[PATCH net-next 3/3] net/sched: act_api: budget TCA_ROOT_EXT_WARN_MSG in notify skbs
flat view
COLD16d
From: Victor Nogueira <hidden>
Date: 2026-09-19 23:04:49
Subsystem:
networking [general], tc subsystem, the rest · Maintainers:
"David S. Miller", Eric Dumazet, Jakub Kicinski, Paolo Abeni, Jamal Hadi Salim, Jiri Pirko, Linus Torvalds
tca_get_fill may emit TCA_ROOT_EXT_WARN_MSG from extack->_msg. The string is whatever NL_SET_ERR_MSG and friends stored, so its length is bounded only by the caller, and nothing in the budget that tcf_add_notify_msg and tcf_del_notify_msg hand to alloc_skb accounts for it. The notify skb can therefore be sized smaller than what tca_get_fill goes on to write into it. The attribute reaches a successful add because tcf_action_init keeps going when an action that is not skip_sw fails to offload: err = tcf_action_offload_add(act, extack); if (tc_act_skip_sw(act->tcfa_flags) && err) goto err; The action is created while extack->_msg still holds the offload diagnostic, and tcf_add_notify echoes it back. A pedit action with mixed key commands (one SET and one ADD) takes that path: the non-bind tcf_pedit_offload_act_setup sets "Unsupported pedit command offload" and returns -EOPNOTSUPP. In practice, no underbudgeting has been observed because of this, and the gap is not easy to reach given some other spots account for more than necessary. However, for correctness, budget the attribute so the size handed to alloc_skb covers what tca_get_fill can write. Reported-by: Sashiko <sashiko-bot@kernel.org> Link: https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260824153903.4143642-1-victor@mojatatu.com Co-developed-by: Jamal Hadi Salim <jhs@mojatatu.com> Signed-off-by: Jamal Hadi Salim <jhs@mojatatu.com> Signed-off-by: Victor Nogueira <redacted> --- net/sched/act_api.c | 15 +++++++++++++-- 1 file changed, 13 insertions(+), 2 deletions(-)
diff --git a/net/sched/act_api.c b/net/sched/act_api.c
index 3f653721c45f..db06ddcf6ae6 100644
--- a/net/sched/act_api.c
+++ b/net/sched/act_api.c@@ -475,6 +475,15 @@ static size_t tcf_action_full_attrs_size(size_t sz) + sz; } +/* tca_get_fill() may append TCA_ROOT_EXT_WARN_MSG from extack->_msg */ +static size_t tcf_action_warn_attr_size(const struct netlink_ext_ack *extack) +{ + if (unlikely(extack && extack->_msg)) + return nla_total_size(strlen(extack->_msg) + 1); + + return 0; +} + static size_t tcf_action_fill_size(const struct tc_action *act) { size_t sz = tcf_action_shared_attrs_size(act);
@@ -1980,7 +1989,8 @@ static struct sk_buff *tcf_del_notify_msg(struct net *net, struct nlmsghdr *n, { struct sk_buff *skb; - skb = alloc_skb(max(attr_size, NLMSG_GOODSIZE), GFP_KERNEL); + skb = alloc_skb(max(attr_size + tcf_action_warn_attr_size(extack), + NLMSG_GOODSIZE), GFP_KERNEL); if (!skb) return ERR_PTR(-ENOBUFS);
@@ -2078,7 +2088,8 @@ static struct sk_buff *tcf_add_notify_msg(struct net *net, struct nlmsghdr *n, { struct sk_buff *skb; - skb = alloc_skb(max(attr_size, NLMSG_GOODSIZE), GFP_KERNEL); + skb = alloc_skb(max(attr_size + tcf_action_warn_attr_size(extack), + NLMSG_GOODSIZE), GFP_KERNEL); if (!skb) return ERR_PTR(-ENOBUFS);
--
2.55.0