net/sched: cake: reject overhead values that underflow length

[ Upstream commit b7f97cae7e ]

CAKE accepts signed overhead values and stores them in an s16, but the
adjusted packet length calculation uses unsigned arithmetic.  A negative
effective length can therefore wrap to a large value.

Such configurations make rate accounting depend on integer wraparound
rather than on the packet size userspace intended to model.  A static
netlink lower bound is not enough because packets reaching CAKE can be
smaller than any reasonable manual-overhead allowance.

Fold the signed overhead adjustment into the existing datapath MPU clamp
so negative adjusted lengths are clamped before link-layer framing
adjustments.

Fixes: a729b7f0bd ("sch_cake: Add overhead compensation support to the rate shaper")
Assisted-by: Codex:gpt-5.5-cyber-preview
Signed-off-by: Samuel Moelius <sam.moelius@trailofbits.com>
Acked-by: Toke Høiland-Jørgensen <toke@toke.dk>
Link: https://patch.msgid.link/20260702000758.297407.e5c888d9d99d.cake-overhead-underflow@trailofbits.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
This commit is contained in:
Samuel Moelius
2026-07-24 16:03:28 +02:00
committed by Greg Kroah-Hartman
parent ff431529d3
commit 336c1e414f
+1 -4
View File
@@ -1382,10 +1382,7 @@ static u32 cake_calc_overhead(struct cake_sched_data *q, u32 len, u32 off)
if (q->min_netlen > len)
q->min_netlen = len;
len += q->rate_overhead;
if (len < q->rate_mpu)
len = q->rate_mpu;
len = max((s32)len + q->rate_overhead, (s32)q->rate_mpu);
if (q->atm_mode == CAKE_ATM_ATM) {
len += 47;