BPF List
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Hangbin Liu" <hangbin.liu@linux.dev>
Cc: bpf@vger.kernel.org
Subject: Re: [PATCH net-next 1/6] net: lwtunnel: change encap fill order
Date: Fri, 18 Sep 2026 06:36:54 +0000	[thread overview]
Message-ID: <20260918063655.418681F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260917-ynl_rt_encap-v1-1-fbbe6e680571@kylinos.cn>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] net: lwtunnel: incomplete rollback on fallback path leaves orphan RTA_ENCAP_TYPE
--

commit b32da4e3fb34d0c2a7a1afb438a76ca410be21ec
Author: Hangbin Liu <liuhangbin@kylinos.cn>

net: lwtunnel: change encap fill order

This commit changes the order in which lwtunnel netlink attributes are
emitted. It places the encap_type_attr before the encap_attr nest to
ensure userspace YNL can decode the sub-messages correctly.

> diff --git a/net/core/lwtunnel.c b/net/core/lwtunnel.c
> index b01a395d9a966..f13dfa02e026e 100644
> --- a/net/core/lwtunnel.c
> +++ b/net/core/lwtunnel.c
> @@ -240,6 +240,10 @@ int lwtunnel_fill_encap(struct sk_buff *skb, struct lwtunnel_state *lwtstate,
>  	    lwtstate->type > LWTUNNEL_ENCAP_MAX)
>  		return 0;
>  
> +	ret = nla_put_u16(skb, encap_type_attr, lwtstate->type);
> +	if (ret)
> +		return ret;
> +
>  	nest = nla_nest_start_noflag(skb, encap_attr);
>  	if (!nest)
>  		return -EMSGSIZE;
> @@ -254,9 +258,6 @@ int lwtunnel_fill_encap(struct sk_buff *skb, struct lwtunnel_state *lwtstate,
>  	if (ret)
>  		goto nla_put_failure;

[Severity: Medium]
Does this leave an orphaned attribute in the buffer on the fallback path?

If ops->fill_encap is unsupported, it evaluates to -EOPNOTSUPP and execution
jumps to nla_put_failure:

net/core/lwtunnel.c:lwtunnel_fill_encap() {
...
nla_put_failure:
	nla_nest_cancel(skb, nest);

	return (ret == -EOPNOTSUPP ? 0 : ret);
}

Because nla_put_u16() was moved before nla_nest_start_noflag(),
nla_nest_cancel() only unwinds the buffer up to the start of the nest.
This leaves the encap_type_attr orphaned in the skb payload.

Since the function returns 0 (success) in the -EOPNOTSUPP case, the caller
is prevented from discarding the message, which results in a malformed
netlink message being sent to userspace.

Could we record the skb tail pointer before nla_put_u16() and restore it on
failure, or is there another preferred way to unwind the encap_type_attr?

>  	nla_nest_end(skb, nest);
> -	ret = nla_put_u16(skb, encap_type_attr, lwtstate->type);
> -	if (ret)
> -		goto nla_put_failure;
>  
>  	return 0;

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260917-ynl_rt_encap-v1-0-fbbe6e680571@kylinos.cn?part=1

  reply	other threads:[~2026-09-18  6:36 UTC|newest]

Thread overview: 20+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-17  6:35 [PATCH net-next 0/6] netlink: add lwtunnel encap sub-message support to rt-route Hangbin Liu
2026-09-17  6:35 ` [PATCH net-next 1/6] net: lwtunnel: change encap fill order Hangbin Liu
2026-09-18  6:36   ` sashiko-bot [this message]
2026-09-21  6:38   ` netdev-bot+sashiko
2026-09-17  6:35 ` [PATCH net-next 2/6] tools: ynl: convert enum selector to string for sub-message parsing Hangbin Liu
2026-09-18  6:36   ` sashiko-bot
2026-09-21  6:38   ` netdev-bot+sashiko
2026-09-17  6:35 ` [PATCH net-next 3/6] netlink: specs: rt-route: add lwtunnel encap sub-message support Hangbin Liu
2026-09-18  6:36   ` sashiko-bot
2026-09-21  6:38   ` netdev-bot+sashiko
2026-09-17  6:35 ` [PATCH net-next 4/6] netlink: specs: rt-route: describe lwtunnel IP options Hangbin Liu
2026-09-18  6:36   ` sashiko-bot
2026-09-21  6:38   ` netdev-bot+sashiko
2026-09-21  9:26     ` Hangbin Liu
2026-09-17  6:35 ` [PATCH net-next 5/6] netlink: specs: rt-route: describe lwt BPF program options Hangbin Liu
2026-09-18  6:36   ` sashiko-bot
2026-09-21  6:38   ` netdev-bot+sashiko
2026-09-21  9:46     ` Hangbin Liu
2026-09-17  6:35 ` [PATCH net-next 6/6] netlink: specs: rt-route: describe seg6-local actions, counters and flavors Hangbin Liu
2026-09-21  6:38   ` netdev-bot+sashiko

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260918063655.418681F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=bpf@vger.kernel.org \
    --cc=hangbin.liu@linux.dev \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox