skb_segment() clears gso_size on the last output of a group which holds one MSS or less, but leaves gso_segs and gso_type as the grouping set them, so the tail is still counted as the whole group. Readers which take gso_segs without testing gso_size first, such as the ECT statistics in ip_rcv_core() and tp->rcv_ooopack in tcp_rcv_established(), see that stale count, and a re-segmented output reaches them when a veth or bridge port delivers it back into the receive path.
Clear gso_size, gso_segs and gso_type together with skb_gso_reset(). Suggested-by: Willem de Bruijn <[email protected]> Assisted-by: LLM Signed-off-by: Wang Zhan <[email protected]> --- net/core/skbuff.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/net/core/skbuff.c b/net/core/skbuff.c index 1feb038d9ff680..43d63cd29f694f 100644 --- a/net/core/skbuff.c +++ b/net/core/skbuff.c @@ -5125,7 +5125,7 @@ struct sk_buff *skb_segment(struct sk_buff *head_skb, } if (tail->len - doffset <= gso_size) - skb_shinfo(tail)->gso_size = 0; + skb_gso_reset(tail); else if (tail != segs) skb_shinfo(tail)->gso_segs = DIV_ROUND_UP(tail->len - doffset, gso_size); } -- 2.47.3 _______________________________________________ dev mailing list [email protected] https://mail.openvswitch.org/mailman/listinfo/ovs-dev
