Thread (3 messages) 3 messages, 2 authors, 18d ago

Re: [PATCH] netfilter: nf_nat: Fix stale outer UDP checksum on VXLAN encapsulated packets

flat view

From: lvjunyu <hidden>
Date: 2026-09-22 05:56:15
Also in: lkml, netfilter-devel, stable

Thank you for the review.  Both High issues are legitimate.

1. Incomplete fix: nf_csum_update() indeed takes the pseudo-header
   branch for CHECKSUM_PARTIAL, applying the address delta with the
   wrong sign.  My test environment had delta=0 (masqueraded address
   equals the original), so this was not exposed.  The same applies
   to IPv6 via inet_proto_csum_replace16().

2. Wrong discriminator: skb->encapsulation cannot distinguish the LCO
   state (complete checksum, needs fixup) from the seed/offload state
   (pseudo-header seed, must not touch).  SCTP-over-UDP would be a
   false positive; L2TP-over-UDP a false negative.

I have prepared a v2 that:
  - Uses the offload target (csum_start + csum_offset != &hdr->check)
    to distinguish LCO from seed/offload state
  - Temporarily flips ip_summed to CHECKSUM_NONE so both the address
    and port updates use the csum_replace*() path
  - Updates the comment to describe both CHECKSUM_PARTIAL states

v2 will be submitted as a new thread shortly.


Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help