• Paolo Abeni's avatar
    mptcp: fix possible divide by zero · 1094c6fe
    Paolo Abeni authored
    Florian noted that if mptcp_alloc_tx_skb() allocation fails
    in __mptcp_push_pending(), we can end-up invoking
    mptcp_push_release()/tcp_push() with a zero mss, causing
    a divide by 0 error.
    
    This change addresses the issue refactoring the skb allocation
    code checking if skb collapsing will happen for sure and doing
    the skb allocation only after such check. Skb allocation will
    now happen only after the call to tcp_send_mss() which
    correctly initializes mss_now.
    
    As side bonuses we now fill the skb tx cache only when needed,
    and this also clean-up a bit the output path.
    
    v1 -> v2:
     - use lockdep_assert_held_once() - Jakub
     - fix indentation - Jakub
    Reported-by: default avatarFlorian Westphal <fw@strlen.de>
    Fixes: 724cfd2e ("mptcp: allocate TX skbs in msk context")
    Signed-off-by: default avatarPaolo Abeni <pabeni@redhat.com>
    Signed-off-by: default avatarMat Martineau <mathew.j.martineau@linux.intel.com>
    Signed-off-by: default avatarJakub Kicinski <kuba@kernel.org>
    1094c6fe
protocol.c 89.1 KB