Re: [PATCH net] tcp: fix icsk_ack.ato bitfield overflow
From: Neal Cardwell
Date: Fri Aug 07 2026 - 13:27:33 EST
On Thu, Aug 6, 2026 at 9:45 PM Jiayuan Chen <jiayuan.chen@xxxxxxxxx> wrote:
>
> On cross-region connections we observed delayed ACKs suddenly turning
> into immediate ACKs plus a TCP_MAX_QUICKACKS burst, as if the
> connection had just received its first data segment.
>
> Commit 95b9a87c6a6b ("tcp: record last received ipv6 flowlabel")
> squeezed icsk_ack.ato into 8 bits, sized for TCP_DELACK_MAX. But both
> writers still bound ato by icsk_rto, which can be well above 255
> jiffies, so the bitfield assignment silently wraps mod 256: repeated
> delack timer misses double ato up to icsk_rto, storing 320 as 64 and
> 256 as 0, and ato == 0 is the "first data packet" sentinel in
> tcp_event_data_recv().
>
> Clamp both writers to TCP_DELACK_MAX, which the static_assert already
> guarantees to fit and tcp_send_delayed_ack() effectively caps ato at
> anyway.
>
> Fixes: 95b9a87c6a6b ("tcp: record last received ipv6 flowlabel")
> Signed-off-by: Jiayuan Chen <jiayuan.chen@xxxxxxxxx>
Reviewed-by: Neal Cardwell <ncardwell@xxxxxxxxxx>
Thanks for the fix!
neal