* [PATCH net-next v3 0/3] tcp: fix a few divide-by-zero in congestion control modules
@ 2026-10-08 9:26 Jiayuan Chen
2026-10-08 9:26 ` [PATCH net-next v3 1/3] tcp_bic: fix divide by zero on max_increment == 0 Jiayuan Chen
` (3 more replies)
0 siblings, 4 replies; 5+ messages in thread
From: Jiayuan Chen @ 2026-10-08 9:26 UTC (permalink / raw)
To: netdev
Cc: Jiayuan Chen, Eric Dumazet, Neal Cardwell, Kuniyuki Iwashima,
David S. Miller, Jakub Kicinski, Paolo Abeni, Simon Horman,
Stephen Hemminger, linux-kernel
Patch 1 and 2 were reported by VEGA <vega@nebusec.ai>.
Patch 3 was found while reviewing the other TCP congestion control
modules for the same kind of divide-by-zero on module parameters.
Target net-next since it is not a big problem.
v2 -> v3:
- Patch 3: spell out the divide by zero in the commit message (Kuba,
Neal), read beta once with READ_ONCE() (Eric).
v2: https://lore.kernel.org/netdev/20261001112948.322463-1-jiayuan.chen@linux.dev/
v1 -> v2:
- Patch 3: rework as suggested by Eric.
- Patch 1 and 2: add Eric's Reviewed-by.
v1: https://lore.kernel.org/netdev/20260930100937.206377-1-jiayuan.chen@linux.dev/
Jiayuan Chen (3):
tcp_bic: fix divide by zero on max_increment == 0
tcp_hybla: fix divide by zero on rtt0 == 0
tcp_cubic: fix divide by zero and endless loop on bad module params
net/ipv4/tcp_bic.c | 14 ++++++++++++--
net/ipv4/tcp_cubic.c | 14 ++++++++++++--
net/ipv4/tcp_hybla.c | 16 ++++++++++++++--
3 files changed, 38 insertions(+), 6 deletions(-)
--
2.43.0
^ permalink raw reply [flat|nested] 5+ messages in thread
* [PATCH net-next v3 1/3] tcp_bic: fix divide by zero on max_increment == 0
2026-10-08 9:26 [PATCH net-next v3 0/3] tcp: fix a few divide-by-zero in congestion control modules Jiayuan Chen
@ 2026-10-08 9:26 ` Jiayuan Chen
2026-10-08 9:26 ` [PATCH net-next v3 2/3] tcp_hybla: fix divide by zero on rtt0 " Jiayuan Chen
` (2 subsequent siblings)
3 siblings, 0 replies; 5+ messages in thread
From: Jiayuan Chen @ 2026-10-08 9:26 UTC (permalink / raw)
To: netdev
Cc: Jiayuan Chen, VEGA, Eric Dumazet, Eric Dumazet, Neal Cardwell,
Kuniyuki Iwashima, David S. Miller, Jakub Kicinski, Paolo Abeni,
Simon Horman, Stephen Hemminger, linux-kernel
max_increment is how many packets cwnd can grow per RTT, so 0 makes
no sense, and bictcp_update() divides by it.
Reject values below 1 when the parameter is written.
Fixes: 83803034f423 ("[TCP]: Add TCP BIC congestion control module.")
Reported-by: VEGA <vega@nebusec.ai>
Signed-off-by: Jiayuan Chen <jiayuan.chen@linux.dev>
Reviewed-by: Eric Dumazet <edumazet@kernel.org>
---
No __MODULE_PARM_TYPE() on purpose, same as dctcp_shift_g in
tcp_dctcp.c. It only changes the type suffix modinfo prints.
---
net/ipv4/tcp_bic.c | 14 ++++++++++++--
1 file changed, 12 insertions(+), 2 deletions(-)
diff --git a/net/ipv4/tcp_bic.c b/net/ipv4/tcp_bic.c
index 65444ff142413..27d2e38ff7932 100644
--- a/net/ipv4/tcp_bic.c
+++ b/net/ipv4/tcp_bic.c
@@ -27,15 +27,25 @@
*/
static int fast_convergence = 1;
-static int max_increment = 16;
+static unsigned int max_increment = 16;
static int low_window = 14;
static int beta = 819; /* = 819/1024 (BICTCP_BETA_SCALE) */
static int initial_ssthresh;
static int smooth_part = 20;
+static int max_increment_set(const char *val, const struct kernel_param *kp)
+{
+ return param_set_uint_minmax(val, kp, 1, INT_MAX);
+}
+
+static const struct kernel_param_ops max_increment_ops = {
+ .set = max_increment_set,
+ .get = param_get_uint,
+};
+
module_param(fast_convergence, int, 0644);
MODULE_PARM_DESC(fast_convergence, "turn on/off fast convergence");
-module_param(max_increment, int, 0644);
+module_param_cb(max_increment, &max_increment_ops, &max_increment, 0644);
MODULE_PARM_DESC(max_increment, "Limit on increment allowed during binary search");
module_param(low_window, int, 0644);
MODULE_PARM_DESC(low_window, "lower bound on congestion window (for TCP friendliness)");
--
2.43.0
^ permalink raw reply [flat|nested] 5+ messages in thread
* [PATCH net-next v3 2/3] tcp_hybla: fix divide by zero on rtt0 == 0
2026-10-08 9:26 [PATCH net-next v3 0/3] tcp: fix a few divide-by-zero in congestion control modules Jiayuan Chen
2026-10-08 9:26 ` [PATCH net-next v3 1/3] tcp_bic: fix divide by zero on max_increment == 0 Jiayuan Chen
@ 2026-10-08 9:26 ` Jiayuan Chen
2026-10-08 9:26 ` [PATCH net-next v3 3/3] tcp_cubic: fix divide by zero and endless loop on bad module params Jiayuan Chen
2026-10-08 9:30 ` [PATCH net-next v3 0/3] tcp: fix a few divide-by-zero in congestion control modules netdev-bot+sinfo
3 siblings, 0 replies; 5+ messages in thread
From: Jiayuan Chen @ 2026-10-08 9:26 UTC (permalink / raw)
To: netdev
Cc: Jiayuan Chen, VEGA, Eric Dumazet, Eric Dumazet, Neal Cardwell,
Kuniyuki Iwashima, David S. Miller, Jakub Kicinski, Paolo Abeni,
Simon Horman, Stephen Hemminger, linux-kernel
rtt0 is the reference RTT in ms, so 0 makes no sense, and
hybla_recalc_param() divides by it right from hybla_init().
Reject values below 1 when the parameter is written. Also cap it at
U32_MAX / USEC_PER_MSEC, since rtt0 * USEC_PER_MSEC can wrap to 0 on
32-bit. An rtt0 above that (about 71 minutes) makes no sense anyway.
Fixes: 835b3f0c0d7e ("[TCP]: Add TCP Hybla congestion control module.")
Fixes: 740b0f1841f6 ("tcp: switch rtt estimations to usec resolution")
Reported-by: VEGA <vega@nebusec.ai>
Signed-off-by: Jiayuan Chen <jiayuan.chen@linux.dev>
Reviewed-by: Eric Dumazet <edumazet@kernel.org>
---
No __MODULE_PARM_TYPE() on purpose, same as dctcp_shift_g in
tcp_dctcp.c. It only changes the type suffix modinfo prints.
---
net/ipv4/tcp_hybla.c | 16 ++++++++++++++--
1 file changed, 14 insertions(+), 2 deletions(-)
diff --git a/net/ipv4/tcp_hybla.c b/net/ipv4/tcp_hybla.c
index abd7d91807e54..b9b482180d30b 100644
--- a/net/ipv4/tcp_hybla.c
+++ b/net/ipv4/tcp_hybla.c
@@ -26,8 +26,20 @@ struct hybla {
};
/* Hybla reference round trip time (default= 1/40 sec = 25 ms), in ms */
-static int rtt0 = 25;
-module_param(rtt0, int, 0644);
+static unsigned int rtt0 = 25;
+
+static int rtt0_set(const char *val, const struct kernel_param *kp)
+{
+ /* avoid rtt0 * USEC_PER_MSEC overflow */
+ return param_set_uint_minmax(val, kp, 1, U32_MAX / USEC_PER_MSEC);
+}
+
+static const struct kernel_param_ops rtt0_ops = {
+ .set = rtt0_set,
+ .get = param_get_uint,
+};
+
+module_param_cb(rtt0, &rtt0_ops, &rtt0, 0644);
MODULE_PARM_DESC(rtt0, "reference rout trip time (ms)");
/* This is called to refresh values for hybla parameters */
--
2.43.0
^ permalink raw reply [flat|nested] 5+ messages in thread
* [PATCH net-next v3 3/3] tcp_cubic: fix divide by zero and endless loop on bad module params
2026-10-08 9:26 [PATCH net-next v3 0/3] tcp: fix a few divide-by-zero in congestion control modules Jiayuan Chen
2026-10-08 9:26 ` [PATCH net-next v3 1/3] tcp_bic: fix divide by zero on max_increment == 0 Jiayuan Chen
2026-10-08 9:26 ` [PATCH net-next v3 2/3] tcp_hybla: fix divide by zero on rtt0 " Jiayuan Chen
@ 2026-10-08 9:26 ` Jiayuan Chen
2026-10-08 9:30 ` [PATCH net-next v3 0/3] tcp: fix a few divide-by-zero in congestion control modules netdev-bot+sinfo
3 siblings, 0 replies; 5+ messages in thread
From: Jiayuan Chen @ 2026-10-08 9:26 UTC (permalink / raw)
To: netdev
Cc: Jiayuan Chen, Eric Dumazet, Eric Dumazet, Neal Cardwell,
Kuniyuki Iwashima, David S. Miller, Jakub Kicinski, Paolo Abeni,
Simon Horman, Stephen Hemminger, linux-kernel
beta_scale and cube_factor are computed once at module init, and
beta == 1024 or bic_scale == 0 is a divide by zero right there. Other
out of range values give garbage: negative beta can make beta_scale 0,
and bic_scale * 10 can overflow. Reject them. Read beta once, as it
can be written through sysfs before the init function runs.
A small beta also gives a small beta_scale, and (cwnd * beta_scale) >> 3
truncates to 0 for a tiny cwnd, so the TCP friendliness loop never
ends. Rather than testing delta on every ACK, make sure beta_scale is
at least 8 at init, so delta is >= 1 within the cwnd < 1 million
packets limit this code is designed for. This slows the TCP friendly
estimate for beta < 512, a backoff harder than Reno's 0.5, which is
not a setting anyone should use.
Fixes: df3271f3361b ("[TCP] BIC: CUBIC window growth (2.0)")
Suggested-by: Eric Dumazet <edumazet@kernel.org>
Reviewed-by: Eric Dumazet <edumazet@kernel.org>
Signed-off-by: Jiayuan Chen <jiayuan.chen@linux.dev>
---
(cwnd * beta_scale) can wrap for cwnd >= 33M packets, far beyond the
1 million packets this code is designed for, so no fast path check.
---
net/ipv4/tcp_cubic.c | 14 ++++++++++++--
1 file changed, 12 insertions(+), 2 deletions(-)
diff --git a/net/ipv4/tcp_cubic.c b/net/ipv4/tcp_cubic.c
index 119bf8cbb007c..a88e4bf86150f 100644
--- a/net/ipv4/tcp_cubic.c
+++ b/net/ipv4/tcp_cubic.c
@@ -500,16 +500,26 @@ static const struct btf_kfunc_id_set tcp_cubic_kfunc_set = {
static int __init cubictcp_register(void)
{
+ int b = READ_ONCE(beta);
int ret;
BUILD_BUG_ON(sizeof(struct bictcp) > ICSK_CA_PRIV_SIZE);
+ if (b < 0 || b >= BICTCP_BETA_SCALE ||
+ bic_scale <= 0 || bic_scale > INT_MAX / 10) {
+ pr_err("tcp_cubic: invalid beta %d or bic_scale %d\n",
+ b, bic_scale);
+ return -EINVAL;
+ }
+
/* Precompute a bunch of the scaling factors that are used per-packet
* based on SRTT of 100ms
*/
- beta_scale = 8*(BICTCP_BETA_SCALE+beta) / 3
- / (BICTCP_BETA_SCALE - beta);
+ beta_scale = 8 * (BICTCP_BETA_SCALE + b) / 3
+ / (BICTCP_BETA_SCALE - b);
+ /* bictcp_update() needs (cwnd * beta_scale) >> 3 to be >= 1 */
+ beta_scale = max(beta_scale, 8U);
cube_rtt_scale = (bic_scale * 10); /* 1024*c/rtt */
--
2.43.0
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH net-next v3 0/3] tcp: fix a few divide-by-zero in congestion control modules
2026-10-08 9:26 [PATCH net-next v3 0/3] tcp: fix a few divide-by-zero in congestion control modules Jiayuan Chen
` (2 preceding siblings ...)
2026-10-08 9:26 ` [PATCH net-next v3 3/3] tcp_cubic: fix divide by zero and endless loop on bad module params Jiayuan Chen
@ 2026-10-08 9:30 ` netdev-bot+sinfo
3 siblings, 0 replies; 5+ messages in thread
From: netdev-bot+sinfo @ 2026-10-08 9:30 UTC (permalink / raw)
To: Jiayuan Chen
Cc: netdev, Eric Dumazet, Neal Cardwell, Kuniyuki Iwashima,
David S. Miller, Jakub Kicinski, Paolo Abeni, Simon Horman,
Stephen Hemminger, linux-kernel
Hi!
This is an automated message. This series looks like a fix, but its
commit messages seem to be missing some information:
- Whether the issue was actually triggered, or is only theoretical
(e.g. found by code inspection). If it was triggered please include
the symptoms, like the stack trace or error messages.
Please do not repost the series just to address the above. Instead,
reply to this email with the missing information, so that reviewers
can take it into account. If the series needs another revision for
other reasons, please include the information in the commit messages
then.
The evaluation is done by an LLM so it may be wrong, if you think
that is the case please reply and explain.
^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2026-10-08 9:30 UTC | newest]
Thread overview: 5+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-08 9:26 [PATCH net-next v3 0/3] tcp: fix a few divide-by-zero in congestion control modules Jiayuan Chen
2026-10-08 9:26 ` [PATCH net-next v3 1/3] tcp_bic: fix divide by zero on max_increment == 0 Jiayuan Chen
2026-10-08 9:26 ` [PATCH net-next v3 2/3] tcp_hybla: fix divide by zero on rtt0 " Jiayuan Chen
2026-10-08 9:26 ` [PATCH net-next v3 3/3] tcp_cubic: fix divide by zero and endless loop on bad module params Jiayuan Chen
2026-10-08 9:30 ` [PATCH net-next v3 0/3] tcp: fix a few divide-by-zero in congestion control modules netdev-bot+sinfo
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®