| From 6db8a37dfc541e059851652cfd4f0bb13b8ff6af Mon Sep 17 00:00:00 2001 |
| From: Paolo Abeni <pabeni@redhat.com> |
| Date: Wed, 18 Oct 2023 11:23:53 -0700 |
| Subject: tcp: check mptcp-level constraints for backlog coalescing |
| |
| From: Paolo Abeni <pabeni@redhat.com> |
| |
| commit 6db8a37dfc541e059851652cfd4f0bb13b8ff6af upstream. |
| |
| The MPTCP protocol can acquire the subflow-level socket lock and |
| cause the tcp backlog usage. When inserting new skbs into the |
| backlog, the stack will try to coalesce them. |
| |
| Currently, we have no check in place to ensure that such coalescing |
| will respect the MPTCP-level DSS, and that may cause data stream |
| corruption, as reported by Christoph. |
| |
| Address the issue by adding the relevant admission check for coalescing |
| in tcp_add_backlog(). |
| |
| Note the issue is not easy to reproduce, as the MPTCP protocol tries |
| hard to avoid acquiring the subflow-level socket lock. |
| |
| Fixes: 648ef4b88673 ("mptcp: Implement MPTCP receive path") |
| Cc: stable@vger.kernel.org |
| Reported-by: Christoph Paasch <cpaasch@apple.com> |
| Closes: https://github.com/multipath-tcp/mptcp_net-next/issues/420 |
| Reviewed-by: Mat Martineau <martineau@kernel.org> |
| Signed-off-by: Paolo Abeni <pabeni@redhat.com> |
| Signed-off-by: Mat Martineau <martineau@kernel.org> |
| Link: https://lore.kernel.org/r/20231018-send-net-20231018-v1-2-17ecb002e41d@kernel.org |
| Signed-off-by: Jakub Kicinski <kuba@kernel.org> |
| Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
| --- |
| net/ipv4/tcp_ipv4.c | 1 + |
| 1 file changed, 1 insertion(+) |
| |
| --- a/net/ipv4/tcp_ipv4.c |
| +++ b/net/ipv4/tcp_ipv4.c |
| @@ -1869,6 +1869,7 @@ bool tcp_add_backlog(struct sock *sk, st |
| #ifdef CONFIG_TLS_DEVICE |
| tail->decrypted != skb->decrypted || |
| #endif |
| + !mptcp_skb_can_collapse(tail, skb) || |
| thtail->doff != th->doff || |
| memcmp(thtail + 1, th + 1, hdrlen - sizeof(*th))) |
| goto no_coalesce; |