From: Yan Zhai <yan@cloudflare.com>
To: "open list:NETWORKING [TCP]" <netdev@vger.kernel.org>
Cc: kernel-team@cloudflare.com, Eric Dumazet <edumazet@google.com>,
"David S. Miller" <davem@davemloft.net>,
David Ahern <dsahern@kernel.org>,
Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
Marcelo Ricardo Leitner <marcelo.leitner@gmail.com>,
Xin Long <lucien.xin@gmail.com>,
Herbert Xu <herbert@gondor.apana.org.au>,
Andrew Melnychenko <andrew@daynix.com>,
Jason Wang <jasowang@redhat.com>,
Willem de Bruijn <willemdebruijn.kernel@gmail.com>,
open list <linux-kernel@vger.kernel.org>,
"open list:SCTP PROTOCOL" <linux-sctp@vger.kernel.org>
Subject: [PATCH net] gso: fix GSO_DODGY bit handling for related protocols
Date: Wed, 12 Jul 2023 18:55:20 -0700 [thread overview]
Message-ID: <ZK9ZiNMsJX8+1F3N@debian.debian> (raw)
SKB_GSO_DODGY bit indicates a GSO packet comes from an untrusted source.
The canonical way is to recompute the gso_segs to avoid device driver
issues. Afterwards, the DODGY bit can be removed to avoid re-check at the
egress of later devices, e.g. packets can egress to a vlan device backed
by a real NIC.
Commit 1fd54773c267 ("udp: allow header check for dodgy GSO_UDP_L4
packets.") checks DODGY bit for UDP, but for packets that can be fed
directly to the device after gso_segs reset, it actually falls through
to fragmentation [1].
Commit 90017accff61 ("sctp: Add GSO support") and commit 3820c3f3e417
("[TCP]: Reset gso_segs if packet is dodgy") both didn't remove the DODGY
bit after recomputing gso_segs.
This change fixes the GSO_UDP_L4 handling case, and remove the DODGY bit
at other places.
Fixes: 90017accff61 ("sctp: Add GSO support")
Fixes: 3820c3f3e417 ("[TCP]: Reset gso_segs if packet is dodgy")
Fixes: 1fd54773c267 ("udp: allow header check for dodgy GSO_UDP_L4 packets.")
Signed-off-by: Yan Zhai <yan@cloudflare.com>
---
[1]:
https://lore.kernel.org/all/CAJPywTKDdjtwkLVUW6LRA2FU912qcDmQOQGt2WaDo28KzYDg+A@mail.gmail.com/
---
net/ipv4/tcp_offload.c | 1 +
net/ipv4/udp_offload.c | 19 +++++++++++++++----
net/ipv6/udp_offload.c | 19 +++++++++++++++----
net/sctp/offload.c | 2 ++
4 files changed, 33 insertions(+), 8 deletions(-)
diff --git a/net/ipv4/tcp_offload.c b/net/ipv4/tcp_offload.c
index 8311c38267b5..f9b93708c22e 100644
--- a/net/ipv4/tcp_offload.c
+++ b/net/ipv4/tcp_offload.c
@@ -87,6 +87,7 @@ struct sk_buff *tcp_gso_segment(struct sk_buff *skb,
/* Packet is from an untrusted source, reset gso_segs. */
skb_shinfo(skb)->gso_segs = DIV_ROUND_UP(skb->len, mss);
+ skb_shinfo(skb)->gso_type &= ~SKB_GSO_DODGY;
segs = NULL;
goto out;
diff --git a/net/ipv4/udp_offload.c b/net/ipv4/udp_offload.c
index 75aa4de5b731..bd29cf19bb6b 100644
--- a/net/ipv4/udp_offload.c
+++ b/net/ipv4/udp_offload.c
@@ -388,11 +388,22 @@ static struct sk_buff *udp4_ufo_fragment(struct sk_buff *skb,
if (!pskb_may_pull(skb, sizeof(struct udphdr)))
goto out;
- if (skb_shinfo(skb)->gso_type & SKB_GSO_UDP_L4 &&
- !skb_gso_ok(skb, features | NETIF_F_GSO_ROBUST))
- return __udp_gso_segment(skb, features, false);
-
mss = skb_shinfo(skb)->gso_size;
+
+ if (skb_shinfo(skb)->gso_type & SKB_GSO_UDP_L4) {
+ if (skb_gso_ok(skb, features | NETIF_F_GSO_ROBUST)) {
+ /* Packet is from an untrusted source, reset actual gso_segs */
+ skb_shinfo(skb)->gso_segs = DIV_ROUND_UP(skb->len - sizeof(*uh),
+ mss);
+ skb_shinfo(skb)->gso_type &= ~SKB_GSO_DODGY;
+
+ segs = NULL;
+ goto out;
+ } else {
+ return __udp_gso_segment(skb, features, false);
+ }
+ }
+
if (unlikely(skb->len <= mss))
goto out;
diff --git a/net/ipv6/udp_offload.c b/net/ipv6/udp_offload.c
index ad3b8726873e..6857d9f7bd06 100644
--- a/net/ipv6/udp_offload.c
+++ b/net/ipv6/udp_offload.c
@@ -43,11 +43,22 @@ static struct sk_buff *udp6_ufo_fragment(struct sk_buff *skb,
if (!pskb_may_pull(skb, sizeof(struct udphdr)))
goto out;
- if (skb_shinfo(skb)->gso_type & SKB_GSO_UDP_L4 &&
- !skb_gso_ok(skb, features | NETIF_F_GSO_ROBUST))
- return __udp_gso_segment(skb, features, true);
-
mss = skb_shinfo(skb)->gso_size;
+
+ if (skb_shinfo(skb)->gso_type & SKB_GSO_UDP_L4) {
+ if (skb_gso_ok(skb, features | NETIF_F_GSO_ROBUST)) {
+ /* Packet is from an untrusted source, reset actual gso_segs */
+ skb_shinfo(skb)->gso_segs = DIV_ROUND_UP(skb->len - sizeof(*uh),
+ mss);
+ skb_shinfo(skb)->gso_type &= ~SKB_GSO_DODGY;
+
+ segs = NULL;
+ goto out;
+ } else {
+ return __udp_gso_segment(skb, features, true);
+ }
+ }
+
if (unlikely(skb->len <= mss))
goto out;
diff --git a/net/sctp/offload.c b/net/sctp/offload.c
index 502095173d88..3d2b44db0d42 100644
--- a/net/sctp/offload.c
+++ b/net/sctp/offload.c
@@ -65,6 +65,8 @@ static struct sk_buff *sctp_gso_segment(struct sk_buff *skb,
skb_walk_frags(skb, frag_iter)
pinfo->gso_segs++;
+ pinfo->gso_type &= ~SKB_GSO_DODGY;
+
segs = NULL;
goto out;
}
--
2.30.2
next reply other threads:[~2023-07-13 1:55 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2023-07-13 1:55 Yan Zhai [this message]
2023-07-13 2:01 ` [PATCH net] gso: fix GSO_DODGY bit handling for related protocols Willem de Bruijn
2023-07-13 2:11 ` Jason Wang
2023-07-13 2:57 ` Yan Zhai
2023-07-13 2:11 ` Jason Wang
2023-07-13 2:58 ` Yan Zhai
2023-07-13 7:11 ` Paolo Abeni
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=ZK9ZiNMsJX8+1F3N@debian.debian \
--to=yan@cloudflare.com \
--cc=andrew@daynix.com \
--cc=davem@davemloft.net \
--cc=dsahern@kernel.org \
--cc=edumazet@google.com \
--cc=herbert@gondor.apana.org.au \
--cc=jasowang@redhat.com \
--cc=kernel-team@cloudflare.com \
--cc=kuba@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-sctp@vger.kernel.org \
--cc=lucien.xin@gmail.com \
--cc=marcelo.leitner@gmail.com \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=willemdebruijn.kernel@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.