* [PATCH v2 1/1] xfrm: Use skb_mac_header_was_set() to check for MAC header presence
@ 2023-09-04 10:32 Marcello Sylvester Bauer
2023-09-05 9:59 ` Paolo Abeni
0 siblings, 1 reply; 3+ messages in thread
From: Marcello Sylvester Bauer @ 2023-09-04 10:32 UTC (permalink / raw)
To: Steffen Klassert, Herbert Xu, David S. Miller, Eric Dumazet,
Jakub Kicinski, Paolo Abeni
Cc: Marcello Sylvester Bauer, netdev, linux-kernel
From: Marcello Sylvester Bauer <sylv@sylv.io>
Add skb_mac_header_was_set() in xfrm4_remove_tunnel_encap() and
xfrm6_remove_tunnel_encap() to detect the presence of a MAC header.
This change prevents a kernel page fault on a non-zero mac_len when the
mac_header is not set.
Signed-off-by: Marcello Sylvester Bauer <sylv@sylv.io>
---
net/xfrm/xfrm_input.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/net/xfrm/xfrm_input.c b/net/xfrm/xfrm_input.c
index d5ee96789d4b..6d74bfa1e6e8 100644
--- a/net/xfrm/xfrm_input.c
+++ b/net/xfrm/xfrm_input.c
@@ -250,7 +250,7 @@ static int xfrm4_remove_tunnel_encap(struct xfrm_state *x, struct sk_buff *skb)
skb_reset_network_header(skb);
skb_mac_header_rebuild(skb);
- if (skb->mac_len)
+ if (skb->mac_len && skb_mac_header_was_set(skb))
eth_hdr(skb)->h_proto = skb->protocol;
err = 0;
@@ -287,7 +287,7 @@ static int xfrm6_remove_tunnel_encap(struct xfrm_state *x, struct sk_buff *skb)
skb_reset_network_header(skb);
skb_mac_header_rebuild(skb);
- if (skb->mac_len)
+ if (skb->mac_len && skb_mac_header_was_set(skb))
eth_hdr(skb)->h_proto = skb->protocol;
err = 0;
--
2.42.0
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH v2 1/1] xfrm: Use skb_mac_header_was_set() to check for MAC header presence
2023-09-04 10:32 [PATCH v2 1/1] xfrm: Use skb_mac_header_was_set() to check for MAC header presence Marcello Sylvester Bauer
@ 2023-09-05 9:59 ` Paolo Abeni
2023-09-05 10:13 ` Marcello Sylverster Bauer
0 siblings, 1 reply; 3+ messages in thread
From: Paolo Abeni @ 2023-09-05 9:59 UTC (permalink / raw)
To: Marcello Sylvester Bauer, Steffen Klassert, Herbert Xu,
David S. Miller, Eric Dumazet, Jakub Kicinski
Cc: Marcello Sylvester Bauer, netdev, linux-kernel
On Mon, 2023-09-04 at 12:32 +0200, Marcello Sylvester Bauer wrote:
> From: Marcello Sylvester Bauer <sylv@sylv.io>
>
> Add skb_mac_header_was_set() in xfrm4_remove_tunnel_encap() and
> xfrm6_remove_tunnel_encap() to detect the presence of a MAC header.
> This change prevents a kernel page fault on a non-zero mac_len when the
> mac_header is not set.
>
> Signed-off-by: Marcello Sylvester Bauer <sylv@sylv.io>
Please include a suitable fixes tag.
Please also include in the commit message the stacktrace:
https://lore.kernel.org/netdev/636d3434-d47a-4cd4-b3ba-7f7254317b64@sylv.io/
trimming the asm code and lines starting with ' ? '
I think the real issue could be elsewhere, we should not reach here
with mac_len > 0 && !skb_mac_header_was_set().
Could you please try the following debug patch in your setup, and see
if hints at some other relevant place?
Thanks,
Paolo
---
diff --git a/include/linux/skbuff.h b/include/linux/skbuff.h
index 4174c4b82d13..38ca2c7e50ca 100644
--- a/include/linux/skbuff.h
+++ b/include/linux/skbuff.h
@@ -2793,6 +2793,7 @@ static inline void skb_reset_inner_headers(struct sk_buff *skb)
static inline void skb_reset_mac_len(struct sk_buff *skb)
{
+ WARN_ON_ONCE(!skb_mac_header_was_set(skb));
skb->mac_len = skb->network_header - skb->mac_header;
}
^ permalink raw reply [flat|nested] 3+ messages in thread* Re: [PATCH v2 1/1] xfrm: Use skb_mac_header_was_set() to check for MAC header presence
2023-09-05 9:59 ` Paolo Abeni
@ 2023-09-05 10:13 ` Marcello Sylverster Bauer
0 siblings, 0 replies; 3+ messages in thread
From: Marcello Sylverster Bauer @ 2023-09-05 10:13 UTC (permalink / raw)
To: Paolo Abeni, Steffen Klassert, Herbert Xu, David S. Miller,
Eric Dumazet, Jakub Kicinski
Cc: netdev, linux-kernel
Hi Paolo,
On 9/5/23 11:59, Paolo Abeni wrote:
> On Mon, 2023-09-04 at 12:32 +0200, Marcello Sylvester Bauer wrote:
>> From: Marcello Sylvester Bauer <sylv@sylv.io>
>>
>> Add skb_mac_header_was_set() in xfrm4_remove_tunnel_encap() and
>> xfrm6_remove_tunnel_encap() to detect the presence of a MAC header.
>> This change prevents a kernel page fault on a non-zero mac_len when the
>> mac_header is not set.
>>
>> Signed-off-by: Marcello Sylvester Bauer <sylv@sylv.io>
>
> Please include a suitable fixes tag.
>
> Please also include in the commit message the stacktrace:
>
> https://lore.kernel.org/netdev/636d3434-d47a-4cd4-b3ba-7f7254317b64@sylv.io/
>
> trimming the asm code and lines starting with ' ? '
Sure, will be added to the next version in addition to a cover letter to
give additional context to this patch.
>
> I think the real issue could be elsewhere, we should not reach here
> with mac_len > 0 && !skb_mac_header_was_set().
>
> Could you please try the following debug patch in your setup, and see
> if hints at some other relevant place?
Unfortunately the person with the hardware is OOO for two weeks. But I
could ask him to test it when he gets back.
Thanks,
Marcello
>
> Thanks,
>
> Paolo
>
> ---
> diff --git a/include/linux/skbuff.h b/include/linux/skbuff.h
> index 4174c4b82d13..38ca2c7e50ca 100644
> --- a/include/linux/skbuff.h
> +++ b/include/linux/skbuff.h
> @@ -2793,6 +2793,7 @@ static inline void skb_reset_inner_headers(struct sk_buff *skb)
>
> static inline void skb_reset_mac_len(struct sk_buff *skb)
> {
> + WARN_ON_ONCE(!skb_mac_header_was_set(skb));
> skb->mac_len = skb->network_header - skb->mac_header;
> }
>
>
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2023-09-05 16:33 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2023-09-04 10:32 [PATCH v2 1/1] xfrm: Use skb_mac_header_was_set() to check for MAC header presence Marcello Sylvester Bauer
2023-09-05 9:59 ` Paolo Abeni
2023-09-05 10:13 ` Marcello Sylverster Bauer
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®