[RFC bpf-next v2 0/3] bpf: Add PPPoE encap/decap support to bpf_skb_adjust_room
From: ThisSeanZhang <hidden>
Date: 2026-10-03 19:33:57
Also in:
bpf
Hello,
A concrete use case for this support is a TC BPF PPPoE forwarding
path. When such a path forwards a GSO packet larger than the negotiated
PPPoE MTU, inserting the PPPoE header manually leaves skb->protocol set
to the original IP protocol. The stack then cannot select the PPPoE
segmentation path, and the packet can be dropped.
The kernel already provides PPPoE GRO/GSO support for ETH_P_PPP_SES
(added by commit 55a5d8fca836 ("net: pppoe: implement GRO/GSO support")),
but a TC BPF program currently cannot update skb->protocol and related
metadata when it adds or removes the PPPoE header. As a result, later
networking code does not see the packet as a PPPoE frame and cannot use
those handlers correctly.
The current workaround uses
BPF_F_ADJ_ROOM_ENCAP_L3_IPV4/IPV6, which marks the skb as IP-in-IP
while the wire format is PPPoE. This requires the program to adjust
gso_size itself and leaves the skb metadata describing an encapsulation
that is not on the wire [1].
This series adds PPPoE session encapsulation and decapsulation support
to bpf_skb_adjust_room(). The new operations update the packet layout
and skb metadata together, making the skb compatible with the kernel's
existing PPPoE GRO/GSO handlers.
Examples:
bpf_skb_adjust_room(skb, PPPOE_SES_HLEN, BPF_ADJ_ROOM_MAC,
BPF_F_ADJ_ROOM_ENCAP_PPPOE);
bpf_skb_adjust_room(skb, -PPPOE_SES_HLEN, BPF_ADJ_ROOM_MAC,
BPF_F_ADJ_ROOM_DECAP_PPPOE);
Encapsulation changes skb->protocol to ETH_P_PPP_SES. Decapsulation
accepts only packets whose skb->protocol is ETH_P_PPP_SES, reads the
PPP protocol field, and restores ETH_P_IP or ETH_P_IPV6. Both flags
require BPF_ADJ_ROOM_MAC and a fixed eight-byte adjustment.
The PPPoE GRO/GSO support must be built in or loaded before this path
is used for receive-side GRO or software GSO; loading pppoe.ko remains
the responsibility of the user-space setup.
The interface follows the existing BPF_F_ADJ_ROOM_ENCAP_* family. I
also considered a kfunc-based interface and would appreciate
feedback on whether that would be preferred.
The selftest covers IPv4 and IPv6 round trips, protocol transitions,
and invalid flag, size, mode, protocol, and truncated-packet cases. It
passes in a QEMU/KVM boot of the resulting kernel (11/11 subtests).
[1] https://github.com/ThisSeanZhang/landscape/blob/80bc43eef7143ad029283fe2a8d510718c22af12/landscape-ebpf/src/bpf/tc_chain/tc_pppoe.bpf.c#L38-L47
ThisSeanZhang (3):
bpf: Add PPPoE encap support to bpf_skb_adjust_room
bpf: Add PPPoE decap support to bpf_skb_adjust_room
selftests/bpf: Add a test for the PPPoE encap/decap adjust_room flags
include/uapi/linux/bpf.h | 22 ++
net/core/filter.c | 85 +++++-
tools/include/uapi/linux/bpf.h | 22 ++
.../selftests/bpf/prog_tests/tc_pppoe.c | 254 ++++++++++++++++++
tools/testing/selftests/bpf/progs/tc_pppoe.c | 163 +++++++++++
5 files changed, 543 insertions(+), 3 deletions(-)
create mode 100644 tools/testing/selftests/bpf/prog_tests/tc_pppoe.c
create mode 100644 tools/testing/selftests/bpf/progs/tc_pppoe.c
---
Changes since v1:
- Rework the cover letter to explain the forwarding use case and the
PPPoE skb metadata transition.
- Clarify the PPPoE module prerequisite and GRO/GSO scope.
- Replace the reviewer questions with a single question about the
interface choice.
- Fix multi-line comment style in the selftests.
v1: https://lore.kernel.org/bpf/20260926210757.2152159-1-thisseanzhang@gmail.com/ (local)
--
2.47.3