From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 5B20931E106 for ; Thu, 1 Oct 2026 12:19:55 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.225.141 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790857196; cv=none; b=a1UU0+YjRQWPx9Tp2ieNtg3RGyfCpH5L7W45U6z3a4RTTS9BaqO2hyhSh3sFDzTZgrOB1JEJEM6dtXvR70tzUk7Fvg7uxataUqhHB2JntVvJIBJpDncLBBruPwnf0n+GxQtwyxVoABtGymACTSUZwaAUea55vUjlW36BusllFBk= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790857196; c=relaxed/simple; bh=nRbfMwngHUKsiqlMccbHxJzWFiHdULg4qLygabHKz1s=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=Yr7ce1a+w0Zu0sKOOb85LkwqwiWa38HfJli1kOfat/Dm+Zx1DnKGVj3gGbjBTaXQFdFrhI/cHOytagVWVPOPNhb4nVFjzyMp38e0LaBfwC4mQF2+HR1OjZaSWKd9z2QyR/X4p6J1YnjxSaIizXKue16IUcaGG0amxjIrP+kDwTQ= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=FssrDfft; arc=none smtp.client-ip=74.125.225.141 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="FssrDfft" Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-49e7d2bb404so12290895e9.1 for ; Thu, 01 Oct 2026 05:19:55 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790857194; x=1791461994; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=VqJs1lu9yYEnrWjWAn/NSnJmVPwl6cd9S/MSijAAG84=; b=FssrDfftmVycbPoCtmvGbdHXG4hyJu2I936FwJ47OhkXC2ycAYG9xb10wsp5Nukbde s9vbGWSId7hNsjJs09tbC433CZy94XpDmXJWJW+qm3nY+h+/b2OdxJNFtrvOKeHdaPrl 3bekCkKDkUimH9GalBB4DzZnjEeC702R1LalEob7bgm0z3PhtxRpM4DRXsVoCrb4BRH1 sQI3jMlOzuUnvMl9ni7uU2xGv8PmXPIc0XeMwNwAZveMgyWCViejB7kLMeBNjh23sV0W ztf7qkM4sFbAAJvGHc80S7GfqLa/f5FAmaJ+FHkgbgLhMGy3NHa1e+ePRfAXCibPRwvP XkDg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790857194; x=1791461994; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=VqJs1lu9yYEnrWjWAn/NSnJmVPwl6cd9S/MSijAAG84=; b=KINmN/RN8HpskxL75VYc44E0n8GHv1s7zsByjub5Vf2wAXSdAHol4HPdpvNEKoGOF3 OqChzLD/LMiqMYc2Xc9Sj1R8My/nKx+3urg2VcYyLA4rxfrQcAtGabGVo6osl3jqDE9s 1QK68ZhOCwJpC8VMyNHiwcfC7VqQzuY97wu5V5vypEMpyEVtes7Q9lEpl2FMLO7DonZz P+ke6VZsxsnYMYdyfdtjjcApAsUHh+YryWASxlwLElelipny9zwYCfLE/MsfUpXBKTBX X2vyvoXAkHY47GBYi93oUum/YZ0GCf/bkBcQrCBYJbp86F0WmtpRUVrouCJo5jQM7ZdR z/Pg== X-Forwarded-Encrypted: i=1; AKwUvBwaFkPA5fb7l/FYwQEx4NtmZMxMZZJNg8OKDKdaKDnzh/IUrDcRgQIi/TEGkU8PjZREAb7tyremoxlj1+w=@vger.kernel.org X-Gm-Message-State: AFuF++kSku6aGZclSbkyC8zPPv1kmadplomzJi/rhNwNx0mOeSyWTYXW Q4qNinupNTUXJwe5M69iOAhFoWHBfdIpD6zABD9ldKl2A5cm2r1Zl936 X-Gm-Gg: AYBFou3w7vptGC0ZLVEE4bVKOygY35OOrq7OFI0SfX3oEcXMzfNAC5CTJmFkzpEK/JD jnTIi2DT5lSPmJvam4tDoQbcB4Dp3l3n/rVAGhKSFKNejvxRIJbHJoGRVyah+nq8BXzcu4bX4Ez PfLdPk9YqV9pcPHRA9rBqDkx32TByyvw2tSYFOZUsrJk3HhA5xsi/gB9zjzmJIUrrnv/7lME48D hNXZ3brb2xk1JEK6hGStgx0oWNni2ndxEPbBMfyfvPLat7bZzjUzMLzlcheK3fR36hmaaNhgiwZ addSa3+KBy7+mE9GZfw6vyS1S9rsLvGnz/rW/bTS2IND+m/IN1Dlt3F4HjKgmgcjXpG9TLKlV7f tXko6X9x6WWkjFTqr6oPyEa2n1HP2c3RMda++nOVgGReWOxkodWaAbix63gxsfMp43LmMEXh+OL RfVbZgUSJmsbON0QWEKxmxA1YjyveP0OWkBtzmyd0D8zp6+xl9ZbMUODze3Gkf40JyUR52iQNH2 HG3/l33rqAKuE9IFG6ZsY2mDL7q47jsUDkSU2Ve5FQj5lh2 X-Received: by 2002:a05:600c:859c:b0:49c:e37e:4389 with SMTP id 5b1f17b1804b1-4a01eaf5b37mr37503985e9.4.1790857193367; Thu, 01 Oct 2026 05:19:53 -0700 (PDT) Received: from andreayoga.localdomain ([151.43.138.29]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4a01f923320sm69506935e9.7.2026.10.01.05.19.50 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 01 Oct 2026 05:19:52 -0700 (PDT) From: Andrea Parri To: netdev-bot+sashiko@kernel.org Cc: Andrea Parri , Pablo Neira Ayuso , Florian Westphal , netfilter-devel@vger.kernel.org, Phil Sutter , Nikolay Aleksandrov , Ido Schimmel , coreteam@netfilter.org, bridge@lists.linux.dev, netdev@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org, Jakub Kicinski Subject: Re: [PATCH nf] netfilter: br_netfilter: restore VLAN tag on refragmented IPv6 packets Date: Thu, 1 Oct 2026 14:19:34 +0200 Message-ID: <20261001121941.31364-1-parri.andrea@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <179084999520.434549.4764913674478855382@kernel.org> References: <20260928161830.351199-1-parri.andrea@gmail.com> <179084999520.434549.4764913674478855382@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit On Thu, Oct 01, 2026 at 10:19:55AM +0000, netdev-bot+sashiko@kernel.org wrote: > For an untagged packet this helper saves vlan_proto = 0. The consumer only > ever sets a tag and never clears one: [...] > So would fragments 2..N reach br_nf_push_frag_xmit()->br_dev_queue_push_xmit() > with their ingress 802.1Q/802.1ad tag still set, while the first fragment > goes out untagged? Yes. Conntrack defrag keeps the original fragments on frag_list for both IPv6 and IPv4 here (ip_frag_coalesce_ok() is true only for local delivery), each with its ingress tag, and br_handle_vlan() clears the tag of the head skb only. On the fast path those skbs are sent as the fragments. I extended my reproducer with a port that is untagged in VLAN 10 and a static FDB entry, so the packet is not cloned. With this patch applied, 6/9 IPv6 and 6/9 IPv4 fragments left that port with "vlan 10"; only the first fragment of each packet was untagged. This is not introduced by this patch, but it means the changelog claim was too broad. v2 will add a second patch that clears the tag in br_nf_push_frag_xmit() when none was saved, as nf_ct_bridge_frag_restore() does, and narrow the changelog of this one to the fragments ip6_fragment() builds. The BR_VLAN_TUNNEL case does not reach the refragmentation code: br_handle_egress_vlan_tunnel() attaches a metadata dst, so br_nf_dev_queue_xmit() drops the packet at the !skb_valid_dst() check. > Also, the comment "Fragments may not inherit the MAC header or VLAN tag" > does not seem accurate for reused frag_list skbs, which keep their own tag. Agreed, v2 rewords it. pw-bot: cr Thanks, Andrea