From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A9829519E0C; Wed, 30 Sep 2026 17:29:45 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790789387; cv=none; b=ArD0AzsHIcnKIT3ppVYlumbYfcPUJg+MFqh5H1Av6qbCOSx2il3qwcJEOWP6FMziKXac/9q6uiufPCq7QWcTTdLkGSR+Bmkaj5Fmjv0x4D7oZyjyf2mqEn2lFhdtkcJdMth8WaPpxpr4TiZtJZ9ZZNq996SsFJasmzySllL4z1k= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790789387; c=relaxed/simple; bh=JOqw0p84XrQ5RmvnE0j4RaeY3RHIJNRSxg8yF2eF1l0=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=MrgbBhJG93Uaua70Dpe+n2sV9a2foKHnsEzwQXYDMqXfuCTxXRbcV3HiBmcudGavZ0CE3GZdBgds+nfkuF+0nmSMkvxc9+kkgdmYMmHYOsONNhFYevIbIMPTQbqRqIN5dopFaYPdcb/5L+8eUDZ9g5eVsq+PwGOzyv3ysI16ngE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=q1GwhyEP; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="q1GwhyEP" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 08DA41F00899; Wed, 30 Sep 2026 17:29:44 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790789385; bh=YJ8l9HarIZMYqqZqNc74wjgDnGiPs6Ls7ZAhZVnMI8c=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=q1GwhyEPWnhvG2qt9xV/V2wAD71XTm7n8KRzz40rKiV0GdBXMYk8OR2B/bFzJbDC4 nQK+okzUZvt6mdoGcKFtF0wu2jn1Xc5N0Vzt9P5E6SnSfwPofQ8C6KKu1kAW3qRrK2 q2jdouxjG+mkZnHygDJDJlFPUDFjhO8Yj/stXOIU= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Willem de Bruijn , Eric Dumazet , Daniel Zahka , Jakub Kicinski Subject: [PATCH 6.12 460/877] tcp: prevent collapsing skbs across boundary in rtx queue Date: Wed, 30 Sep 2026 17:22:51 +0200 Message-ID: <20260930152424.603944625@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260930152414.738996857@linuxfoundation.org> References: <20260930152414.738996857@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 6.12-stable review patch. If anyone has any objections, please let me know. ------------------ From: Willem de Bruijn commit fc6d80eb504458d6416b75a94188b268c95c6533 upstream. tcp_write_collapse_fence() sets TCP_SKB_CB(skb)->eor = 1 on tcp_write_queue_tail(sk) to prevent skbs queued after a switch to device encryption from being collapsed into earlier skbs. The fence is a no-op if all earlier data has already been transmitted when the switch happens: sk->sk_write_queue is empty. The not yet acknowledged earlier skbs wait in sk->tcp_rtx_queue with eor 0. On a subsequent retransmit or SACK shift, tcp_retrans_try_collapse() or tcp_shift_skb_data() can then merge an skb queued after the switch into one queued before it. Both users of the fence are affected: - psp: devices only encrypt skbs with skb->decrypted set. The merged skb keeps decrypted = 0 from the earlier skb, so merged data sent after psp_sock_assoc_set_tx() is retransmitted in cleartext. - tls device offload: the merged skb straddles the start marker set in tls_set_device_offload(). The software fallback (fill_sg_in() returns -EINVAL) and the mlx5, nfp and funeth drivers cannot handle such an skb and drop it. Every retransmit rebuilds the same skb, so the connection stalls. Fix this in two places, for defense in depth: 1. Fall back to tcp_rtx_queue_tail(sk) in tcp_write_collapse_fence() when tcp_write_queue_tail(sk) is NULL. 2. Check !skb_cmp_decrypted(to, from) in tcp_skb_can_collapse(), as tcp_skb_can_collapse_rx() does on receive. skb_shift(), which both collapse paths call, already has a DEBUG_NET_WARN_ON_ONCE() for this condition. Fixes: e8f69799810c ("net/tls: Add generic NIC offload infrastructure") Cc: stable@vger.kernel.org Signed-off-by: Willem de Bruijn Reviewed-by: Eric Dumazet Reviewed-by: Daniel Zahka Link: https://patch.msgid.link/20260924154427.953800-1-willemdebruijn.kernel@gmail.com Signed-off-by: Jakub Kicinski Signed-off-by: Greg Kroah-Hartman --- include/net/tcp.h | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) --- a/include/net/tcp.h +++ b/include/net/tcp.h @@ -1058,9 +1058,9 @@ static inline bool tcp_skb_can_collapse_ static inline bool tcp_skb_can_collapse(const struct sk_buff *to, const struct sk_buff *from) { - /* skb_cmp_decrypted() not needed, use tcp_write_collapse_fence() */ return likely(tcp_skb_can_collapse_to(to) && mptcp_skb_can_collapse(to, from) && + !skb_cmp_decrypted(to, from) && skb_pure_zcopy_same(to, from) && skb_frags_readable(to) == skb_frags_readable(from)); } @@ -2119,7 +2119,7 @@ static inline void tcp_rtx_queue_unlink_ static inline void tcp_write_collapse_fence(struct sock *sk) { - struct sk_buff *skb = tcp_write_queue_tail(sk); + struct sk_buff *skb = tcp_write_queue_tail(sk) ?: tcp_rtx_queue_tail(sk); if (skb) TCP_SKB_CB(skb)->eor = 1;