All of lore.kernel.org
 help / color / mirror / Atom feed
From: David Ahern <dsahern@kernel.org>
To: Andrea Mayer <andrea.mayer@uniroma2.it>,
	"David S. Miller" <davem@davemloft.net>,
	Eric Dumazet <edumazet@google.com>,
	Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
	Simon Horman <horms@kernel.org>
Cc: netdev@vger.kernel.org, linux-kernel@vger.kernel.org,
	David Lebrun <david.lebrun@uclouvain.be>,
	Stefano Salsano <stefano.salsano@uniroma2.it>
Subject: Re: [PATCH net] seg6: set IPSKB_L3SLAVE from IP6SKB_L3SLAVE on IPIP decapsulation
Date: Sun, 13 Sep 2026 14:19:42 -0600	[thread overview]
Message-ID: <7c095018-267f-4097-9d38-fe116041f47c@kernel.org> (raw)
In-Reply-To: <20260913194421.31-1-andrea.mayer@uniroma2.it>

On 9/13/26 2:44 PM, Andrea Mayer wrote:
> When an SRv6 packet arrives on an interface enslaved to a VRF,
> vrf_ip6_rcv() sets IP6SKB_L3SLAVE in IP6CB, but decap_and_validate()
> has never set IPSKB_L3SLAVE in IPCB. The bit stayed clear in the
> common case, and with CONFIG_IPV6_MIP6 the leftover frag_max_size of
> a reassembled outer packet could even set it, with no VRF involved.
> Commit 44930446dde4 ("ipv6: seg6: clear IPv4 control block on IPIP
> decapsulation") then made the unreliable bit reliably clear.
> 
> The effect of the missing flag is visible with End.DX4 when a
> delivery to a local address of the node reaches the socket lookup.
> For example, a UDP socket bound to the enslaved ingress interface
> does not receive any of the decapsulated packets, while an unbound
> socket outside the VRF does.
> This contradicts Documentation/networking/vrf.rst: by default the
> scope of an unbound UDP or TCP socket is limited to the default VRF.
> 
> Set IPSKB_L3SLAVE for IPv4 in decap_and_validate(), which already does
> the same for IPv6. The socket lookup then matches the decapsulated
> packet like any other packet received on that enslaved interface. Such
> a packet matches an unbound UDP or TCP socket only when
> udp_l3mdev_accept or tcp_l3mdev_accept is set.
> 
> Fixes: 891ef8dd2a8d ("ipv6: sr: implement additional seg6local actions")
> Signed-off-by: Andrea Mayer <andrea.mayer@uniroma2.it>
> ---
>  net/ipv6/seg6_local.c | 3 +++
>  1 file changed, 3 insertions(+)
> 

Reviewed-by: David Ahern <dsahern@kernel.org>



      reply	other threads:[~2026-09-13 20:19 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-13 19:44 [PATCH net] seg6: set IPSKB_L3SLAVE from IP6SKB_L3SLAVE on IPIP decapsulation Andrea Mayer
2026-09-13 20:19 ` David Ahern [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=7c095018-267f-4097-9d38-fe116041f47c@kernel.org \
    --to=dsahern@kernel.org \
    --cc=andrea.mayer@uniroma2.it \
    --cc=davem@davemloft.net \
    --cc=david.lebrun@uclouvain.be \
    --cc=edumazet@google.com \
    --cc=horms@kernel.org \
    --cc=kuba@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    --cc=stefano.salsano@uniroma2.it \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.