* [PATCH] net/sched: sch_netem: prevent packet length underflow with negative overhead
@ 2026-10-08 3:56 Bui Viet Dung
2026-10-08 3:59 ` netdev-bot+sinfo
0 siblings, 1 reply; 2+ messages in thread
From: Bui Viet Dung @ 2026-10-08 3:56 UTC (permalink / raw)
To: Stephen Hemminger, Jamal Hadi Salim, Jiri Pirko,
David S . Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni
Cc: Simon Horman, netdev, linux-kernel, stable, Bui Viet Dung
packet_time_ns() calculates transmission time for netem rate shaping.
It adds q->packet_overhead (signed 32-bit int) to len (unsigned
64-bit int).
When userspace configures a negative packet overhead (via
TCA_NETEM_RATE packet_overhead attribute) and an enqueued packet's
length is smaller than the absolute overhead, (s64)len +
q->packet_overhead is negative. Because len is u64, the addition wraps
into an astronomical value (~2^64 - 1). When multiplied by NSEC_PER_SEC
and divided by q->rate, the calculated delay spans hours or days,
causing enqueued packets to be frozen in the qdisc indefinitely and
stalling transmission.
A similar underflow can occur in cell length calculation when
(q->cell_size + q->cell_overhead) is non-positive.
Clamp the effective packet length to 0 if the overhead adjustment
would underflow, and return 0 delay if effective cell length is
non-positive, matching the behavior in sch_cake and sch_tbf.
Fixes: 7bc0f28c7a0c ("netem: rate extension")
Cc: stable@vger.kernel.org
Signed-off-by: Bui Viet Dung <dungvn2345@gmail.com>
---
net/sched/sch_netem.c | 8 +++++++-
1 file changed, 7 insertions(+), 1 deletion(-)
diff --git a/net/sched/sch_netem.c b/net/sched/sch_netem.c
index 8a1b89a289d..a3dcd33bec4 100644
--- a/net/sched/sch_netem.c
+++ b/net/sched/sch_netem.c
@@ -366,14 +366,20 @@ static s64 tabledist(s64 mu, s32 sigma,
static u64 packet_time_ns(u64 len, const struct netem_sched_data *q)
{
+ if ((s64)len + q->packet_overhead <= 0)
+ return 0;
+
len += q->packet_overhead;
if (q->cell_size) {
u32 cells = reciprocal_divide(len, q->cell_size_reciprocal);
+ s32 cell_len = (s32)q->cell_size + q->cell_overhead;
if (len > cells * q->cell_size) /* extra cell needed for remainder */
cells++;
- len = cells * (q->cell_size + q->cell_overhead);
+ if (cell_len <= 0)
+ return 0;
+ len = (u64)cells * cell_len;
}
return div64_u64(len * NSEC_PER_SEC, q->rate);
--
2.43.0
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: [PATCH] net/sched: sch_netem: prevent packet length underflow with negative overhead
2026-10-08 3:56 [PATCH] net/sched: sch_netem: prevent packet length underflow with negative overhead Bui Viet Dung
@ 2026-10-08 3:59 ` netdev-bot+sinfo
0 siblings, 0 replies; 2+ messages in thread
From: netdev-bot+sinfo @ 2026-10-08 3:59 UTC (permalink / raw)
To: Bui Viet Dung
Cc: Stephen Hemminger, Jamal Hadi Salim, Jiri Pirko,
David S . Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni,
Simon Horman, netdev, linux-kernel, stable
Hi!
This is an automated message. This series looks like a fix, but its
commit messages seem to be missing some information:
- How the issue was discovered, e.g. hit in production, hit during
development, syzbot report, manual code inspection, LLM or static
analysis tool scan.
- Whether the issue was actually triggered, or is only theoretical
(e.g. found by code inspection). If it was triggered please include
the symptoms, like the stack trace or error messages.
Please do not repost the series just to address the above. Instead,
reply to this email with the missing information, so that reviewers
can take it into account. If the series needs another revision for
other reasons, please include the information in the commit messages
then.
The evaluation is done by an LLM so it may be wrong, if you think
that is the case please reply and explain.
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-10-08 3:59 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-08 3:56 [PATCH] net/sched: sch_netem: prevent packet length underflow with negative overhead Bui Viet Dung
2026-10-08 3:59 ` netdev-bot+sinfo
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®