mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: netdev-bot+sashiko@kernel.org
To: fmancera@suse.de
Cc: netdev@vger.kernel.org, horms@kernel.org, kuba@kernel.org,
	pabeni@redhat.com, edumazet@kernel.org, davem@davemloft.net,
	edumazet@google.com, ebiggers@kernel.org, ardb@kernel.org,
	krzk@kernel.org, linux-kernel@vger.kernel.org
Subject: Re: [PATCH 06/16 net-next v2] ipv4: udp: split IPv4 specific logic into udp_ipv4.c
Date: Fri, 02 Oct 2026 10:32:22 +0000	[thread overview]
Message-ID: <179093714260.434549.7181479065811703026@kernel.org> (raw)
In-Reply-To: <20260928193046.6698-7-fmancera@suse.de>

Thank you for your contribution! Sashiko AI review found 1 potential
issue(s) to consider.

Critical: 0 · High: 1 · Medium: 0 · Low: 0

If you believe none of the issues are legitimate, please reply to each
issue of Medium severity or higher and explain why the AI is wrong.
If any of them are legitimate and you plan to respin, please let patchwork
know by including "pw-bot: cr" as a separate line at the end of your reply
(one such reply per series is enough).

- [High] The patch moves udp_rcv() from net/ipv4/udp.c into the new
  net/ipv4/udp_ipv4.c, but the moved copy is stale and undoes commit…

--

ipv4: udp: split IPv4 specific logic into udp_ipv4.c

This patch moves the IPv4 specific UDP code (lookup, input/output, error
handling, multicast and the AF_INET udp_prot) out of net/ipv4/udp.c and
into a new net/ipv4/udp_ipv4.c. The new file is built only when
CONFIG_IPV4 is enabled, which is a step toward building INET without IPv4.

> diff --git a/net/ipv4/udp.c b/net/ipv4/udp.c
> index b534b85bc623c..0f2ff5a9d4ae4 100644
> --- a/net/ipv4/udp.c
> +++ b/net/ipv4/udp.c

[ ... ]

> -int udp_rcv(struct sk_buff *skb)
> -{
> -	struct rtable *rt = skb_rtable(skb);
> -	struct net *net = dev_net(skb->dev);
> -	struct sock *sk = NULL;
> -	__be32 saddr, daddr;
> -	unsigned int ulen;
> -	struct udphdr *uh;
> -	bool refcounted;
> -	int drop_reason;
> -
> -	drop_reason = SKB_DROP_REASON_NOT_SPECIFIED;
> -
> -	/*
> -	 *  Validate the packet.
> -	 */
> -	if (!pskb_may_pull(skb, sizeof(struct udphdr)))
> -		goto drop;		/* No space for header. */
> -
> -	uh   = udp_hdr(skb);
> -	ulen = udp_get_len(skb, uh, 0);

[ ... ]

> diff --git a/net/ipv4/udp_ipv4.c b/net/ipv4/udp_ipv4.c
> new file mode 100644
> index 0000000000000..466008c218df4
> --- /dev/null
> +++ b/net/ipv4/udp_ipv4.c

[ ... ]

> +int udp_rcv(struct sk_buff *skb)
> +{
> +	struct rtable *rt = skb_rtable(skb);
> +	struct net *net = dev_net(skb->dev);
> +	struct sock *sk = NULL;
> +	unsigned short ulen;
> +	__be32 saddr, daddr;
> +	struct udphdr *uh;
> +	bool refcounted;
> +	int drop_reason;
> +
> +	drop_reason = SKB_DROP_REASON_NOT_SPECIFIED;
> +
> +	/*
> +	 *  Validate the packet.
> +	 */
> +	if (!pskb_may_pull(skb, sizeof(struct udphdr)))
> +		goto drop;		/* No space for header. */
> +
> +	uh   = udp_hdr(skb);
> +	ulen = ntohs(uh->len);
> +	saddr = ip_hdr(skb)->saddr;
> +	daddr = ip_hdr(skb)->daddr;
> +
> +	if (ulen > skb->len)
> +		goto short_packet;
> +
> +	if (ulen < sizeof(*uh))
> +		goto short_packet;

[Severity: High]
The moved copy of udp_rcv() doesn't match the one being removed from
net/ipv4/udp.c. Was this copied from a tree older than commit
efbc1aa8ed54 ("udp: Support gro_ipv4_max_size > 65536")?

The removed version has:

	unsigned int ulen;
	...
	ulen = udp_get_len(skb, uh, 0);

The new version has:

	unsigned short ulen;
	...
	ulen = ntohs(uh->len);

Those are the two lines efbc1aa8ed54 replaced.

The GRO completion side still relies on the newer rule. Both
udp_gro_complete() and the fraglist branch of udp4_gro_complete() call
udp_set_len(), which writes a zero length for large aggregates:

include/linux/udp.h:udp_set_len() {
	uh->len = len < GRO_LEGACY_MAX_SIZE ? htons(len) : 0;
}

udp_get_len() is the helper that reads this marker back:

include/linux/udp.h:udp_get_len() {
	if (uh->len)
		return ntohs(uh->len);
	if (skb_is_gso(skb)) /* BIG TCP */
		return skb->len - dataoff;
	return 0;
}

Take gro_ipv4_max_size or gro_max_size set above 65536, with BIG TCP
running over VXLAN or GENEVE. When a 64KB or larger aggregate reaches
udp_rcv(), won't ulen be 0 here? The "ulen < sizeof(*uh)" check would
then send it to short_packet, and the packet would be dropped with
SKB_DROP_REASON_PKT_TOO_SMALL and counted in UDP_MIB_INERRORS.

__udp6_lib_rcv() in net/ipv6/udp.c still uses udp_get_len(), so IPv4
and IPv6 would now read the same header field differently.

Restoring only the udp_get_len() call would not be enough. With
ulen still declared unsigned short, lengths above 65535 would be
truncated. Could both the unsigned int declaration and the
udp_get_len() call be carried over, so this stays a pure code move as
the commit message describes?

> +
> +	if (ulen < skb->len) {
> +		if (pskb_trim_rcsum(skb, ulen))
> +			goto short_packet;
> +
> +		uh = udp_hdr(skb);
> +	}

[ ... ]

-- 
Sashiko AI review · https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260928193046.6698-1-fmancera%40suse.de

  reply	other threads:[~2026-10-02 10:32 UTC|newest]

Thread overview: 32+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <20260928193046.6698-1-fmancera@suse.de>
2026-09-28 19:29 ` [PATCH 01/16 net-next v2] ipv4: introduce CONFIG_IPV4 to decouple the IPv4 stack Fernando Fernandez Mancera
2026-10-02 10:32   ` netdev-bot+sashiko
2026-09-28 19:29 ` [PATCH 02/16 net-next v2] net: core: add IPv4 fallback stubs and guards for CONFIG_IPV4=n Fernando Fernandez Mancera
2026-10-02 10:32   ` netdev-bot+sashiko
2026-09-28 19:29 ` [PATCH 03/16 net-next v2] net: inet: relocate ip_generic_getfrag and guard IPv4 socket logic Fernando Fernandez Mancera
2026-10-02 10:32   ` netdev-bot+sashiko
2026-09-28 19:30 ` [PATCH 04/16 net-next v2] tcp: move protocol agnostic TCP functions out of tcp_ipv4.c Fernando Fernandez Mancera
2026-10-02 10:32   ` netdev-bot+sashiko
2026-09-28 19:30 ` [PATCH 05/16 net-next v2] ipv4: raw: split IPv4 specific logic into raw_ipv4.c Fernando Fernandez Mancera
2026-10-02 10:32   ` netdev-bot+sashiko
2026-09-28 19:30 ` [PATCH 06/16 net-next v2] ipv4: udp: split IPv4 specific logic into udp_ipv4.c Fernando Fernandez Mancera
2026-10-02 10:32   ` netdev-bot+sashiko [this message]
2026-09-28 19:30 ` [PATCH 07/16 net-next v2] ipv4: icmp: split IPv4 specific logic into icmp_ipv4.c Fernando Fernandez Mancera
2026-10-02 10:32   ` netdev-bot+sashiko
2026-09-28 19:30 ` [PATCH 08/16 net-next v2] ipv4: ping: split IPv4 specific logic into ping_ipv4.c Fernando Fernandez Mancera
2026-09-28 19:30 ` [PATCH 09/16 net-next v2] ipv4: fib: split common nexthop logic to fib_core.c Fernando Fernandez Mancera
2026-10-02 10:32   ` netdev-bot+sashiko
2026-09-28 19:30 ` [PATCH 10/16 net-next v2] tunnels: guard IPv4 tunnel functions with CONFIG_IPV4 Fernando Fernandez Mancera
2026-09-28 19:30 ` [PATCH 11/16 net-next v2] ipv4: disable IPv4-only sysctls when CONFIG_IPV4=n Fernando Fernandez Mancera
2026-09-29  7:14   ` Joel Granados
2026-09-29  8:20     ` Fernando Fernandez Mancera
2026-10-02 10:32   ` netdev-bot+sashiko
2026-09-28 19:30 ` [PATCH 12/16 net-next v2] netfilter: ipv4: guard ip_route_me_harder() with CONFIG_IPV4 Fernando Fernandez Mancera
2026-10-02 10:32   ` netdev-bot+sashiko
2026-09-28 19:30 ` [PATCH 13/16 net-next v2] net: bridge: guard ARP/RARP proxy and suppression " Fernando Fernandez Mancera
2026-10-02 10:32   ` netdev-bot+sashiko
2026-09-28 19:30 ` [PATCH 14/16 net-next v2] wifi: mac80211: replace CONFIG_INET with CONFIG_IPV4 guards Fernando Fernandez Mancera
2026-09-28 19:30 ` [PATCH 15/16 net-next v2] netlabel: cipso: introduce CONFIG_CIPSO to decouple IPv4 dependency Fernando Fernandez Mancera
2026-09-30  1:37   ` Paul Moore
2026-10-02 10:32   ` netdev-bot+sashiko
2026-09-28 19:30 ` [PATCH 16/16 net-next v2] ipv4: make CONFIG_IPV4 boolean Fernando Fernandez Mancera
2026-10-02 10:32   ` netdev-bot+sashiko

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=179093714260.434549.7181479065811703026@kernel.org \
    --to=netdev-bot+sashiko@kernel.org \
    --cc=ardb@kernel.org \
    --cc=davem@davemloft.net \
    --cc=ebiggers@kernel.org \
    --cc=edumazet@google.com \
    --cc=edumazet@kernel.org \
    --cc=fmancera@suse.de \
    --cc=horms@kernel.org \
    --cc=krzk@kernel.org \
    --cc=kuba@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®