From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-lr2-f12.google.com (mail-lr2-f12.google.com [74.125.230.76]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 954C73016F5 for ; Sun, 13 Sep 2026 03:49:48 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.230.76 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789271390; cv=none; b=JIeXGoXOk4ASFv+np4c+TzNcjIUQvK6O+MiKmM0EhZfDrbnifTXv+R5TaNq9+sSgWwbGOnza/yNeX7qNhW3MiRLqBU7qB9FUOc/OhBy6vciimMfQ5WtIqOpwv8XmQtYDgpPGP9kqFLP6RyCXaHrT/tL/gQCUscrtoGlE2hYfJqM= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789271390; c=relaxed/simple; bh=gMpfD+mqQiDzLTP0fxIcjUewF8bwoxfTKr+VsxpO3rs=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=IcGGJ8XuCs1zGXIikRKWhXI87LQguFX8gNxZfjMSf7JCnsKBtnibNgtq9Czx1wR54nlEaIfoS9yBoE2WzPBc9SN/mfuSn2GztJaRmeZTOSlFZWvV/zWQjjPjcWO5U9+KnfIyVjN6VzMJaOAewZYYdPCpEDIBvKH1KaMLmePHoMk= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=MTUEhmFo; arc=none smtp.client-ip=74.125.230.76 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="MTUEhmFo" Received: by mail-lr2-f12.google.com with SMTP id 38308e7fff4ca-3a306a4f735so6972921fa.1 for ; Sat, 12 Sep 2026 20:49:48 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789271386; x=1789876186; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=BkACxqCXl6mybpuTCqEI04LMPdFiJukVxDGD6ehdJS0=; b=MTUEhmFoWPnUWQeUK9wXRvu/lGrp8bIS7tOvBHlehTp2MXYw1EWlyMbfY2jVJOC6wm P2QZZ5GAaCJsJD2p68pGHZxqBMey+yHVJSQ7dMfjYXr5PH+f/Iu6D8h9iZM1AvsPuf5X h+AH0kfUmg7mVhDF4UbwNLUXsXuTNaoyfXO2Et7vFgRRWQvJJQ6IK1CHGWr6wGDQZqiZ hQ+nnZjQNjWD3N92fBRsInVljnsN5amikebPFmcS37RLWLLrDLLVl3igYmRd58laY6Hb 3b8GNIqB26/g5kpjjmVHIhFtjFX1IzY1k0WqeNlg87Y0IJg5+cOcvxznZymi4pmMotDc eWjQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789271386; x=1789876186; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=BkACxqCXl6mybpuTCqEI04LMPdFiJukVxDGD6ehdJS0=; b=ILhSItXpw211GsFHHzVHkGghohW0HYqyQwxouyuvwIwYqoO52T0GxMccnHTbUQ5HWe s7NRk9UIGoWCC0Bg7BcLFMEPfpmHpeiN4E5BRVyT52Vcv4f3xkAAwHxXRk5xht3ovG0U sOIDTdR0m60Kgiq2nnuTLf6kk8K/knsJLttlR/xcsQmi6Xuk4dPI9GeoMqveOu1n2c8b xc0strYb8ss9i1vyCps6HrtgaobrkobZoAmfN/TAmO+hOom7vKlBP8+sLamUnJQQ2qe+ kHM0kDhi36TOOozADRKUB9dFusVzn/6A9pFj0IblqfPI8GBoCO9tKcRziL+q8vXe2IiF moLw== X-Forwarded-Encrypted: i=1; AKwUvByyG167FVgHao5e0JhRRT75QCd9lK4v1yg0PaVoD+au5keCKvVpbh2fR4ruN14Am03W6KXP3ZdlSM2/YyM=@vger.kernel.org X-Gm-Message-State: AFuF++mWiyDtIaWn4eANHKJJeMu3X/m/kECdC9uacv9n8l1nXUDykxEv uAZ3zjwWlXMIrLHJG5DN23Yj6gITGNZYi/CrlNUz5ivJB3ra3HCTscNC X-Gm-Gg: AYBFou2FZQr7GvxFvRz2XmngFYPszTht7tl+8/ZY43GgljGJP1SR6863sJjwnmloswZ WvXiaK/lpXvtAkOHM50z5zEQG5Jrizz2IngFIZ+XBI3PHl7TZTLIk1JQ3QfZZQtyxS11KNTpz1M 7LYiupHwTNPnFfBzXrxkUodYpKGpwJWLcfT3EtR+LwpUKIF8h4CFdo81fjqhwPRmlclrFh8sr1J tWYbFGA3SxPfI8GV1GZezUvwYbIX7qKR7K79ar4SgQKxp5avb+QX3v6YA3ZUZ1XtlO6JlFzhxB3 gvfy89R5xA9qJ+2IVVizmkpfKDYT4/y/932CqFa08lO2UlHUYaU37/R8yER9G0+48t2z/F34yxV WGaK256zvG9v8InW9h1Ay4DRuB0TU+eqjeCjUsDJrLhKl/6c62Dq/IPkYMznC0Vu0VufdF0AXb2 POScqpPuJolQFnjGF3diJ0pYN6x/QBgXvIiHujR3ycGFaFr2MgmDwM0mvB1ziEqr8WzZ0WXhWd/ CwCEu/Bj6zLm1JVdeVvDZ/flIKqIj630xksPORs06eP X-Received: by 2002:a2e:b894:0:b0:3a3:74b9:8a7f with SMTP id 38308e7fff4ca-3a5b384d6efmr6117411fa.24.1789271385981; Sat, 12 Sep 2026 20:49:45 -0700 (PDT) Received: from dau-home-pc.. ([95.139.134.117]) by smtp.gmail.com with ESMTPSA id 38308e7fff4ca-3a5a332737dsm17277051fa.22.2026.09.12.20.49.43 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 12 Sep 2026 20:49:44 -0700 (PDT) From: Anton Danilov To: netdev@vger.kernel.org Cc: "David S . Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , David Ahern , Simon Horman , Ido Schimmel , linux-kernel@vger.kernel.org Subject: [PATCH net-next v2 0/8] tunnels: add core and gre drop reasons Date: Sun, 13 Sep 2026 06:49:29 +0300 Message-ID: <20260913034937.875068-1-littlesmilingcloud@gmail.com> X-Mailer: git-send-email 2.47.3 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Only vxlan reports drop reasons among the tunnel drivers today. Everything else, on both the receive and the transmit side, ends in a plain kfree_skb(), so a packet that a tunnel throws away is invisible to dropwatch, drop_monitor and perf trace -e skb:kfree_skb. The device counters group the failures coarsely: rx_errors and tx_errors each cover half a dozen unrelated conditions. This series covers the generic paths shared by ipip, sit, vti, gre and their IPv6 counterparts, plus the GRE specific parsing, on both directions. A later series will do the same for geneve, bareudp, fou and the remaining IP in IP drivers. Patches 1-2 convert the generic receive paths, ip_tunnel_rcv() and __ip6_tnl_rcv(). Two reasons are added: TNL_OPT_MISMATCH the options a packet carries do not match the tunnel configuration TNL_OLD_SEQ the sequence number is older than the one the tunnel expects, next to the existing TCP_OLD_SEQUENCE The second one has a failure mode worth naming: when a peer reboots, its outgoing sequence number restarts at zero and the receiver drops everything until its own counter catches up. That is indistinguishable from a misconfiguration by the counters alone. Patches 3-5 do the GRE specific receive path. gre_parse_header() returns -EINVAL for six different reasons, and the only detail its callers could get was a csum_err flag that none of them read: both ip_gre and ip6_gre declared it, passed it in and ignored it. It is replaced by a drop reason. Three reasons are added, mirroring vxlan: GRE_INVALID_HDR, GRE_CSUM and GRE_TUNNEL_NOT_FOUND. Patches 6-8 do the transmit side, about forty failure paths across ip_tunnel, ip_gre, ip6_tunnel and ip6_gre. One reason is added, TNL_ENCAP, for a failure to build the encapsulation header. The transmit side has its own case worth naming: tnl_update_pmtu() returns -E2BIG after it has already sent an ICMP fragmentation needed back, which is path MTU discovery working exactly as intended, yet the drop lands in tx_errors next to genuine failures. An MTU black hole cannot be told from a broken route by looking at the counters. Drop reasons on transmit are not new: vxlan already reports several from its xmit path, and ip_tunnel_core.c reports RECURSION_LIMIT. Tested under virtme-ng with a script that builds tunnel pairs over veth in network namespaces, makes each of them fail in one specific way and reads the reason back from the skb:kfree_skb tracepoint: twelve cases, each reporting the expected reason from the expected function. Breaking the new mechanisms on purpose makes exactly the corresponding cases fail. No DEBUG_NET splat from the SKB_NOT_DROPPED_YET check in sk_skb_reason_drop(). v1 carried that script as three selftest patches; they are dropped here. Changes since v1: - dropped the three selftest patches (Jakub) - renamed IP_TUNNEL_CFG_OPTS_MISMATCH to TNL_OPT_MISMATCH (Jakub); renamed the other two reasons the series adds for the generic paths, IP_TUNNEL_OLD_SEQ and IP_TUNNEL_ENCAP, to TNL_OLD_SEQ and TNL_ENCAP so that the three do not end up under two prefixes - documented the new @reason parameter of ip6_tnl_xmit() (Jakub) - fixed the local variable ordering in the blocks this series adds declarations to (Jakub) - rebased on current net-next - v1: https://lore.kernel.org/netdev/20260831215137.549324-1-littlesmilingcloud@gmail.com/ Anton Danilov (8): ip_tunnel: add drop reasons to the generic RX path ip6_tunnel: add drop reasons to the generic RX path gre: make gre_parse_header() report a drop reason ip_gre: add drop reasons to the RX path ip6_gre: add drop reasons to the RX path ip_tunnel: add drop reasons to the transmit path ip_gre: add drop reasons to the transmit path ip6_tunnel: add drop reasons to the transmit path include/net/dropreason-core.h | 38 ++++++++ include/net/gre.h | 2 +- include/net/ip6_tunnel.h | 3 +- net/ipv4/gre_demux.c | 51 ++++++++--- net/ipv4/ip_gre.c | 144 +++++++++++++++++++++--------- net/ipv4/ip_tunnel.c | 60 ++++++++++--- net/ipv6/ip6_gre.c | 163 ++++++++++++++++++++++++---------- net/ipv6/ip6_tunnel.c | 96 ++++++++++++++------ 8 files changed, 415 insertions(+), 142 deletions(-) -- 2.47.3