Thread (7 messages) 7 messages, 4 authors, 6d ago

Re: [PATCH net] seg6: keep room for the mac header when growing the headroom

From: Andrea Mayer <andrea.mayer@uniroma2.it>
Date: 2026-09-17 16:43:41
Also in: lkml

On Thu, 17 Sep 2026 12:12:11 +0200
Justin Iurman [off-list ref] wrote:
On 9/16/26 23:38, Yuya Kusakabe wrote:
quoted
[snip]
Overall, LGTM, thanks. However, I think we'd need a v2 with the followings:

- use max_t(unsigned int, skb->mac_len, dst_dev_overhead(cache_dst, 
skb)) instead of max()
- apply the same changes to ioam6_iptunnel and rpl_iptunnel (all in one 
patch is fine)

Reviewed-by: Justin Iurman <justin.iurman@gmail.com>
Hi Justin,

Agreed, rpl and ioam6 inline do trigger. Single VLAN device per side,
reorder_hdr off on the receiving one, plain ping:

  BUG: KASAN: slab-out-of-bounds in rpl_do_srh_inline.isra.0+0x3d3/0x770
  Write of size 18 at addr ffff88810deeba7e by task ping/447

  CPU: 0 UID: 0 PID: 447 Comm: ping Not tainted 7.3.0-rc1 #364
  Call Trace:
   <IRQ>
   __asan_memmove+0x38/0x60
   rpl_do_srh_inline.isra.0+0x3d3/0x770
   rpl_input+0xd3/0x5e0
   lwtunnel_input+0x18d/0x420
   ipv6_rcv+0x452/0x460

  BUG: KASAN: slab-use-after-free in ioam6_do_inline+0x2d8/0x5e0
  Write of size 18 at addr ffff88811480fa7e by task ping/432

  CPU: 0 UID: 0 PID: 432 Comm: ping Not tainted 7.3.0-rc1 #364
  Call Trace:
   <IRQ>
   __asan_memmove+0x38/0x60
   ioam6_do_inline+0x2d8/0x5e0
   ioam6_output+0x335/0x970
   lwtunnel_output+0x1b0/0x440
   ip6_forward+0x16a7/0x16f0
   ipv6_rcv+0x452/0x460

ioam6_do_encap triggers too, with three VLAN tags via tc push:

  BUG: KASAN: use-after-free in ioam6_do_encap+0x202/0x5c0
  Write of size 26 at addr ffff88810de227fe by task ping/453

  CPU: 0 UID: 0 PID: 453 Comm: ping Not tainted 7.3.0-rc1 #364
  Call Trace:
   <IRQ>
   __asan_memmove+0x38/0x60
   ioam6_do_encap+0x202/0x5c0
   ioam6_output+0x3cc/0x970
   lwtunnel_output+0x1b0/0x440
   ip6_forward+0x16a7/0x16f0
   ipv6_rcv+0x452/0x460

I would fix dst_dev_overhead() itself rather than patching every
caller individually, that covers all callers at once and protects
any future user of the helper. dst_dev_overhead() already returns
skb->mac_len when dst is NULL, the fix would make the other branch
consistent:
--- a/include/net/dst.h
+++ b/include/net/dst.h
@@ -455,7 +455,8 @@ static inline unsigned int dst_dev_overhead(struct dst_entry *dst,
 					    struct sk_buff *skb)
 {
 	if (likely(dst))
-		return LL_RESERVED_SPACE(dst->dev);
+		return max_t(unsigned int, skb->mac_len,
+			     LL_RESERVED_SPACE(dst->dev));

 	return skb->mac_len;
 }
What do you think?

Thanks,
Andrea
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help