewO3BSBe/LM1NQKvc6CcYHS65zRhQj14=; fh=ykXs4up0cAOeejMGRtEjiKD0aU+5KBD0abBfOjR3z4g=; b=THxRbTcdF0SVqS80QqcYgDFR4otzCYiT7xOUPDzPbIuykh9slVRiokfuL94a8LT7b2 xAgtBFA/HuDFD5/rgtQS35wpkXpf0/l1bRB0jOrSDDwuIv9GtXKHI96ouCO7elDIEGBy hWxZ7ZRKo9p+vQvzo2zI4z+f77t1WP3BlKrbYzuuKfHO93oAqAWp95MXWhRYia8SBcmk MsXDBE2EcigXtrlcQZUdmee8kvxIl1t5mlUNeYHy+TTKeGNYyaYH8LnQtPOdNYYD5W6o wPS3U/wSqBacEk1YSDoArI1xMmX+uPIuw7Kfhh8hTV2IQ+bL0OkEFoBgztYMEPXk5JpL bTQA==; darn=lists.bufferbloat.net ARC-Authentication-Results: i=1; mx.google.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1790327585; x=1790932385; darn=lists.bufferbloat.net; h=content-transfer-encoding:content-type:cc:to:subject:message-id :date:from:in-reply-to:references:mime-version:from:to:cc:subject :date:message-id:reply-to:content-type; bh=bz9SxP4paTpewO3BSBe/LM1NQKvc6CcYHS65zRhQj14=; b=smKHattQ9FpusjIDaQPYiBZ2h8SxgXhezfRy+kZ/pD4xMM18MggZPsDhPeh8O63Vqk t3+6RQ/G50Vk/0Gktcb6eILFS7N7NUIsqM6nw7hpzH/w4se25uwLpkcDXcS7pH9X/thG luAF346pzx2yKm0SacWSNMalhg+Vsb2FkpDN7xvA75kT7SxOg4CnJ+GR/7ek9q3BJnqo wM5B87jQV0sKa5nMCJAvbZMctGYZRedUBlhgQl/oy3PkWJMVV7xkwqitma4YqQWj3tp1 rv/xkluT3q9BYdpfp6ozAFyi7AWESAM0k1uNGmjgmj3tqWb4NnenMZ3ysd7ATJEVqUqz 3XAw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790327585; x=1790932385; h=content-transfer-encoding:content-type:cc:to:subject:message-id :date:from:in-reply-to:references:mime-version:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=bz9SxP4paTpewO3BSBe/LM1NQKvc6CcYHS65zRhQj14=; b=GW8Cfb6n9AO7BZFOlWzR2RxK4Q5aNtXrwujur2qWZhAE0jPDkzIkA/3JJnsy/l7G0F EyO8gtB8LqTS778BsKiR/eyTgaQbVtgCzM4WS1EryaVUUG2WSEoQxRdZSlUNztElylKl 33NiT+k4TX4P5M5HB7mhU4ziL56KxgoEG5JsCNOW4H3HyDQUQWmotgE+2rY54IrQBusH TNOU0CY8bWygFrVHPtmuIwCm2WCPpR7rX7aQEd8PWI4QEU5wkiBStdtZdnqmLZtnPvWt i8trHCKAPzF/SScMLYjgYYsSJupoWjXZmmb18dd6OExKj7Jo5J7KHo9bWLbbhcJ9vBUQ eABA== X-Forwarded-Encrypted: i=1; AKwUvBxKw+3MTJmSXsPRu8F/Bdgg9nKKXG+DMbGv2AcnEZq7+rU1EGFtDMPqKqCknFdx3yRbv5gb@lists.bufferbloat.net X-Gm-Message-State: AFuF++kNAj+jnSwTJOvIetV7/XwS8kC+4fV6i385Y+zW3eTbbl2CCkAj 1lYM/1ztrwAm8lqb12u9lTi80SdDZImpfalfEXNHP74Ijg49aP0ZYlu8IhhX9eGzFTYUq1eVrXv Qt0euu8gVjZHONxGEOXaha3S1OmhQ8604I8hq1NWu X-Gm-Gg: AYBFou3i/+/Ikepl6461Kz2ted6yQNXO9XiFb+K06/8S/duJbwmeXCv9oVHblMHVGxN EkSUYXgn6A17YFIbJHID15gneNm2MEu6i0ZZjXyfNwU5zOpG0LQ/tcuhyA6mpuf5TEWctbVSKqn 0vKIxRY5AqjhW7GjAlxmVVWYmo/wKoRcep0lKsONfhpXQBD4NKesMzl8m7fJ+IDSlA6bTTy0pMK 3/hADGJxg6xafmQW3qU5Hi5j2zA0Eww8zjw8eEkEQ8wKmbelnLoRRTjSYRKQj/yAGP0JlubE+f6 ogm3omZ5z71MRjIgTcrEk34xKgFoxC4rUD2wonamoi2h2EW+jIKprZqb8e7EK3PHHWo7aPSQoeB rVCwJyzFiCBQMKtHI/iGBsmFUZy1XznhFkriBKw8hI99keSqQV1ssqN9ty6FiX0Kex2Tq X-Received: by 2002:a05:622a:156:b0:530:d429:c70a with SMTP id d75a77b69052e-5330b5f31bdmr29787901cf.26.1790327584464; Fri, 25 Sep 2026 02:13:04 -0700 (PDT) MIME-Version: 1.0 References: In-Reply-To: From: Eric Dumazet Date: Fri, 25 Sep 2026 11:12:53 +0200 X-Gm-Features: AclHuK8GCiEqq2_4rQ3AwZboOt1ZnIczmCQY-4PqwzAjbQfTPZ2smYUW_vtZ6Bk Message-ID: To: Jamal Hadi Salim Cc: netdev@vger.kernel.org, =?UTF-8?B?VG9rZSBIw7hpbGFuZC1Kw7hyZ2Vuc2Vu?= , cake@lists.bufferbloat.net, Jiri Pirko , "David S . Miller" , Jakub Kicinski , Paolo Abeni , Simon Horman , Victor Nogueira , hybris , Sashiko Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Message-ID-Hash: JRC625GNHNL4NM5MV5XDHYUNPBEWCCPP X-Message-ID-Hash: JRC625GNHNL4NM5MV5XDHYUNPBEWCCPP X-MailFrom: edumazet@google.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list Subject: [Cake] Re: [PATCH net-next] net/sched: fq_codel, cake: widen backlogs to u64 List-Id: Cake - FQ_codel the next generation Archived-At: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: On Fri, Sep 25, 2026 at 10:54=E2=80=AFAM Jamal Hadi Salim wrote: > > This is a follow-up to commit 8f735d64382d ("net/sched: bound > qdisc_pkt_len to prevent qdisc soft lockup"), which capped > qdisc_pkt_len() at QDISC_PKT_LEN_MAX (1 MiB). That cap bounds the stab > amplifier but leaves the per-flow backlog counter u32: > fq_codel_enqueue() accumulates qdisc_pkt_len(skb) into q->backlogs[idx], > so a flow can still accumulate 4096 packets of 1 MiB each and wrap the > counter mod 2^32. After a wrap, fq_codel_drop() sees a tiny maxbacklog > and drops from an almost-empty flow, and the dequeue-side subtractions > corrupt the counter further. > > Widen the fq_codel backlogs table, the fat-flow scan (maxbacklog/len) and > the drop threshold to u64. fq_codel is not lockless: every writer runs > under the root qdisc lock, so plain u64 arithmetic keeps the WRITE_ONCE > publish / READ_ONCE-consume pattern. The dump path > (fq_codel_dump_class_stats) stays a lockless stat-only read. > > CAKE accumulates the same generic qdisc_pkt_len(skb) into its per-flow > b->backlogs[] and per-tin b->tin_backlog and consumes the values for > longest-flow pruning (cake_heapify/cake_heapify_up) and for the shaper > staleness check, so it shares the bug. Widen those counters and the heap > comparison locals to u64; the class/tin stats keep exporting the low 32 > bits through the unchanged uAPI fields. > > Conditions to recreate the bug: CAP_NET_ADMIN in a user namespace; > CONFIG_NET_SCH_FQ_CODEL=3Dy. > > ip tuntap add tun0 mode tun > ip link set tun0 txqueuelen 32 up > ip addr add 10.99.0.1/24 dev tun0 > tc qdisc add dev tun0 root handle 1: stab overhead 2000000000 \ > fq_codel flows 1 limit 4200 ecn drop_batch 4096 > # hold the tun fd open without reading (IFF_BACKPRESSURE) so the qdisc > # backlog persists, then send at least 4300 packets (the wrap starts > # at 4096 resident; the over-limit drop that reads the wrapped > # threshold fires past the 4200 limit): backlogs[0] wraps at 4096 x > # 1 MiB and the fat-flow threshold reads the wrapped value. > > With a 1 MiB qdisc_pkt_len cap the counter wraps at 4096 resident > packets. At limit 4200 the first over-limit enqueue (the 4201st) sees a > wrapped 105 MiB (half-backlog threshold 52 MiB, a ~52 packet drop burst), > where the u64 counter sees 4201 MiB (threshold 2100 MiB, a ~2100 packet > drop burst). > > Reported-by: Sashiko (nipa) > Closes: https://netdev-ai.bots.linux.dev/sashiko/#/patchset/2026081810113= 0.16203-1-jhs@mojatatu.com > Link: https://lore.kernel.org/netdev/20260818101130.16203-1-jhs@mojatatu.= com/ > Tested-by: hybris > Signed-off-by: Jamal Hadi Salim > --- This makes no sense. These qdisc have been developped to address bufferbloat issues. Storing 4GB in a qdisc is absolutely insane. Let's drop at enqueue if the current backlog is approaching 4GB (this can later be a new config/attribute in net-next)