Commit 685f605a authored by David S. Miller's avatar David S. Miller Committed by Greg Kroah-Hartman

pkt_sched: Fix return value corruption in HTB and TBF.

[ Upstream commit 69747650 ]

Based upon a bug report by Josip Rodin.

Packet schedulers should only return NET_XMIT_DROP iff
the packet really was dropped.  If the packet does reach
the device after we return NET_XMIT_DROP then TCP can
crash because it depends upon the enqueue path return
values being accurate.
Signed-off-by: default avatarDavid S. Miller <davem@davemloft.net>
Signed-off-by: default avatarGreg Kroah-Hartman <gregkh@suse.de>
parent 7b29aece
No related merge requests found
...@@ -595,11 +595,13 @@ static int htb_enqueue(struct sk_buff *skb, struct Qdisc *sch) ...@@ -595,11 +595,13 @@ static int htb_enqueue(struct sk_buff *skb, struct Qdisc *sch)
kfree_skb(skb); kfree_skb(skb);
return ret; return ret;
#endif #endif
} else if (cl->un.leaf.q->enqueue(skb, cl->un.leaf.q) != } else if ((ret = cl->un.leaf.q->enqueue(skb, cl->un.leaf.q)) !=
NET_XMIT_SUCCESS) { NET_XMIT_SUCCESS) {
sch->qstats.drops++; if (ret == NET_XMIT_DROP) {
cl->qstats.drops++; sch->qstats.drops++;
return NET_XMIT_DROP; cl->qstats.drops++;
}
return ret;
} else { } else {
cl->bstats.packets += cl->bstats.packets +=
skb_is_gso(skb)?skb_shinfo(skb)->gso_segs:1; skb_is_gso(skb)?skb_shinfo(skb)->gso_segs:1;
...@@ -639,11 +641,13 @@ static int htb_requeue(struct sk_buff *skb, struct Qdisc *sch) ...@@ -639,11 +641,13 @@ static int htb_requeue(struct sk_buff *skb, struct Qdisc *sch)
kfree_skb(skb); kfree_skb(skb);
return ret; return ret;
#endif #endif
} else if (cl->un.leaf.q->ops->requeue(skb, cl->un.leaf.q) != } else if ((ret = cl->un.leaf.q->ops->requeue(skb, cl->un.leaf.q)) !=
NET_XMIT_SUCCESS) { NET_XMIT_SUCCESS) {
sch->qstats.drops++; if (ret == NET_XMIT_DROP) {
cl->qstats.drops++; sch->qstats.drops++;
return NET_XMIT_DROP; cl->qstats.drops++;
}
return ret;
} else } else
htb_activate(q, cl); htb_activate(q, cl);
......
...@@ -123,15 +123,8 @@ static int tbf_enqueue(struct sk_buff *skb, struct Qdisc* sch) ...@@ -123,15 +123,8 @@ static int tbf_enqueue(struct sk_buff *skb, struct Qdisc* sch)
struct tbf_sched_data *q = qdisc_priv(sch); struct tbf_sched_data *q = qdisc_priv(sch);
int ret; int ret;
if (skb->len > q->max_size) { if (skb->len > q->max_size)
sch->qstats.drops++; return qdisc_reshape_fail(skb, sch);
#ifdef CONFIG_NET_CLS_ACT
if (sch->reshape_fail == NULL || sch->reshape_fail(skb, sch))
#endif
kfree_skb(skb);
return NET_XMIT_DROP;
}
if ((ret = q->qdisc->enqueue(skb, q->qdisc)) != 0) { if ((ret = q->qdisc->enqueue(skb, q->qdisc)) != 0) {
sch->qstats.drops++; sch->qstats.drops++;
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment