All of lore.kernel.org
 help / color / mirror / Atom feed
From: Nikolay Aleksandrov <razor@blackwall.org>
To: Danielle Ratson <danieller@nvidia.com>
Cc: netdev@vger.kernel.org, dsahern@kernel.org, idosch@nvidia.com,
	davem@davemloft.net, edumazet@google.com, kuba@kernel.org,
	pabeni@redhat.com, horms@kernel.org, ja@ssi.bg, petrm@nvidia.com,
	fw@strlen.de, kuniyu@google.com, bridge@lists.linux.dev,
	linux-kernel@vger.kernel.org
Subject: Re: [PATCH net-next v2 4/5] bridge: Linearize skb once the ND message type is validated
Date: Mon, 3 Aug 2026 18:25:21 +0300	[thread overview]
Message-ID: <anCy4eCZAbz3Tv4u@penguin> (raw)
In-Reply-To: <20260803112505.613873-5-danieller@nvidia.com>

On Mon, Aug 03, 2026 at 02:25:04PM +0300, Danielle Ratson wrote:
> br_nd_send() parses ND options from ns->opt[] and therefore needs the skb
> to be linear. Commit a01aee7cafc5 ("bridge: br_nd_send: linearize skb
> before parsing ND options") ensured that by linearizing inside
> br_nd_send() itself.
> 
> Move the linearization up into br_is_nd_neigh_msg(), right after
> ndisc_check_ns_na() has validated the message as an NS/NA. This makes a
> linear buffer a property of every recognized ND message, so that this and
> any future ND message handling operate on a linear skb and cannot
> reintroduce that class of bug by forgetting to linearize.
> 
> Since the skb is now linear by the time br_nd_send() runs, drop the
> linearization there and derive ns from the transport header set by
> ndisc_check_ns_na(), instead of recomputing it from the network header.
> 
> If linearization fails under memory pressure, br_is_nd_neigh_msg() returns
> NULL and the packet falls back to normal forwarding rather than being
> suppressed.
> 
> Reviewed-by: Petr Machata <petrm@nvidia.com>
> Signed-off-by: Danielle Ratson <danieller@nvidia.com>
> ---
> 
> Notes:
>     v2:
>     	* Add a comment noting that br_is_nd_neigh_msg() also linearizes the
>     	  skb.
> 
>  net/bridge/br_arp_nd_proxy.c | 11 ++++++++---
>  1 file changed, 8 insertions(+), 3 deletions(-)
> 
> diff --git a/net/bridge/br_arp_nd_proxy.c b/net/bridge/br_arp_nd_proxy.c
> index 445c930ed59b..6b6de0eff38c 100644
> --- a/net/bridge/br_arp_nd_proxy.c
> +++ b/net/bridge/br_arp_nd_proxy.c
> @@ -235,11 +235,17 @@ void br_do_proxy_suppress_arp(struct sk_buff *skb, struct net_bridge *br,
>  #endif
>  
>  #if IS_ENABLED(CONFIG_IPV6)
> +/* Validate skb as an NS/NA and linearize it for br_nd_send()'s ND
> + * option parsing; returns the nd_msg, or NULL on failure.
> + */
>  struct nd_msg *br_is_nd_neigh_msg(struct sk_buff *skb)
>  {
>  	if (ndisc_check_ns_na(skb))
>  		return NULL;
>  
> +	if (skb_linearize(skb))
> +		return NULL;
> +
>  	return (struct nd_msg *)skb_transport_header(skb);
>  }
>  
> @@ -259,7 +265,7 @@ static void br_nd_send(struct net_bridge *br, struct net_bridge_port *p,
>  	bool dad;
>  	u16 pvid;
>  
> -	if (!dev || skb_linearize(request))
> +	if (!dev)
>  		return;
>  
>  	len = LL_RESERVED_SPACE(dev) + sizeof(struct ipv6hdr) +
> @@ -276,8 +282,7 @@ static void br_nd_send(struct net_bridge *br, struct net_bridge_port *p,
>  	skb_set_mac_header(reply, 0);
>  
>  	daddr = eth_hdr(request)->h_source;
> -	ns = (struct nd_msg *)(skb_network_header(request) +
> -			       sizeof(struct ipv6hdr));
> +	ns = (struct nd_msg *)skb_transport_header(request);
>  
>  	/* Do we need option processing ? */
>  	ns_olen = request->len - (skb_network_offset(request) +
> -- 
> 2.54.0
> 

Thanks,
Acked-by: Nikolay Aleksandrov <razor@blackwall.org>

  reply	other threads:[~2026-08-03 15:25 UTC|newest]

Thread overview: 11+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-03 11:25 [PATCH net-next v2 0/5] bridge: Validate and clean up IPv6 neighbour suppression Danielle Ratson
2026-08-03 11:25 ` [PATCH net-next v2 1/5] bridge: Use direct pointer in br_is_nd_neigh_msg() Danielle Ratson
2026-08-05  8:06   ` Danielle Ratson
2026-08-03 11:25 ` [PATCH net-next v2 2/5] ipv6: ndisc: Add ndisc_check_ns_na() validation helper Danielle Ratson
2026-08-05  8:06   ` Danielle Ratson
2026-08-03 11:25 ` [PATCH net-next v2 3/5] bridge: Validate NS/NA messages using ndisc_check_ns_na() Danielle Ratson
2026-08-03 11:25 ` [PATCH net-next v2 4/5] bridge: Linearize skb once the ND message type is validated Danielle Ratson
2026-08-03 15:25   ` Nikolay Aleksandrov [this message]
2026-08-03 11:25 ` [PATCH net-next v2 5/5] bridge: Use ndisc_parse_options() to parse ND options in br_nd_send() Danielle Ratson
2026-08-05  8:07   ` Danielle Ratson
2026-08-07 23:40 ` [PATCH net-next v2 0/5] bridge: Validate and clean up IPv6 neighbour suppression patchwork-bot+netdevbpf

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=anCy4eCZAbz3Tv4u@penguin \
    --to=razor@blackwall.org \
    --cc=bridge@lists.linux.dev \
    --cc=danieller@nvidia.com \
    --cc=davem@davemloft.net \
    --cc=dsahern@kernel.org \
    --cc=edumazet@google.com \
    --cc=fw@strlen.de \
    --cc=horms@kernel.org \
    --cc=idosch@nvidia.com \
    --cc=ja@ssi.bg \
    --cc=kuba@kernel.org \
    --cc=kuniyu@google.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    --cc=petrm@nvidia.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.