* [PATCH net 0/2] ipv4: fix IP ID reuse for GSO packets
@ 2026-09-29 13:12 Eric Dumazet
2026-09-29 13:12 ` [PATCH net 1/2] ipv4: fix IP ID reuse in ip_select_ident_segs() Eric Dumazet
2026-09-29 13:12 ` [PATCH net 2/2] ipv4: reserve one IP ID per segment for UDP GSO packets Eric Dumazet
0 siblings, 2 replies; 10+ messages in thread
From: Eric Dumazet @ 2026-09-29 13:12 UTC (permalink / raw)
To: David S . Miller, Jakub Kicinski, Paolo Abeni
Cc: Simon Horman, Willem de Bruijn, David Ahern, Ido Schimmel, netdev,
edumazet, Eric Dumazet
This series fixes two cases where IPv4 GSO packets can reuse the IP IDs
of previous packets:
- Patch 1 fixes ip_select_ident_segs() for non-TCP sockets, which uses
the first IP ID of the next packet since commit f866fbc842de
("ipv4: fix data-races around inet->inet_id"). SCTP GSO is affected.
- Patch 2 makes __ip_make_skb() reserve one IP ID per segment for
UDP GSO packets, instead of a single one.
Both issues were found by code inspection.
Eric Dumazet (2):
ipv4: fix IP ID reuse in ip_select_ident_segs()
ipv4: reserve one IP ID per segment for UDP GSO packets
include/net/ip.h | 2 +-
net/ipv4/ip_output.c | 15 ++++++++++++++-
2 files changed, 15 insertions(+), 2 deletions(-)
--
2.56.0.rc1.315.gc6ed9934b7-goog
^ permalink raw reply [flat|nested] 10+ messages in thread
* [PATCH net 1/2] ipv4: fix IP ID reuse in ip_select_ident_segs()
2026-09-29 13:12 [PATCH net 0/2] ipv4: fix IP ID reuse for GSO packets Eric Dumazet
@ 2026-09-29 13:12 ` Eric Dumazet
2026-09-30 6:20 ` Jiayuan Chen
2026-09-30 12:30 ` David Ahern
2026-09-29 13:12 ` [PATCH net 2/2] ipv4: reserve one IP ID per segment for UDP GSO packets Eric Dumazet
1 sibling, 2 replies; 10+ messages in thread
From: Eric Dumazet @ 2026-09-29 13:12 UTC (permalink / raw)
To: David S . Miller, Jakub Kicinski, Paolo Abeni
Cc: Simon Horman, Willem de Bruijn, David Ahern, Ido Schimmel, netdev,
edumazet, Eric Dumazet
ip_select_ident_segs() must put the first of the @segs reserved IP IDs
in iph->id, as GSO assigns id, id + 1, ..., id + segs - 1 to segments.
Commit f866fbc842de ("ipv4: fix data-races around inet->inet_id")
used atomic_add_return() for non-TCP sockets, which returns the first
ID of the next packet instead. Consecutive GSO packets can then reuse
IP IDs.
SCTP GSO is affected. Other callers use segs == 1, and only see
a harmless off-by-one (UDP GSO has a separate, older issue, see
following patch in this series).
Use atomic_fetch_add() instead, like the TCP path.
Fixes: f866fbc842de ("ipv4: fix data-races around inet->inet_id")
Signed-off-by: Eric Dumazet <edumazet@kernel.org>
---
include/net/ip.h | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/include/net/ip.h b/include/net/ip.h
index 6f602df72ee621ee4ee45e70beef0a1b5145367f..6a3e8271a73b3669e97c4b389e916dbcbfa9f6ae 100644
--- a/include/net/ip.h
+++ b/include/net/ip.h
@@ -598,7 +598,7 @@ static inline void ip_select_ident_segs(struct net *net, struct sk_buff *skb,
val = atomic_read(&inet_sk(sk)->inet_id);
atomic_set(&inet_sk(sk)->inet_id, val + segs);
} else {
- val = atomic_add_return(segs, &inet_sk(sk)->inet_id);
+ val = atomic_fetch_add(segs, &inet_sk(sk)->inet_id);
}
iph->id = htons(val);
return;
--
2.56.0.rc1.315.gc6ed9934b7-goog
^ permalink raw reply related [flat|nested] 10+ messages in thread
* [PATCH net 2/2] ipv4: reserve one IP ID per segment for UDP GSO packets
2026-09-29 13:12 [PATCH net 0/2] ipv4: fix IP ID reuse for GSO packets Eric Dumazet
2026-09-29 13:12 ` [PATCH net 1/2] ipv4: fix IP ID reuse in ip_select_ident_segs() Eric Dumazet
@ 2026-09-29 13:12 ` Eric Dumazet
2026-09-30 6:18 ` Jiayuan Chen
2026-09-30 12:28 ` David Ahern
1 sibling, 2 replies; 10+ messages in thread
From: Eric Dumazet @ 2026-09-29 13:12 UTC (permalink / raw)
To: David S . Miller, Jakub Kicinski, Paolo Abeni
Cc: Simon Horman, Willem de Bruijn, David Ahern, Ido Schimmel, netdev,
edumazet, Eric Dumazet
__ip_make_skb() reserves a single IP ID for UDP GSO packets, but GSO
assigns one IP ID per segment. Following packets then reuse these IDs,
either from inet->inet_id or from the shared generator.
Unless IP_PMTUDISC_DO/PROBE is used, DF is not set on UDP GSO packets,
so segments can be fragmented on the path and IP ID reuse can lead to
incorrect reassembly.
Reserve one IP ID per segment, using the same test as udp_send_skb().
Fixes: bec1f6f69736 ("udp: generate gso with UDP_SEGMENT")
Signed-off-by: Eric Dumazet <edumazet@kernel.org>
---
net/ipv4/ip_output.c | 15 ++++++++++++++-
1 file changed, 14 insertions(+), 1 deletion(-)
diff --git a/net/ipv4/ip_output.c b/net/ipv4/ip_output.c
index a24cc8ee11d3ea3069bcc0d4d12e6867c2c475f7..b1cf0c6bfc79c8d234cc81ff32332116c1ee3401 100644
--- a/net/ipv4/ip_output.c
+++ b/net/ipv4/ip_output.c
@@ -1410,6 +1410,7 @@ struct sk_buff *__ip_make_skb(struct sock *sk,
struct iphdr *iph;
u8 pmtudisc, ttl;
__be16 df = 0;
+ int segs;
skb = __skb_dequeue(queue);
if (!skb)
@@ -1464,7 +1465,19 @@ struct sk_buff *__ip_make_skb(struct sock *sk,
iph->ttl = ttl;
iph->protocol = sk->sk_protocol;
ip_copy_addrs(iph, fl4);
- ip_select_ident(net, skb, sk);
+
+ /* UDP GSO packets are segmented later (see udp_send_skb()):
+ * reserve one IP ID per segment.
+ */
+ segs = 1;
+ if (cork->gso_size) {
+ int datalen = skb->len - skb_transport_offset(skb) -
+ sizeof(struct udphdr);
+
+ if (datalen > cork->gso_size)
+ segs = DIV_ROUND_UP(datalen, cork->gso_size);
+ }
+ ip_select_ident_segs(net, skb, sk, segs);
if (opt) {
iph->ihl += opt->optlen >> 2;
--
2.56.0.rc1.315.gc6ed9934b7-goog
^ permalink raw reply related [flat|nested] 10+ messages in thread
* Re: [PATCH net 2/2] ipv4: reserve one IP ID per segment for UDP GSO packets
2026-09-29 13:12 ` [PATCH net 2/2] ipv4: reserve one IP ID per segment for UDP GSO packets Eric Dumazet
@ 2026-09-30 6:18 ` Jiayuan Chen
2026-09-30 12:28 ` David Ahern
1 sibling, 0 replies; 10+ messages in thread
From: Jiayuan Chen @ 2026-09-30 6:18 UTC (permalink / raw)
To: Eric Dumazet, David S . Miller, Jakub Kicinski, Paolo Abeni
Cc: Simon Horman, Willem de Bruijn, David Ahern, Ido Schimmel, netdev,
edumazet
On 9/29/26 9:12 PM, Eric Dumazet wrote:
> __ip_make_skb() reserves a single IP ID for UDP GSO packets, but GSO
> assigns one IP ID per segment. Following packets then reuse these IDs,
> either from inet->inet_id or from the shared generator.
>
> Unless IP_PMTUDISC_DO/PROBE is used, DF is not set on UDP GSO packets,
> so segments can be fragmented on the path and IP ID reuse can lead to
> incorrect reassembly.
>
> Reserve one IP ID per segment, using the same test as udp_send_skb().
>
> Fixes: bec1f6f69736 ("udp: generate gso with UDP_SEGMENT")
> Signed-off-by: Eric Dumazet <edumazet@kernel.org>
Reviewed-by: Jiayuan Chen <jiayuan.chen@linux.dev>
> ---
> net/ipv4/ip_output.c | 15 ++++++++++++++-
> 1 file changed, 14 insertions(+), 1 deletion(-)
>
> diff --git a/net/ipv4/ip_output.c b/net/ipv4/ip_output.c
> index a24cc8ee11d3ea3069bcc0d4d12e6867c2c475f7..b1cf0c6bfc79c8d234cc81ff32332116c1ee3401 100644
> --- a/net/ipv4/ip_output.c
> +++ b/net/ipv4/ip_output.c
> @@ -1410,6 +1410,7 @@ struct sk_buff *__ip_make_skb(struct sock *sk,
> struct iphdr *iph;
> u8 pmtudisc, ttl;
> __be16 df = 0;
> + int segs;
>
> skb = __skb_dequeue(queue);
> if (!skb)
> @@ -1464,7 +1465,19 @@ struct sk_buff *__ip_make_skb(struct sock *sk,
> iph->ttl = ttl;
> iph->protocol = sk->sk_protocol;
> ip_copy_addrs(iph, fl4);
> - ip_select_ident(net, skb, sk);
> +
> + /* UDP GSO packets are segmented later (see udp_send_skb()):
> + * reserve one IP ID per segment.
> + */
> + segs = 1;
> + if (cork->gso_size) {
> + int datalen = skb->len - skb_transport_offset(skb) -
> + sizeof(struct udphdr);
> +
> + if (datalen > cork->gso_size)
> + segs = DIV_ROUND_UP(datalen, cork->gso_size);
> + }
> + ip_select_ident_segs(net, skb, sk, segs);
>
> if (opt) {
> iph->ihl += opt->optlen >> 2;
^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [PATCH net 1/2] ipv4: fix IP ID reuse in ip_select_ident_segs()
2026-09-29 13:12 ` [PATCH net 1/2] ipv4: fix IP ID reuse in ip_select_ident_segs() Eric Dumazet
@ 2026-09-30 6:20 ` Jiayuan Chen
2026-09-30 12:30 ` David Ahern
1 sibling, 0 replies; 10+ messages in thread
From: Jiayuan Chen @ 2026-09-30 6:20 UTC (permalink / raw)
To: Eric Dumazet, David S . Miller, Jakub Kicinski, Paolo Abeni
Cc: Simon Horman, Willem de Bruijn, David Ahern, Ido Schimmel, netdev,
edumazet
On 9/29/26 9:12 PM, Eric Dumazet wrote:
> ip_select_ident_segs() must put the first of the @segs reserved IP IDs
> in iph->id, as GSO assigns id, id + 1, ..., id + segs - 1 to segments.
>
> Commit f866fbc842de ("ipv4: fix data-races around inet->inet_id")
> used atomic_add_return() for non-TCP sockets, which returns the first
> ID of the next packet instead. Consecutive GSO packets can then reuse
> IP IDs.
>
> SCTP GSO is affected. Other callers use segs == 1, and only see
> a harmless off-by-one (UDP GSO has a separate, older issue, see
> following patch in this series).
>
> Use atomic_fetch_add() instead, like the TCP path.
>
> Fixes: f866fbc842de ("ipv4: fix data-races around inet->inet_id")
> Signed-off-by: Eric Dumazet <edumazet@kernel.org>
Reviewed-by: Jiayuan Chen <jiayuan.chen@linux.dev>
> ---
> include/net/ip.h | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/include/net/ip.h b/include/net/ip.h
> index 6f602df72ee621ee4ee45e70beef0a1b5145367f..6a3e8271a73b3669e97c4b389e916dbcbfa9f6ae 100644
> --- a/include/net/ip.h
> +++ b/include/net/ip.h
> @@ -598,7 +598,7 @@ static inline void ip_select_ident_segs(struct net *net, struct sk_buff *skb,
> val = atomic_read(&inet_sk(sk)->inet_id);
> atomic_set(&inet_sk(sk)->inet_id, val + segs);
> } else {
> - val = atomic_add_return(segs, &inet_sk(sk)->inet_id);
> + val = atomic_fetch_add(segs, &inet_sk(sk)->inet_id);
> }
> iph->id = htons(val);
> return;
^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [PATCH net 2/2] ipv4: reserve one IP ID per segment for UDP GSO packets
2026-09-29 13:12 ` [PATCH net 2/2] ipv4: reserve one IP ID per segment for UDP GSO packets Eric Dumazet
2026-09-30 6:18 ` Jiayuan Chen
@ 2026-09-30 12:28 ` David Ahern
2026-09-30 12:58 ` Eric Dumazet
1 sibling, 1 reply; 10+ messages in thread
From: David Ahern @ 2026-09-30 12:28 UTC (permalink / raw)
To: Eric Dumazet, David S . Miller, Jakub Kicinski, Paolo Abeni
Cc: Simon Horman, Willem de Bruijn, Ido Schimmel, netdev, edumazet
On 9/29/26 8:12 AM, Eric Dumazet wrote:
> @@ -1464,7 +1465,19 @@ struct sk_buff *__ip_make_skb(struct sock *sk,
> iph->ttl = ttl;
> iph->protocol = sk->sk_protocol;
> ip_copy_addrs(iph, fl4);
> - ip_select_ident(net, skb, sk);
> +
> + /* UDP GSO packets are segmented later (see udp_send_skb()):
> + * reserve one IP ID per segment.
> + */
> + segs = 1;
> + if (cork->gso_size) {
> + int datalen = skb->len - skb_transport_offset(skb) -
> + sizeof(struct udphdr);
hard coding a specific transport header in L3 code is crossing layers.
> +
> + if (datalen > cork->gso_size)
> + segs = DIV_ROUND_UP(datalen, cork->gso_size);
> + }
> + ip_select_ident_segs(net, skb, sk, segs);
>
> if (opt) {
> iph->ihl += opt->optlen >> 2;
^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [PATCH net 1/2] ipv4: fix IP ID reuse in ip_select_ident_segs()
2026-09-29 13:12 ` [PATCH net 1/2] ipv4: fix IP ID reuse in ip_select_ident_segs() Eric Dumazet
2026-09-30 6:20 ` Jiayuan Chen
@ 2026-09-30 12:30 ` David Ahern
1 sibling, 0 replies; 10+ messages in thread
From: David Ahern @ 2026-09-30 12:30 UTC (permalink / raw)
To: Eric Dumazet, David S . Miller, Jakub Kicinski, Paolo Abeni
Cc: Simon Horman, Willem de Bruijn, Ido Schimmel, netdev, edumazet
On 9/29/26 8:12 AM, Eric Dumazet wrote:
> ip_select_ident_segs() must put the first of the @segs reserved IP IDs
> in iph->id, as GSO assigns id, id + 1, ..., id + segs - 1 to segments.
>
> Commit f866fbc842de ("ipv4: fix data-races around inet->inet_id")
> used atomic_add_return() for non-TCP sockets, which returns the first
> ID of the next packet instead. Consecutive GSO packets can then reuse
> IP IDs.
>
> SCTP GSO is affected. Other callers use segs == 1, and only see
> a harmless off-by-one (UDP GSO has a separate, older issue, see
> following patch in this series).
>
> Use atomic_fetch_add() instead, like the TCP path.
>
> Fixes: f866fbc842de ("ipv4: fix data-races around inet->inet_id")
> Signed-off-by: Eric Dumazet <edumazet@kernel.org>
> ---
> include/net/ip.h | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
Reviewed-by: David Ahern <dsahern@kernel.org>
^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [PATCH net 2/2] ipv4: reserve one IP ID per segment for UDP GSO packets
2026-09-30 12:28 ` David Ahern
@ 2026-09-30 12:58 ` Eric Dumazet
2026-09-30 13:50 ` David Ahern
0 siblings, 1 reply; 10+ messages in thread
From: Eric Dumazet @ 2026-09-30 12:58 UTC (permalink / raw)
To: David Ahern
Cc: Eric Dumazet, David S . Miller, Jakub Kicinski, Paolo Abeni,
Simon Horman, Willem de Bruijn, Ido Schimmel, netdev
On Wed, Sep 30, 2026 at 2:29 PM David Ahern <dsahern@kernel.org> wrote:
>
> On 9/29/26 8:12 AM, Eric Dumazet wrote:
> > @@ -1464,7 +1465,19 @@ struct sk_buff *__ip_make_skb(struct sock *sk,
> > iph->ttl = ttl;
> > iph->protocol = sk->sk_protocol;
> > ip_copy_addrs(iph, fl4);
> > - ip_select_ident(net, skb, sk);
> > +
> > + /* UDP GSO packets are segmented later (see udp_send_skb()):
> > + * reserve one IP ID per segment.
> > + */
> > + segs = 1;
> > + if (cork->gso_size) {
> > + int datalen = skb->len - skb_transport_offset(skb) -
> > + sizeof(struct udphdr);
>
> hard coding a specific transport header in L3 code is crossing layers.
>
Only UDP sets cork->gso_size, so this is UDP specific code in
__ip_make_skb(), like the existing sk_is_tcp() case in the same
function.
I can make this explicit in v2 with:
if (cork->gso_size && sk_is_udp(sk)) {
Selecting the IP ID from udp_send_skb() instead would either burn
one extra IP ID per packet (50 % more for 2-segment GSO packets,
making wraparound faster), or require __ip_make_skb() to leave
iph->id unset for UDP GSO packets, with a simlar kayer violation concern.
Would this be acceptable, or do you have another suggestion?
^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [PATCH net 2/2] ipv4: reserve one IP ID per segment for UDP GSO packets
2026-09-30 12:58 ` Eric Dumazet
@ 2026-09-30 13:50 ` David Ahern
2026-09-30 14:24 ` Eric Dumazet
0 siblings, 1 reply; 10+ messages in thread
From: David Ahern @ 2026-09-30 13:50 UTC (permalink / raw)
To: Eric Dumazet
Cc: Eric Dumazet, David S . Miller, Jakub Kicinski, Paolo Abeni,
Simon Horman, Willem de Bruijn, Ido Schimmel, netdev
On 9/30/26 7:58 AM, Eric Dumazet wrote:
> On Wed, Sep 30, 2026 at 2:29 PM David Ahern <dsahern@kernel.org> wrote:
>>
>> On 9/29/26 8:12 AM, Eric Dumazet wrote:
>>> @@ -1464,7 +1465,19 @@ struct sk_buff *__ip_make_skb(struct sock *sk,
>>> iph->ttl = ttl;
>>> iph->protocol = sk->sk_protocol;
>>> ip_copy_addrs(iph, fl4);
>>> - ip_select_ident(net, skb, sk);
>>> +
>>> + /* UDP GSO packets are segmented later (see udp_send_skb()):
>>> + * reserve one IP ID per segment.
>>> + */
>>> + segs = 1;
>>> + if (cork->gso_size) {
>>> + int datalen = skb->len - skb_transport_offset(skb) -
>>> + sizeof(struct udphdr);
>>
>> hard coding a specific transport header in L3 code is crossing layers.
>>
>
> Only UDP sets cork->gso_size, so this is UDP specific code in
> __ip_make_skb(), like the existing sk_is_tcp() case in the same
> function.
I went looking for other transport references in L3 code and missed this
one.
>
> I can make this explicit in v2 with:
>
> if (cork->gso_size && sk_is_udp(sk)) {
>
> Selecting the IP ID from udp_send_skb() instead would either burn
> one extra IP ID per packet (50 % more for 2-segment GSO packets,
> making wraparound faster), or require __ip_make_skb() to leave
> iph->id unset for UDP GSO packets, with a simlar kayer violation concern.
>
> Would this be acceptable, or do you have another suggestion?
sure. I went down the path of adding an input arg to __ip_make_skb, but
this is simpler.
^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [PATCH net 2/2] ipv4: reserve one IP ID per segment for UDP GSO packets
2026-09-30 13:50 ` David Ahern
@ 2026-09-30 14:24 ` Eric Dumazet
0 siblings, 0 replies; 10+ messages in thread
From: Eric Dumazet @ 2026-09-30 14:24 UTC (permalink / raw)
To: David Ahern
Cc: Eric Dumazet, David S . Miller, Jakub Kicinski, Paolo Abeni,
Simon Horman, Willem de Bruijn, Ido Schimmel, netdev
On Wed, Sep 30, 2026 at 3:50 PM David Ahern <dsahern@kernel.org> wrote:
>
> On 9/30/26 7:58 AM, Eric Dumazet wrote:
> > On Wed, Sep 30, 2026 at 2:29 PM David Ahern <dsahern@kernel.org> wrote:
> >>
> >> On 9/29/26 8:12 AM, Eric Dumazet wrote:
> >>> @@ -1464,7 +1465,19 @@ struct sk_buff *__ip_make_skb(struct sock *sk,
> >>> iph->ttl = ttl;
> >>> iph->protocol = sk->sk_protocol;
> >>> ip_copy_addrs(iph, fl4);
> >>> - ip_select_ident(net, skb, sk);
> >>> +
> >>> + /* UDP GSO packets are segmented later (see udp_send_skb()):
> >>> + * reserve one IP ID per segment.
> >>> + */
> >>> + segs = 1;
> >>> + if (cork->gso_size) {
> >>> + int datalen = skb->len - skb_transport_offset(skb) -
> >>> + sizeof(struct udphdr);
> >>
> >> hard coding a specific transport header in L3 code is crossing layers.
> >>
> >
> > Only UDP sets cork->gso_size, so this is UDP specific code in
> > __ip_make_skb(), like the existing sk_is_tcp() case in the same
> > function.
>
> I went looking for other transport references in L3 code and missed this
> one.
>
> >
> > I can make this explicit in v2 with:
> >
> > if (cork->gso_size && sk_is_udp(sk)) {
> >
> > Selecting the IP ID from udp_send_skb() instead would either burn
> > one extra IP ID per packet (50 % more for 2-segment GSO packets,
> > making wraparound faster), or require __ip_make_skb() to leave
> > iph->id unset for UDP GSO packets, with a simlar kayer violation concern.
> >
> > Would this be acceptable, or do you have another suggestion?
>
> sure. I went down the path of adding an input arg to __ip_make_skb, but
> this is simpler.
Great, thanks, I will send V2 shortly.
pw-bot: cr
^ permalink raw reply [flat|nested] 10+ messages in thread
end of thread, other threads:[~2026-09-30 14:24 UTC | newest]
Thread overview: 10+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-29 13:12 [PATCH net 0/2] ipv4: fix IP ID reuse for GSO packets Eric Dumazet
2026-09-29 13:12 ` [PATCH net 1/2] ipv4: fix IP ID reuse in ip_select_ident_segs() Eric Dumazet
2026-09-30 6:20 ` Jiayuan Chen
2026-09-30 12:30 ` David Ahern
2026-09-29 13:12 ` [PATCH net 2/2] ipv4: reserve one IP ID per segment for UDP GSO packets Eric Dumazet
2026-09-30 6:18 ` Jiayuan Chen
2026-09-30 12:28 ` David Ahern
2026-09-30 12:58 ` Eric Dumazet
2026-09-30 13:50 ` David Ahern
2026-09-30 14:24 ` Eric Dumazet
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.