[PATCH net v4 0/2] net/sched: sch_cake: prevent shaper corruption and stall in cake_overhead()
From: Yuchao Zhang
Date: Mon Sep 28 2026 - 09:26:00 EST
This series addresses two issues in cake_overhead() that can lead to
corrupted rate shaper accounting or long dequeue stalls:
Patch 1 fixes an integer underflow when segs == 0. When an skb with
segs == 0 (such as dodgy GSO packets where gso_segs is not recomputed)
reaches cake_overhead(), (segs - 1) wraps around to UINT32_MAX,
multiplying per-segment overhead by ~4.29 billion and returning a length
close to 4.29 GB. cake_advance_shaper() then charges that length to the
shaper, stalling the dequeue queue for tens of seconds at 1 Gbit/s, and
for minutes to hours at lower rates. This was introduced by commit
c5d34f4583ea ("net_sched: cake: use qdisc_pkt_segs()").
Patch 2 validates the transport header offset computed in cake_overhead().
When the transport header was never set, skb_transport_offset() returns
the ~0U sentinel (~65535), which inflates shaper accounting by ~66 KB
per segment. Furthermore, if preceding egress BPF filters (e.g.
sch_handle_egress()) or cake classifier actions (e.g. act_bpf trimming
headers via bpf_skb_adjust_room(BPF_ADJ_ROOM_MAC)) leave the transport
header stale (bpf_skb_net_hdr_pop() only re-syncs it when it aliased
network_header), skb_transport_offset() can become negative. Because
hdr_len was declared as unsigned int, a negative offset wraps to near
UINT_MAX. Patch 2 checks !skb_transport_header_was_set() and ensures
hdr_len >= 0, unifying all early fallback exits to an 'err' label at the
end of the function. Both hunks date back to commit a729b7f0bd5b
("sch_cake: Add overhead compensation support to the rate shaper").
Changes in v4:
- Patch 1: Add Acked-by: Toke Høiland-Jørgensen <toke@xxxxxxx>.
- Patch 2: Consolidate the 3 duplicate calls to cake_calc_overhead() into
a single 'err' label at the end of the function, turning early returns
into 'goto err' statements per Toke Høiland-Jørgensen review.
- Link to v3: https://lore.kernel.org/netdev/20260927131009.24250-1-ndaugoing@xxxxxxxxx/
Changes in v3:
- Split the v2 patch into a 2-patch series per Simon Horman and Sashiko
AI review so each logical fix carries its own accurate Fixes: tag and
matches proper stable tree backport ranges:
- Patch 1 Fixes: c5d34f4583ea ("net_sched: cake: use qdisc_pkt_segs()")
- Patch 2 Fixes: a729b7f0bd5b ("sch_cake: Add overhead
compensation support to the rate shaper")
- Clarify the timing and code paths where header mangling can occur
(sch_handle_egress() and cake_classify() before cake_overhead()) rather
than inaccurate "post-enqueue mangling" wording.
- Link to v2: https://lore.kernel.org/netdev/20260922084124.36858-1-ndaugoing@xxxxxxxxx/
Changes in v2:
- Accurately describe the impact as shaper accounting corruption / stall
rather than OOB read past the allocation.
- Fix integer underflow when segs == 0 by checking segs <= 1.
- Import companion check !skb_transport_header_was_set(skb) from
qdisc_pkt_len_segs_init() to prevent unset transport header sentinel
(~0U) from inflating packet length to ~66 KB.
- Link to v1: https://lore.kernel.org/netdev/20260917122153.62722-1-ndaugoing@xxxxxxxxx/
Yuchao Zhang (2):
net/sched: sch_cake: fix shaper stall on segs == 0 in cake_overhead()
net/sched: sch_cake: validate transport header offset in
cake_overhead()
net/sched/sch_cake.c | 20 +++++++++++++++-----
1 file changed, 15 insertions(+), 5 deletions(-)
--
2.53.0