From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 09EDD2147E6 for ; Sat, 13 Jun 2026 07:04:02 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781334244; cv=none; b=HN43Igro7FKzhdOTDHXZ/1XNdJrGowNW5MAs/VxY5j6EujQtl8ssOu0VNZBxI2uaXZO+3vaMqr89Nn7vtdXHf3raz2fLrpuYdJvU0BgbgDtLfzYxwo652keV8psmtrikbY743mr55m/vNMdibiRsu4tMbG/C/Yz/scJNM1fas1w= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781334244; c=relaxed/simple; bh=Xs9nia55xXUUlN2PV5chD7GQx+qWkVCeZz5Ph6ZPaZg=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=mVGXUu5lmOWaORFs3Kqlv+feLVNUzBQGr5MqPwPb5EhRBgYX6S1+P3/mP7io4aPM7FBRtCZLUt1jwQPznYA/M+rloIBvgWPmwO9brOtdyNdKZZVv90lt+iWlBkojWoacFEDgcI9diuj5k+WZimtxciYlOur6JZlT4EMm5eUfhqs= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=aEv6TLoW; dkim=pass (2048-bit key) header.d=redhat.com header.i=@redhat.com header.b=eDOOOwXT; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="aEv6TLoW"; dkim=pass (2048-bit key) header.d=redhat.com header.i=@redhat.com header.b="eDOOOwXT" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1781334242; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=EreY/yKlC3Kp2dA9cbWzZG8YYEl55OvJbhqoHDYKfgk=; b=aEv6TLoW7nTk+oABTIbmO1x+/A5t/gi23iLxoMwm25gbIZdJrsLAjrvIvdPD0Q7C7FeN4k tc3fBP33UajRskMa00f24/8yQbLNKjQ5P/Bj7fnxHRi0ibJC9IeG/8u6pP04dR67Y+kG0w WNOR6HKMCBWOEw0mcv6pWy7ZetTf+Dw= Received: from mail-wr1-f71.google.com (mail-wr1-f71.google.com [209.85.221.71]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-34-TJ2Kps5nNGuLLdsREjqvuw-1; Sat, 13 Jun 2026 03:04:00 -0400 X-MC-Unique: TJ2Kps5nNGuLLdsREjqvuw-1 X-Mimecast-MFC-AGG-ID: TJ2Kps5nNGuLLdsREjqvuw_1781334239 Received: by mail-wr1-f71.google.com with SMTP id ffacd0b85a97d-45ef697092fso1061097f8f.1 for ; Sat, 13 Jun 2026 00:03:59 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1781334239; x=1781939039; darn=vger.kernel.org; h=content-transfer-encoding:in-reply-to:content-language:from :references:cc:to:subject:user-agent:mime-version:date:message-id :from:to:cc:subject:date:message-id:reply-to; bh=EreY/yKlC3Kp2dA9cbWzZG8YYEl55OvJbhqoHDYKfgk=; b=eDOOOwXTORJbGTQT1GR3fEAwaE6eIYJIHYRxToE7eeeWz2Gf5ufNQPm+30gGtQMwlX hwDWbTkei3QoVD72svSBYZzrpiCe9ZvN9fcbxWR7HFukK1zMgw6RMdnunBm4JMzOarge wLY14oMrw96jPw1PXDgjh6qbOahczgC7U31dXv2tYiv6exY4Mf5lnWfZtscyxHu1ROI7 589Onv6371WVUOjnFEIfteo0SGdxb7I36faZW5NoVxxNQLZuj6R/43EdyxYbyvcCAOTL iHVQl2oBMoHJLGHkfvhyTukNfVGTd5i3bXNioQSLme3KAsIYVaWoKBLEU1Qv2QuQjEkn cvZw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1781334239; x=1781939039; h=content-transfer-encoding:in-reply-to:content-language:from :references:cc:to:subject:user-agent:mime-version:date:message-id :x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=EreY/yKlC3Kp2dA9cbWzZG8YYEl55OvJbhqoHDYKfgk=; b=sPQGpQRYFZdZ4YP37tlQUIR0e9Z4Mxeg/zF88wmt7X8TyCsp7EUVP8HI+R6h9jvfUk /3zJNmecap4zXyhQvwQWbCCrd2tCyZjqcNsHzgSbs/L3C9NIgRySLyRVZmba4u3Oc15D jRG1+YNb760/0fLvaAPNk6P2vaLC3spTyfVqLEOJgt/RteG6P8p3ycDyGd8l16/aQUSh Tf+wfJzm04nSxLuEChC1ln2TJNLH0Xi9rdzxB0zkWSXUvjV/TqdVx4QavNg5TWRZhmXQ DnNHBKqwGW2n6urKcQu0QTclLEfqqQtushI6Q2NaCx4d1TZtTstm746M5LxF3M7mD5qw 7Bvg== X-Forwarded-Encrypted: i=1; AFNElJ9VNiAYYh+smneDnWixbE/Bnk9aZmxDLMP5q18VYNnc49n/Byn2LXSHQhKyeQVQYR154540nz7lLhQxczg=@vger.kernel.org X-Gm-Message-State: AOJu0Yxs/iAwuVeX92W2kly7Ng1vn+Z+y4T87fU3j7XTl/q8V18RfG7m IGlYUp/Lj7XGGK2ej5smmN6O12eVke/Wf/tIRBG3VYYfuwIUDruUh80H11cSQIyJMm3k0TjxNMv nqeoBhKi5UPLoy8zNKfJL/ap/V2Oot/Sdh1fELjKgI5GOp75K02aM3DbiMoPUYLd7zA== X-Gm-Gg: Acq92OFn4lbCcRpP+I06lcEMrpsil7CWVrqlwuaVL7LlRC82fOyd+oHCChiO9u8x6Py rX0x4k9I+FQlseOd/6gHS54bTTDD+D/qJgCCJY6BVP2uHMXFukE0R1T/IQkD1aTM/x8SlKnqxjh SMwqI0NcL3MtO2lLG+GHsuOWnjCWEiJvBSR4PM4oCuoyLlLjv2LHK96y+nofZ6qRDVOTFaBZoFn VsCfTU5v2IJsdEJFzwM4VQXXkg7Vb7QF/uNFYlYZPaZTRnJtPkU9YDD/xF3MCAqzVACp21OHSlA KdkP2IhEOu3+FZqxyFdSR2KnhNlxaOnxpWqA+NzKuIHaEhGo/NsLcRz5H/m5tYY+tyhFi8vyVui v5AusfS5MRgsUJFYe4L6AxadD4zFl2LUoek4Bp0rE6gYRfEEPFYHPNls= X-Received: by 2002:a5d:5d85:0:b0:45e:dacb:8885 with SMTP id ffacd0b85a97d-4606dbf15a9mr8221369f8f.35.1781334238789; Sat, 13 Jun 2026 00:03:58 -0700 (PDT) X-Received: by 2002:a5d:5d85:0:b0:45e:dacb:8885 with SMTP id ffacd0b85a97d-4606dbf15a9mr8221327f8f.35.1781334238353; Sat, 13 Jun 2026 00:03:58 -0700 (PDT) Received: from [192.168.88.32] ([150.228.25.72]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4606f26f450sm13540936f8f.10.2026.06.13.00.03.57 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Sat, 13 Jun 2026 00:03:57 -0700 (PDT) Message-ID: <7b42a031-5574-4398-8e9e-36248e22df2d@redhat.com> Date: Sat, 13 Jun 2026 09:03:56 +0200 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH net] ip_tunnel: drop stale dst from generated PMTU ICMP replies To: laikabcprice@gmail.com, David Ahern , Ido Schimmel , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Simon Horman Cc: netdev@vger.kernel.org, linux-kernel@vger.kernel.org References: <20260613-master-v1-1-df796e8e2d74@gmail.com> From: Paolo Abeni Content-Language: en-US In-Reply-To: <20260613-master-v1-1-df796e8e2d74@gmail.com> Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit On 6/13/26 3:00 AM, Laika Price via B4 Relay wrote: > From: Laika Price > > iptunnel_pmtud_build_icmp(...) and iptunnel_pmtud_build_icmpv6(...) take > in an sk_buff, modify it to create a PMTU ICMP error reply, and return it. > As part of these modifications, the source/destination ethernet and IP > addresses are swapped around which makes the sk_buff's current dst invalid. > > If the stale dst is left, the packet can skip input routing and be > forwarded using the original output device. This was observed when sending > packets to a VXLAN over a WireGuard tunnel - the ICMP reply was generated > but it was sent over the VXLAN instead of to the WireGuard tunnel. > > Drop the stale dst after building the PMTU reply so that the packet is > routed using its new headers when it is reinjected. > > Signed-off-by: Laika Price > --- > net/ipv4/ip_tunnel_core.c | 2 ++ > 1 file changed, 2 insertions(+) > > diff --git a/net/ipv4/ip_tunnel_core.c b/net/ipv4/ip_tunnel_core.c > index d3c677e9b..949150e43 100644 > --- a/net/ipv4/ip_tunnel_core.c > +++ b/net/ipv4/ip_tunnel_core.c > @@ -267,6 +267,7 @@ static int iptunnel_pmtud_build_icmp(struct sk_buff *skb, int mtu) > > eth_header(skb, skb->dev, ntohs(eh.h_proto), eh.h_source, eh.h_dest, 0); > skb_reset_mac_header(skb); > + skb_dst_drop(skb); > > return skb->len; > } > @@ -370,6 +371,7 @@ static int iptunnel_pmtud_build_icmpv6(struct sk_buff *skb, int mtu) > > eth_header(skb, skb->dev, ntohs(eh.h_proto), eh.h_source, eh.h_dest, 0); > skb_reset_mac_header(skb); > + skb_dst_drop(skb); > > return skb->len; > } > This apparently causes self-tests pmtu failure for the virtio_net device: # 135.54 [+6.50] TEST: IPv4, bridged vxlan4: PMTU exceptions [FAIL] # 142.17 [+6.63] TEST: IPv4, bridged vxlan4: PMTU exceptions - nexthop objects [FAIL] # 148.71 [+6.53] TEST: IPv6, bridged vxlan4: PMTU exceptions [FAIL] # 155.44 [+6.74] TEST: IPv6, bridged vxlan4: PMTU exceptions - nexthop objects [FAIL] # 161.94 [+6.49] TEST: IPv4, bridged vxlan6: PMTU exceptions [FAIL] # 168.69 [+6.76] TEST: IPv4, bridged vxlan6: PMTU exceptions - nexthop objects [FAIL] # 175.01 [+6.32] TEST: IPv6, bridged vxlan6: PMTU exceptions [FAIL] # 181.83 [+6.82] TEST: IPv6, bridged vxlan6: PMTU exceptions - nexthop objects [FAIL] # 188.42 [+6.59] TEST: IPv4, bridged geneve4: PMTU exceptions [FAIL] # 195.31 [+6.89] TEST: IPv4, bridged geneve4: PMTU exceptions - nexthop objects [FAIL] # 201.99 [+6.68] TEST: IPv6, bridged geneve4: PMTU exceptions [FAIL] # 209.10 [+7.11] TEST: IPv6, bridged geneve4: PMTU exceptions - nexthop objects [FAIL] # 216.12 [+7.02] TEST: IPv4, bridged geneve6: PMTU exceptions [FAIL] # 223.36 [+7.23] TEST: IPv4, bridged geneve6: PMTU exceptions - nexthop objects [FAIL] # 230.26 [+6.90] TEST: IPv6, bridged geneve6: PMTU exceptions [FAIL] # 237.52 [+7.26] TEST: IPv6, bridged geneve6: PMTU exceptions - nexthop objects [FAIL] # 264.58 [+27.06] TEST: IPv4, OVS vxlan4: PMTU exceptions [FAIL] # 293.85 [+29.27] TEST: IPv4, OVS vxlan4: PMTU exceptions - nexthop objects [FAIL] # 322.61 [+28.76] TEST: IPv6, OVS vxlan4: PMTU exceptions [FAIL] # 350.36 [+27.75] TEST: IPv6, OVS vxlan4: PMTU exceptions - nexthop objects [FAIL] # 376.99 [+26.62] TEST: IPv4, OVS vxlan6: PMTU exceptions [FAIL] # 404.00 [+27.02] TEST: IPv4, OVS vxlan6: PMTU exceptions - nexthop objects [FAIL] # 429.71 [+25.71] TEST: IPv6, OVS vxlan6: PMTU exceptions [FAIL] # 455.60 [+25.88] TEST: IPv6, OVS vxlan6: PMTU exceptions - nexthop objects [FAIL] # 481.32 [+25.72] TEST: IPv4, OVS geneve4: PMTU exceptions [FAIL] # 507.38 [+26.06] TEST: IPv4, OVS geneve4: PMTU exceptions - nexthop objects [FAIL] # 533.62 [+26.24] TEST: IPv6, OVS geneve4: PMTU exceptions [FAIL] # 560.92 [+27.30] TEST: IPv6, OVS geneve4: PMTU exceptions - nexthop objects [FAIL] # 588.20 [+27.29] TEST: IPv4, OVS geneve6: PMTU exceptions [FAIL] # 615.22 [+27.02] TEST: IPv4, OVS geneve6: PMTU exceptions - nexthop objects [FAIL] # 641.40 [+26.18] TEST: IPv6, OVS geneve6: PMTU exceptions [FAIL] # 666.47 [+25.07] TEST: IPv6, OVS geneve6: PMTU exceptions - nexthop objects [FAIL] See: https://github.com/linux-netdev/nipa/wiki/How-to-run-netdev-selftests-CI-style on how to reproduce that results. /P