* [PATCH] ipv6: exthdrs: copy old IPv6 header before skb_mac_header_rebuild() in ipv6_rpl_srh_rcv()
@ 2026-09-19 21:06 Hui Peng
2026-09-21 15:14 ` krzk
0 siblings, 1 reply; 2+ messages in thread
From: Hui Peng @ 2026-09-19 21:06 UTC (permalink / raw)
To: dsahern, idosch, davem, edumazet, kuba, pabeni
Cc: alex.aring, horms, netdev, linux-kernel
In ipv6_rpl_srh_rcv(), after pulling the compressed RPL SRH and calling
skb_push(skb, chdr_len) to expand the buffer for the decompressed SRH,
the function calls skb_mac_header_rebuild(skb) BEFORE copying the saved
IPv6 header from oldhdr to ipv6_hdr(skb).
When chdr_len - pull_len < skb->mac_len (for example, an 8-byte
expansion with a 14-byte Ethernet MAC header), the newly rebuilt MAC
header at [skb->data - skb->mac_len, skb->data) overlaps with the old
IPv6 header at [oldhdr, oldhdr + 40). Calling
skb_mac_header_rebuild(skb) first overwrites the beginning of oldhdr
(version, traffic class, flow label, payload_len, nexthdr, hop_limit,
and the start of saddr) with the Ethernet header bytes, and the
subsequent memmove(ipv6_hdr(skb), oldhdr, sizeof(struct ipv6hdr)) copies
those corrupted bytes into the new IPv6 header. Moreover, oldhdr's
nexthdr is only updated to NEXTHDR_ROUTING before the pull, which also
gets clobbered by the overlapping MAC rebuild.
Fix this by copying the 40-byte IPv6 header from oldhdr to skb->data
immediately after skb_push(skb, chdr_len) and before calling
skb_reset_network_header(skb) and skb_mac_header_rebuild(skb), and
explicitly setting ipv6_hdr(skb)->nexthdr = NEXTHDR_ROUTING.
Fixes: 8610c7c6e3bd ("net: ipv6: add support for rpl sr exthdr")
Assisted-by: LLM
Signed-off-by: Hui Peng <benquike@gmail.com>
---
net/ipv6/exthdrs.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/net/ipv6/exthdrs.c b/net/ipv6/exthdrs.c
index 09a4552f7f08..f9563294c5b9 100644
--- a/net/ipv6/exthdrs.c
+++ b/net/ipv6/exthdrs.c
@@ -598,11 +598,12 @@ static int ipv6_rpl_srh_rcv(struct sk_buff *skb, struct inet6_dev *idev)
oldhdr = ipv6_hdr(skb);
}
skb_push(skb, chdr_len);
+ memmove(skb->data, oldhdr, sizeof(struct ipv6hdr));
skb_reset_network_header(skb);
skb_mac_header_rebuild(skb);
skb_set_transport_header(skb, sizeof(struct ipv6hdr));
+ ipv6_hdr(skb)->nexthdr = NEXTHDR_ROUTING;
- memmove(ipv6_hdr(skb), oldhdr, sizeof(struct ipv6hdr));
memcpy(skb_transport_header(skb), chdr, (chdr->hdrlen + 1) << 3);
ipv6_hdr(skb)->payload_len = htons(skb->len - sizeof(struct ipv6hdr));
--
2.55.0.1082.g2b9226bbc0-goog
^ permalink raw reply [flat|nested] 2+ messages in thread* Re: [PATCH] ipv6: exthdrs: copy old IPv6 header before skb_mac_header_rebuild() in ipv6_rpl_srh_rcv()
2026-09-19 21:06 [PATCH] ipv6: exthdrs: copy old IPv6 header before skb_mac_header_rebuild() in ipv6_rpl_srh_rcv() Hui Peng
@ 2026-09-21 15:14 ` krzk
0 siblings, 0 replies; 2+ messages in thread
From: krzk @ 2026-09-21 15:14 UTC (permalink / raw)
To: Hui Peng
Cc: alex.aring, horms, kuba, pabeni, netdev, davem, linux-kernel,
dsahern, edumazet, idosch
On Sat, 19 Sep 2026 21:06:18 +0000, Hui Peng wrote:
> In ipv6_rpl_srh_rcv(), after pulling the compressed RPL SRH and calling
> skb_push(skb, chdr_len) to expand the buffer for the decompressed SRH,
> the function calls skb_mac_header_rebuild(skb) BEFORE copying the saved
> IPv6 header from oldhdr to ipv6_hdr(skb).
>
> When chdr_len - pull_len < skb->mac_len (for example, an 8-byte
> expansion with a 14-byte Ethernet MAC header), the newly rebuilt MAC
> header at [skb->data - skb->mac_len, skb->data) overlaps with the old
> IPv6 header at [oldhdr, oldhdr + 40). Calling
> skb_mac_header_rebuild(skb) first overwrites the beginning of oldhdr
> (version, traffic class, flow label, payload_len, nexthdr, hop_limit,
> and the start of saddr) with the Ethernet header bytes, and the
> subsequent memmove(ipv6_hdr(skb), oldhdr, sizeof(struct ipv6hdr)) copies
> those corrupted bytes into the new IPv6 header. Moreover, oldhdr's
> nexthdr is only updated to NEXTHDR_ROUTING before the pull, which also
> gets clobbered by the overlapping MAC rebuild.
>
> Fix this by copying the 40-byte IPv6 header from oldhdr to skb->data
> immediately after skb_push(skb, chdr_len) and before calling
> skb_reset_network_header(skb) and skb_mac_header_rebuild(skb), and
> explicitly setting ipv6_hdr(skb)->nexthdr = NEXTHDR_ROUTING.
>
> Fixes: 8610c7c6e3bd ("net: ipv6: add support for rpl sr exthdr")
> Assisted-by: LLM
> Signed-off-by: Hui Peng <benquike@gmail.com>
>
> ---
> net/ipv6/exthdrs.c | 3 ++-
> 1 file changed, 2 insertions(+), 1 deletion(-)
>
You sent multiple independent patches, to multiple independent
subsystems. The amount of these patches clearly suggest this was
AI generated and most likely not tested.
More importantly, you sent all this work without properly organizing
relevant patches into patchsets. This makes reviewing difficult
and might cause multiple reviewers to address the same issue.
Replying to the entire set is impossible and requires handling each
patch independently, instead of applying or discarding the set.
Maintainers also won't see the bigger picture of your work. Quite
worrying.
This is on the verge of hostile patch: bomb us with so many
contributions, we won't be able to handle them in efficient manner,
like responding ONCE to ask you to slow down. Considering all this
is untested and LLM generated, I have even more doubts whether this
should be considered for review.
Please read kernel documentation BEFORE posting more work. It will
explain you how to identify subsystems, how to organize your work per
subsystem, how to document usage of LLM and how what you should not
do if this was posted in a good faith.
Best regards,
Krzysztof
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-09-21 15:14 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-19 21:06 [PATCH] ipv6: exthdrs: copy old IPv6 header before skb_mac_header_rebuild() in ipv6_rpl_srh_rcv() Hui Peng
2026-09-21 15:14 ` krzk
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®