On Mon, Sep 14, 2026 at 2:04 AM Inbal Schussheim
<[email protected]> wrote:
>
> Exclude old ACKs before SND.UNA from the tcp fast path
> as well as ACKs after SND.NXT.
>
> Such ACKs will fall through to the slow path, where tcp_ack()
> performs the appropriate validation and challenge ACK handling
> according to RFC5961 and Commit 3d501dd326fb1c7 ("tcp: do not
> accept ACK of bytes we never sent").
>
> This prevents old ACKs from being accepted
> or modifying connection state as part of the fast path before
> appropriate ACK validation is applied.
> In particular, this prevents payload carried by a segment with
> an excessively old ACK from advancing RCV.NXT before the ACK
> is rejected.
>
> Fixes: 31770e34e43d ("tcp: Revert "tcp: remove header prediction"")
> Reported-by: Amit Klein <[email protected]>
> Reported-by: Tamir Shahar <[email protected]>
> Reported-by: Inbal Schussheim <[email protected]>

nit: (no need for a new version)
You are the patch author, the " Reported-by: Inbal Schussheim
<[email protected]>"
is redundant with Signed-off-by from the same person.

Reviewed-by: Eric Dumazet <[email protected]>

> Suggested-by: Eric Dumazet <[email protected]>
> Cc: [email protected]
> Signed-off-by: Inbal Schussheim <[email protected]>
> ---
>  net/ipv4/tcp_input.c | 3 ++-
>  1 file changed, 2 insertions(+), 1 deletion(-)
>
> diff --git a/net/ipv4/tcp_input.c b/net/ipv4/tcp_input.c
> index daff93d51342..03d317a58132 100644
> --- a/net/ipv4/tcp_input.c
> +++ b/net/ipv4/tcp_input.c
> @@ -6490,6 +6490,7 @@ static bool tcp_validate_incoming(struct sock *sk, 
> struct sk_buff *skb,
>   *       or pure receivers (this means either the sequence number or the ack
>   *       value must stay constant)
>   *     - Unexpected TCP option.
> + *     - ACK sequence number is outside [SND.UNA, SND.NXT].
>   *
>   *     When these conditions are not satisfied it drops into a standard
>   *     receive procedure patterned after RFC793 to handle all cases.
> @@ -6539,7 +6540,7 @@ void tcp_rcv_established(struct sock *sk, struct 
> sk_buff *skb)
>
>         if ((tcp_flag_word(th) & TCP_HP_BITS) == tp->pred_flags &&
>             TCP_SKB_CB(skb)->seq == tp->rcv_nxt &&
> -           !after(TCP_SKB_CB(skb)->ack_seq, tp->snd_nxt)) {
> +           between(TCP_SKB_CB(skb)->ack_seq, tp->snd_una, tp->snd_nxt)) {
>                 int tcp_header_len = tp->tcp_header_len;
>                 s32 delta = 0;
>                 int flag = 0;
> --
> 2.43.0
>

Reply via email to