From: Nikolay Aleksandrov <razor@blackwall.org>
To: netdev@vger.kernel.org
Cc: idosch@nvidia.com, davem@davemloft.net, edumazet@google.com,
kuba@kernel.org, pabeni@redhat.com, horms@kernel.org,
roopa@nvidia.com, bridge@lists.linux.dev, andrew+netdev@lunn.ch,
dlstevens@us.ibm.com, amwang@redhat.com,
Nikolay Aleksandrov <razor@blackwall.org>
Subject: [PATCH net v2 0/2] bridge/vxlan: fix reading neigh ha without synchronization
Date: Tue, 18 Aug 2026 18:07:54 +0300 [thread overview]
Message-ID: <20260818150756.890025-1-razor@blackwall.org> (raw)
Hi,
Neigh ha address must be read using the seqlock to get a stable snapshot.
Both the bridge and vxlan read it directly and can see partial updates.
I reproduced both issues with running neigh updates and exercising these
paths in parallel and saw partial addresses, e.g. updating between
neigh A: 02:00:00:00:00:00 neigh B: fe:ff:ff:ff:ff:ff was able to observe
02:00:ff:ff:ff:ff and fe:ff:00:00:00:00 in packets. Noticed this initially
in the bridge, then checked vxlan and its arp/neigh_reduce functions have
the same bug, route_shortcircuit is doing the right thing already.
v1 link: https://lore.kernel.org/netdev/20260817143613.685769-1-razor@blackwall.org/
v2: - use ETH_ALEN instead of MAX_ADDR_LEN, the bridge devices all use
ETH_ALEN and vxlan allows arp/nd reduce only when not in raw/gpe
so it also always uses ETH_ALEN
- align ha to 2 bytes because ether_addr_copy() expects it (Sashiko)
2-byte alignment is not strictly necessary everywhere (e.g. the ARP
suppress side can't reach ether_addr_copy) but it doesn't cost us anything
and is aligned with the rest of the code.
Cheers,
Nik
Nikolay Aleksandrov (2):
net: bridge: arp/nd proxy: fix reading neigh ha
vxlan: fix reading neigh ha
drivers/net/vxlan/vxlan_core.c | 20 +++++++++++++-------
net/bridge/br_arp_nd_proxy.c | 24 ++++++++++++++----------
2 files changed, 27 insertions(+), 17 deletions(-)
--
2.47.3
next reply other threads:[~2026-08-18 15:08 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-18 15:07 Nikolay Aleksandrov [this message]
2026-08-18 15:07 ` [PATCH net v2 1/2] net: bridge: arp/nd proxy: fix reading neigh ha Nikolay Aleksandrov
2026-08-19 8:31 ` Petr Machata
2026-08-19 15:49 ` Ido Schimmel
2026-08-18 15:07 ` [PATCH net v2 2/2] vxlan: " Nikolay Aleksandrov
2026-08-19 8:32 ` Petr Machata
2026-08-19 15:49 ` Ido Schimmel
2026-08-20 21:40 ` [PATCH net v2 0/2] bridge/vxlan: fix reading neigh ha without synchronization patchwork-bot+netdevbpf
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260818150756.890025-1-razor@blackwall.org \
--to=razor@blackwall.org \
--cc=amwang@redhat.com \
--cc=andrew+netdev@lunn.ch \
--cc=bridge@lists.linux.dev \
--cc=davem@davemloft.net \
--cc=dlstevens@us.ibm.com \
--cc=edumazet@google.com \
--cc=horms@kernel.org \
--cc=idosch@nvidia.com \
--cc=kuba@kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=roopa@nvidia.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.