public inbox for linux-kselftest@vger.kernel.org
 help / color / mirror / Atom feed
From: Simon Horman <horms@kernel.org>
To: "Ilpo Järvinen" <ij@kernel.org>
Cc: chia-yu.chang@nokia-bell-labs.com, dsahern@kernel.org,
	kuniyu@amazon.com, bpf@vger.kernel.org, netdev@vger.kernel.org,
	dave.taht@gmail.com, pabeni@redhat.com, jhs@mojatatu.com,
	kuba@kernel.org, stephen@networkplumber.org,
	xiyou.wangcong@gmail.com, jiri@resnulli.us, davem@davemloft.net,
	edumazet@google.com, andrew+netdev@lunn.ch,
	donald.hunter@gmail.com, ast@fiberby.net, liuhangbin@gmail.com,
	shuah@kernel.org, linux-kselftest@vger.kernel.org,
	ncardwell@google.com, koen.de_schepper@nokia-bell-labs.com,
	g.white@cablelabs.com, ingemar.s.johansson@ericsson.com,
	mirja.kuehlewind@ericsson.com, cheshire@apple.com,
	rs.ietf@gmx.at, Jason_Livingood@comcast.com,
	vidhi_goel@apple.com
Subject: Re: [PATCH v4 net-next 09/15] tcp: accecn: AccECN option
Date: Tue, 22 Apr 2025 17:23:18 +0100	[thread overview]
Message-ID: <20250422162318.GI2843373@horms.kernel.org> (raw)
In-Reply-To: <8b6f580b-d682-91f7-f958-1806ee6e8bbe@kernel.org>

On Fri, Apr 18, 2025 at 10:35:14PM +0300, Ilpo Järvinen wrote:
> On Fri, 18 Apr 2025, Simon Horman wrote:
> 
> > On Fri, Apr 18, 2025 at 01:00:23AM +0200, chia-yu.chang@nokia-bell-labs.com wrote:
> > 
> > ...
> > 
> > > diff --git a/net/ipv4/tcp_output.c b/net/ipv4/tcp_output.c
> > 
> > ...
> > 
> > > @@ -766,6 +769,47 @@ static void tcp_options_write(struct tcphdr *th, struct tcp_sock *tp,
> > >  		*ptr++ = htonl(opts->tsecr);
> > >  	}
> > >  
> > > +	if (OPTION_ACCECN & options) {
> > > +		const u8 ect0_idx = INET_ECN_ECT_0 - 1;
> > > +		const u8 ect1_idx = INET_ECN_ECT_1 - 1;
> > > +		const u8 ce_idx = INET_ECN_CE - 1;
> > > +		u32 e0b;
> > > +		u32 e1b;
> > > +		u32 ceb;
> > > +		u8 len;
> > > +
> > > +		e0b = opts->ecn_bytes[ect0_idx] + TCP_ACCECN_E0B_INIT_OFFSET;
> > > +		e1b = opts->ecn_bytes[ect1_idx] + TCP_ACCECN_E1B_INIT_OFFSET;
> > > +		ceb = opts->ecn_bytes[ce_idx] + TCP_ACCECN_CEB_INIT_OFFSET;
> > > +		len = TCPOLEN_ACCECN_BASE +
> > > +		      opts->num_accecn_fields * TCPOLEN_ACCECN_PERFIELD;
> > > +
> > > +		if (opts->num_accecn_fields == 2) {
> > > +			*ptr++ = htonl((TCPOPT_ACCECN1 << 24) | (len << 16) |
> > > +				       ((e1b >> 8) & 0xffff));
> > > +			*ptr++ = htonl(((e1b & 0xff) << 24) |
> > > +				       (ceb & 0xffffff));
> > > +		} else if (opts->num_accecn_fields == 1) {
> > > +			*ptr++ = htonl((TCPOPT_ACCECN1 << 24) | (len << 16) |
> > > +				       ((e1b >> 8) & 0xffff));
> > > +			leftover_bytes = ((e1b & 0xff) << 8) |
> > > +					 TCPOPT_NOP;
> > > +			leftover_size = 1;
> > > +		} else if (opts->num_accecn_fields == 0) {
> > > +			leftover_bytes = (TCPOPT_ACCECN1 << 8) | len;
> > > +			leftover_size = 2;
> > > +		} else if (opts->num_accecn_fields == 3) {
> > > +			*ptr++ = htonl((TCPOPT_ACCECN1 << 24) | (len << 16) |
> > > +				       ((e1b >> 8) & 0xffff));
> > > +			*ptr++ = htonl(((e1b & 0xff) << 24) |
> > > +				       (ceb & 0xffffff));
> > > +			*ptr++ = htonl(((e0b & 0xffffff) << 8) |
> > > +				       TCPOPT_NOP);
> > > +		}
> > > +		if (tp)
> > > +			tp->accecn_minlen = 0;
> > 
> > Hi,
> > 
> > I'm sorry if this is a false positive: Smatch flags that here we assume
> > that tp might be NULL, while elsewhere in this function tp is dereferenced
> > unconditionally. So my question is, can tp be NULL here?
> 
> Hi Simon,
> 
> Thanks for taking look!
> 
> This looks a false positive. It's because tcp_options_write() is shared by 
> the handshake and established connections. A direct caller from the 
> handshake path passes NULL as tp:
> 
> 	tcp_options_write(th, NULL, tcp_rsk(req), &opts, &key);
> 
> The thing that smatch doesn't know is that some TCP options are not going 
> to be present during handshake. Those code paths that only deal with 
> options that are for an established connection can assume full sk/tp has 
> been already instantiated so they don't need to check tp. In addition, 
> some funcs tcp_options_write() calls to make the opposite check by 
> checking tcprsk instead but it has the same effect.

Thanks for checking, I appreciate you clarifying this.

  reply	other threads:[~2025-04-22 16:23 UTC|newest]

Thread overview: 22+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-04-17 23:00 [PATCH v4 net-next 00/15] AccECN protocol patch series chia-yu.chang
2025-04-17 23:00 ` [PATCH v4 net-next 01/15] tcp: reorganize SYN ECN code chia-yu.chang
2025-04-17 23:00 ` [PATCH v4 net-next 02/15] tcp: fast path functions later chia-yu.chang
2025-04-17 23:00 ` [PATCH v4 net-next 03/15] tcp: AccECN core chia-yu.chang
2025-04-17 23:00 ` [PATCH v4 net-next 04/15] tcp: accecn: AccECN negotiation chia-yu.chang
2025-04-17 23:00 ` [PATCH v4 net-next 05/15] tcp: accecn: add AccECN rx byte counters chia-yu.chang
2025-04-17 23:00 ` [PATCH v4 net-next 06/15] tcp: accecn: AccECN needs to know delivered bytes chia-yu.chang
2025-04-17 23:00 ` [PATCH v4 net-next 07/15] tcp: allow embedding leftover into option padding chia-yu.chang
2025-04-17 23:00 ` [PATCH v4 net-next 08/15] tcp: sack option handling improvements chia-yu.chang
2025-04-17 23:00 ` [PATCH v4 net-next 09/15] tcp: accecn: AccECN option chia-yu.chang
2025-04-18 18:31   ` Simon Horman
2025-04-18 19:35     ` Ilpo Järvinen
2025-04-22 16:23       ` Simon Horman [this message]
2025-04-17 23:00 ` [PATCH v4 net-next 10/15] tcp: accecn: AccECN option send control chia-yu.chang
2025-04-18 17:34   ` Simon Horman
2025-04-18 18:24     ` Simon Horman
2025-04-22 15:48       ` Chia-Yu Chang (Nokia)
2025-04-17 23:00 ` [PATCH v4 net-next 11/15] tcp: accecn: AccECN option failure handling chia-yu.chang
2025-04-17 23:00 ` [PATCH v4 net-next 12/15] tcp: accecn: AccECN option ceb/cep heuristic chia-yu.chang
2025-04-17 23:00 ` [PATCH v4 net-next 13/15] tcp: accecn: AccECN ACE field multi-wrap heuristic chia-yu.chang
2025-04-17 23:00 ` [PATCH v4 net-next 14/15] tcp: accecn: try to fit AccECN option with SACK chia-yu.chang
2025-04-17 23:00 ` [PATCH v4 net-next 15/15] tcp: try to avoid safer when ACKs are thinned chia-yu.chang

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20250422162318.GI2843373@horms.kernel.org \
    --to=horms@kernel.org \
    --cc=Jason_Livingood@comcast.com \
    --cc=andrew+netdev@lunn.ch \
    --cc=ast@fiberby.net \
    --cc=bpf@vger.kernel.org \
    --cc=cheshire@apple.com \
    --cc=chia-yu.chang@nokia-bell-labs.com \
    --cc=dave.taht@gmail.com \
    --cc=davem@davemloft.net \
    --cc=donald.hunter@gmail.com \
    --cc=dsahern@kernel.org \
    --cc=edumazet@google.com \
    --cc=g.white@cablelabs.com \
    --cc=ij@kernel.org \
    --cc=ingemar.s.johansson@ericsson.com \
    --cc=jhs@mojatatu.com \
    --cc=jiri@resnulli.us \
    --cc=koen.de_schepper@nokia-bell-labs.com \
    --cc=kuba@kernel.org \
    --cc=kuniyu@amazon.com \
    --cc=linux-kselftest@vger.kernel.org \
    --cc=liuhangbin@gmail.com \
    --cc=mirja.kuehlewind@ericsson.com \
    --cc=ncardwell@google.com \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    --cc=rs.ietf@gmx.at \
    --cc=shuah@kernel.org \
    --cc=stephen@networkplumber.org \
    --cc=vidhi_goel@apple.com \
    --cc=xiyou.wangcong@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox