* [PATCH net-next 00/10] net: remove skb mac_header assumptions in TX paths (I)
@ 2026-09-02 0:33 Eric Dumazet
2026-09-02 0:33 ` [PATCH net-next 01/10] bonding: do not assume mac header is set in ALB/TLB tx paths Eric Dumazet
` (10 more replies)
0 siblings, 11 replies; 14+ messages in thread
From: Eric Dumazet @ 2026-09-02 0:33 UTC (permalink / raw)
To: David S . Miller, Jakub Kicinski, Paolo Abeni
Cc: Simon Horman, Andrew Lunn, netdev, eric.dumazet, Eric Dumazet
In the transmit path, network drivers should not assume that
skb->mac_header has been set.
In the TX path, skb->data points to the start of the L2 header. Using
eth_hdr(skb) or vlan_eth_hdr(skb) when mac_header is unset reads from
skb->head + (u16)~0, leading to out-of-bounds reads (flagged by KASAN)
or triggering DEBUG_NET warnings.
Commit 96cc4b69581d ("macvlan: do not assume mac_header is set in
macvlan_broadcast()") introduced skb_eth_hdr() (and later commit
1f5020acb33f ("net: vlan: introduce skb_vlan_eth_hdr()")) to safely
access L2 headers in TX paths via skb->data without needing to call
skb_reset_mac_header().
This series converts the first batch of 10 network drivers and virtual
devices to use skb_eth_hdr(), skb_vlan_eth_hdr(), and
skb_checksum_start_offset() in their TX paths, and removes now redundant
skb_reset_mac_header() calls.
When all drivers are converted, we will remove skb_reset_mac_header()
from our TX fast paths.
Eric Dumazet (10):
bonding: do not assume mac header is set in ALB/TLB tx paths
atlantic: do not assume mac header is set in aq_ndev_start_xmit()
ibmveth: do not assume mac header is set in ibmveth_start_xmit()
net: mediatek: do not assume mac header is set in mtk_start_xmit()
netvsc: do not assume mac header is set in netvsc_start_xmit()
macsec: do not assume mac header is set in macsec_encrypt_finish()
macvlan: do not assume mac header is set in macvlan_broadcast()
vxlan: do not assume mac header is set in tx paths
cdc_mbim: do not assume mac header is set in cdc_mbim_tx_fixup()
ice: do not assume mac header is set in tx paths
drivers/net/bonding/bond_alb.c | 8 +++----
.../net/ethernet/aquantia/atlantic/aq_main.c | 2 +-
drivers/net/ethernet/ibm/ibmveth.c | 2 +-
drivers/net/ethernet/intel/ice/ice_eswitch.c | 2 +-
drivers/net/ethernet/intel/ice/ice_txrx.c | 4 ++--
drivers/net/ethernet/mediatek/mtk_eth_soc.c | 2 +-
drivers/net/hyperv/netvsc_drv.c | 3 +--
drivers/net/macsec.c | 3 +--
drivers/net/macvlan.c | 5 ++--
drivers/net/usb/cdc_mbim.c | 5 ++--
drivers/net/vxlan/vxlan_core.c | 24 +++++++++----------
drivers/net/vxlan/vxlan_mdb.c | 4 ++--
12 files changed, 28 insertions(+), 36 deletions(-)
--
2.55.0.966.g6673acef38-goog
^ permalink raw reply [flat|nested] 14+ messages in thread
* [PATCH net-next 01/10] bonding: do not assume mac header is set in ALB/TLB tx paths
2026-09-02 0:33 [PATCH net-next 00/10] net: remove skb mac_header assumptions in TX paths (I) Eric Dumazet
@ 2026-09-02 0:33 ` Eric Dumazet
2026-09-02 0:33 ` [PATCH net-next 02/10] atlantic: do not assume mac header is set in aq_ndev_start_xmit() Eric Dumazet
` (9 subsequent siblings)
10 siblings, 0 replies; 14+ messages in thread
From: Eric Dumazet @ 2026-09-02 0:33 UTC (permalink / raw)
To: David S . Miller, Jakub Kicinski, Paolo Abeni
Cc: Simon Horman, Andrew Lunn, netdev, eric.dumazet, Eric Dumazet
We should not assume mac header is set in output path.
Use skb_eth_hdr() instead of eth_hdr() to fix the issue,
and remove now redundant skb_reset_mac_header() calls.
Signed-off-by: Eric Dumazet <edumazet@google.com>
---
drivers/net/bonding/bond_alb.c | 8 +++-----
1 file changed, 3 insertions(+), 5 deletions(-)
diff --git a/drivers/net/bonding/bond_alb.c b/drivers/net/bonding/bond_alb.c
index 839f7482dc1823b12a13437a4b6639e3b63d46ec..3d2c6a9fe3b7bfdd46299aeff14689d323c525d3 100644
--- a/drivers/net/bonding/bond_alb.c
+++ b/drivers/net/bonding/bond_alb.c
@@ -1339,7 +1339,7 @@ static netdev_tx_t bond_do_alb_xmit(struct sk_buff *skb, struct bonding *bond,
struct slave *tx_slave)
{
struct alb_bond_info *bond_info = &(BOND_ALB_INFO(bond));
- struct ethhdr *eth_data = eth_hdr(skb);
+ struct ethhdr *eth_data = skb_eth_hdr(skb);
if (!tx_slave) {
/* unbalanced or unassigned, send through primary */
@@ -1374,8 +1374,7 @@ struct slave *bond_xmit_tlb_slave_get(struct bonding *bond,
struct ethhdr *eth_data;
u32 hash_index;
- skb_reset_mac_header(skb);
- eth_data = eth_hdr(skb);
+ eth_data = skb_eth_hdr(skb);
/* Do not TX balance any multicast or broadcast */
if (!is_multicast_ether_addr(eth_data->h_dest)) {
@@ -1427,8 +1426,7 @@ struct slave *bond_xmit_alb_slave_get(struct bonding *bond,
u32 hash_index = 0;
int hash_size = 0;
- skb_reset_mac_header(skb);
- eth_data = eth_hdr(skb);
+ eth_data = skb_eth_hdr(skb);
switch (ntohs(skb->protocol)) {
case ETH_P_IP: {
--
2.55.0.966.g6673acef38-goog
^ permalink raw reply related [flat|nested] 14+ messages in thread
* [PATCH net-next 02/10] atlantic: do not assume mac header is set in aq_ndev_start_xmit()
2026-09-02 0:33 [PATCH net-next 00/10] net: remove skb mac_header assumptions in TX paths (I) Eric Dumazet
2026-09-02 0:33 ` [PATCH net-next 01/10] bonding: do not assume mac header is set in ALB/TLB tx paths Eric Dumazet
@ 2026-09-02 0:33 ` Eric Dumazet
2026-09-02 0:33 ` [PATCH net-next 03/10] ibmveth: do not assume mac header is set in ibmveth_start_xmit() Eric Dumazet
` (8 subsequent siblings)
10 siblings, 0 replies; 14+ messages in thread
From: Eric Dumazet @ 2026-09-02 0:33 UTC (permalink / raw)
To: David S . Miller, Jakub Kicinski, Paolo Abeni
Cc: Simon Horman, Andrew Lunn, netdev, eric.dumazet, Eric Dumazet
We should not assume mac header is set in output path.
Use skb_eth_hdr() instead of eth_hdr() to fix the issue.
Signed-off-by: Eric Dumazet <edumazet@google.com>
---
drivers/net/ethernet/aquantia/atlantic/aq_main.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/aquantia/atlantic/aq_main.c b/drivers/net/ethernet/aquantia/atlantic/aq_main.c
index 1da14786fe5cc73234227222569f1f6c8207eeab..d7cbab46a943a87fed7cdd80b22d2542bbf12282 100644
--- a/drivers/net/ethernet/aquantia/atlantic/aq_main.c
+++ b/drivers/net/ethernet/aquantia/atlantic/aq_main.c
@@ -120,7 +120,7 @@ static netdev_tx_t aq_ndev_start_xmit(struct sk_buff *skb, struct net_device *nd
udp_hdr(skb)->dest == htons(PTP_GEN_PORT))))
return aq_ptp_xmit(aq_nic, skb);
- if (unlikely(eth_hdr(skb)->h_proto == htons(ETH_P_1588)))
+ if (unlikely(skb_eth_hdr(skb)->h_proto == htons(ETH_P_1588)))
return aq_ptp_xmit(aq_nic, skb);
}
#endif
--
2.55.0.966.g6673acef38-goog
^ permalink raw reply related [flat|nested] 14+ messages in thread
* [PATCH net-next 03/10] ibmveth: do not assume mac header is set in ibmveth_start_xmit()
2026-09-02 0:33 [PATCH net-next 00/10] net: remove skb mac_header assumptions in TX paths (I) Eric Dumazet
2026-09-02 0:33 ` [PATCH net-next 01/10] bonding: do not assume mac header is set in ALB/TLB tx paths Eric Dumazet
2026-09-02 0:33 ` [PATCH net-next 02/10] atlantic: do not assume mac header is set in aq_ndev_start_xmit() Eric Dumazet
@ 2026-09-02 0:33 ` Eric Dumazet
2026-09-07 5:20 ` mingming cao
2026-09-02 0:33 ` [PATCH net-next 04/10] net: mediatek: do not assume mac header is set in mtk_start_xmit() Eric Dumazet
` (7 subsequent siblings)
10 siblings, 1 reply; 14+ messages in thread
From: Eric Dumazet @ 2026-09-02 0:33 UTC (permalink / raw)
To: David S . Miller, Jakub Kicinski, Paolo Abeni
Cc: Simon Horman, Andrew Lunn, netdev, eric.dumazet, Eric Dumazet
We should not assume mac header is set in output path.
Use skb_eth_hdr() instead of eth_hdr() to fix the issue.
Signed-off-by: Eric Dumazet <edumazet@google.com>
---
drivers/net/ethernet/ibm/ibmveth.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/ibm/ibmveth.c b/drivers/net/ethernet/ibm/ibmveth.c
index 73e051d26b9d8887cfed1c4168684ae199bd3108..88e8bdfbcd11293d2cc0a36ebea6dfffa50bcedd 100644
--- a/drivers/net/ethernet/ibm/ibmveth.c
+++ b/drivers/net/ethernet/ibm/ibmveth.c
@@ -1218,7 +1218,7 @@ static int ibmveth_is_packet_unsupported(struct sk_buff *skb,
struct ethhdr *ether_header;
int ret = 0;
- ether_header = eth_hdr(skb);
+ ether_header = skb_eth_hdr(skb);
if (ether_addr_equal(ether_header->h_dest, netdev->dev_addr)) {
netdev_dbg(netdev, "veth doesn't support loopback packets, dropping packet.\n");
--
2.55.0.966.g6673acef38-goog
^ permalink raw reply related [flat|nested] 14+ messages in thread
* [PATCH net-next 04/10] net: mediatek: do not assume mac header is set in mtk_start_xmit()
2026-09-02 0:33 [PATCH net-next 00/10] net: remove skb mac_header assumptions in TX paths (I) Eric Dumazet
` (2 preceding siblings ...)
2026-09-02 0:33 ` [PATCH net-next 03/10] ibmveth: do not assume mac header is set in ibmveth_start_xmit() Eric Dumazet
@ 2026-09-02 0:33 ` Eric Dumazet
2026-09-02 0:33 ` [PATCH net-next 05/10] netvsc: do not assume mac header is set in netvsc_start_xmit() Eric Dumazet
` (6 subsequent siblings)
10 siblings, 0 replies; 14+ messages in thread
From: Eric Dumazet @ 2026-09-02 0:33 UTC (permalink / raw)
To: David S . Miller, Jakub Kicinski, Paolo Abeni
Cc: Simon Horman, Andrew Lunn, netdev, eric.dumazet, Eric Dumazet
We should not assume mac header is set in output path.
Use skb_eth_hdr() instead of eth_hdr() to fix the issue.
Signed-off-by: Eric Dumazet <edumazet@google.com>
---
drivers/net/ethernet/mediatek/mtk_eth_soc.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/mediatek/mtk_eth_soc.c b/drivers/net/ethernet/mediatek/mtk_eth_soc.c
index be3bd025c41a1c90511f2d36806bfd075856e486..6be0080e6233fad3bfd8b5c9027d3d1759f74878 100644
--- a/drivers/net/ethernet/mediatek/mtk_eth_soc.c
+++ b/drivers/net/ethernet/mediatek/mtk_eth_soc.c
@@ -1785,7 +1785,7 @@ static netdev_tx_t mtk_start_xmit(struct sk_buff *skb, struct net_device *dev)
int tx_num;
if (skb_vlan_tag_present(skb) &&
- !eth_proto_is_802_3(eth_hdr(skb)->h_proto)) {
+ !eth_proto_is_802_3(skb_eth_hdr(skb)->h_proto)) {
skb = __vlan_hwaccel_push_inside(skb);
if (!skb)
goto dropped;
--
2.55.0.966.g6673acef38-goog
^ permalink raw reply related [flat|nested] 14+ messages in thread
* [PATCH net-next 05/10] netvsc: do not assume mac header is set in netvsc_start_xmit()
2026-09-02 0:33 [PATCH net-next 00/10] net: remove skb mac_header assumptions in TX paths (I) Eric Dumazet
` (3 preceding siblings ...)
2026-09-02 0:33 ` [PATCH net-next 04/10] net: mediatek: do not assume mac header is set in mtk_start_xmit() Eric Dumazet
@ 2026-09-02 0:33 ` Eric Dumazet
2026-09-02 0:33 ` [PATCH net-next 06/10] macsec: do not assume mac header is set in macsec_encrypt_finish() Eric Dumazet
` (5 subsequent siblings)
10 siblings, 0 replies; 14+ messages in thread
From: Eric Dumazet @ 2026-09-02 0:33 UTC (permalink / raw)
To: David S . Miller, Jakub Kicinski, Paolo Abeni
Cc: Simon Horman, Andrew Lunn, netdev, eric.dumazet, Eric Dumazet
We should not assume mac header is set in output path.
Use skb_eth_hdr() instead of eth_hdr() to fix the issue,
and remove now redundant skb_reset_mac_header().
Signed-off-by: Eric Dumazet <edumazet@google.com>
---
drivers/net/hyperv/netvsc_drv.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/drivers/net/hyperv/netvsc_drv.c b/drivers/net/hyperv/netvsc_drv.c
index 1d43c73fd73f10200ee0c69c9221a2a44971b08a..d78ed0f3a3bd1de37a05187b4d7f499099041668 100644
--- a/drivers/net/hyperv/netvsc_drv.c
+++ b/drivers/net/hyperv/netvsc_drv.c
@@ -533,8 +533,7 @@ static int netvsc_xmit(struct sk_buff *skb, struct net_device *net, bool xdp_tx)
if (skb->protocol == htons(ETH_P_8021Q)) {
u16 vlan_tci;
- skb_reset_mac_header(skb);
- if (eth_type_vlan(eth_hdr(skb)->h_proto)) {
+ if (eth_type_vlan(skb_eth_hdr(skb)->h_proto)) {
if (unlikely(__skb_vlan_pop(skb, &vlan_tci) != 0)) {
++net_device_ctx->eth_stats.vlan_error;
goto drop;
--
2.55.0.966.g6673acef38-goog
^ permalink raw reply related [flat|nested] 14+ messages in thread
* [PATCH net-next 06/10] macsec: do not assume mac header is set in macsec_encrypt_finish()
2026-09-02 0:33 [PATCH net-next 00/10] net: remove skb mac_header assumptions in TX paths (I) Eric Dumazet
` (4 preceding siblings ...)
2026-09-02 0:33 ` [PATCH net-next 05/10] netvsc: do not assume mac header is set in netvsc_start_xmit() Eric Dumazet
@ 2026-09-02 0:33 ` Eric Dumazet
2026-09-02 0:33 ` [PATCH net-next 07/10] macvlan: do not assume mac header is set in macvlan_broadcast() Eric Dumazet
` (4 subsequent siblings)
10 siblings, 0 replies; 14+ messages in thread
From: Eric Dumazet @ 2026-09-02 0:33 UTC (permalink / raw)
To: David S . Miller, Jakub Kicinski, Paolo Abeni
Cc: Simon Horman, Andrew Lunn, netdev, eric.dumazet, Eric Dumazet
We should not assume mac header is set in output path.
Use skb_eth_hdr() instead of eth_hdr() to fix the issue,
and remove now redundant skb_reset_mac_header().
Signed-off-by: Eric Dumazet <edumazet@google.com>
---
drivers/net/macsec.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/drivers/net/macsec.c b/drivers/net/macsec.c
index 6f9f3aceffaad311d5d47bb93fa0df59082aa9f9..da7f917e71807410c050bcf4a8ed836272ab87cb 100644
--- a/drivers/net/macsec.c
+++ b/drivers/net/macsec.c
@@ -503,8 +503,7 @@ static void macsec_encrypt_finish(struct sk_buff *skb, struct net_device *dev)
struct macsec_dev *macsec = netdev_priv(dev);
skb->dev = macsec->real_dev;
- skb_reset_mac_header(skb);
- skb->protocol = eth_hdr(skb)->h_proto;
+ skb->protocol = skb_eth_hdr(skb)->h_proto;
}
static unsigned int macsec_msdu_len(struct sk_buff *skb)
--
2.55.0.966.g6673acef38-goog
^ permalink raw reply related [flat|nested] 14+ messages in thread
* [PATCH net-next 07/10] macvlan: do not assume mac header is set in macvlan_broadcast()
2026-09-02 0:33 [PATCH net-next 00/10] net: remove skb mac_header assumptions in TX paths (I) Eric Dumazet
` (5 preceding siblings ...)
2026-09-02 0:33 ` [PATCH net-next 06/10] macsec: do not assume mac header is set in macsec_encrypt_finish() Eric Dumazet
@ 2026-09-02 0:33 ` Eric Dumazet
2026-09-02 0:33 ` [PATCH net-next 08/10] vxlan: do not assume mac header is set in tx paths Eric Dumazet
` (3 subsequent siblings)
10 siblings, 0 replies; 14+ messages in thread
From: Eric Dumazet @ 2026-09-02 0:33 UTC (permalink / raw)
To: David S . Miller, Jakub Kicinski, Paolo Abeni
Cc: Simon Horman, Andrew Lunn, netdev, eric.dumazet, Eric Dumazet
We should not assume mac header is set in output path.
Use skb_eth_hdr() instead of eth_hdr() to fix the issue,
and remove now redundant skb_reset_mac_header() call in macvlan_queue_xmit().
Signed-off-by: Eric Dumazet <edumazet@google.com>
---
drivers/net/macvlan.c | 5 ++---
1 file changed, 2 insertions(+), 3 deletions(-)
diff --git a/drivers/net/macvlan.c b/drivers/net/macvlan.c
index afad90b9222a287214418e93221d569d4d83a1a6..62cf0f6922168984249af647338102f1a8afcb25 100644
--- a/drivers/net/macvlan.c
+++ b/drivers/net/macvlan.c
@@ -266,7 +266,7 @@ static void macvlan_broadcast(struct sk_buff *skb,
struct net_device *src,
enum macvlan_mode mode)
{
- const struct ethhdr *eth = eth_hdr(skb);
+ const struct ethhdr *eth = skb_eth_hdr(skb);
const struct macvlan_dev *vlan;
struct sk_buff *nskb;
unsigned int i;
@@ -424,7 +424,7 @@ static void macvlan_forward_source_one(struct sk_buff *skb,
len = nskb->len + ETH_HLEN;
nskb->dev = dev;
- if (ether_addr_equal_64bits(eth_hdr(skb)->h_dest, dev->dev_addr))
+ if (ether_addr_equal_64bits(skb_eth_hdr(skb)->h_dest, dev->dev_addr))
nskb->pkt_type = PACKET_HOST;
ret = __netif_rx(nskb);
@@ -557,7 +557,6 @@ static int macvlan_queue_xmit(struct sk_buff *skb, struct net_device *dev)
/* send to other bridge ports directly */
if (is_multicast_ether_addr(eth->h_dest)) {
- skb_reset_mac_header(skb);
macvlan_broadcast(skb, port, dev, MACVLAN_MODE_BRIDGE);
goto xmit_world;
}
--
2.55.0.966.g6673acef38-goog
^ permalink raw reply related [flat|nested] 14+ messages in thread
* [PATCH net-next 08/10] vxlan: do not assume mac header is set in tx paths
2026-09-02 0:33 [PATCH net-next 00/10] net: remove skb mac_header assumptions in TX paths (I) Eric Dumazet
` (6 preceding siblings ...)
2026-09-02 0:33 ` [PATCH net-next 07/10] macvlan: do not assume mac header is set in macvlan_broadcast() Eric Dumazet
@ 2026-09-02 0:33 ` Eric Dumazet
2026-09-02 0:33 ` [PATCH net-next 09/10] cdc_mbim: do not assume mac header is set in cdc_mbim_tx_fixup() Eric Dumazet
` (2 subsequent siblings)
10 siblings, 0 replies; 14+ messages in thread
From: Eric Dumazet @ 2026-09-02 0:33 UTC (permalink / raw)
To: David S . Miller, Jakub Kicinski, Paolo Abeni
Cc: Simon Horman, Andrew Lunn, netdev, eric.dumazet, Eric Dumazet
We should not assume mac header is set in output path.
Use skb_eth_hdr() instead of eth_hdr() in tx paths,
and remove now redundant skb_reset_mac_header() call in vxlan_xmit().
Signed-off-by: Eric Dumazet <edumazet@google.com>
---
drivers/net/vxlan/vxlan_core.c | 24 +++++++++++-------------
drivers/net/vxlan/vxlan_mdb.c | 4 ++--
2 files changed, 13 insertions(+), 15 deletions(-)
diff --git a/drivers/net/vxlan/vxlan_core.c b/drivers/net/vxlan/vxlan_core.c
index 459f19f7071e5bafe9e4c57ef8819645c3da7121..a1c3bc530b97cb8617ac324b60e32b77ea23e5ee 100644
--- a/drivers/net/vxlan/vxlan_core.c
+++ b/drivers/net/vxlan/vxlan_core.c
@@ -1967,7 +1967,7 @@ static struct sk_buff *vxlan_na_create(struct sk_buff *request,
ns = (struct nd_msg *)(ipv6_hdr(request) + 1);
- daddr = eth_hdr(request)->h_source;
+ daddr = skb_eth_hdr(request)->h_source;
ns_olen = request->len - skb_network_offset(request) -
sizeof(struct ipv6hdr) - sizeof(*ns);
for (i = 0; i < ns_olen-1; i += (ns->opt[i+1]<<3)) {
@@ -2108,11 +2108,11 @@ static bool route_shortcircuit(struct net_device *dev, struct sk_buff *skb)
struct vxlan_dev *vxlan = netdev_priv(dev);
struct neighbour *n;
- if (is_multicast_ether_addr(eth_hdr(skb)->h_dest))
+ if (is_multicast_ether_addr(skb_eth_hdr(skb)->h_dest))
return false;
n = NULL;
- switch (ntohs(eth_hdr(skb)->h_proto)) {
+ switch (ntohs(skb_eth_hdr(skb)->h_proto)) {
case ETH_P_IP:
{
struct iphdr *pip;
@@ -2169,15 +2169,15 @@ static bool route_shortcircuit(struct net_device *dev, struct sk_buff *skb)
bool diff;
neigh_ha_snapshot(haddr, n, dev);
- diff = !ether_addr_equal_unaligned(eth_hdr(skb)->h_dest, haddr);
+ diff = !ether_addr_equal_unaligned(skb_eth_hdr(skb)->h_dest, haddr);
if (diff) {
if (skb_cow_head(skb, 0)) {
neigh_release(n);
return false;
}
- memcpy(eth_hdr(skb)->h_source, eth_hdr(skb)->h_dest,
+ memcpy(skb_eth_hdr(skb)->h_source, skb_eth_hdr(skb)->h_dest,
dev->addr_len);
- memcpy(eth_hdr(skb)->h_dest, haddr, dev->addr_len);
+ memcpy(skb_eth_hdr(skb)->h_dest, haddr, dev->addr_len);
}
neigh_release(n);
return diff;
@@ -2296,7 +2296,7 @@ static void vxlan_encap_bypass(struct sk_buff *skb, struct vxlan_dev *src_vxlan,
}
if ((dst_vxlan->cfg.flags & VXLAN_F_LEARN) && snoop)
- vxlan_snoop(dev, &loopback, eth_hdr(skb)->h_source, 0, vni);
+ vxlan_snoop(dev, &loopback, skb_eth_hdr(skb)->h_source, 0, vni);
dev_dstats_tx_add(src_vxlan->dev, len);
vxlan_vnifilter_count(src_vxlan, vni, NULL, VXLAN_VNI_STATS_TX, len);
@@ -2513,7 +2513,7 @@ void vxlan_xmit_one(struct sk_buff *skb, struct net_device *dev,
if (vxlan->cfg.df == VXLAN_DF_SET) {
df = htons(IP_DF);
} else if (vxlan->cfg.df == VXLAN_DF_INHERIT) {
- struct ethhdr *eth = eth_hdr(skb);
+ struct ethhdr *eth = skb_eth_hdr(skb);
if (ntohs(eth->h_proto) == ETH_P_IPV6 ||
(ntohs(eth->h_proto) == ETH_P_IP &&
@@ -2747,8 +2747,6 @@ static netdev_tx_t vxlan_xmit(struct sk_buff *skb, struct net_device *dev)
info = skb_tunnel_info(skb);
- skb_reset_mac_header(skb);
-
if (vxlan->cfg.flags & VXLAN_F_COLLECT_METADATA) {
if (info && info->mode & IP_TUNNEL_INFO_BRIDGE &&
info->mode & IP_TUNNEL_INFO_TX) {
@@ -2764,7 +2762,7 @@ static netdev_tx_t vxlan_xmit(struct sk_buff *skb, struct net_device *dev)
}
if (vxlan->cfg.flags & VXLAN_F_PROXY) {
- eth = eth_hdr(skb);
+ eth = skb_eth_hdr(skb);
if (ntohs(eth->h_proto) == ETH_P_ARP)
return arp_reduce(dev, skb, vni);
#if IS_ENABLED(CONFIG_IPV6)
@@ -2799,7 +2797,7 @@ static netdev_tx_t vxlan_xmit(struct sk_buff *skb, struct net_device *dev)
rcu_read_unlock();
}
- eth = eth_hdr(skb);
+ eth = skb_eth_hdr(skb);
rcu_read_lock();
f = vxlan_find_mac_tx(vxlan, eth->h_dest, vni);
did_rsc = false;
@@ -2808,7 +2806,7 @@ static netdev_tx_t vxlan_xmit(struct sk_buff *skb, struct net_device *dev)
(ntohs(eth->h_proto) == ETH_P_IP ||
ntohs(eth->h_proto) == ETH_P_IPV6)) {
did_rsc = route_shortcircuit(dev, skb);
- eth = eth_hdr(skb);
+ eth = skb_eth_hdr(skb);
if (did_rsc)
f = vxlan_find_mac_tx(vxlan, eth->h_dest, vni);
}
diff --git a/drivers/net/vxlan/vxlan_mdb.c b/drivers/net/vxlan/vxlan_mdb.c
index d71e1925ecfdbd6fa7b78b38cb4168b51c85a553..2ec005c003e3c0ada7eacf1f5af9a3bf5ab433da 100644
--- a/drivers/net/vxlan/vxlan_mdb.c
+++ b/drivers/net/vxlan/vxlan_mdb.c
@@ -1619,8 +1619,8 @@ struct vxlan_mdb_entry *vxlan_mdb_entry_skb_get(struct vxlan_dev *vxlan,
struct vxlan_mdb_entry *mdb_entry;
struct vxlan_mdb_entry_key group;
- if (!is_multicast_ether_addr(eth_hdr(skb)->h_dest) ||
- is_broadcast_ether_addr(eth_hdr(skb)->h_dest))
+ if (!is_multicast_ether_addr(skb_eth_hdr(skb)->h_dest) ||
+ is_broadcast_ether_addr(skb_eth_hdr(skb)->h_dest))
return NULL;
/* When not in collect metadata mode, 'src_vni' is zero, but MDB
--
2.55.0.966.g6673acef38-goog
^ permalink raw reply related [flat|nested] 14+ messages in thread
* [PATCH net-next 09/10] cdc_mbim: do not assume mac header is set in cdc_mbim_tx_fixup()
2026-09-02 0:33 [PATCH net-next 00/10] net: remove skb mac_header assumptions in TX paths (I) Eric Dumazet
` (7 preceding siblings ...)
2026-09-02 0:33 ` [PATCH net-next 08/10] vxlan: do not assume mac header is set in tx paths Eric Dumazet
@ 2026-09-02 0:33 ` Eric Dumazet
2026-09-02 0:33 ` [PATCH net-next 10/10] ice: do not assume mac header is set in tx paths Eric Dumazet
2026-09-02 11:22 ` [PATCH net-next 00/10] net: remove skb mac_header assumptions in TX paths (I) Eric Dumazet
10 siblings, 0 replies; 14+ messages in thread
From: Eric Dumazet @ 2026-09-02 0:33 UTC (permalink / raw)
To: David S . Miller, Jakub Kicinski, Paolo Abeni
Cc: Simon Horman, Andrew Lunn, netdev, eric.dumazet, Eric Dumazet
We should not assume mac header is set in output path.
Use skb_vlan_eth_hdr() and skb_eth_hdr() instead of vlan_eth_hdr()
and eth_hdr(), and remove now redundant skb_reset_mac_header().
Signed-off-by: Eric Dumazet <edumazet@google.com>
---
drivers/net/usb/cdc_mbim.c | 5 ++---
1 file changed, 2 insertions(+), 3 deletions(-)
diff --git a/drivers/net/usb/cdc_mbim.c b/drivers/net/usb/cdc_mbim.c
index 877fb0ed7d3d71c0e55fb5d29c269030b6c5b684..c773be03875634d16f64cc60c2bfe8a718356071 100644
--- a/drivers/net/usb/cdc_mbim.c
+++ b/drivers/net/usb/cdc_mbim.c
@@ -240,13 +240,12 @@ static struct sk_buff *cdc_mbim_tx_fixup(struct usbnet *dev, struct sk_buff *skb
* the accelerated out-of-band tag, but fall back if
* required
*/
- skb_reset_mac_header(skb);
if (vlan_get_tag(skb, &tci) < 0 && skb->len > VLAN_ETH_HLEN &&
__vlan_get_tag(skb, &tci) == 0) {
- is_ip = is_ip_proto(vlan_eth_hdr(skb)->h_vlan_encapsulated_proto);
+ is_ip = is_ip_proto(skb_vlan_eth_hdr(skb)->h_vlan_encapsulated_proto);
skb_pull(skb, VLAN_ETH_HLEN);
} else {
- is_ip = is_ip_proto(eth_hdr(skb)->h_proto);
+ is_ip = is_ip_proto(skb_eth_hdr(skb)->h_proto);
skb_pull(skb, ETH_HLEN);
}
--
2.55.0.966.g6673acef38-goog
^ permalink raw reply related [flat|nested] 14+ messages in thread
* [PATCH net-next 10/10] ice: do not assume mac header is set in tx paths
2026-09-02 0:33 [PATCH net-next 00/10] net: remove skb mac_header assumptions in TX paths (I) Eric Dumazet
` (8 preceding siblings ...)
2026-09-02 0:33 ` [PATCH net-next 09/10] cdc_mbim: do not assume mac header is set in cdc_mbim_tx_fixup() Eric Dumazet
@ 2026-09-02 0:33 ` Eric Dumazet
2026-09-02 11:22 ` [PATCH net-next 00/10] net: remove skb mac_header assumptions in TX paths (I) Eric Dumazet
10 siblings, 0 replies; 14+ messages in thread
From: Eric Dumazet @ 2026-09-02 0:33 UTC (permalink / raw)
To: David S . Miller, Jakub Kicinski, Paolo Abeni
Cc: Simon Horman, Andrew Lunn, netdev, eric.dumazet, Eric Dumazet
We should not assume mac header is set in output path.
Use skb_eth_hdr() instead of skb_mac_header() in ice_xmit_frame_ring()
and ice_eswitch_set_target_vsi(). Also use skb_checksum_start_offset()
instead of skb->csum_start - skb->mac_header in ice_tx_csum().
Signed-off-by: Eric Dumazet <edumazet@google.com>
---
drivers/net/ethernet/intel/ice/ice_eswitch.c | 2 +-
drivers/net/ethernet/intel/ice/ice_txrx.c | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/drivers/net/ethernet/intel/ice/ice_eswitch.c b/drivers/net/ethernet/intel/ice/ice_eswitch.c
index b069e6c514fb1279ddd9e941e76271be0e72c912..387e8fa8e924c64ce1146e0d86e0f8a853640085 100644
--- a/drivers/net/ethernet/intel/ice/ice_eswitch.c
+++ b/drivers/net/ethernet/intel/ice/ice_eswitch.c
@@ -244,7 +244,7 @@ ice_eswitch_set_target_vsi(struct sk_buff *skb,
u64 cd_cmd, dst_vsi;
if (!dst) {
- struct ethhdr *eth = (struct ethhdr *)skb_mac_header(skb);
+ struct ethhdr *eth = skb_eth_hdr(skb);
if (unlikely(eth->h_proto == htons(ETH_P_LLDP)))
return;
diff --git a/drivers/net/ethernet/intel/ice/ice_txrx.c b/drivers/net/ethernet/intel/ice/ice_txrx.c
index 31303ab5be175a5ce698f16715ea8d75eeea7bc5..5e73cdc71a68dc23022ff91d10b2c8c872939ff2 100644
--- a/drivers/net/ethernet/intel/ice/ice_txrx.c
+++ b/drivers/net/ethernet/intel/ice/ice_txrx.c
@@ -1743,7 +1743,7 @@ int ice_tx_csum(struct ice_tx_buf *first, struct ice_tx_offload_params *off)
!(first->tx_flags & ICE_TX_FLAGS_TSO) &&
!skb_csum_is_sctp(skb)) {
/* Set GCS */
- u16 csum_start = (skb->csum_start - skb->mac_header) / 2;
+ u16 csum_start = skb_checksum_start_offset(skb) / 2;
u16 csum_offset = skb->csum_offset / 2;
u16 gcs_params;
@@ -2219,7 +2219,7 @@ ice_xmit_frame_ring(struct sk_buff *skb, struct ice_tx_ring *tx_ring)
goto out_drop;
/* allow CONTROL frames egress from main VSI if FW LLDP disabled */
- eth = (struct ethhdr *)skb_mac_header(skb);
+ eth = skb_eth_hdr(skb);
if ((ice_is_switchdev_running(vsi->back) ||
ice_lag_is_switchdev_running(vsi->back)) &&
--
2.55.0.966.g6673acef38-goog
^ permalink raw reply related [flat|nested] 14+ messages in thread
* Re: [PATCH net-next 00/10] net: remove skb mac_header assumptions in TX paths (I)
2026-09-02 0:33 [PATCH net-next 00/10] net: remove skb mac_header assumptions in TX paths (I) Eric Dumazet
` (9 preceding siblings ...)
2026-09-02 0:33 ` [PATCH net-next 10/10] ice: do not assume mac header is set in tx paths Eric Dumazet
@ 2026-09-02 11:22 ` Eric Dumazet
10 siblings, 0 replies; 14+ messages in thread
From: Eric Dumazet @ 2026-09-02 11:22 UTC (permalink / raw)
To: David S . Miller, Jakub Kicinski, Paolo Abeni
Cc: Simon Horman, Andrew Lunn, netdev, eric.dumazet
On Wed, Sep 2, 2026 at 2:33 AM Eric Dumazet <edumazet@google.com> wrote:
>
> In the transmit path, network drivers should not assume that
> skb->mac_header has been set.
>
> In the TX path, skb->data points to the start of the L2 header. Using
> eth_hdr(skb) or vlan_eth_hdr(skb) when mac_header is unset reads from
> skb->head + (u16)~0, leading to out-of-bounds reads (flagged by KASAN)
> or triggering DEBUG_NET warnings.
>
> Commit 96cc4b69581d ("macvlan: do not assume mac_header is set in
> macvlan_broadcast()") introduced skb_eth_hdr() (and later commit
> 1f5020acb33f ("net: vlan: introduce skb_vlan_eth_hdr()")) to safely
> access L2 headers in TX paths via skb->data without needing to call
> skb_reset_mac_header().
>
> This series converts the first batch of 10 network drivers and virtual
> devices to use skb_eth_hdr(), skb_vlan_eth_hdr(), and
> skb_checksum_start_offset() in their TX paths, and removes now redundant
> skb_reset_mac_header() calls.
>
> When all drivers are converted, we will remove skb_reset_mac_header()
> from our TX fast paths.
AI-reviews have killed the notion of patch series.
I will send stand alone patches, to avoid 10+ versions ;)
pw-bot: cr
^ permalink raw reply [flat|nested] 14+ messages in thread
* Re: [PATCH net-next 03/10] ibmveth: do not assume mac header is set in ibmveth_start_xmit()
2026-09-02 0:33 ` [PATCH net-next 03/10] ibmveth: do not assume mac header is set in ibmveth_start_xmit() Eric Dumazet
@ 2026-09-07 5:20 ` mingming cao
2026-09-07 6:41 ` Eric Dumazet
0 siblings, 1 reply; 14+ messages in thread
From: mingming cao @ 2026-09-07 5:20 UTC (permalink / raw)
To: Eric Dumazet, David S . Miller, Jakub Kicinski, Paolo Abeni
Cc: Simon Horman, Andrew Lunn, netdev, eric.dumazet
On 9/1/26 5:33 PM, Eric Dumazet wrote:
> We should not assume mac header is set in output path.
>
> Use skb_eth_hdr() instead of eth_hdr() to fix the issue.
>
> Signed-off-by: Eric Dumazet <edumazet@google.com>
> ---
> drivers/net/ethernet/ibm/ibmveth.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/drivers/net/ethernet/ibm/ibmveth.c b/drivers/net/ethernet/ibm/ibmveth.c
> index 73e051d26b9d8887cfed1c4168684ae199bd3108..88e8bdfbcd11293d2cc0a36ebea6dfffa50bcedd 100644
> --- a/drivers/net/ethernet/ibm/ibmveth.c
> +++ b/drivers/net/ethernet/ibm/ibmveth.c
> @@ -1218,7 +1218,7 @@ static int ibmveth_is_packet_unsupported(struct sk_buff *skb,
> struct ethhdr *ether_header;
> int ret = 0;
>
> - ether_header = eth_hdr(skb);
> + ether_header = skb_eth_hdr(skb);
>
> if (ether_addr_equal(ether_header->h_dest, netdev->dev_addr)) {
> netdev_dbg(netdev, "veth doesn't support loopback packets, dropping packet.\n");
Correct. mac_header is not guaranteed to be set on entry to
ndo_start_xmit; skb->data is the stable anchor in the TX path.
The RX poll path already reads the IP header check through skb->data
after eth_type_trans(), so no parallel fix is needed there.
ibmvnic has a similar issue in its TX path: build_hdr_descs_arr(),
called from ibmvnic_xmit(), passes skb_mac_header(skb) to
create_hdr_descs(). Is that covered in a later batch, or shall I
send a fix?
Reviewed-by: Mingming Cao <mmc@linux.ibm.com>
^ permalink raw reply [flat|nested] 14+ messages in thread
* Re: [PATCH net-next 03/10] ibmveth: do not assume mac header is set in ibmveth_start_xmit()
2026-09-07 5:20 ` mingming cao
@ 2026-09-07 6:41 ` Eric Dumazet
0 siblings, 0 replies; 14+ messages in thread
From: Eric Dumazet @ 2026-09-07 6:41 UTC (permalink / raw)
To: mingming cao
Cc: David S . Miller, Jakub Kicinski, Paolo Abeni, Simon Horman,
Andrew Lunn, netdev, eric.dumazet
On Mon, Sep 7, 2026 at 7:20 AM mingming cao <mmc@linux.ibm.com> wrote:
>
>
> On 9/1/26 5:33 PM, Eric Dumazet wrote:
> > We should not assume mac header is set in output path.
> >
> > Use skb_eth_hdr() instead of eth_hdr() to fix the issue.
> >
> > Signed-off-by: Eric Dumazet <edumazet@google.com>
> > ---
> > drivers/net/ethernet/ibm/ibmveth.c | 2 +-
> > 1 file changed, 1 insertion(+), 1 deletion(-)
> >
> > diff --git a/drivers/net/ethernet/ibm/ibmveth.c b/drivers/net/ethernet/ibm/ibmveth.c
> > index 73e051d26b9d8887cfed1c4168684ae199bd3108..88e8bdfbcd11293d2cc0a36ebea6dfffa50bcedd 100644
> > --- a/drivers/net/ethernet/ibm/ibmveth.c
> > +++ b/drivers/net/ethernet/ibm/ibmveth.c
> > @@ -1218,7 +1218,7 @@ static int ibmveth_is_packet_unsupported(struct sk_buff *skb,
> > struct ethhdr *ether_header;
> > int ret = 0;
> >
> > - ether_header = eth_hdr(skb);
> > + ether_header = skb_eth_hdr(skb);
> >
> > if (ether_addr_equal(ether_header->h_dest, netdev->dev_addr)) {
> > netdev_dbg(netdev, "veth doesn't support loopback packets, dropping packet.\n");
> Correct. mac_header is not guaranteed to be set on entry to
> ndo_start_xmit; skb->data is the stable anchor in the TX path.
>
> The RX poll path already reads the IP header check through skb->data
> after eth_type_trans(), so no parallel fix is needed there.
>
> ibmvnic has a similar issue in its TX path: build_hdr_descs_arr(),
> called from ibmvnic_xmit(), passes skb_mac_header(skb) to
> create_hdr_descs(). Is that covered in a later batch, or shall I
> send a fix?
>
> Reviewed-by: Mingming Cao <mmc@linux.ibm.com>
Series has been dropped, I will post single patches at a time.
Feel free to join the effort!
Thanks.
^ permalink raw reply [flat|nested] 14+ messages in thread
end of thread, other threads:[~2026-09-07 6:41 UTC | newest]
Thread overview: 14+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-02 0:33 [PATCH net-next 00/10] net: remove skb mac_header assumptions in TX paths (I) Eric Dumazet
2026-09-02 0:33 ` [PATCH net-next 01/10] bonding: do not assume mac header is set in ALB/TLB tx paths Eric Dumazet
2026-09-02 0:33 ` [PATCH net-next 02/10] atlantic: do not assume mac header is set in aq_ndev_start_xmit() Eric Dumazet
2026-09-02 0:33 ` [PATCH net-next 03/10] ibmveth: do not assume mac header is set in ibmveth_start_xmit() Eric Dumazet
2026-09-07 5:20 ` mingming cao
2026-09-07 6:41 ` Eric Dumazet
2026-09-02 0:33 ` [PATCH net-next 04/10] net: mediatek: do not assume mac header is set in mtk_start_xmit() Eric Dumazet
2026-09-02 0:33 ` [PATCH net-next 05/10] netvsc: do not assume mac header is set in netvsc_start_xmit() Eric Dumazet
2026-09-02 0:33 ` [PATCH net-next 06/10] macsec: do not assume mac header is set in macsec_encrypt_finish() Eric Dumazet
2026-09-02 0:33 ` [PATCH net-next 07/10] macvlan: do not assume mac header is set in macvlan_broadcast() Eric Dumazet
2026-09-02 0:33 ` [PATCH net-next 08/10] vxlan: do not assume mac header is set in tx paths Eric Dumazet
2026-09-02 0:33 ` [PATCH net-next 09/10] cdc_mbim: do not assume mac header is set in cdc_mbim_tx_fixup() Eric Dumazet
2026-09-02 0:33 ` [PATCH net-next 10/10] ice: do not assume mac header is set in tx paths Eric Dumazet
2026-09-02 11:22 ` [PATCH net-next 00/10] net: remove skb mac_header assumptions in TX paths (I) Eric Dumazet
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.