All of lore.kernel.org
 help / color / mirror / Atom feed
From: Nikolay Aleksandrov <razor@blackwall.org>
To: David Corvaglia <david@corvaglia.dev>
Cc: Ido Schimmel <idosch@nvidia.com>,
	"David S . Miller" <davem@davemloft.net>,
	Eric Dumazet <edumazet@google.com>,
	Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
	Simon Horman <horms@kernel.org>,
	bridge@lists.linux.dev, netdev@vger.kernel.org,
	linux-kernel@vger.kernel.org
Subject: Re: [PATCH net-next] bridge: mrp: fix MRP_Test option TLV length
Date: Sat, 25 Jul 2026 17:51:21 +0300	[thread overview]
Message-ID: <amTNacya_ZXLjoDn@penguin> (raw)
In-Reply-To: <20260724051202.61946-1-david@corvaglia.dev>

On Fri, Jul 24, 2026 at 05:12:02AM +0000, David Corvaglia wrote:
> oui is a pointer, so sizeof(oui) is the pointer size. The MRA
> Option TLV thus advertises a wrong length (15 vs 10 on x86_64),
> causing misparsing of the frame on peers. Fix is to replace
> with sizeof(*oui).
> 
> Signed-off-by: David Corvaglia <david@corvaglia.dev>
> ---
>  net/bridge/br_mrp.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/net/bridge/br_mrp.c b/net/bridge/br_mrp.c
> index 3f7126a7d720..179d2470b724 100644
> --- a/net/bridge/br_mrp.c
> +++ b/net/bridge/br_mrp.c
> @@ -215,7 +215,7 @@ static struct sk_buff *br_mrp_alloc_test_skb(struct br_mrp *mrp,
>  		struct br_mrp_oui_hdr *oui = NULL;
>  		u8 length;
>  
> -		length = sizeof(*sub_opt) + sizeof(*sub_tlv) + sizeof(oui) +
> +		length = sizeof(*sub_opt) + sizeof(*sub_tlv) + sizeof(*oui) +
>  			MRP_OPT_PADDING;
>  		br_mrp_skb_tlv(skb, BR_MRP_TLV_HEADER_OPTION, length);
>  
> -- 
> 2.55.0
> 

This is clearly a fix and looks like it is needed for proper parsing.
I think it should be targeted at -net with a fixes tag, probably
f7458934b0791 ("net: bridge: mrp: Update the Test frames for MRA")

Cheers,
 Nik

      reply	other threads:[~2026-07-25 14:51 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-24  5:12 [PATCH net-next] bridge: mrp: fix MRP_Test option TLV length David Corvaglia
2026-07-25 14:51 ` Nikolay Aleksandrov [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=amTNacya_ZXLjoDn@penguin \
    --to=razor@blackwall.org \
    --cc=bridge@lists.linux.dev \
    --cc=davem@davemloft.net \
    --cc=david@corvaglia.dev \
    --cc=edumazet@google.com \
    --cc=horms@kernel.org \
    --cc=idosch@nvidia.com \
    --cc=kuba@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.