From: Jiayuan Chen <jiayuan.chen@linux.dev>
To: netdev@vger.kernel.org
Cc: Jiayuan Chen <jiayuan.chen@linux.dev>, VEGA <vega@nebusec.ai>,
Eric Dumazet <edumazet@google.com>,
Neal Cardwell <ncardwell@google.com>,
Kuniyuki Iwashima <kuniyu@google.com>,
"David S. Miller" <davem@davemloft.net>,
Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
Simon Horman <horms@kernel.org>,
Stephen Hemminger <stephen@networkplumber.org>,
linux-kernel@vger.kernel.org
Subject: [PATCH net-next 2/3] tcp_hybla: fix divide by zero on rtt0 == 0
Date: Wed, 30 Sep 2026 18:09:31 +0800 [thread overview]
Message-ID: <20260930100937.206377-3-jiayuan.chen@linux.dev> (raw)
In-Reply-To: <20260930100937.206377-1-jiayuan.chen@linux.dev>
rtt0 is the reference RTT in ms, so 0 makes no sense, and
hybla_recalc_param() divides by it right from hybla_init().
Reject values below 1 when the parameter is written. Also cap it at
U32_MAX / USEC_PER_MSEC, since rtt0 * USEC_PER_MSEC can wrap to 0 on
32-bit. An rtt0 above that (about 71 minutes) makes no sense anyway.
Fixes: 835b3f0c0d7e ("[TCP]: Add TCP Hybla congestion control module.")
Fixes: 740b0f1841f6 ("tcp: switch rtt estimations to usec resolution")
Reported-by: VEGA <vega@nebusec.ai>
Signed-off-by: Jiayuan Chen <jiayuan.chen@linux.dev>
---
Target net-next since it is not a big problem.
---
net/ipv4/tcp_hybla.c | 16 ++++++++++++++--
1 file changed, 14 insertions(+), 2 deletions(-)
diff --git a/net/ipv4/tcp_hybla.c b/net/ipv4/tcp_hybla.c
index abd7d91807e54..b9b482180d30b 100644
--- a/net/ipv4/tcp_hybla.c
+++ b/net/ipv4/tcp_hybla.c
@@ -26,8 +26,20 @@ struct hybla {
};
/* Hybla reference round trip time (default= 1/40 sec = 25 ms), in ms */
-static int rtt0 = 25;
-module_param(rtt0, int, 0644);
+static unsigned int rtt0 = 25;
+
+static int rtt0_set(const char *val, const struct kernel_param *kp)
+{
+ /* avoid rtt0 * USEC_PER_MSEC overflow */
+ return param_set_uint_minmax(val, kp, 1, U32_MAX / USEC_PER_MSEC);
+}
+
+static const struct kernel_param_ops rtt0_ops = {
+ .set = rtt0_set,
+ .get = param_get_uint,
+};
+
+module_param_cb(rtt0, &rtt0_ops, &rtt0, 0644);
MODULE_PARM_DESC(rtt0, "reference rout trip time (ms)");
/* This is called to refresh values for hybla parameters */
--
2.43.0
next prev parent reply other threads:[~2026-09-30 10:10 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-30 10:09 [PATCH net-next 0/3] tcp: fix a few divide-by-zero in congestion control modules Jiayuan Chen
2026-09-30 10:09 ` [PATCH net-next 1/3] tcp_bic: fix divide by zero on max_increment == 0 Jiayuan Chen
2026-09-30 11:22 ` Eric Dumazet
2026-09-30 10:09 ` Jiayuan Chen [this message]
2026-09-30 11:23 ` [PATCH net-next 2/3] tcp_hybla: fix divide by zero on rtt0 " Eric Dumazet
2026-09-30 10:09 ` [PATCH net-next 3/3] tcp_cubic: fix divide by zero and endless loop on bad module params Jiayuan Chen
2026-09-30 11:21 ` Eric Dumazet
2026-09-30 14:03 ` Jiayuan Chen
2026-10-01 13:10 ` netdev-bot+sashiko
2026-09-30 10:14 ` [PATCH net-next 0/3] tcp: fix a few divide-by-zero in congestion control modules netdev-bot+sinfo
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260930100937.206377-3-jiayuan.chen@linux.dev \
--to=jiayuan.chen@linux.dev \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=horms@kernel.org \
--cc=kuba@kernel.org \
--cc=kuniyu@google.com \
--cc=linux-kernel@vger.kernel.org \
--cc=ncardwell@google.com \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=stephen@networkplumber.org \
--cc=vega@nebusec.ai \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.