From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pl1-f174.google.com (mail-pl1-f174.google.com [209.85.214.174]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8C2AC369D78 for ; Tue, 19 May 2026 12:36:01 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.174 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779194162; cv=none; b=t9XoEDja/c+R2BhS+OKDMEP5KmtwD4oXTBaK0vrwQ1unel6pzgMqE4jQv0IFGYEVIGFN0Ke5wgGND7qIJzJ8Aikotmv7rsyVblPuCAfomlP0C+t/huEoxDJ+fXpsI9VK8RB8l0m4bMuQxLSXvj6Na2uXL076n+ZrT7rPAGzKNKg= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779194162; c=relaxed/simple; bh=lIc9IvGukuTxrcKPyEANUt/P7j7/XDF0to6T1xKrVwg=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=VFmuuktCaDUZKXh+14y6SLvp8LQKwD7KceaqoIsyG34Ptah6fXT/MbNiKxzXn6v39FRhDsd10wIKI2IySmblk0m/m4u8wIepONIuIYGeWRV6vQ2XnqX8Vm10JwaYdifxBLwSvpDLPdRIECdi+xBFt99k4y3c0XuYPifIax2slbY= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=RxdNV23U; arc=none smtp.client-ip=209.85.214.174 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="RxdNV23U" Received: by mail-pl1-f174.google.com with SMTP id d9443c01a7336-2b4583f0a1aso21764785ad.3 for ; Tue, 19 May 2026 05:36:01 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1779194159; x=1779798959; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=WnqfNLPf1FZpTLzCn6yNj1v+FRpfxLX1loWYM78LAiU=; b=RxdNV23U+rPsSJ2il8ENIcIFV40H/lty0OrdzTXSVqMXYIz66s5o3jbYDXuRgDRHZc mocdfsHTWeH9IxBBe0SpTmTOyhbvkoQYYcewzG1coz4ZXz9ebX1CjusnhKYHmlIAKyHG APx13kdteRvuESCs92OtIkWtLS64LSRezJpseyRGKI+MwXAvBcnDuCeLpXWa1lf1qcLV s94bvNCIl2PF6LeweFQBTzIQ6Xk74SazVQE0VsSY7VtGWCxu7IZZa7oc3ZMPTkFLf5z9 Aibou2FWyPxzTDquj6XAkfcb3Bs2SJ7ePLXMFsP97O+thyIjOqZtrtz29wNF/n+9vyWE 1hdA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779194159; x=1779798959; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=WnqfNLPf1FZpTLzCn6yNj1v+FRpfxLX1loWYM78LAiU=; b=N0jIDuZA6TMeHeYtuTY1zK10znfPmP7WVQxPfI2UcctM5p7S3TcZ9cUn9cwo3on13I 7ScexMMpZH3bz44TzX6EH53zLIBpae5oI2QpbAOeJEA4Ck+T4a7E71dnl2lf6YlJEFda WAnAVNoJ5eGg9JsdflzahlLI66/WSypPfc3Iky/G9n6YrzMXLJJclNvmmySDjlUTsDMV o3FYMgiObK/CXWT6OeCZounOqhlkvxrVJW7AlcYvADp5EsQTwgXckH/+3MCO9FQT+p3h s1b787R3Ni8K+4reEcrQOn0JKiT4HzWHJWRcTxxXDiQ8B+dKEUetuiLtPNrCeWvHXRew 00ng== X-Forwarded-Encrypted: i=1; AFNElJ8eXXHZI7FJeCM4mR615iCcDLZTGTywaoF2tfQJS0AEaG35086IH6XSBa1/e7X1nvH+Ri59Rc5DLGqmv5c=@vger.kernel.org X-Gm-Message-State: AOJu0YzkZItCZohbE+dx0W/kqStvXXTN6x08ra1h/+H6GGIxgWXMd518 tfeo4pDju7DTwiMfZWApsPBfYlF0b/SuTRu7LPr0g//Ia+yaOxiKiNIE X-Gm-Gg: Acq92OHTnIwXHtOqM6s809hYT6QbRIpm2gVgROn3EQlc2ndLP/rBVMcx/b1bu/OZ3gO /dW9fPok+dSKHaidW5zOFhrakFbU3pP5phpWZan687wWYZdlIl1Ad6JSPbTquYJTFNDzFJdK325 CrSwW++liGP3k2V53nZ4v2hoGg7xijfPVKwHxqkrJUJfZZuCQ/r5JUheyXKjKx/AANBlfnG66xX HmV1A54T6Jig/ghGVDH29T56Fnhfz3G//tJM5bxzZlIr8HWA21UPAWZ1eF83rLAOxg7vBwDa7nQ qerlygVqzG7L3hyFBrxa7l6k3c/vdgs4dWj9N+yw2OUmOg6fAXmk6Pq19kw35+LgIWS1WJaYVAZ AFMMuHTKiMeXGtYy0akDykfgTDJ3ebAVQaBEIfW0zwbKr0yO9aHf84SYbP+7SHFJh6a53wUQWFg PjHfGN0TEb0q+aGkCgIDrXTW5ZGLaM4J6ZIsrGiVHvbXqTTpUY X-Received: by 2002:a17:903:950:b0:2bd:a3c5:6d96 with SMTP id d9443c01a7336-2bda3c56ef9mr147376025ad.14.1779194158910; Tue, 19 May 2026 05:35:58 -0700 (PDT) Received: from csl-conti-dell7858.ntu.edu.sg ([155.69.195.57]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2bd5bd5fc60sm193216245ad.9.2026.05.19.05.35.56 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 19 May 2026 05:35:58 -0700 (PDT) From: Maoyi Xie To: Jakub Kicinski , "David S . Miller" , Paolo Abeni , Eric Dumazet , David Ahern Cc: Kuniyuki Iwashima , Steffen Klassert , Shaw Leon , netdev@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org Subject: [PATCH net v3 2/2] ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate(). Date: Tue, 19 May 2026 20:35:47 +0800 Message-Id: <20260519123547.2055911-3-maoyixie.tju@gmail.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260519123547.2055911-1-maoyixie.tju@gmail.com> References: <20260519123547.2055911-1-maoyixie.tju@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit After "ip6: vti: Use ip6_tnl.net in vti6_changelink()." in the same series, vti6_update() unlinks and relinks the tunnel through t->net. vti6_siocdevprivate() still uses dev_net(dev) for the collision lookup. For a tunnel migrated through IFLA_NET_NS_FD, dev_net(dev) is the new namespace, not t->net. The SIOCCHGTUNNEL path on a migrated tunnel then proceeds as follows: net = dev_net(dev) /* migrated netns */ t = vti6_locate(net, &p1, false) /* misses target in t->net */ ... t = netdev_priv(dev) vti6_update(t, &p1, false) /* mutates t->net's hash */ A caller in the migrated netns sets the migrated tunnel's parameters to those of a tunnel that lives only in the creation netns. The collision check in dev_net(dev) sees nothing. vti6_update() then prepends the migrated tunnel at the head of the creation netns hash bucket for those parameters. Subsequent lookups in the creation netns resolve to the migrated device. xfrm receive delivers packets matching those parameters through a device the caller controls. Reachable from an unprivileged user namespace ("unshare --user --map-root-user --net"). Cross tenant scope on container hosts. Use t->net for the SIOCCHGTUNNEL path on a non fallback device. The lookup then matches the namespace vti6_update() operates on. SIOCADDTUNNEL and SIOCCHGTUNNEL on the fallback device retain dev_net(dev), which equals init_net for the fallback. Fixes: 5e72ce3e3980 ("net: ipv6: Use link netns in newlink() of rtnl_link_ops") Suggested-by: Jakub Kicinski Cc: stable@vger.kernel.org # v5.15+ Signed-off-by: Maoyi Xie --- net/ipv6/ip6_vti.c | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/net/ipv6/ip6_vti.c b/net/ipv6/ip6_vti.c --- a/net/ipv6/ip6_vti.c +++ b/net/ipv6/ip6_vti.c @@ -834,15 +834,19 @@ vti6_siocdevprivate(struct net_device *dev, struct ifreq *ifr, void __user *data if (p.proto != IPPROTO_IPV6 && p.proto != 0) break; vti6_parm_from_user(&p1, &p); - t = vti6_locate(net, &p1, cmd == SIOCADDTUNNEL); if (dev != ip6n->fb_tnl_dev && cmd == SIOCCHGTUNNEL) { + struct ip6_tnl *self = netdev_priv(dev); + + t = vti6_locate(self->net, &p1, false); if (t) { if (t->dev != dev) { err = -EEXIST; break; } } else - t = netdev_priv(dev); + t = self; err = vti6_update(t, &p1, false); + } else { + t = vti6_locate(net, &p1, cmd == SIOCADDTUNNEL); } if (t) { -- 2.34.1