skb_segment() clears gso_size on the last output of a group which holds one
MSS or less, but leaves gso_segs and gso_type as the grouping set them, so
the tail is still counted as the whole group.  Readers which take gso_segs
without testing gso_size first, such as the ECT statistics in ip_rcv_core()
and tp->rcv_ooopack in tcp_rcv_established(), see that stale count, and a
re-segmented output reaches them when a veth or bridge port delivers it back
into the receive path.

Clear gso_size, gso_segs and gso_type together with skb_gso_reset().

Suggested-by: Willem de Bruijn <[email protected]>
Assisted-by: LLM
Signed-off-by: Wang Zhan <[email protected]>
---
 net/core/skbuff.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/net/core/skbuff.c b/net/core/skbuff.c
index 1feb038d9ff680..43d63cd29f694f 100644
--- a/net/core/skbuff.c
+++ b/net/core/skbuff.c
@@ -5125,7 +5125,7 @@ struct sk_buff *skb_segment(struct sk_buff *head_skb,
                }
 
                if (tail->len - doffset <= gso_size)
-                       skb_shinfo(tail)->gso_size = 0;
+                       skb_gso_reset(tail);
                else if (tail != segs)
                        skb_shinfo(tail)->gso_segs = DIV_ROUND_UP(tail->len - 
doffset, gso_size);
        }
-- 
2.47.3

_______________________________________________
dev mailing list
[email protected]
https://mail.openvswitch.org/mailman/listinfo/ovs-dev

Reply via email to