[PATCH net-next 2/4] ip_tunnel: make __iptunnel_pull_header() return a drop reason
flat view
WARM2d
IN NET-NEXT
From: Anton Danilov <hidden>
Date: 2026-10-05 20:14:28
Also in:
lkml
Subsystem:
networking [general], networking [ipv4/ipv6], the rest · Maintainers:
"David S. Miller", Eric Dumazet, Jakub Kicinski, Paolo Abeni, David Ahern, Ido Schimmel, Linus Torvalds
Queued in net-next as 6c0509aa8900 on 2026-10-08.
__iptunnel_pull_header() returns -ENOMEM whenever it fails. It can fail in two pskb_may_pull() calls, one for the tunnel header and one for the inner Ethernet header of ETH_P_TEB, and in the skb_unclone() done for GSO packets. pskb_may_pull() fails when the packet is shorter than the requested length as well as when pulling from the frags cannot allocate, so a truncated packet and an allocation failure look the same to the callers. The ones that report a drop reason can only pick SKB_DROP_REASON_NOMEM, as vxlan_rcv() does, and so would the GRE receive paths once they report drop reasons. In ip6_gre, gre_rcv() pulls the header before the tunnel lookup, so a packet from any sender whose ETH_P_TEB inner Ethernet header or WCCPv2 extra word is cut short would be reported as an out of memory condition. Make __iptunnel_pull_header() and iptunnel_pull_header() return the reason pskb_may_pull_reason() already computes, SKB_DROP_REASON_NOMEM when skb_unclone() fails, and SKB_NOT_DROPPED_YET on success. A failure is still non-zero, so the callers that only test the result keep working. Three callers, in ip_gre and ip6_gre, test it with "< 0" instead; the enum has no negative values, so that test would always be false, and the compiler does not warn about it. Make them test for a non-zero value. vxlan_rcv() keeps reporting NOMEM for any failure until the next patch has it report the returned reason. Suggested-by: Ido Schimmel <idosch@nvidia.com> Assisted-by: LLM Signed-off-by: Anton Danilov <redacted> --- include/net/ip_tunnels.h | 10 ++++++---- net/ipv4/ip_gre.c | 4 ++-- net/ipv4/ip_tunnel_core.c | 22 +++++++++++++++------- net/ipv6/ip6_gre.c | 2 +- 4 files changed, 24 insertions(+), 14 deletions(-)
diff --git a/include/net/ip_tunnels.h b/include/net/ip_tunnels.h
index 7102aa11fae2..5cccf4c0e691 100644
--- a/include/net/ip_tunnels.h
+++ b/include/net/ip_tunnels.h@@ -614,11 +614,13 @@ static inline u8 ip_tunnel_ecn_encap(u8 tos, const struct iphdr *iph, return INET_ECN_encapsulate(tos, inner); } -int __iptunnel_pull_header(struct sk_buff *skb, int hdr_len, - __be16 inner_proto, bool raw_proto, bool xnet); +enum skb_drop_reason +__iptunnel_pull_header(struct sk_buff *skb, int hdr_len, + __be16 inner_proto, bool raw_proto, bool xnet); -static inline int iptunnel_pull_header(struct sk_buff *skb, int hdr_len, - __be16 inner_proto, bool xnet) +static inline enum skb_drop_reason +iptunnel_pull_header(struct sk_buff *skb, int hdr_len, + __be16 inner_proto, bool xnet) { return __iptunnel_pull_header(skb, hdr_len, inner_proto, false, xnet); }
diff --git a/net/ipv4/ip_gre.c b/net/ipv4/ip_gre.c
index 51fcd603939c..3ee437fa3eae 100644
--- a/net/ipv4/ip_gre.c
+++ b/net/ipv4/ip_gre.c@@ -312,7 +312,7 @@ static int erspan_rcv(struct sk_buff *skb, struct tnl_ptk_info *tpi, if (__iptunnel_pull_header(skb, len, htons(ETH_P_TEB), - false, false) < 0) + false, false)) goto drop; if (tunnel->collect_md) {
@@ -378,7 +378,7 @@ static int __ipgre_rcv(struct sk_buff *skb, const struct tnl_ptk_info *tpi, const struct iphdr *tnl_params; if (__iptunnel_pull_header(skb, hdr_len, tpi->proto, - raw_proto, false) < 0) + raw_proto, false)) goto drop; /* Special case for ipgre_header_parse(), which expects the
diff --git a/net/ipv4/ip_tunnel_core.c b/net/ipv4/ip_tunnel_core.c
index bab42b9e277f..6c2855adff28 100644
--- a/net/ipv4/ip_tunnel_core.c
+++ b/net/ipv4/ip_tunnel_core.c@@ -106,19 +106,24 @@ void iptunnel_xmit(struct sock *sk, struct rtable *rt, struct sk_buff *skb, } EXPORT_SYMBOL_GPL(iptunnel_xmit); -int __iptunnel_pull_header(struct sk_buff *skb, int hdr_len, - __be16 inner_proto, bool raw_proto, bool xnet) +enum skb_drop_reason +__iptunnel_pull_header(struct sk_buff *skb, int hdr_len, + __be16 inner_proto, bool raw_proto, bool xnet) { - if (unlikely(!pskb_may_pull(skb, hdr_len))) - return -ENOMEM; + enum skb_drop_reason reason; + + reason = pskb_may_pull_reason(skb, hdr_len); + if (unlikely(reason)) + return reason; skb_pull_rcsum(skb, hdr_len); if (!raw_proto && inner_proto == htons(ETH_P_TEB)) { struct ethhdr *eh; - if (unlikely(!pskb_may_pull(skb, ETH_HLEN))) - return -ENOMEM; + reason = pskb_may_pull_reason(skb, ETH_HLEN); + if (unlikely(reason)) + return reason; eh = (struct ethhdr *)skb->data; if (likely(eth_proto_is_802_3(eh->h_proto)))
@@ -135,7 +140,10 @@ int __iptunnel_pull_header(struct sk_buff *skb, int hdr_len, skb_set_queue_mapping(skb, 0); skb_scrub_packet(skb, xnet); - return iptunnel_pull_offloads(skb); + if (unlikely(iptunnel_pull_offloads(skb))) + return SKB_DROP_REASON_NOMEM; + + return SKB_NOT_DROPPED_YET; } EXPORT_SYMBOL_GPL(__iptunnel_pull_header);
diff --git a/net/ipv6/ip6_gre.c b/net/ipv6/ip6_gre.c
index 258239a7c53b..0392f6ba862b 100644
--- a/net/ipv6/ip6_gre.c
+++ b/net/ipv6/ip6_gre.c@@ -512,7 +512,7 @@ static int ip6erspan_rcv(struct sk_buff *skb, if (__iptunnel_pull_header(skb, len, htons(ETH_P_TEB), - false, false) < 0) + false, false)) return PACKET_REJECT; if (tunnel->parms.collect_md) {
--
2.47.3