All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH v8 net-next 0/2] Explicit TSO segment count
@ 2026-08-24 16:31 chia-yu.chang
  2026-08-24 16:31 ` [PATCH v8 net-next 1/2] tcp: Replace min_tso_segs() with tso_segs() CC callback chia-yu.chang
                   ` (3 more replies)
  0 siblings, 4 replies; 10+ messages in thread
From: chia-yu.chang @ 2026-08-24 16:31 UTC (permalink / raw)
  To: john.fastabend, jakub, jiayuan.chen, netdev, bpf, ast, daniel,
	andrii, eddyz87, memxor, martin.lau, song, yonghong.song, jolsa,
	emil, linux-kselftest, shuah, horms, dsahern, pabeni, jhs, kuba,
	stephen, davem, edumazet, andrew+netdev, donald.hunter, kuniyu,
	ij, ncardwell, koen.de_schepper, g.white, ingemar.s.johansson,
	mirja.kuehlewind, cheshire, rs.ietf, Jason_Livingood, vidhi_goel,
	Mike_Rudolph, Jeff_Howe, srichard
  Cc: Chia-Yu Chang

From: Chia-Yu Chang <chia-yu.chang@nokia-bell-labs.com>

Hello,

This series replaces the existing min_tso_segs() congestion control
callback with a new tso_segs() callback that allows congestion control
algorithms to provide an explicit TSO segment count for each data burst.
 
To support BPF congestion controls, the series also exposes
tcp_tso_autosize() as a BPF kfunc, allowing BPF implementations to
reuse the kernel TSO autosizing logic while implementing custom
tso_segs() callbacks.
 
Changes since v7:
- Deprecate bbr_min_tso_segs() kfunc instead of removing it
- Add bbr_tso_segs() kfunc
- Update tso_segs() callback documentation
- Sanitize min_tso_segs in tcp_tso_autosize()
- Return the sanitized min_tso_segs value when mss_now == 0
- Update commit messages
 
Thanks,
Chia-Yu

---
Chia-Yu Chang (2):
  tcp: Replace min_tso_segs() with tso_segs() CC callback
  bpf: make tcp_tso_autosize() available to BPF congestion controls

 include/net/tcp.h                             | 15 ++++++++--
 net/ipv4/bpf_tcp_ca.c                         |  5 ++--
 net/ipv4/tcp_bbr.c                            | 12 ++++++--
 net/ipv4/tcp_output.c                         | 28 ++++++++++++-------
 .../selftests/bpf/progs/tcp_ca_kfunc.c        |  8 +++---
 5 files changed, 48 insertions(+), 20 deletions(-)

-- 
2.34.1


^ permalink raw reply	[flat|nested] 10+ messages in thread

* [PATCH v8 net-next 1/2] tcp: Replace min_tso_segs() with tso_segs() CC callback
  2026-08-24 16:31 [PATCH v8 net-next 0/2] Explicit TSO segment count chia-yu.chang
@ 2026-08-24 16:31 ` chia-yu.chang
  2026-08-24 16:31 ` [PATCH v8 net-next 2/2] bpf: make tcp_tso_autosize() available to BPF congestion controls chia-yu.chang
                   ` (2 subsequent siblings)
  3 siblings, 0 replies; 10+ messages in thread
From: chia-yu.chang @ 2026-08-24 16:31 UTC (permalink / raw)
  To: john.fastabend, jakub, jiayuan.chen, netdev, bpf, ast, daniel,
	andrii, eddyz87, memxor, martin.lau, song, yonghong.song, jolsa,
	emil, linux-kselftest, shuah, horms, dsahern, pabeni, jhs, kuba,
	stephen, davem, edumazet, andrew+netdev, donald.hunter, kuniyu,
	ij, ncardwell, koen.de_schepper, g.white, ingemar.s.johansson,
	mirja.kuehlewind, cheshire, rs.ietf, Jason_Livingood, vidhi_goel,
	Mike_Rudolph, Jeff_Howe, srichard
  Cc: Chia-Yu Chang

From: Chia-Yu Chang <chia-yu.chang@nokia-bell-labs.com>

This patch replaces the existing min_tso_segs() callback with a new
tso_segs() callback, allowing congestion control algorithms to provide
an explicit TSO segment count for each data burst and bypass
tcp_tso_autosize(). The resulting tso_segs value is clamped to
[1, sk->sk_gso_max_segs], preventing congestion-control implementations
from returning an invalid zero-segment value.

This change has the following impacts on BPF struct_ops users:
- The callback is renamed from min_tso_segs() to tso_segs()
- The signature gains an extra u32 mss_now argument
- The return value semantics is changed from "floor value passed into
  tcp_tso_autosize()" to "final tso_segs value", bypassing autosizing

As a result, existing BPF programs must be updated, because returning a
small constant will now directly limit the final tso_segs value instead
of specifying the minimum value passed to tcp_tso_autosize().

Signed-off-by: Chia-Yu Chang <chia-yu.chang@nokia-bell-labs.com>
Signed-off-by: Ilpo Järvinen <ij@kernel.org>
Reviewed-by: Emil Tsalapatis <emil@etsalapatis.com>

---
v8:
- Deprecate bbr_min_tso_segs() kfunc instead of removing it
- Add bbr_tso_segs() kfunc
- Update tso_segs() callback documentation
- Document tso_segs value clamping
- Update commit messages

v7:
- Update the comments for tso_segs()
- Restore bpf_tcp_ca_tso_segs() to return 0
- Move READ_ONCE() to the else branch if ca_ops->tso_segs() is undefined
- Update tcp_tso_autosize() to use EXPORT_SYMBOL_GPL

v6:
- Add clamp_t to avoid returning 0 by ca_ops->tso_segs()
- Update commit message

v5:
- Revert back to v3 and add Reviewed-by tag

v4:
- Use union for both min_tso_segs() and tso_segs() and a

v3:
- Update bpf_tcp_ca_tso_segs() to use tcp_tso_autosize()
- Add divide by 0 protection in case of mss_now=0

v2:
- Export tcp_tso_autosize()
---
 include/net/tcp.h                              | 15 +++++++++++++--
 net/ipv4/bpf_tcp_ca.c                          |  4 ++--
 net/ipv4/tcp_bbr.c                             | 12 ++++++++++--
 net/ipv4/tcp_output.c                          | 18 +++++++++---------
 .../testing/selftests/bpf/progs/tcp_ca_kfunc.c |  8 ++++----
 5 files changed, 38 insertions(+), 19 deletions(-)

diff --git a/include/net/tcp.h b/include/net/tcp.h
index 2c5b889530b5..7ae91e59dd6b 100644
--- a/include/net/tcp.h
+++ b/include/net/tcp.h
@@ -824,6 +824,9 @@ unsigned int tcp_sync_mss(struct sock *sk, u32 pmtu);
 unsigned int tcp_current_mss(struct sock *sk);
 u32 tcp_clamp_probe0_to_user_timeout(const struct sock *sk, u32 when);
 
+u32 tcp_tso_autosize(const struct sock *sk, unsigned int mss_now,
+		     int min_tso_segs);
+
 /* Bound MSS / TSO packet size with the half of the window */
 static inline int tcp_bound_to_half_wnd(struct tcp_sock *tp, int pktsize)
 {
@@ -1361,8 +1364,16 @@ struct tcp_congestion_ops {
 	/* hook for packet ack accounting (optional) */
 	void (*pkts_acked)(struct sock *sk, const struct ack_sample *sample);
 
-	/* override sysctl_tcp_min_tso_segs (optional) */
-	u32 (*min_tso_segs)(struct sock *sk);
+	/* Override tcp_tso_autosize() (optional)
+	 *
+	 * If provided, this callback supplies the TSO segment target count
+	 * instead of using tcp_tso_autosize(). The returned value is
+	 * subsequently clamped to [1, sk->sk_gso_max_segs] by the caller.
+	 *
+	 * For the kernel callback path, mss_now originates from
+	 * tcp_current_mss() and should never be zero.
+	 */
+	u32 (*tso_segs)(struct sock *sk, u32 mss_now);
 
 	/* new value of cwnd after loss (required) */
 	u32  (*undo_cwnd)(struct sock *sk);
diff --git a/net/ipv4/bpf_tcp_ca.c b/net/ipv4/bpf_tcp_ca.c
index 791e15063237..ed4fea98dfde 100644
--- a/net/ipv4/bpf_tcp_ca.c
+++ b/net/ipv4/bpf_tcp_ca.c
@@ -284,7 +284,7 @@ static void bpf_tcp_ca_pkts_acked(struct sock *sk, const struct ack_sample *samp
 {
 }
 
-static u32 bpf_tcp_ca_min_tso_segs(struct sock *sk)
+static u32 bpf_tcp_ca_tso_segs(struct sock *sk, u32 mss_now)
 {
 	return 0;
 }
@@ -320,7 +320,7 @@ static struct tcp_congestion_ops __bpf_ops_tcp_congestion_ops = {
 	.cwnd_event_tx_start = bpf_tcp_ca_cwnd_event_tx_start,
 	.in_ack_event = bpf_tcp_ca_in_ack_event,
 	.pkts_acked = bpf_tcp_ca_pkts_acked,
-	.min_tso_segs = bpf_tcp_ca_min_tso_segs,
+	.tso_segs = bpf_tcp_ca_tso_segs,
 	.cong_control = bpf_tcp_ca_cong_control,
 	.undo_cwnd = bpf_tcp_ca_undo_cwnd,
 	.sndbuf_expand = bpf_tcp_ca_sndbuf_expand,
diff --git a/net/ipv4/tcp_bbr.c b/net/ipv4/tcp_bbr.c
index 82378a2bfd1e..c92d904b13be 100644
--- a/net/ipv4/tcp_bbr.c
+++ b/net/ipv4/tcp_bbr.c
@@ -302,6 +302,13 @@ __bpf_kfunc static u32 bbr_min_tso_segs(struct sock *sk)
 	return READ_ONCE(sk->sk_pacing_rate) < (bbr_min_tso_rate >> 3) ? 1 : 2;
 }
 
+__bpf_kfunc static u32 bbr_tso_segs(struct sock *sk, u32 mss_now)
+{
+	if (unlikely(!mss_now))
+		return bbr_min_tso_segs(sk);
+	return tcp_tso_autosize(sk, mss_now, bbr_min_tso_segs(sk));
+}
+
 static u32 bbr_tso_segs_goal(struct sock *sk)
 {
 	struct tcp_sock *tp = tcp_sk(sk);
@@ -1151,7 +1158,7 @@ static struct tcp_congestion_ops tcp_bbr_cong_ops __read_mostly = {
 	.undo_cwnd	= bbr_undo_cwnd,
 	.cwnd_event_tx_start	= bbr_cwnd_event_tx_start,
 	.ssthresh	= bbr_ssthresh,
-	.min_tso_segs	= bbr_min_tso_segs,
+	.tso_segs	= bbr_tso_segs,
 	.get_info	= bbr_get_info,
 	.set_state	= bbr_set_state,
 };
@@ -1163,7 +1170,8 @@ BTF_ID_FLAGS(func, bbr_sndbuf_expand)
 BTF_ID_FLAGS(func, bbr_undo_cwnd)
 BTF_ID_FLAGS(func, bbr_cwnd_event_tx_start)
 BTF_ID_FLAGS(func, bbr_ssthresh)
-BTF_ID_FLAGS(func, bbr_min_tso_segs)
+BTF_ID_FLAGS(func, bbr_min_tso_segs, KF_DEPRECATED)
+BTF_ID_FLAGS(func, bbr_tso_segs)
 BTF_ID_FLAGS(func, bbr_set_state)
 BTF_KFUNCS_END(tcp_bbr_check_kfunc_ids)
 
diff --git a/net/ipv4/tcp_output.c b/net/ipv4/tcp_output.c
index fcaa04e65189..7d3e0e715c4b 100644
--- a/net/ipv4/tcp_output.c
+++ b/net/ipv4/tcp_output.c
@@ -2253,8 +2253,8 @@ static bool tcp_nagle_check(bool partial, const struct tcp_sock *tp,
  * for every 2^9 usec (aka 512 us) of RTT, so that the RTT-based allowance
  * is below 1500 bytes after 6 * ~500 usec = 3ms.
  */
-static u32 tcp_tso_autosize(const struct sock *sk, unsigned int mss_now,
-			    int min_tso_segs)
+u32 tcp_tso_autosize(const struct sock *sk, unsigned int mss_now,
+		     int min_tso_segs)
 {
 	unsigned long bytes;
 	u32 r;
@@ -2269,6 +2269,7 @@ static u32 tcp_tso_autosize(const struct sock *sk, unsigned int mss_now,
 
 	return max_t(u32, bytes / mss_now, min_tso_segs);
 }
+EXPORT_SYMBOL_GPL(tcp_tso_autosize);
 
 /* Return the number of segments we want in the skb we are transmitting.
  * See if congestion control module wants to decide; otherwise, autosize.
@@ -2276,14 +2277,13 @@ static u32 tcp_tso_autosize(const struct sock *sk, unsigned int mss_now,
 static u32 tcp_tso_segs(struct sock *sk, unsigned int mss_now)
 {
 	const struct tcp_congestion_ops *ca_ops = inet_csk(sk)->icsk_ca_ops;
-	u32 min_tso, tso_segs;
+	u32 tso_segs;
 
-	min_tso = ca_ops->min_tso_segs ?
-			ca_ops->min_tso_segs(sk) :
-			READ_ONCE(sock_net(sk)->ipv4.sysctl_tcp_min_tso_segs);
-
-	tso_segs = tcp_tso_autosize(sk, mss_now, min_tso);
-	return min_t(u32, tso_segs, sk->sk_gso_max_segs);
+	tso_segs = ca_ops->tso_segs ?
+			ca_ops->tso_segs(sk, mss_now) :
+			tcp_tso_autosize(sk, mss_now,
+					 READ_ONCE(sock_net(sk)->ipv4.sysctl_tcp_min_tso_segs));
+	return clamp_t(u32, tso_segs, 1, sk->sk_gso_max_segs);
 }
 
 /* Returns the portion of skb which can be sent right away */
diff --git a/tools/testing/selftests/bpf/progs/tcp_ca_kfunc.c b/tools/testing/selftests/bpf/progs/tcp_ca_kfunc.c
index 0a3e9d35bf6f..58262e490336 100644
--- a/tools/testing/selftests/bpf/progs/tcp_ca_kfunc.c
+++ b/tools/testing/selftests/bpf/progs/tcp_ca_kfunc.c
@@ -10,7 +10,7 @@ extern u32 bbr_sndbuf_expand(struct sock *sk) __ksym;
 extern u32 bbr_undo_cwnd(struct sock *sk) __ksym;
 extern void bbr_cwnd_event_tx_start(struct sock *sk) __ksym;
 extern u32 bbr_ssthresh(struct sock *sk) __ksym;
-extern u32 bbr_min_tso_segs(struct sock *sk) __ksym;
+extern u32 bbr_tso_segs(struct sock *sk, u32 mss_now) __ksym;
 extern void bbr_set_state(struct sock *sk, u8 new_state) __ksym;
 
 extern void dctcp_init(struct sock *sk) __ksym;
@@ -90,9 +90,9 @@ u32 BPF_PROG(ssthresh, struct sock *sk)
 }
 
 SEC("struct_ops")
-u32 BPF_PROG(min_tso_segs, struct sock *sk)
+u32 BPF_PROG(tso_segs, struct sock *sk, u32 mss_now)
 {
-	return bbr_min_tso_segs(sk);
+	return bbr_tso_segs(sk, mss_now);
 }
 
 SEC("struct_ops")
@@ -120,7 +120,7 @@ struct tcp_congestion_ops tcp_ca_kfunc = {
 	.cwnd_event	= (void *)cwnd_event,
 	.cwnd_event_tx_start = (void *)cwnd_event_tx_start,
 	.ssthresh	= (void *)ssthresh,
-	.min_tso_segs	= (void *)min_tso_segs,
+	.tso_segs	= (void *)tso_segs,
 	.set_state	= (void *)set_state,
 	.pkts_acked     = (void *)pkts_acked,
 	.name		= "tcp_ca_kfunc",
-- 
2.34.1


^ permalink raw reply related	[flat|nested] 10+ messages in thread

* [PATCH v8 net-next 2/2] bpf: make tcp_tso_autosize() available to BPF congestion controls
  2026-08-24 16:31 [PATCH v8 net-next 0/2] Explicit TSO segment count chia-yu.chang
  2026-08-24 16:31 ` [PATCH v8 net-next 1/2] tcp: Replace min_tso_segs() with tso_segs() CC callback chia-yu.chang
@ 2026-08-24 16:31 ` chia-yu.chang
  2026-08-25 16:31   ` sashiko-bot
  2026-08-24 18:08 ` [PATCH v8 net-next 0/2] Explicit TSO segment count Jakub Kicinski
  2026-08-24 20:05 ` Jakub Kicinski
  3 siblings, 1 reply; 10+ messages in thread
From: chia-yu.chang @ 2026-08-24 16:31 UTC (permalink / raw)
  To: john.fastabend, jakub, jiayuan.chen, netdev, bpf, ast, daniel,
	andrii, eddyz87, memxor, martin.lau, song, yonghong.song, jolsa,
	emil, linux-kselftest, shuah, horms, dsahern, pabeni, jhs, kuba,
	stephen, davem, edumazet, andrew+netdev, donald.hunter, kuniyu,
	ij, ncardwell, koen.de_schepper, g.white, ingemar.s.johansson,
	mirja.kuehlewind, cheshire, rs.ietf, Jason_Livingood, vidhi_goel,
	Mike_Rudolph, Jeff_Howe, srichard
  Cc: Chia-Yu Chang

From: Chia-Yu Chang <chia-yu.chang@nokia-bell-labs.com>

Expose tcp_tso_autosize() as a BPF kfunc and register it in the TCP
congestion-control kfunc set. This allows BPF congestion controls to
reuse the kernel TSO autosizing logic while applying their own
minimum TSO segment policy.

To make the kfunc robust against BPF-provided inputs, min_tso_segs is
sanitized to at least 1 and mss_now == 0 returns the sanitized minimum
value instead of performing autosizing.

Signed-off-by: Chia-Yu Chang <chia-yu.chang@nokia-bell-labs.com>

--
v8:
- Sanitize min_tso_segs in tcp_tso_autosize()
- Return sanitized min_tso_segs when mss_now == 0
- Update commit messages
---
 net/ipv4/bpf_tcp_ca.c |  1 +
 net/ipv4/tcp_output.c | 14 +++++++++++---
 2 files changed, 12 insertions(+), 3 deletions(-)

diff --git a/net/ipv4/bpf_tcp_ca.c b/net/ipv4/bpf_tcp_ca.c
index ed4fea98dfde..9deed2244c2d 100644
--- a/net/ipv4/bpf_tcp_ca.c
+++ b/net/ipv4/bpf_tcp_ca.c
@@ -194,6 +194,7 @@ BTF_ID_FLAGS(func, tcp_reno_cong_avoid)
 BTF_ID_FLAGS(func, tcp_reno_undo_cwnd)
 BTF_ID_FLAGS(func, tcp_slow_start)
 BTF_ID_FLAGS(func, tcp_cong_avoid_ai)
+BTF_ID_FLAGS(func, tcp_tso_autosize)
 BTF_KFUNCS_END(bpf_tcp_ca_check_kfunc_ids)
 
 static const struct btf_kfunc_id_set bpf_tcp_ca_kfunc_set = {
diff --git a/net/ipv4/tcp_output.c b/net/ipv4/tcp_output.c
index 7d3e0e715c4b..a98036bcd987 100644
--- a/net/ipv4/tcp_output.c
+++ b/net/ipv4/tcp_output.c
@@ -2252,13 +2252,21 @@ static bool tcp_nagle_check(bool partial, const struct tcp_sock *tp,
  * in bigger TSO bursts. We we cut the RTT-based allowance in half
  * for every 2^9 usec (aka 512 us) of RTT, so that the RTT-based allowance
  * is below 1500 bytes after 6 * ~500 usec = 3ms.
+ *
+ * The min_tso_segs is floored to 1 to avoid surprising conversion. Also,
+ * BPF callers may pass mss_now == 0. In that case the function returns the
+ * sanitized min_tso_segs value and skips autosizing.
  */
-u32 tcp_tso_autosize(const struct sock *sk, unsigned int mss_now,
-		     int min_tso_segs)
+__bpf_kfunc u32 tcp_tso_autosize(const struct sock *sk, unsigned int mss_now,
+				 int min_tso_segs)
 {
+	u32 min_tso = max(min_tso_segs, 1);
 	unsigned long bytes;
 	u32 r;
 
+	if (unlikely(!mss_now))
+		return min_tso;
+
 	bytes = READ_ONCE(sk->sk_pacing_rate) >> READ_ONCE(sk->sk_pacing_shift);
 
 	r = tcp_min_rtt(tcp_sk(sk)) >> READ_ONCE(sock_net(sk)->ipv4.sysctl_tcp_tso_rtt_log);
@@ -2267,7 +2275,7 @@ u32 tcp_tso_autosize(const struct sock *sk, unsigned int mss_now,
 
 	bytes = min_t(unsigned long, bytes, sk->sk_gso_max_size);
 
-	return max_t(u32, bytes / mss_now, min_tso_segs);
+	return max_t(u32, bytes / mss_now, min_tso);
 }
 EXPORT_SYMBOL_GPL(tcp_tso_autosize);
 
-- 
2.34.1


^ permalink raw reply related	[flat|nested] 10+ messages in thread

* Re: [PATCH v8 net-next 0/2] Explicit TSO segment count
  2026-08-24 16:31 [PATCH v8 net-next 0/2] Explicit TSO segment count chia-yu.chang
  2026-08-24 16:31 ` [PATCH v8 net-next 1/2] tcp: Replace min_tso_segs() with tso_segs() CC callback chia-yu.chang
  2026-08-24 16:31 ` [PATCH v8 net-next 2/2] bpf: make tcp_tso_autosize() available to BPF congestion controls chia-yu.chang
@ 2026-08-24 18:08 ` Jakub Kicinski
  2026-08-24 20:05 ` Jakub Kicinski
  3 siblings, 0 replies; 10+ messages in thread
From: Jakub Kicinski @ 2026-08-24 18:08 UTC (permalink / raw)
  To: chia-yu.chang
  Cc: john.fastabend, jakub, jiayuan.chen, netdev, bpf, ast, daniel,
	andrii, eddyz87, memxor, martin.lau, song, yonghong.song, jolsa,
	emil, linux-kselftest, shuah, horms, dsahern, pabeni, jhs,
	stephen, davem, edumazet, andrew+netdev, donald.hunter, kuniyu,
	ij, ncardwell, koen.de_schepper, g.white, ingemar.s.johansson,
	mirja.kuehlewind, cheshire, rs.ietf, Jason_Livingood, vidhi_goel,
	Mike_Rudolph, Jeff_Howe, srichard

On Mon, 24 Aug 2026 18:31:37 +0200 chia-yu.chang@nokia-bell-labs.com
wrote:
> Subject: [PATCH v8 net-next 0/2] Explicit TSO segment count

## Form letter - net-next-closed

net-next pull request for v7.3 has already been merged, and therefore
the net-next tree is closed for new drivers, features, code refactoring
and optimizations. We are currently accepting bug fixes only.

Please repost when net-next reopens after Aug 31st.

RFC patches sent for review only are obviously welcome at any time.

See: https://www.kernel.org/doc/html/next/process/maintainer-netdev.html#development-cycle
-- 
pw-bot: defer
pv-bot: closed

^ permalink raw reply	[flat|nested] 10+ messages in thread

* Re: [PATCH v8 net-next 0/2] Explicit TSO segment count
  2026-08-24 16:31 [PATCH v8 net-next 0/2] Explicit TSO segment count chia-yu.chang
                   ` (2 preceding siblings ...)
  2026-08-24 18:08 ` [PATCH v8 net-next 0/2] Explicit TSO segment count Jakub Kicinski
@ 2026-08-24 20:05 ` Jakub Kicinski
  2026-08-24 20:09   ` Kumar Kartikeya Dwivedi
  3 siblings, 1 reply; 10+ messages in thread
From: Jakub Kicinski @ 2026-08-24 20:05 UTC (permalink / raw)
  To: chia-yu.chang
  Cc: john.fastabend, jakub, jiayuan.chen, netdev, bpf, ast, daniel,
	andrii, eddyz87, memxor, martin.lau, song, yonghong.song, jolsa,
	emil, linux-kselftest, shuah, horms, dsahern, pabeni, jhs,
	stephen, davem, edumazet, andrew+netdev, donald.hunter, kuniyu,
	ij, ncardwell, koen.de_schepper, g.white, ingemar.s.johansson,
	mirja.kuehlewind, cheshire, rs.ietf, Jason_Livingood, vidhi_goel,
	Mike_Rudolph, Jeff_Howe, srichard

On Mon, 24 Aug 2026 18:31:37 +0200 chia-yu.chang@nokia-bell-labs.com
wrote:
> From: Chia-Yu Chang <chia-yu.chang@nokia-bell-labs.com>
> 
> Hello,
> 
> This series replaces the existing min_tso_segs() congestion control
> callback with a new tso_segs() callback that allows congestion control
> algorithms to provide an explicit TSO segment count for each data burst.
>  
> To support BPF congestion controls, the series also exposes
> tcp_tso_autosize() as a BPF kfunc, allowing BPF implementations to
> reuse the kernel TSO autosizing logic while implementing custom
> tso_segs() callbacks.

AI CI says:

The bpf-ci build jobs are failing for this patch on all tested
architectures/toolchains (x86-64 gcc-15, x86-64 llvm-21, aarch64 gcc-15,
s390x gcc-15), all with the same link-time error:

  net/ipv4/tcp_bbr.o: in function `__BTF_ID__set8__tcp_bbr_check_kfunc_ids':
  tcp_bbr.c:(.BTF_ids+0x...): undefined reference to `KF_DEPRECATED'

This comes from the change to net/ipv4/tcp_bbr.c that marks the retained
bbr_min_tso_segs() kfunc entry with the KF_DEPRECATED flag:

  BTF_ID_FLAGS(func, bbr_min_tso_segs, KF_DEPRECATED)
  BTF_ID_FLAGS(func, bbr_tso_segs)

KF_DEPRECATED does not resolve to a usable symbol/flag in this tree, so
the BTF id set for tcp_bbr fails to link into vmlinux on every
architecture and toolchain -- it's a straight undefined-reference error,
not a per-arch/per-config issue.

Could you drop the KF_DEPRECATED flag (or use a flag that this kfunc
infrastructure actually defines) on bbr_min_tso_segs, and re-verify that
the kernel links cleanly? A local `make net/ipv4/tcp_bbr.o vmlinux`
build (or the bpf-ci selftest build job) should reproduce this quickly.

Full build log for reference:

  ld.lld-21: error: undefined symbol: KF_DEPRECATED
  >>> referenced by usercopy_64.c
  >>>               vmlinux.o:(__BTF_ID__set8__tcp_bbr_check_kfunc_ids)  

^ permalink raw reply	[flat|nested] 10+ messages in thread

* Re: [PATCH v8 net-next 0/2] Explicit TSO segment count
  2026-08-24 20:05 ` Jakub Kicinski
@ 2026-08-24 20:09   ` Kumar Kartikeya Dwivedi
  2026-08-24 20:21     ` Chia-Yu Chang (Nokia)
  0 siblings, 1 reply; 10+ messages in thread
From: Kumar Kartikeya Dwivedi @ 2026-08-24 20:09 UTC (permalink / raw)
  To: Jakub Kicinski, chia-yu.chang
  Cc: john.fastabend, jakub, jiayuan.chen, netdev, bpf, ast, daniel,
	andrii, eddyz87, martin.lau, song, yonghong.song, jolsa, emil,
	linux-kselftest, shuah, horms, dsahern, pabeni, jhs, stephen,
	davem, edumazet, andrew+netdev, donald.hunter, kuniyu, ij,
	ncardwell, koen.de_schepper, g.white, ingemar.s.johansson,
	mirja.kuehlewind, cheshire, rs.ietf, Jason_Livingood, vidhi_goel,
	Mike_Rudolph, Jeff_Howe, srichard

On Mon Aug 24, 2026 at 10:05 PM CEST, Jakub Kicinski wrote:
> On Mon, 24 Aug 2026 18:31:37 +0200 chia-yu.chang@nokia-bell-labs.com
> wrote:
>> From: Chia-Yu Chang <chia-yu.chang@nokia-bell-labs.com>
>>
>> Hello,
>>
>> This series replaces the existing min_tso_segs() congestion control
>> callback with a new tso_segs() callback that allows congestion control
>> algorithms to provide an explicit TSO segment count for each data burst.
>>  
>> To support BPF congestion controls, the series also exposes
>> tcp_tso_autosize() as a BPF kfunc, allowing BPF implementations to
>> reuse the kernel TSO autosizing logic while implementing custom
>> tso_segs() callbacks.
>
> AI CI says:
>
> The bpf-ci build jobs are failing for this patch on all tested
> architectures/toolchains (x86-64 gcc-15, x86-64 llvm-21, aarch64 gcc-15,
> s390x gcc-15), all with the same link-time error:
>
>   net/ipv4/tcp_bbr.o: in function `__BTF_ID__set8__tcp_bbr_check_kfunc_ids':
>   tcp_bbr.c:(.BTF_ids+0x...): undefined reference to `KF_DEPRECATED'
>
> This comes from the change to net/ipv4/tcp_bbr.c that marks the retained
> bbr_min_tso_segs() kfunc entry with the KF_DEPRECATED flag:
>
>   BTF_ID_FLAGS(func, bbr_min_tso_segs, KF_DEPRECATED)
>   BTF_ID_FLAGS(func, bbr_tso_segs)
>
> KF_DEPRECATED does not resolve to a usable symbol/flag in this tree, so
> the BTF id set for tcp_bbr fails to link into vmlinux on every
> architecture and toolchain -- it's a straight undefined-reference error,
> not a per-arch/per-config issue.
>
> Could you drop the KF_DEPRECATED flag (or use a flag that this kfunc
> infrastructure actually defines) on bbr_min_tso_segs, and re-verify that
> the kernel links cleanly? A local `make net/ipv4/tcp_bbr.o vmlinux`
> build (or the bpf-ci selftest build job) should reproduce this quickly.
>
> Full build log for reference:
>
>   ld.lld-21: error: undefined symbol: KF_DEPRECATED
>   >>> referenced by usercopy_64.c
>   >>>               vmlinux.o:(__BTF_ID__set8__tcp_bbr_check_kfunc_ids)

I think Chia-Yu's AI is hallucinating, it was a proposed flag but not added yet...


^ permalink raw reply	[flat|nested] 10+ messages in thread

* RE: [PATCH v8 net-next 0/2] Explicit TSO segment count
  2026-08-24 20:09   ` Kumar Kartikeya Dwivedi
@ 2026-08-24 20:21     ` Chia-Yu Chang (Nokia)
  2026-08-24 20:26       ` Kumar Kartikeya Dwivedi
  0 siblings, 1 reply; 10+ messages in thread
From: Chia-Yu Chang (Nokia) @ 2026-08-24 20:21 UTC (permalink / raw)
  To: Kumar Kartikeya Dwivedi, Jakub Kicinski
  Cc: john.fastabend@gmail.com, jakub@cloudflare.com,
	jiayuan.chen@linux.dev, netdev@vger.kernel.org,
	bpf@vger.kernel.org, ast@kernel.org, daniel@iogearbox.net,
	andrii@kernel.org, eddyz87@gmail.com, martin.lau@linux.dev,
	song@kernel.org, yonghong.song@linux.dev, jolsa@kernel.org,
	emil@etsalapatis.com, linux-kselftest@vger.kernel.org,
	shuah@kernel.org, horms@kernel.org, dsahern@kernel.org,
	pabeni@redhat.com, jhs@mojatatu.com, stephen@networkplumber.org,
	davem@davemloft.net, edumazet@google.com, andrew+netdev@lunn.ch,
	donald.hunter@gmail.com, kuniyu@google.com, ij@kernel.org,
	ncardwell@google.com, Koen De Schepper (Nokia),
	g.white@cablelabs.com, ingemar.s.johansson@ericsson.com,
	mirja.kuehlewind@ericsson.com, cheshire@apple.com, rs.ietf@gmx.at,
	Jason_Livingood@comcast.com, vidhi_goel@apple.com,
	Mike_Rudolph@comcast.com, Jeff_Howe@comcast.com,
	srichard@netapp.com

> -----Original Message-----
> From: Kumar Kartikeya Dwivedi <memxor@gmail.com> 
> Sent: Monday, August 24, 2026 10:10 PM
> To: Jakub Kicinski <kuba@kernel.org>; Chia-Yu Chang (Nokia) <chia-yu.chang@nokia-bell-labs.com>
> Cc: john.fastabend@gmail.com; jakub@cloudflare.com; jiayuan.chen@linux.dev; netdev@vger.kernel.org; bpf@vger.kernel.org; ast@kernel.org; daniel@iogearbox.net; andrii@kernel.org; eddyz87@gmail.com; martin.lau@linux.dev; song@kernel.org; yonghong.song@linux.dev; jolsa@kernel.org; emil@etsalapatis.com; linux-kselftest@vger.kernel.org; shuah@kernel.org; horms@kernel.org; dsahern@kernel.org; pabeni@redhat.com; jhs@mojatatu.com; stephen@networkplumber.org; davem@davemloft.net; edumazet@google.com; andrew+netdev@lunn.ch; donald.hunter@gmail.com; kuniyu@google.com; ij@kernel.org; ncardwell@google.com; Koen De Schepper (Nokia) <koen.de_schepper@nokia-bell-labs.com>; g.white@cablelabs.com; ingemar.s.johansson@ericsson.com; mirja.kuehlewind@ericsson.com; cheshire@apple.com; rs.ietf@gmx.at; Jason_Livingood@comcast.com; vidhi_goel@apple.com; Mike_Rudolph@comcast.com; Jeff_Howe@comcast.com; srichard@netapp.com
> Subject: Re: [PATCH v8 net-next 0/2] Explicit TSO segment count
> 
> 
> CAUTION: This is an external email. Please be very careful when clicking links or opening attachments. See the URL nok.it/ext for additional information.
> 
> 
> 
> On Mon Aug 24, 2026 at 10:05 PM CEST, Jakub Kicinski wrote:
> > On Mon, 24 Aug 2026 18:31:37 +0200 chia-yu.chang@nokia-bell-labs.com
> > wrote:
> >> From: Chia-Yu Chang <chia-yu.chang@nokia-bell-labs.com>
> >>
> >> Hello,
> >>
> >> This series replaces the existing min_tso_segs() congestion control 
> >> callback with a new tso_segs() callback that allows congestion 
> >> control algorithms to provide an explicit TSO segment count for each data burst.
> >>
> >> To support BPF congestion controls, the series also exposes
> >> tcp_tso_autosize() as a BPF kfunc, allowing BPF implementations to 
> >> reuse the kernel TSO autosizing logic while implementing custom
> >> tso_segs() callbacks.
> >
> > AI CI says:
> >
> > The bpf-ci build jobs are failing for this patch on all tested 
> > architectures/toolchains (x86-64 gcc-15, x86-64 llvm-21, aarch64 
> > gcc-15, s390x gcc-15), all with the same link-time error:
> >
> >   net/ipv4/tcp_bbr.o: in function `__BTF_ID__set8__tcp_bbr_check_kfunc_ids':
> >   tcp_bbr.c:(.BTF_ids+0x...): undefined reference to `KF_DEPRECATED'
> >
> > This comes from the change to net/ipv4/tcp_bbr.c that marks the 
> > retained
> > bbr_min_tso_segs() kfunc entry with the KF_DEPRECATED flag:
> >
> >   BTF_ID_FLAGS(func, bbr_min_tso_segs, KF_DEPRECATED)
> >   BTF_ID_FLAGS(func, bbr_tso_segs)
> >
> > KF_DEPRECATED does not resolve to a usable symbol/flag in this tree, 
> > so the BTF id set for tcp_bbr fails to link into vmlinux on every 
> > architecture and toolchain -- it's a straight undefined-reference 
> > error, not a per-arch/per-config issue.
> >
> > Could you drop the KF_DEPRECATED flag (or use a flag that this kfunc 
> > infrastructure actually defines) on bbr_min_tso_segs, and re-verify 
> > that the kernel links cleanly? A local `make net/ipv4/tcp_bbr.o 
> > vmlinux` build (or the bpf-ci selftest build job) should reproduce this quickly.
> >
> > Full build log for reference:
> >
> >   ld.lld-21: error: undefined symbol: KF_DEPRECATED
> >   >>> referenced by usercopy_64.c
> >   >>>               vmlinux.o:(__BTF_ID__set8__tcp_bbr_check_kfunc_ids)
> 
> I think Chia-Yu's AI is hallucinating, it was a proposed flag but not added yet...

Hi Kumar and Kuba,

I will drop it in the next version; however, this AI hallucination is from Sashiko's feedback I got:

https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260814173034.749151-1-chia-yu.chang%40nokia-bell-labs.com

BTW, any BPF-related flag is suggested to be added for graceful degradation?

Thanks.
Chia-Yu

^ permalink raw reply	[flat|nested] 10+ messages in thread

* Re: [PATCH v8 net-next 0/2] Explicit TSO segment count
  2026-08-24 20:21     ` Chia-Yu Chang (Nokia)
@ 2026-08-24 20:26       ` Kumar Kartikeya Dwivedi
  0 siblings, 0 replies; 10+ messages in thread
From: Kumar Kartikeya Dwivedi @ 2026-08-24 20:26 UTC (permalink / raw)
  To: Chia-Yu Chang (Nokia), Jakub Kicinski
  Cc: john.fastabend@gmail.com, jakub@cloudflare.com,
	jiayuan.chen@linux.dev, netdev@vger.kernel.org,
	bpf@vger.kernel.org, ast@kernel.org, daniel@iogearbox.net,
	andrii@kernel.org, eddyz87@gmail.com, martin.lau@linux.dev,
	song@kernel.org, yonghong.song@linux.dev, jolsa@kernel.org,
	emil@etsalapatis.com, linux-kselftest@vger.kernel.org,
	shuah@kernel.org, horms@kernel.org, dsahern@kernel.org,
	pabeni@redhat.com, jhs@mojatatu.com, stephen@networkplumber.org,
	davem@davemloft.net, edumazet@google.com, andrew+netdev@lunn.ch,
	donald.hunter@gmail.com, kuniyu@google.com, ij@kernel.org,
	ncardwell@google.com, Koen De Schepper (Nokia),
	g.white@cablelabs.com, ingemar.s.johansson@ericsson.com,
	mirja.kuehlewind@ericsson.com, cheshire@apple.com, rs.ietf@gmx.at,
	Jason_Livingood@comcast.com, vidhi_goel@apple.com,
	Mike_Rudolph@comcast.com, Jeff_Howe@comcast.com,
	srichard@netapp.com

On Mon Aug 24, 2026 at 10:21 PM CEST, Chia-Yu Chang (Nokia) wrote:
>> -----Original Message-----
>> From: Kumar Kartikeya Dwivedi <memxor@gmail.com>
>> Sent: Monday, August 24, 2026 10:10 PM
>> To: Jakub Kicinski <kuba@kernel.org>; Chia-Yu Chang (Nokia) <chia-yu.chang@nokia-bell-labs.com>
>> Cc: john.fastabend@gmail.com; jakub@cloudflare.com; jiayuan.chen@linux.dev; netdev@vger.kernel.org; bpf@vger.kernel.org; ast@kernel.org; daniel@iogearbox.net; andrii@kernel.org; eddyz87@gmail.com; martin.lau@linux.dev; song@kernel.org; yonghong.song@linux.dev; jolsa@kernel.org; emil@etsalapatis.com; linux-kselftest@vger.kernel.org; shuah@kernel.org; horms@kernel.org; dsahern@kernel.org; pabeni@redhat.com; jhs@mojatatu.com; stephen@networkplumber.org; davem@davemloft.net; edumazet@google.com; andrew+netdev@lunn.ch; donald.hunter@gmail.com; kuniyu@google.com; ij@kernel.org; ncardwell@google.com; Koen De Schepper (Nokia) <koen.de_schepper@nokia-bell-labs.com>; g.white@cablelabs.com; ingemar.s.johansson@ericsson.com; mirja.kuehlewind@ericsson.com; cheshire@apple.com; rs.ietf@gmx.at; Jason_Livingood@comcast.com; vidhi_goel@apple.com; Mike_Rudolph@comcast.com; Jeff_Howe@comcast.com; srichard@netapp.com
>> Subject: Re: [PATCH v8 net-next 0/2] Explicit TSO segment count
>>
>>
>> CAUTION: This is an external email. Please be very careful when clicking links or opening attachments. See the URL nok.it/ext for additional information.
>>
>>
>>
>> On Mon Aug 24, 2026 at 10:05 PM CEST, Jakub Kicinski wrote:
>> > On Mon, 24 Aug 2026 18:31:37 +0200 chia-yu.chang@nokia-bell-labs.com
>> > wrote:
>> >> From: Chia-Yu Chang <chia-yu.chang@nokia-bell-labs.com>
>> >>
>> >> Hello,
>> >>
>> >> This series replaces the existing min_tso_segs() congestion control
>> >> callback with a new tso_segs() callback that allows congestion
>> >> control algorithms to provide an explicit TSO segment count for each data burst.
>> >>
>> >> To support BPF congestion controls, the series also exposes
>> >> tcp_tso_autosize() as a BPF kfunc, allowing BPF implementations to
>> >> reuse the kernel TSO autosizing logic while implementing custom
>> >> tso_segs() callbacks.
>> >
>> > AI CI says:
>> >
>> > The bpf-ci build jobs are failing for this patch on all tested
>> > architectures/toolchains (x86-64 gcc-15, x86-64 llvm-21, aarch64
>> > gcc-15, s390x gcc-15), all with the same link-time error:
>> >
>> >   net/ipv4/tcp_bbr.o: in function `__BTF_ID__set8__tcp_bbr_check_kfunc_ids':
>> >   tcp_bbr.c:(.BTF_ids+0x...): undefined reference to `KF_DEPRECATED'
>> >
>> > This comes from the change to net/ipv4/tcp_bbr.c that marks the
>> > retained
>> > bbr_min_tso_segs() kfunc entry with the KF_DEPRECATED flag:
>> >
>> >   BTF_ID_FLAGS(func, bbr_min_tso_segs, KF_DEPRECATED)
>> >   BTF_ID_FLAGS(func, bbr_tso_segs)
>> >
>> > KF_DEPRECATED does not resolve to a usable symbol/flag in this tree,
>> > so the BTF id set for tcp_bbr fails to link into vmlinux on every
>> > architecture and toolchain -- it's a straight undefined-reference
>> > error, not a per-arch/per-config issue.
>> >
>> > Could you drop the KF_DEPRECATED flag (or use a flag that this kfunc
>> > infrastructure actually defines) on bbr_min_tso_segs, and re-verify
>> > that the kernel links cleanly? A local `make net/ipv4/tcp_bbr.o
>> > vmlinux` build (or the bpf-ci selftest build job) should reproduce this quickly.
>> >
>> > Full build log for reference:
>> >
>> >   ld.lld-21: error: undefined symbol: KF_DEPRECATED
>> >   >>> referenced by usercopy_64.c
>> >   >>>               vmlinux.o:(__BTF_ID__set8__tcp_bbr_check_kfunc_ids)
>>
>> I think Chia-Yu's AI is hallucinating, it was a proposed flag but not added yet...
>
> Hi Kumar and Kuba,
>
> I will drop it in the next version; however, this AI hallucination is from Sashiko's feedback I got:
>
> https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260814173034.749151-1-chia-yu.chang%40nokia-bell-labs.com
>
> BTW, any BPF-related flag is suggested to be added for graceful degradation?
>

We don't have anything yet, but I will add something this cycle and figure out
how this can be marked deprecated then.

> Thanks.
> Chia-Yu


^ permalink raw reply	[flat|nested] 10+ messages in thread

* Re: [PATCH v8 net-next 2/2] bpf: make tcp_tso_autosize() available to BPF congestion controls
  2026-08-24 16:31 ` [PATCH v8 net-next 2/2] bpf: make tcp_tso_autosize() available to BPF congestion controls chia-yu.chang
@ 2026-08-25 16:31   ` sashiko-bot
  2026-08-26 12:23     ` Chia-Yu Chang (Nokia)
  0 siblings, 1 reply; 10+ messages in thread
From: sashiko-bot @ 2026-08-25 16:31 UTC (permalink / raw)
  To: chia-yu.chang; +Cc: bpf

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] Type confusion in `tcp_tso_autosize` leading to out-of-bounds read when called with a non-TCP socket from BPF.
--

--- Patch [2]: [PATCH v8 net-next 2/2] bpf: make tcp_tso_autosize() available to BPF congestion controls ---
commit 6f535d3aed5d0c1f1117963d858318f7f63354f5
Author: Chia-Yu Chang <chia-yu.chang@nokia-bell-labs.com>

bpf: make tcp_tso_autosize() available to BPF congestion controls

Expose tcp_tso_autosize() as a BPF kfunc and register it in the TCP
congestion-control kfunc set. This allows BPF congestion controls to
reuse the kernel TSO autosizing logic while applying their own
minimum TSO segment policy.

> diff --git a/net/ipv4/bpf_tcp_ca.c b/net/ipv4/bpf_tcp_ca.c
> index ed4fea98dfde1..9deed2244c2de 100644
> --- a/net/ipv4/bpf_tcp_ca.c
> +++ b/net/ipv4/bpf_tcp_ca.c

[ ... ]

> @@ -194,6 +194,7 @@ BTF_ID_FLAGS(func, tcp_reno_cong_avoid)
>  BTF_ID_FLAGS(func, tcp_reno_undo_cwnd)
>  BTF_ID_FLAGS(func, tcp_slow_start)
>  BTF_ID_FLAGS(func, tcp_cong_avoid_ai)
> +BTF_ID_FLAGS(func, tcp_tso_autosize)
>  BTF_KFUNCS_END(bpf_tcp_ca_check_kfunc_ids)
>  
>  static const struct btf_kfunc_id_set bpf_tcp_ca_kfunc_set = {

[Severity: High]
Does this allow non-TCP struct_ops programs to call tcp_tso_autosize()?

Because bpf_tcp_ca_kfunc_set lacks a .filter callback, it appears this kfunc
becomes callable by any BPF program that can access a generic struct sock,
such as a bpf_qdisc program.

> diff --git a/net/ipv4/tcp_output.c b/net/ipv4/tcp_output.c
> index 7d3e0e715c4bf..a98036bcd987e 100644
> --- a/net/ipv4/tcp_output.c
> +++ b/net/ipv4/tcp_output.c

[ ... ]

> @@ -2252,13 +2252,21 @@ static bool tcp_nagle_check(bool partial, const struct tcp_sock *tp,
>   * in bigger TSO bursts. We we cut the RTT-based allowance in half
>   * for every 2^9 usec (aka 512 us) of RTT, so that the RTT-based allowance
>   * is below 1500 bytes after 6 * ~500 usec = 3ms.
> + *
> + * The min_tso_segs is floored to 1 to avoid surprising conversion. Also,
> + * BPF callers may pass mss_now == 0. In that case the function returns the
> + * sanitized min_tso_segs value and skips autosizing.
>   */
> -u32 tcp_tso_autosize(const struct sock *sk, unsigned int mss_now,
> -		     int min_tso_segs)
> +__bpf_kfunc u32 tcp_tso_autosize(const struct sock *sk, unsigned int mss_now,
> +				 int min_tso_segs)
>  {
> +	u32 min_tso = max(min_tso_segs, 1);
>  	unsigned long bytes;
>  	u32 r;
>  
> +	if (unlikely(!mss_now))
> +		return min_tso;
> +
>  	bytes = READ_ONCE(sk->sk_pacing_rate) >> READ_ONCE(sk->sk_pacing_shift);
>  
>  	r = tcp_min_rtt(tcp_sk(sk)) >> READ_ONCE(sock_net(sk)->ipv4.sysctl_tcp_tso_rtt_log);

[Severity: High]
If a non-TCP BPF program passes a generic struct sock to this kfunc, can this
lead to an out-of-bounds read?

The tcp_sk() macro casts the generic struct sock to a struct tcp_sock without
validating the socket type. If a smaller socket structure (like struct udp_sock)
is passed, accessing tp->rtt_min in tcp_min_rtt() could read past the end of
the allocated socket structure.

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260824163139.990734-1-chia-yu.chang@nokia-bell-labs.com?part=2

^ permalink raw reply	[flat|nested] 10+ messages in thread

* RE: [PATCH v8 net-next 2/2] bpf: make tcp_tso_autosize() available to BPF congestion controls
  2026-08-25 16:31   ` sashiko-bot
@ 2026-08-26 12:23     ` Chia-Yu Chang (Nokia)
  0 siblings, 0 replies; 10+ messages in thread
From: Chia-Yu Chang (Nokia) @ 2026-08-26 12:23 UTC (permalink / raw)
  To: sashiko-reviews@lists.linux.dev, bpf@vger.kernel.org

-----Original Message-----
From: sashiko-bot@kernel.org <sashiko-bot@kernel.org> 
Sent: Tuesday, August 25, 2026 6:32 PM
To: Chia-Yu Chang (Nokia) <chia-yu.chang@nokia-bell-labs.com>
Cc: bpf@vger.kernel.org
Subject: Re: [PATCH v8 net-next 2/2] bpf: make tcp_tso_autosize() available to BPF congestion controls


CAUTION: This is an external email. Please be very careful when clicking links or opening attachments. See the URL nok.it/ext for additional information.



> Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
> - [High] Type confusion in `tcp_tso_autosize` leading to out-of-bounds read when called with a non-TCP socket from BPF.
> --
> 
> --- Patch [2]: [PATCH v8 net-next 2/2] bpf: make tcp_tso_autosize() available to BPF congestion controls --- commit 6f535d3aed5d0c1f1117963d858318f7f63354f5
> Author: Chia-Yu Chang <chia-yu.chang@nokia-bell-labs.com>
> 
> bpf: make tcp_tso_autosize() available to BPF congestion controls
> 
> Expose tcp_tso_autosize() as a BPF kfunc and register it in the TCP congestion-control kfunc set. This allows BPF congestion controls to reuse the kernel TSO autosizing logic while applying their own minimum TSO segment policy.
> 
> > diff --git a/net/ipv4/bpf_tcp_ca.c b/net/ipv4/bpf_tcp_ca.c index 
> > ed4fea98dfde1..9deed2244c2de 100644
> > --- a/net/ipv4/bpf_tcp_ca.c
> > +++ b/net/ipv4/bpf_tcp_ca.c
> 
> [ ... ]
> 
> > @@ -194,6 +194,7 @@ BTF_ID_FLAGS(func, tcp_reno_cong_avoid)  
> > BTF_ID_FLAGS(func, tcp_reno_undo_cwnd)  BTF_ID_FLAGS(func, 
> > tcp_slow_start)  BTF_ID_FLAGS(func, tcp_cong_avoid_ai)
> > +BTF_ID_FLAGS(func, tcp_tso_autosize)
> >  BTF_KFUNCS_END(bpf_tcp_ca_check_kfunc_ids)
> >
> >  static const struct btf_kfunc_id_set bpf_tcp_ca_kfunc_set = {
> 
> [Severity: High]
> Does this allow non-TCP struct_ops programs to call tcp_tso_autosize()?
> 
> Because bpf_tcp_ca_kfunc_set lacks a .filter callback, it appears this kfunc becomes callable by any BPF program that can access a generic struct sock, such as a bpf_qdisc program.
> 
> > diff --git a/net/ipv4/tcp_output.c b/net/ipv4/tcp_output.c index 
> > 7d3e0e715c4bf..a98036bcd987e 100644
> > --- a/net/ipv4/tcp_output.c
> > +++ b/net/ipv4/tcp_output.c
> 
> [ ... ]
> 
> > @@ -2252,13 +2252,21 @@ static bool tcp_nagle_check(bool partial, const struct tcp_sock *tp,
> >   * in bigger TSO bursts. We we cut the RTT-based allowance in half
> >   * for every 2^9 usec (aka 512 us) of RTT, so that the RTT-based allowance
> >   * is below 1500 bytes after 6 * ~500 usec = 3ms.
> > + *
> > + * The min_tso_segs is floored to 1 to avoid surprising conversion. 
> > + Also,
> > + * BPF callers may pass mss_now == 0. In that case the function 
> > + returns the
> > + * sanitized min_tso_segs value and skips autosizing.
> >   */
> > -u32 tcp_tso_autosize(const struct sock *sk, unsigned int mss_now,
> > -                  int min_tso_segs)
> > +__bpf_kfunc u32 tcp_tso_autosize(const struct sock *sk, unsigned int mss_now,
> > +                              int min_tso_segs)
> >  {
> > +     u32 min_tso = max(min_tso_segs, 1);
> >       unsigned long bytes;
> >       u32 r;
> >
> > +     if (unlikely(!mss_now))
> > +             return min_tso;
> > +
> >       bytes = READ_ONCE(sk->sk_pacing_rate) >> 
> > READ_ONCE(sk->sk_pacing_shift);
> >
> >       r = tcp_min_rtt(tcp_sk(sk)) >> 
> > READ_ONCE(sock_net(sk)->ipv4.sysctl_tcp_tso_rtt_log);
> 
> [Severity: High]
> If a non-TCP BPF program passes a generic struct sock to this kfunc, can this lead to an out-of-bounds read?
> 
> The tcp_sk() macro casts the generic struct sock to a struct tcp_sock without validating the socket type. If a smaller socket structure (like struct udp_sock) is passed, accessing tp->rtt_min in tcp_min_rtt() could read past the end of the allocated socket structure.

Hi,

tcp_tso_autosize() is added to the same kfunc set as the existing TCP congestion-control kfuncs (tcp_reno_ssthresh(), tcp_reno_cong_avoid(), etc.), all of which already accept a struct sock* and use tcp_sk() without additional validation.
 
If access to this kfunc set were possible from a non-TCP context, the same concern would already apply to the existing kfuncs.
In this case, this shall be the framework issue and an extra .filter shall be added into bpf_tcp_congestion_ops in other patch series

Thanks.
Chia-Yu


^ permalink raw reply	[flat|nested] 10+ messages in thread

end of thread, other threads:[~2026-08-26 12:23 UTC | newest]

Thread overview: 10+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-24 16:31 [PATCH v8 net-next 0/2] Explicit TSO segment count chia-yu.chang
2026-08-24 16:31 ` [PATCH v8 net-next 1/2] tcp: Replace min_tso_segs() with tso_segs() CC callback chia-yu.chang
2026-08-24 16:31 ` [PATCH v8 net-next 2/2] bpf: make tcp_tso_autosize() available to BPF congestion controls chia-yu.chang
2026-08-25 16:31   ` sashiko-bot
2026-08-26 12:23     ` Chia-Yu Chang (Nokia)
2026-08-24 18:08 ` [PATCH v8 net-next 0/2] Explicit TSO segment count Jakub Kicinski
2026-08-24 20:05 ` Jakub Kicinski
2026-08-24 20:09   ` Kumar Kartikeya Dwivedi
2026-08-24 20:21     ` Chia-Yu Chang (Nokia)
2026-08-24 20:26       ` Kumar Kartikeya Dwivedi

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.