Thread (48 messages) 48 messages, 7 authors, 19d ago

Re: [PATCH 05/12] ipv6: xfrm: use full sockets in local error paths

flat view

From: Steffen Klassert <steffen.klassert@secunet.com>
Date: 2026-09-14 09:25:11

Ccing Author of the patch.

On Tue, Sep 08, 2026 at 03:48:56PM -0700, Jakub Kicinski wrote:
This is an AI-generated review of your patch. The human sending this
email has considered the AI review valid, or at least plausible.
---
ipv6: xfrm: use full sockets in local error paths

xfrm6_local_rxpmtu() and xfrm6_local_error() used skb->sk directly and cast
it to a full inet/IPv6 socket, which is wrong when a SYN-ACK skb is owned by
a TCP_NEW_SYN_RECV request_sock.  Both callbacks now resolve the owner with
skb_to_full_sk() and return early when there is no full socket attached.
quoted
diff --git a/net/ipv6/xfrm6_output.c b/net/ipv6/xfrm6_output.c
index 512bdaf136997..44b221a09a0c8 100644
--- a/net/ipv6/xfrm6_output.c
+++ b/net/ipv6/xfrm6_output.c
[ ... ]
quoted
@@ -31,7 +34,10 @@ void xfrm6_local_error(struct sk_buff *skb, u32 mtu)
 {
 	struct flowi6 fl6;
 	const struct ipv6hdr *hdr;
-	struct sock *sk = skb->sk;
+	struct sock *sk = skb_to_full_sk(skb);
+
+	if (!sk)
+		return;
[Severity: High]
Should the IPv4 sibling of this same afinfo->local_error hook get the same
treatment?  xfrm4_local_error() in net/ipv4/xfrm4_output.c still hands the
raw skb->sk to inet_sk():

net/ipv4/xfrm4_output.c:xfrm4_local_error() {
	hdr = skb->encapsulation ? inner_ip_hdr(skb) : ip_hdr(skb);
	ip_local_error(skb->sk, EMSGSIZE, hdr->daddr,
		       inet_sk(skb->sk)->inet_dport, mtu);
}
There are still direct references of skb->sk that might need to
be moved to skb_to_full_sk in the codebase. The patch fixed what
described in the commit message and did not introduce a regression.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help