From: sashiko-bot@kernel.org
To: "Jens Emil Schulz Østergaard" <jensemil.schulzostergaard@microchip.com>
Cc: conor+dt@kernel.org, wsa+renesas@sang-engineering.com,
robh@kernel.org, devicetree@vger.kernel.org
Subject: Re: [PATCH net-next v13 1/9] net: dsa: add tag driver for LAN9645X
Date: Wed, 30 Sep 2026 07:50:09 +0000 [thread overview]
Message-ID: <20260930075010.004D61F00893@smtp.kernel.org> (raw)
In-Reply-To: <20260929-dsa_lan9645x_switch_driver_base-v13-1-827c2d3617f2@microchip.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Critical] net: dsa: lan9645x: VLAN hopping via fragmented in-band VLAN tags
--
commit f7552b4bce99ac2975ea8145332463c0a3772965
Author: Jens Emil Schulz Østergaard <jensemil.schulzostergaard@microchip.com>
net: dsa: add tag driver for LAN9645X
This commit adds a DSA tag driver for LAN9645x switches using an NPI port.
It implements asymmetric prefix configurations, using a long prefix for
extraction and an internal frame header (IFH) for both extraction and
injection.
> diff --git a/net/dsa/tag_lan9645x.c b/net/dsa/tag_lan9645x.c
> new file mode 100644
> index 0000000000000..f54646d4b3947
> --- /dev/null
> +++ b/net/dsa/tag_lan9645x.c
[ ... ]
> +static struct sk_buff *lan9645x_xmit_get_vlan_info(struct sk_buff *skb,
> + struct net_device *br,
> + u32 *vlan_tci,
> + u32 *tag_type)
> +{
> + struct vlan_ethhdr *hdr;
> + u16 proto, tci;
[ ... ]
> + if (skb_headlen(skb) >= VLAN_ETH_HLEN &&
> + ntohs(hdr->h_vlan_proto) == proto) {
> + vlan_remove_tag(skb, &tci);
> + *vlan_tci = tci;
> + } else {
[Severity: Critical]
Does this logic allow VLAN isolation bypass for fragmented in-band VLAN tags?
If a user with raw socket access constructs a frame where the 14-byte MAC
header is linear, but the in-band 802.1Q VLAN tag is placed in paged
fragments, skb_headlen(skb) >= VLAN_ETH_HLEN will evaluate to false.
Instead of linearizing the header to securely process the VLAN tag using
pskb_may_pull(), the code takes this else branch. This misclassifies the
packet as untagged and assigns it the bridge's PVID, leaving the original
spoofed 802.1Q tag untouched in the payload.
When the frame is later injected into the switch, the hardware rewriter won't
pop the payload tag since the switch believes the frame is untagged. The
packet would then be transmitted on the wire retaining the user's spoofed
802.1Q tag, completely bypassing the bridge's VLAN filtering and isolation.
> + rcu_read_lock();
> + br_vlan_get_pvid_rcu(br, &tci);
> + rcu_read_unlock();
> + *vlan_tci = tci;
> + }
> +
> + *tag_type = (proto != ETH_P_8021Q) ? LAN9645X_IFH_TAG_TYPE_S :
> + LAN9645X_IFH_TAG_TYPE_C;
> +
> + return skb;
> +}
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260929-dsa_lan9645x_switch_driver_base-v13-0-827c2d3617f2@microchip.com?part=1
next prev parent reply other threads:[~2026-09-30 7:50 UTC|newest]
Thread overview: 29+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-29 7:48 [PATCH net-next v13 0/9] net: dsa: add DSA support for the LAN9645x switch chip family Jens Emil Schulz Østergaard
2026-09-29 7:48 ` [PATCH net-next v13 1/9] net: dsa: add tag driver for LAN9645X Jens Emil Schulz Østergaard
2026-09-30 7:50 ` sashiko-bot [this message]
2026-10-02 21:14 ` netdev-bot+sashiko
2026-10-06 7:19 ` Jens Emil Schulz Ostergaard
2026-09-29 7:48 ` [PATCH net-next v13 2/9] dt-bindings: net: lan9645x: add LAN9645X switch bindings Jens Emil Schulz Østergaard
2026-09-30 7:50 ` sashiko-bot
2026-10-02 21:14 ` netdev-bot+sashiko
2026-10-07 14:34 ` Jens Emil Schulz Ostergaard
2026-10-06 3:19 ` Rob Herring (Arm)
2026-09-29 7:48 ` [PATCH net-next v13 3/9] net: dsa: lan9645x: add autogenerated register macros Jens Emil Schulz Østergaard
2026-09-29 7:48 ` [PATCH net-next v13 4/9] net: dsa: lan9645x: add basic dsa driver for LAN9645X Jens Emil Schulz Østergaard
2026-10-02 21:14 ` netdev-bot+sashiko
2026-09-29 7:48 ` [PATCH net-next v13 5/9] net: dsa: lan9645x: add vlan support Jens Emil Schulz Østergaard
2026-10-02 21:14 ` netdev-bot+sashiko
2026-10-06 12:31 ` Jens Emil Schulz Ostergaard
2026-09-29 7:48 ` [PATCH net-next v13 6/9] net: dsa: lan9645x: add mac table integration Jens Emil Schulz Østergaard
2026-10-02 21:14 ` netdev-bot+sashiko
2026-10-06 12:34 ` Jens Emil Schulz Ostergaard
2026-09-29 7:48 ` [PATCH net-next v13 7/9] net: dsa: lan9645x: add mdb management Jens Emil Schulz Østergaard
2026-10-02 21:14 ` netdev-bot+sashiko
2026-10-06 12:51 ` Jens Emil Schulz Ostergaard
2026-09-29 7:48 ` [PATCH net-next v13 8/9] net: dsa: lan9645x: add bridge support Jens Emil Schulz Østergaard
2026-10-02 21:14 ` netdev-bot+sashiko
2026-10-07 14:23 ` Jens Emil Schulz Ostergaard
2026-09-29 7:48 ` [PATCH net-next v13 9/9] net: dsa: lan9645x: add port statistics Jens Emil Schulz Østergaard
2026-09-30 7:50 ` sashiko-bot
2026-10-02 21:14 ` netdev-bot+sashiko
2026-10-07 14:29 ` Jens Emil Schulz Ostergaard
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260930075010.004D61F00893@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=jensemil.schulzostergaard@microchip.com \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=wsa+renesas@sang-engineering.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox