Re: [PATCH net v3 1/2] net/sched: sch_cake: fix shaper stall on segs == 0 in cake_overhead()

From: Toke Høiland-Jørgensen

Date: Mon Sep 28 2026 - 10:10:41 EST


Yuchao Zhang <ndaugoing@xxxxxxxxx> writes:

> In cake_overhead(), packets with a single segment bypass multi-segment
> overhead calculations:
>
> if (segs == 1)
> return cake_calc_overhead(q, len, off);
>
> Commit c5d34f4583ea ("net_sched: cake: use qdisc_pkt_segs()") switched
> cake to retrieve the cached segmentation count via qdisc_pkt_segs(skb)
> instead of calculating it locally for dodgy GSO packets. If an skb with
> segs == 0 reaches cake_overhead(), it skips the segs == 1 early return
> and enters the multi-segment arithmetic:
>
> len = shinfo->gso_size + hdr_len;
> last_len = skb->len - shinfo->gso_size * (segs - 1);
>
> return (cake_calc_overhead(q, len, off) * (segs - 1) +
> cake_calc_overhead(q, last_len, off));
>
> Because segs is an unsigned 16-bit integer, (segs - 1) underflows to
> 65535 (and is promoted to 4294967295 in the 32-bit unsigned arithmetic
> above). This multiplies the per-segment overhead by UINT32_MAX, so
> cake_overhead() returns a length close to 4.29 GB. cake_advance_shaper()
> then charges that length to the shaper, stalling the CAKE dequeue path
> for tens of seconds at 1 Gbit/s, and for minutes to hours at lower rates.
>
> Fix this by returning early with cake_calc_overhead(q, len, off) whenever
> segs <= 1.
>
> Fixes: c5d34f4583ea ("net_sched: cake: use qdisc_pkt_segs()")
> Cc: stable@xxxxxxxxxxxxxxx
> Signed-off-by: Yuchao Zhang <ndaugoing@xxxxxxxxx>

Acked-by: Toke Høiland-Jørgensen <toke@xxxxxxx>