From: sashiko-bot@kernel.org
To: "Hangbin Liu" <hangbin.liu@linux.dev>
Cc: bpf@vger.kernel.org
Subject: Re: [PATCH net-next 1/6] net: lwtunnel: change encap fill order
Date: Fri, 18 Sep 2026 06:36:54 +0000 [thread overview]
Message-ID: <20260918063655.418681F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260917-ynl_rt_encap-v1-1-fbbe6e680571@kylinos.cn>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] net: lwtunnel: incomplete rollback on fallback path leaves orphan RTA_ENCAP_TYPE
--
commit b32da4e3fb34d0c2a7a1afb438a76ca410be21ec
Author: Hangbin Liu <liuhangbin@kylinos.cn>
net: lwtunnel: change encap fill order
This commit changes the order in which lwtunnel netlink attributes are
emitted. It places the encap_type_attr before the encap_attr nest to
ensure userspace YNL can decode the sub-messages correctly.
> diff --git a/net/core/lwtunnel.c b/net/core/lwtunnel.c
> index b01a395d9a966..f13dfa02e026e 100644
> --- a/net/core/lwtunnel.c
> +++ b/net/core/lwtunnel.c
> @@ -240,6 +240,10 @@ int lwtunnel_fill_encap(struct sk_buff *skb, struct lwtunnel_state *lwtstate,
> lwtstate->type > LWTUNNEL_ENCAP_MAX)
> return 0;
>
> + ret = nla_put_u16(skb, encap_type_attr, lwtstate->type);
> + if (ret)
> + return ret;
> +
> nest = nla_nest_start_noflag(skb, encap_attr);
> if (!nest)
> return -EMSGSIZE;
> @@ -254,9 +258,6 @@ int lwtunnel_fill_encap(struct sk_buff *skb, struct lwtunnel_state *lwtstate,
> if (ret)
> goto nla_put_failure;
[Severity: Medium]
Does this leave an orphaned attribute in the buffer on the fallback path?
If ops->fill_encap is unsupported, it evaluates to -EOPNOTSUPP and execution
jumps to nla_put_failure:
net/core/lwtunnel.c:lwtunnel_fill_encap() {
...
nla_put_failure:
nla_nest_cancel(skb, nest);
return (ret == -EOPNOTSUPP ? 0 : ret);
}
Because nla_put_u16() was moved before nla_nest_start_noflag(),
nla_nest_cancel() only unwinds the buffer up to the start of the nest.
This leaves the encap_type_attr orphaned in the skb payload.
Since the function returns 0 (success) in the -EOPNOTSUPP case, the caller
is prevented from discarding the message, which results in a malformed
netlink message being sent to userspace.
Could we record the skb tail pointer before nla_put_u16() and restore it on
failure, or is there another preferred way to unwind the encap_type_attr?
> nla_nest_end(skb, nest);
> - ret = nla_put_u16(skb, encap_type_attr, lwtstate->type);
> - if (ret)
> - goto nla_put_failure;
>
> return 0;
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260917-ynl_rt_encap-v1-0-fbbe6e680571@kylinos.cn?part=1
next prev parent reply other threads:[~2026-09-18 6:36 UTC|newest]
Thread overview: 20+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-17 6:35 [PATCH net-next 0/6] netlink: add lwtunnel encap sub-message support to rt-route Hangbin Liu
2026-09-17 6:35 ` [PATCH net-next 1/6] net: lwtunnel: change encap fill order Hangbin Liu
2026-09-18 6:36 ` sashiko-bot [this message]
2026-09-21 6:38 ` netdev-bot+sashiko
2026-09-17 6:35 ` [PATCH net-next 2/6] tools: ynl: convert enum selector to string for sub-message parsing Hangbin Liu
2026-09-18 6:36 ` sashiko-bot
2026-09-21 6:38 ` netdev-bot+sashiko
2026-09-17 6:35 ` [PATCH net-next 3/6] netlink: specs: rt-route: add lwtunnel encap sub-message support Hangbin Liu
2026-09-18 6:36 ` sashiko-bot
2026-09-21 6:38 ` netdev-bot+sashiko
2026-09-17 6:35 ` [PATCH net-next 4/6] netlink: specs: rt-route: describe lwtunnel IP options Hangbin Liu
2026-09-18 6:36 ` sashiko-bot
2026-09-21 6:38 ` netdev-bot+sashiko
2026-09-21 9:26 ` Hangbin Liu
2026-09-17 6:35 ` [PATCH net-next 5/6] netlink: specs: rt-route: describe lwt BPF program options Hangbin Liu
2026-09-18 6:36 ` sashiko-bot
2026-09-21 6:38 ` netdev-bot+sashiko
2026-09-21 9:46 ` Hangbin Liu
2026-09-17 6:35 ` [PATCH net-next 6/6] netlink: specs: rt-route: describe seg6-local actions, counters and flavors Hangbin Liu
2026-09-21 6:38 ` netdev-bot+sashiko
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260918063655.418681F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=hangbin.liu@linux.dev \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox