[PATCH net-next v5] net: ipv6: seg6: report lwtunnel setup errors via extack
DORMANTno replies
From: Gabriel Goller <hidden>
Date: 2026-10-09 15:20:22
Also in:
lkml
Subsystem:
networking [general], networking [srv6], the rest · Maintainers:
"David S. Miller", Eric Dumazet, Jakub Kicinski, Paolo Abeni, Andrea Mayer, Linus Torvalds
seg6_build_state() rejected invalid configurations with a generic -EINVAL, so "ip route add ... encap seg6 ..." sometimes reported "Invalid argument". Add extack messages to the checks that lacked one, and use NL_REQ_ATTR_CHECK() for the missing SRH attribute so that userspace can tell which attribute is missing. The checks themselves and their return values are unchanged. Signed-off-by: Gabriel Goller <redacted> --- v5 (https://lore.kernel.org/all/20261005140637.644840-1-g.goller@proxmox.com/ (local)): * use NL_REQ_ATTR_CHECK() for the missing SRH attribute (Jakub) * reword the inline mode message to "inline mode requires the IPv6 address family", since it also applies to IPv4 nexthop objects (Andrea) * consistently call the header "IPv6 Segment Routing Header" (RFC 8754) in all messages (Andrea) * include the offending mode value in the invalid mode message * reword the commit message to match v4 (https://lore.kernel.org/all/20260923120228.172643-1-g.goller@proxmox.com/ (local)): * use NL_SET_ERR_MSG when the SRH attr is missing * use NL_SET_ERR_MSG_ATTR when we have an invalid attr v3 (https://lore.kernel.org/all/20260922090851.38978-1-g.goller@proxmox.com/ (local)): * format fix * use NL_SET_ERR_MSG_ATTR v2 (https://lore.kernel.org/all/20260918153544.1178884-1-g.goller@proxmox.com/ (local)): * dropped tests net/ipv6/seg6_iptunnel.c | 26 +++++++++++++++++++++----- 1 file changed, 21 insertions(+), 5 deletions(-)
diff --git a/net/ipv6/seg6_iptunnel.c b/net/ipv6/seg6_iptunnel.c
index 69a6ef5c5317..0d39a38a5dd2 100644
--- a/net/ipv6/seg6_iptunnel.c
+++ b/net/ipv6/seg6_iptunnel.c@@ -762,8 +762,11 @@ static int seg6_build_state(struct net *net, struct nlattr *nla, struct seg6_lwt *slwt; int err; - if (family != AF_INET && family != AF_INET6) + if (family != AF_INET && family != AF_INET6) { + NL_SET_ERR_MSG(extack, + "unsupported address family for SRv6 encapsulation"); return -EINVAL; + } err = nla_parse_nested_deprecated(tb, SEG6_IPTUNNEL_MAX, nla, seg6_iptunnel_policy, extack);
@@ -771,7 +774,7 @@ static int seg6_build_state(struct net *net, struct nlattr *nla, if (err < 0) return err; - if (!tb[SEG6_IPTUNNEL_SRH]) + if (NL_REQ_ATTR_CHECK(extack, nla, tb, SEG6_IPTUNNEL_SRH)) return -EINVAL; tuninfo = nla_data(tb[SEG6_IPTUNNEL_SRH]);
@@ -782,13 +785,19 @@ static int seg6_build_state(struct net *net, struct nlattr *nla, */ min_size = sizeof(*tuninfo) + sizeof(struct ipv6_sr_hdr) + sizeof(struct in6_addr); - if (tuninfo_len < min_size) + if (tuninfo_len < min_size) { + NL_SET_ERR_MSG_ATTR(extack, tb[SEG6_IPTUNNEL_SRH], + "truncated IPv6 Segment Routing Header attribute"); return -EINVAL; + } switch (tuninfo->mode) { case SEG6_IPTUN_MODE_INLINE: - if (family != AF_INET6) + if (family != AF_INET6) { + NL_SET_ERR_MSG_ATTR(extack, tb[SEG6_IPTUNNEL_SRH], + "inline mode requires the IPv6 address family"); return -EINVAL; + } if (tb[SEG6_IPTUNNEL_SRC]) { NL_SET_ERR_MSG(extack, "incompatible mode for tunsrc");
@@ -804,12 +813,19 @@ static int seg6_build_state(struct net *net, struct nlattr *nla, case SEG6_IPTUN_MODE_L2ENCAP_RED: break; default: + NL_SET_ERR_MSG_ATTR_FMT(extack, tb[SEG6_IPTUNNEL_SRH], + "invalid SRv6 encapsulation mode %d", + tuninfo->mode); return -EINVAL; } /* verify that SRH is consistent */ - if (!seg6_validate_srh(tuninfo->srh, tuninfo_len - sizeof(*tuninfo), false)) + if (!seg6_validate_srh(tuninfo->srh, tuninfo_len - sizeof(*tuninfo), + false)) { + NL_SET_ERR_MSG_ATTR(extack, tb[SEG6_IPTUNNEL_SRH], + "invalid IPv6 Segment Routing Header"); return -EINVAL; + } newts = lwtunnel_state_alloc(tuninfo_len + sizeof(*slwt)); if (!newts)
--
2.47.3