* [PATCH net v4] net: erspan: set lltx to avoid sch_direct_xmit deadlock
@ 2026-09-16 6:13 Yun Zhou
2026-09-16 8:20 ` Ido Schimmel
0 siblings, 1 reply; 2+ messages in thread
From: Yun Zhou @ 2026-09-16 6:13 UTC (permalink / raw)
To: dsahern, idosch, davem, edumazet, kuba, pabeni, horms
Cc: netdev, linux-kernel, yun.zhou
erspan_xmit() re-enters the network stack via ip_tunnel_xmit(), causing
nested acquisition of _xmit_lock on the underlay device while already
holding the ERSPAN device's _xmit_lock, creating an ABBA deadlock:
sch_direct_xmit [lock erspan] -> erspan_xmit -> ip_tunnel_xmit ->
ip_output -> __dev_queue_xmit -> sch_direct_xmit [lock underlay]
Set dev->lltx = true so HARD_TX_LOCK() skips the spinlock for ERSPAN.
This is safe as erspan_xmit() has no shared mutable state: o_seqno is
atomic, TX stats are per-CPU u64_stats, dst_cache is per-CPU, and
o_flags is no longer modified in the xmit path since commit 9958e69b9893
("gre: fix ERSPAN o_flags race/corruption in xmit and fill_info").
GRETAP, the sibling device with identical xmit structure, already sets
lltx.
Reported-by: syzbot+9bda1b9fbb7fbdf9b62b@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=9bda1b9fbb7fbdf9b62b
Fixes: 84e54fe0a5ea ("gre: introduce native tunnel support for ERSPAN")
Fixes: 5a963eb61b7c ("ip6_gre: Add ERSPAN native tunnel support")
Cc: stable@vger.kernel.org
Signed-off-by: Yun Zhou <yun.zhou@windriver.com>
---
v4:
- refine commit message
v3:
- add fix for IPv6
v2:
- change subject prefix to [PATCH net]
net/ipv4/ip_gre.c | 2 ++
net/ipv6/ip6_gre.c | 2 ++
2 files changed, 4 insertions(+)
diff --git a/net/ipv4/ip_gre.c b/net/ipv4/ip_gre.c
index 82309efd417e..0058cb20e36a 100644
--- a/net/ipv4/ip_gre.c
+++ b/net/ipv4/ip_gre.c
@@ -1367,6 +1367,8 @@ static int erspan_tunnel_init(struct net_device *dev)
dev->features |= GRE_FEATURES;
dev->hw_features |= GRE_FEATURES;
dev->priv_flags |= IFF_LIVE_ADDR_CHANGE;
+ /* Skip TX lock: xmit re-enters stack, risking ABBA with underlay */
+ dev->lltx = true;
netif_keep_dst(dev);
return ip_tunnel_init(dev);
diff --git a/net/ipv6/ip6_gre.c b/net/ipv6/ip6_gre.c
index 8ebda0b6a78b..578fb3475f8c 100644
--- a/net/ipv6/ip6_gre.c
+++ b/net/ipv6/ip6_gre.c
@@ -1871,6 +1871,8 @@ static int ip6erspan_tap_init(struct net_device *dev)
dev->mtu -= 8;
dev->priv_flags |= IFF_LIVE_ADDR_CHANGE;
+ /* Skip TX lock: xmit re-enters stack, risking ABBA with underlay */
+ dev->lltx = true;
ip6erspan_tnl_link_config(tunnel, 1);
netdev_hold(dev, &tunnel->dev_tracker, GFP_KERNEL);
--
2.43.0
^ permalink raw reply [flat|nested] 2+ messages in thread* Re: [PATCH net v4] net: erspan: set lltx to avoid sch_direct_xmit deadlock
2026-09-16 6:13 [PATCH net v4] net: erspan: set lltx to avoid sch_direct_xmit deadlock Yun Zhou
@ 2026-09-16 8:20 ` Ido Schimmel
0 siblings, 0 replies; 2+ messages in thread
From: Ido Schimmel @ 2026-09-16 8:20 UTC (permalink / raw)
To: Yun Zhou
Cc: dsahern, davem, edumazet, kuba, pabeni, horms, netdev, linux-kernel
On Wed, Sep 16, 2026 at 02:13:14PM +0800, Yun Zhou wrote:
> erspan_xmit() re-enters the network stack via ip_tunnel_xmit(), causing
> nested acquisition of _xmit_lock on the underlay device while already
> holding the ERSPAN device's _xmit_lock, creating an ABBA deadlock:
>
> sch_direct_xmit [lock erspan] -> erspan_xmit -> ip_tunnel_xmit ->
> ip_output -> __dev_queue_xmit -> sch_direct_xmit [lock underlay]
>
> Set dev->lltx = true so HARD_TX_LOCK() skips the spinlock for ERSPAN.
> This is safe as erspan_xmit() has no shared mutable state: o_seqno is
> atomic, TX stats are per-CPU u64_stats, dst_cache is per-CPU, and
> o_flags is no longer modified in the xmit path since commit 9958e69b9893
> ("gre: fix ERSPAN o_flags race/corruption in xmit and fill_info").
> GRETAP, the sibling device with identical xmit structure, already sets
> lltx.
In v3 I asked that the commit message:
1. State that the overlay and underlay devices should be of the same
type (both erspan or both ip6erspan) for the splat to happen.
2. Mention the IPv6 fix. Currently you only describe the IPv4 path:
erspan_xmit() -> ip_tunnel_xmit()
https://lore.kernel.org/netdev/20260803151146.GA766007@shredder/
>
> Reported-by: syzbot+9bda1b9fbb7fbdf9b62b@syzkaller.appspotmail.com
> Closes: https://syzkaller.appspot.com/bug?extid=9bda1b9fbb7fbdf9b62b
> Fixes: 84e54fe0a5ea ("gre: introduce native tunnel support for ERSPAN")
> Fixes: 5a963eb61b7c ("ip6_gre: Add ERSPAN native tunnel support")
> Cc: stable@vger.kernel.org
> Signed-off-by: Yun Zhou <yun.zhou@windriver.com>
> ---
> v4:
> - refine commit message
>
> v3:
> - add fix for IPv6
>
> v2:
> - change subject prefix to [PATCH net]
>
> net/ipv4/ip_gre.c | 2 ++
> net/ipv6/ip6_gre.c | 2 ++
> 2 files changed, 4 insertions(+)
>
> diff --git a/net/ipv4/ip_gre.c b/net/ipv4/ip_gre.c
> index 82309efd417e..0058cb20e36a 100644
> --- a/net/ipv4/ip_gre.c
> +++ b/net/ipv4/ip_gre.c
> @@ -1367,6 +1367,8 @@ static int erspan_tunnel_init(struct net_device *dev)
> dev->features |= GRE_FEATURES;
> dev->hw_features |= GRE_FEATURES;
> dev->priv_flags |= IFF_LIVE_ADDR_CHANGE;
> + /* Skip TX lock: xmit re-enters stack, risking ABBA with underlay */
Nit: I would drop this comment. It doesn't add anything and we don't
have it above similar assignments in the file.
> + dev->lltx = true;
> netif_keep_dst(dev);
>
> return ip_tunnel_init(dev);
> diff --git a/net/ipv6/ip6_gre.c b/net/ipv6/ip6_gre.c
> index 8ebda0b6a78b..578fb3475f8c 100644
> --- a/net/ipv6/ip6_gre.c
> +++ b/net/ipv6/ip6_gre.c
> @@ -1871,6 +1871,8 @@ static int ip6erspan_tap_init(struct net_device *dev)
> dev->mtu -= 8;
>
> dev->priv_flags |= IFF_LIVE_ADDR_CHANGE;
> + /* Skip TX lock: xmit re-enters stack, risking ABBA with underlay */
Same.
> + dev->lltx = true;
> ip6erspan_tnl_link_config(tunnel, 1);
>
> netdev_hold(dev, &tunnel->dev_tracker, GFP_KERNEL);
> --
> 2.43.0
>
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-09-16 8:20 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-16 6:13 [PATCH net v4] net: erspan: set lltx to avoid sch_direct_xmit deadlock Yun Zhou
2026-09-16 8:20 ` Ido Schimmel
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®