Re: [PATCH 05/12] ipv6: xfrm: use full sockets in local error paths
flat view
From: Steffen Klassert <steffen.klassert@secunet.com>
Date: 2026-09-14 09:25:11
Ccing Author of the patch. On Tue, Sep 08, 2026 at 03:48:56PM -0700, Jakub Kicinski wrote:
This is an AI-generated review of your patch. The human sending this email has considered the AI review valid, or at least plausible. --- ipv6: xfrm: use full sockets in local error paths xfrm6_local_rxpmtu() and xfrm6_local_error() used skb->sk directly and cast it to a full inet/IPv6 socket, which is wrong when a SYN-ACK skb is owned by a TCP_NEW_SYN_RECV request_sock. Both callbacks now resolve the owner with skb_to_full_sk() and return early when there is no full socket attached.quoted
diff --git a/net/ipv6/xfrm6_output.c b/net/ipv6/xfrm6_output.c index 512bdaf136997..44b221a09a0c8 100644 --- a/net/ipv6/xfrm6_output.c +++ b/net/ipv6/xfrm6_output.c[ ... ]quoted
@@ -31,7 +34,10 @@ void xfrm6_local_error(struct sk_buff *skb, u32 mtu) { struct flowi6 fl6; const struct ipv6hdr *hdr; - struct sock *sk = skb->sk; + struct sock *sk = skb_to_full_sk(skb); + + if (!sk) + return;[Severity: High] Should the IPv4 sibling of this same afinfo->local_error hook get the same treatment? xfrm4_local_error() in net/ipv4/xfrm4_output.c still hands the raw skb->sk to inet_sk(): net/ipv4/xfrm4_output.c:xfrm4_local_error() { hdr = skb->encapsulation ? inner_ip_hdr(skb) : ip_hdr(skb); ip_local_error(skb->sk, EMSGSIZE, hdr->daddr, inet_sk(skb->sk)->inet_dport, mtu); }
There are still direct references of skb->sk that might need to be moved to skb_to_full_sk in the codebase. The patch fixed what described in the commit message and did not introduce a regression.