From: "Toke Høiland-Jørgensen" <toke@toke.dk>
To: Jamal Hadi Salim <jhs@mojatatu.com>, netdev@vger.kernel.org
Cc: Jamal Hadi Salim <jhs@mojatatu.com>,
stable@vger.kernel.org, Jiri Pirko <jiri@resnulli.us>,
"David S. Miller" <davem@davemloft.net>,
Eric Dumazet <edumazet@google.com>,
Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
Simon Horman <horms@kernel.org>,
Victor Nogueira <victor@mojatatu.com>,
Johannes Berg <johannes@sipsolutions.net>,
linux-wireless@vger.kernel.org, Vega <vega@nebusec.ai>
Subject: Re: [PATCH net repost 1/2] net/sched: codel: bound the dropping loop per dequeue call
Date: Mon, 14 Sep 2026 13:36:01 +0200 [thread overview]
Message-ID: <87ld94ukta.fsf@toke.dk> (raw)
In-Reply-To: <QDISC-1L5H.v1.20260912080102@mojatatu.com>
Jamal Hadi Salim <jhs@mojatatu.com> writes:
> The CoDel control law schedules the next drop one interval/sqrt(count)
> after the previous drop, using the configured interval
> (codel_params.interval). For very small intervals the scheduled step
> rounds down to zero, so the dropping loop in codel_dequeue() never
> advances and drains the entire backlog under the qdisc lock in one
> call - an unprivileged user can trigger a soft lockup this way.
>
> Fix in the shared codel code used by both codel and fq_codel:
>
> 1. Make the control-law step at least 1 tick so the dropping loop
> always moves forward.
>
> 2. Cap the dropping loop at CODEL_MAX_DROPS_PER_DEQUEUE (256) drops
> per codel_dequeue() call, resyncing drop_next to now when the cap
> is hit: the catch-up owed to the loop grows with the idle gap and
> the backlog, which no interval threshold can bound. This is a
> deliberate behaviour change after long idle gaps.
Both of these seem reasonable!
Reviewed-by: Toke Høiland-Jørgensen <toke@toke.dk>
next prev parent reply other threads:[~2026-09-14 11:36 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-12 18:08 [PATCH net repost 1/2] net/sched: codel: bound the dropping loop per dequeue call Jamal Hadi Salim
2026-09-12 18:08 ` [PATCH net repost 2/2] selftests/tc-testing: add codel/fq_codel interval boundary cases Jamal Hadi Salim
2026-09-12 20:36 ` netdev-bot+sashiko
2026-09-12 20:36 ` [PATCH net repost 1/2] net/sched: codel: bound the dropping loop per dequeue call netdev-bot+sashiko
2026-09-13 10:27 ` Jamal Hadi Salim
2026-09-14 11:36 ` Toke Høiland-Jørgensen [this message]
2026-09-17 0:30 ` patchwork-bot+netdevbpf
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=87ld94ukta.fsf@toke.dk \
--to=toke@toke.dk \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=horms@kernel.org \
--cc=jhs@mojatatu.com \
--cc=jiri@resnulli.us \
--cc=johannes@sipsolutions.net \
--cc=kuba@kernel.org \
--cc=linux-wireless@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=stable@vger.kernel.org \
--cc=vega@nebusec.ai \
--cc=victor@mojatatu.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.