• Pengcheng Yang's avatar
    tcp: fix "old stuff" D-SACK causing SACK to be treated as D-SACK · c9655008
    Pengcheng Yang authored
    When we receive a D-SACK, where the sequence number satisfies:
    	undo_marker <= start_seq < end_seq <= prior_snd_una
    we consider this is a valid D-SACK and tcp_is_sackblock_valid()
    returns true, then this D-SACK is discarded as "old stuff",
    but the variable first_sack_index is not marked as negative
    in tcp_sacktag_write_queue().
    
    If this D-SACK also carries a SACK that needs to be processed
    (for example, the previous SACK segment was lost), this SACK
    will be treated as a D-SACK in the following processing of
    tcp_sacktag_write_queue(), which will eventually lead to
    incorrect updates of undo_retrans and reordering.
    
    Fixes: fd6dad61 ("[TCP]: Earlier SACK block verification & simplify access to them")
    Signed-off-by: default avatarPengcheng Yang <yangpc@wangsu.com>
    Signed-off-by: default avatarEric Dumazet <edumazet@google.com>
    Signed-off-by: default avatarDavid S. Miller <davem@davemloft.net>
    c9655008
tcp_input.c 191 KB