[PATCH net-next v5 05/14] ip6_tunnel: add drop reasons to the receive path
flat view
COOLING5d
From: Anton Danilov <hidden>
Date: 2026-09-30 18:39:31
Also in:
lkml
Subsystem:
networking [general], networking [ipv4/ipv6], the rest · Maintainers:
"David S. Miller", Eric Dumazet, Jakub Kicinski, Paolo Abeni, David Ahern, Ido Schimmel, Linus Torvalds
Revision v5 of 5 in this series.
Revisions (5)
__ip6_tnl_rcv() mirrors its IPv4 counterpart: all of its failures share a single plain kfree_skb(). Reuse the drop reasons that ip_tunnel_rcv() now reports and the ones the length helpers already return. Note that skb_vlan_inet_prepare() returns an enum skb_drop_reason that has so far been discarded, and that the ETH_HLEN check gets one by calling pskb_may_pull_reason() instead of pskb_may_pull(). __ip6_tnl_rcv() is reached two ways: ip6_gre (ip6gre, ip6gretap, ip6erspan) goes through the exported ip6_tnl_rcv(), while the ip6_tunnel encapsulations (ip4ip6, ip6ip6, mplsip6) reach it from ipxip6_rcv(). Only ip6_gre sets the checksum and sequence number bits: tpi_v4, tpi_v6 and tpi_mpls carry nothing but .proto, and unlike ipip and sit, ip6_tunnel stores IFLA_IPTUN_FLAGS in parms.flags, not in parms.i_flags. So the option mismatch and the old sequence reasons are reachable through ip6_gre alone. ipxip6_rcv() drops the packets it does not hand to __ip6_tnl_rcv() with a plain kfree_skb() as well. Give them a reason too: SKB_DROP_REASON_UNHANDLED_PROTO when the payload is not the one the tunnel mode carries, the reason the transmit side uses later in the series, SKB_DROP_REASON_XFRM_POLICY when the xfrm policy check fails, SKB_DROP_REASON_DEV_READY when ip6_tnl_rcv_ctl() refuses the packet, the reason iptunnel_pull_header() returns and SKB_DROP_REASON_NOMEM when the metadata dst cannot be allocated. ip6_tnl_rcv_ctl() refuses when the outer destination is not a usable local address, such as a tentative one, when the outer source belongs to this host, and when the tunnel cannot receive with the addresses of the packet. It returns only 0 or 1, so DEV_READY stands for all three, as it does for ip6_tnl_xmit_ctl() on the transmit side later in the series, although it describes only the first. Telling them apart needs both helpers to return a reason, which is left for a follow-up. ipxip6_rcv() and __ip6_tnl_rcv() follow the rule of ip_tunnel_rcv() for the reason: it is initialized to SKB_DROP_REASON_NOT_SPECIFIED, and the drop label falls back to it, as a helper stores its result in the reason. Assisted-by: LLM Signed-off-by: Anton Danilov <redacted> --- net/ipv6/ip6_tunnel.c | 47 ++++++++++++++++++++++++++++++++----------- 1 file changed, 35 insertions(+), 12 deletions(-)
diff --git a/net/ipv6/ip6_tunnel.c b/net/ipv6/ip6_tunnel.c
index d5ff50a2ac01..52f6a38657b9 100644
--- a/net/ipv6/ip6_tunnel.c
+++ b/net/ipv6/ip6_tunnel.c@@ -813,6 +813,7 @@ static int __ip6_tnl_rcv(struct ip6_tnl *tunnel, struct sk_buff *skb, struct sk_buff *skb), bool log_ecn_err) { + enum skb_drop_reason reason = SKB_DROP_REASON_NOT_SPECIFIED; const struct ipv6hdr *ipv6h; int nh, err;
@@ -820,15 +821,22 @@ static int __ip6_tnl_rcv(struct ip6_tnl *tunnel, struct sk_buff *skb, test_bit(IP_TUNNEL_CSUM_BIT, tpi->flags)) { DEV_STATS_INC(tunnel->dev, rx_crc_errors); DEV_STATS_INC(tunnel->dev, rx_errors); + reason = SKB_DROP_REASON_TUNNEL_OPT_MISMATCH; goto drop; } if (test_bit(IP_TUNNEL_SEQ_BIT, tunnel->parms.i_flags)) { - if (!test_bit(IP_TUNNEL_SEQ_BIT, tpi->flags) || - (tunnel->i_seqno && - (s32)(ntohl(tpi->seq) - tunnel->i_seqno) < 0)) { + if (!test_bit(IP_TUNNEL_SEQ_BIT, tpi->flags)) { DEV_STATS_INC(tunnel->dev, rx_fifo_errors); DEV_STATS_INC(tunnel->dev, rx_errors); + reason = SKB_DROP_REASON_TUNNEL_OPT_MISMATCH; + goto drop; + } + if (tunnel->i_seqno && + (s32)(ntohl(tpi->seq) - tunnel->i_seqno) < 0) { + DEV_STATS_INC(tunnel->dev, rx_fifo_errors); + DEV_STATS_INC(tunnel->dev, rx_errors); + reason = SKB_DROP_REASON_TUNNEL_OLD_SEQ; goto drop; } tunnel->i_seqno = ntohl(tpi->seq) + 1;
@@ -838,7 +846,8 @@ static int __ip6_tnl_rcv(struct ip6_tnl *tunnel, struct sk_buff *skb, /* Warning: All skb pointers will be invalidated! */ if (tunnel->dev->type == ARPHRD_ETHER) { - if (!pskb_may_pull(skb, ETH_HLEN)) { + reason = pskb_may_pull_reason(skb, ETH_HLEN); + if (reason) { DEV_STATS_INC(tunnel->dev, rx_length_errors); DEV_STATS_INC(tunnel->dev, rx_errors); goto drop;
@@ -859,7 +868,8 @@ static int __ip6_tnl_rcv(struct ip6_tnl *tunnel, struct sk_buff *skb, skb_reset_network_header(skb); - if (skb_vlan_inet_prepare(skb, true)) { + reason = skb_vlan_inet_prepare(skb, true); + if (reason) { DEV_STATS_INC(tunnel->dev, rx_length_errors); DEV_STATS_INC(tunnel->dev, rx_errors); goto drop;
@@ -881,6 +891,7 @@ static int __ip6_tnl_rcv(struct ip6_tnl *tunnel, struct sk_buff *skb, if (err > 1) { DEV_STATS_INC(tunnel->dev, rx_frame_errors); DEV_STATS_INC(tunnel->dev, rx_errors); + reason = SKB_DROP_REASON_IP_TUNNEL_ECN; goto drop; } }
@@ -896,9 +907,10 @@ static int __ip6_tnl_rcv(struct ip6_tnl *tunnel, struct sk_buff *skb, return 0; drop: + reason = reason ?: SKB_DROP_REASON_NOT_SPECIFIED; if (tun_dst) dst_release((struct dst_entry *)tun_dst); - kfree_skb(skb); + kfree_skb_reason(skb, reason); return 0; }
@@ -941,6 +953,7 @@ static int ipxip6_rcv(struct sk_buff *skb, u8 ipproto, const struct ipv6hdr *ipv6h, struct sk_buff *skb)) { + enum skb_drop_reason reason = SKB_DROP_REASON_NOT_SPECIFIED; struct ip6_tnl *t; const struct ipv6hdr *ipv6h = ipv6_hdr(skb); struct metadata_dst *tun_dst = NULL;
@@ -952,21 +965,30 @@ static int ipxip6_rcv(struct sk_buff *skb, u8 ipproto, if (t) { u8 tproto = READ_ONCE(t->parms.proto); - if (tproto != ipproto && tproto != 0) + if (tproto != ipproto && tproto != 0) { + reason = SKB_DROP_REASON_UNHANDLED_PROTO; goto drop; - if (!xfrm6_policy_check(NULL, XFRM_POLICY_IN, skb)) + } + if (!xfrm6_policy_check(NULL, XFRM_POLICY_IN, skb)) { + reason = SKB_DROP_REASON_XFRM_POLICY; goto drop; + } ipv6h = ipv6_hdr(skb); - if (!ip6_tnl_rcv_ctl(t, &ipv6h->daddr, &ipv6h->saddr)) + if (!ip6_tnl_rcv_ctl(t, &ipv6h->daddr, &ipv6h->saddr)) { + reason = SKB_DROP_REASON_DEV_READY; goto drop; - if (iptunnel_pull_header(skb, 0, tpi->proto, false)) + } + reason = iptunnel_pull_header(skb, 0, tpi->proto, false); + if (reason) goto drop; if (t->parms.collect_md) { IP_TUNNEL_DECLARE_FLAGS(flags) = { }; tun_dst = ipv6_tun_rx_dst(skb, flags, 0, 0); - if (!tun_dst) + if (!tun_dst) { + reason = SKB_DROP_REASON_NOMEM; goto drop; + } } ret = __ip6_tnl_rcv(t, skb, tpi, tun_dst, dscp_ecn_decapsulate, log_ecn_error);
@@ -978,7 +1000,8 @@ static int ipxip6_rcv(struct sk_buff *skb, u8 ipproto, drop: rcu_read_unlock(); - kfree_skb(skb); + reason = reason ?: SKB_DROP_REASON_NOT_SPECIFIED; + kfree_skb_reason(skb, reason); return 0; }
--
2.47.3