beta_scale and cube_factor are computed once at module init, and
beta == 1024 or bic_scale == 0 is a divide by zero right there. Other
out of range values give garbage: negative beta can make beta_scale 0,
and bic_scale * 10 can overflow. Reject them. Read beta once, as it
can be written through sysfs before the init function runs.
A small beta also gives a small beta_scale, and (cwnd * beta_scale) >> 3
truncates to 0 for a tiny cwnd, so the TCP friendliness loop never
ends. Rather than testing delta on every ACK, make sure beta_scale is
at least 8 at init, so delta is >= 1 within the cwnd < 1 million
packets limit this code is designed for. This slows the TCP friendly
estimate for beta < 512, a backoff harder than Reno's 0.5, which is
not a setting anyone should use.
Fixes: df3271f3361b ("[TCP] BIC: CUBIC window growth (2.0)")
Suggested-by: Eric Dumazet <edumazet@kernel.org>
Reviewed-by: Eric Dumazet <edumazet@kernel.org>
Signed-off-by: Jiayuan Chen <jiayuan.chen@linux.dev>
---
(cwnd * beta_scale) can wrap for cwnd >= 33M packets, far beyond the
1 million packets this code is designed for, so no fast path check.
---
net/ipv4/tcp_cubic.c | 14 ++++++++++++--
1 file changed, 12 insertions(+), 2 deletions(-)
diff --git a/net/ipv4/tcp_cubic.c b/net/ipv4/tcp_cubic.c
index 119bf8cbb007c..a88e4bf86150f 100644
--- a/net/ipv4/tcp_cubic.c
+++ b/net/ipv4/tcp_cubic.c
@@ -500,16 +500,26 @@ static const struct btf_kfunc_id_set tcp_cubic_kfunc_set = {
static int __init cubictcp_register(void)
{
+ int b = READ_ONCE(beta);
int ret;
BUILD_BUG_ON(sizeof(struct bictcp) > ICSK_CA_PRIV_SIZE);
+ if (b < 0 || b >= BICTCP_BETA_SCALE ||
+ bic_scale <= 0 || bic_scale > INT_MAX / 10) {
+ pr_err("tcp_cubic: invalid beta %d or bic_scale %d\n",
+ b, bic_scale);
+ return -EINVAL;
+ }
+
/* Precompute a bunch of the scaling factors that are used per-packet
* based on SRTT of 100ms
*/
- beta_scale = 8*(BICTCP_BETA_SCALE+beta) / 3
- / (BICTCP_BETA_SCALE - beta);
+ beta_scale = 8 * (BICTCP_BETA_SCALE + b) / 3
+ / (BICTCP_BETA_SCALE - b);
+ /* bictcp_update() needs (cwnd * beta_scale) >> 3 to be >= 1 */
+ beta_scale = max(beta_scale, 8U);
cube_rtt_scale = (bic_scale * 10); /* 1024*c/rtt */
--
2.43.0