From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pj2-f4.google.com (mail-pj2-f4.google.com [74.125.227.132]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D2FEC471432 for ; Wed, 22 Jul 2026 18:00:35 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.227.132 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784743237; cv=none; b=KYqWnXtJJ5I4NqadJan+rlgBrxNngtTxOQLKXQzBY/jb02MEq7lyTZl8na7IDVXE9XVRRpDbT7irLCVJtnLKJy+EgMSfDH55GJR7YfmDyHKxcut21RDQwg+J8SRggXhqsvCSOjyyLpkaZ1q6QX2DEL+50biSc71jDy7BngljogY= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784743237; c=relaxed/simple; bh=Vm9pdnoQiEjS5jrO+VcZAmAh4KLL2aDUZZ2ez/tDOZU=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=kfjqDM7mDrgmDZ91CgNC/PEHYaBKwnsxa9F0aGtTPcUP6ANLKoEqDe0f9gPX6+9UIMJtA315b6apmtnMQXLglt002PdRIHPfDCZ32aAH+23nVlLqSHaG8jbgVq+wx+yw5Qa7YWUqpFLnNkpaWNTRV6StNWfTzgk6hhfVwR6kUjQ= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=KOvIcX3K; arc=none smtp.client-ip=74.125.227.132 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="KOvIcX3K" Received: by mail-pj2-f4.google.com with SMTP id d9443c01a7336-2cc7ef596c6so110013515ad.1 for ; Wed, 22 Jul 2026 11:00:35 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784743235; x=1785348035; darn=vger.kernel.org; h=in-reply-to:content-disposition:content-type:mime-version :references:message-id:subject:cc:to:from:date:from:to:cc:subject :date:message-id:reply-to:content-type; bh=HnNlfSj3fIGtu585qe6eLWjGneo6zvxtz8A2jHYq8n0=; b=KOvIcX3Ki/9DH/Q+5M2g+Sn5rSwVtABWmBNsDuFWR0iN8/nAaKDq1BIVv+5v2kctGs QnaOKR6zj/PJMwdhPNjmaUEJLPvyigqHaG48exG2TfywbyG7wuXNvSlJlQ5RMd4CPRqG Sd1lgzPEP5trV5+qGfahIqOenKW+OAXMxHEWGpJJiyfFi8a+hnR6sBNl/LJdXPWhBP3b /Nw5J1LIyBArYTTVINrTlXaeIJKIUi9ErdnjxwBKsxf4Y3ptGISvdSGF3QdIkeaLsH7h 7pPLxyM6t4uXy8cTP0QvoNCjtHZUzdcP/bzvrxpIvIeWsCTgPEaPV5Dr1Haz5hTM9v4/ pasw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784743235; x=1785348035; h=in-reply-to:content-disposition:content-type:mime-version :references:message-id:subject:cc:to:from:date:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=HnNlfSj3fIGtu585qe6eLWjGneo6zvxtz8A2jHYq8n0=; b=A1NdRmwzIbdsV2U1OHmQ3hlFN9xKg6ghjL6AefzBVXdaOiAi1rORjNmrraYlByxHx5 4V3mwBqIpIfZ2aaEvdmbNNjmFvkxy8riY13BsIZtJqHZF9TO4Vv/B6JoREUlGYoyGGLU v/2lcQ05zugqagYJREtvJz4a8YbH4erRtzh2b9Sa820SZkhr+cNiiRTIfpvDEyP0ndWG Ld2qUTsZIt0/BrvFcMad83PpJWLoq/NsGAlv58VCADrPr6dnsNv5+SemnSFldKzo7tTP zvyhsXOU1vh1zs3Z1PEf19bOuazd88R9SPJae2MiuLPMEnSX+eLF3TMpgFB0+lo7HSfj CrYg== X-Forwarded-Encrypted: i=1; AHgh+Rq2RiuH9gPzWzqAkn7EKU5px5a75CYcw3PYIFbx+VnNoKP5s8E54LYq30VCn7rUJf4pnkhL9qVbh9c=@vger.kernel.org X-Gm-Message-State: AOJu0Yy0PyHDjxZr2Qdyc8XKiV56pQR2V4oDEZYSJ0SJ7OdUjH4nNiyn qpxsmlq3ebcVBADKj9LyI927YBbYG6Sit3i1XcDaI/RKTTzfr4bt99fN X-Gm-Gg: AR+sD10UrahnMLmUh9qCXYi9r5QfcPJtzPuPoO0eXRgnuXJDctr2ixDr+jOOxwDcBCN FWn+7TNvwHeALKenCoYF5SwO3G2BQRwFGFOVoNMIFwmuQmVC3dAoPcWnXo723RVxiHC4SREJ+Mi hyHst535hAAd92coa6wKZ6qSYMk8/oBZzqhzrcrjC8l9e3lMjXrlodgGzdUeTPfE9i8jobij9Tw mPSmLUhW7OzbGF2RNkJokv/hWnDF7r1MumncPPxrnC5F+rYzIuggdlKnSEJIxw9+pzWcbf80n9y ERL9A880nbEjz/R6ZERDpHAz7ou78+rt/+mQLoQG9e98avwV+CgAFBx39kRnSYwkwRg3w928glr dSozDv2hmBZ614AA6SmGL6RXNJf/In58+CqsN9BaBcOtUUrgAyPV3tiWX74xgnVOPxgGg0w== X-Received: by 2002:aa7:8744:0:b0:84e:89a:b8ed with SMTP id d2e1a72fcca58-84e089ab9d8mr6443533b3a.70.1784743234973; Wed, 22 Jul 2026 11:00:34 -0700 (PDT) Received: from localhost ([2a03:2880:2ff:4::]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-84e17266107sm1750442b3a.17.2026.07.22.11.00.32 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 11:00:33 -0700 (PDT) Date: Wed, 22 Jul 2026 11:00:07 -0700 From: Stanislav Fomichev To: Jakub Kicinski Cc: Lorenzo Bianconi , Donald Hunter , "David S. Miller" , Eric Dumazet , Paolo Abeni , Simon Horman , Alexei Starovoitov , Daniel Borkmann , Jesper Dangaard Brouer , John Fastabend , Stanislav Fomichev , Andrew Lunn , Tony Nguyen , Przemek Kitszel , Alexander Lobakin , Andrii Nakryiko , Martin KaFai Lau , Eduard Zingerman , Song Liu , Yonghong Song , KP Singh , Hao Luo , Jiri Olsa , Shuah Khan , Maciej Fijalkowski , Jonathan Corbet , Shuah Khan , Kumar Kartikeya Dwivedi , Emil Tsalapatis , Vladimir Vdovin , Jakub Sitnicki , netdev@vger.kernel.org, bpf@vger.kernel.org, intel-wired-lan@lists.osuosl.org, linux-kselftest@vger.kernel.org, linux-doc@vger.kernel.org Subject: Re: [PATCH bpf-next v5 8/8] selftests: net: add test for XDP_PASS skb checksum invalidation Message-ID: References: <20260715-bpf-xdp-meta-rxcksum-v5-0-623d5c0d0ab7@kernel.org> <20260715-bpf-xdp-meta-rxcksum-v5-8-623d5c0d0ab7@kernel.org> <20260721082728.74142e6c@kernel.org> <20260721183256.6f49d6e1@kernel.org> Precedence: bulk X-Mailing-List: linux-doc@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline In-Reply-To: <20260721183256.6f49d6e1@kernel.org> On 07/21, Jakub Kicinski wrote: > On Tue, 21 Jul 2026 16:03:37 -0700 Stanislav Fomichev wrote: > > > > For unnecessary, I think the safe expectation is that the bpf program > > > > will update the value of the checksum in the packet if it touches the data? > > > > > > Documenting as expected behavior which no driver currently follows > > > is a bit silly. I thought the ask was to sketch out the plan of > > > explicitly updating/invalidating the checksum even if we don't > > > implement it today? > > > > This is about current drivers that only report UNNECESSARY with xdp: the xdp > > prog has to maintain in-packet checksum if it changes the payload. I think > > it's a fair assumption? > > What about decap? If we decap the header that device validated > as UNNECESSARY there's no possibility of maintaining the checksum > (by which IIUC you mean correcting it in along the payload changes). > > I think we'd need some API to "decrement the csum level" ? > Or some heuristic in the drivers to decrement if the head moved > by at least len(IP+UDP) into the packet ? True :-/ I guess one more case to document? > > In terms of documentation, here is what I have on my side, lmk if that makes > > sense, roughly: > > > > - TODAY > > - some drivers (correctly) disable reporting COMPLETE when XDP is attached > > - the xdp program has to modify the packet checksum value if it > > changes the payload > > - some drivers (incorrectly?) report COMPLETE for xdp-to-skb path -> unsafe, > > needs to be fixed > > - updating the payload doesn't update skb->csum, so the safest > > option right now is to only do UNNECESSARY with xdp for all drivers > > Yes, that sounds fair. > > > - the hw test needs to make sure that the csum is either > > NONE or UNNECESSARY, and will error out on COMPLETE > > Driver can report COMPLETE to XDP, just not to the stack. > I think we can use a tracepoint (bpftrace) or attach in TCP > to check the skb state? No strong opinion on this, it seems easier to report the same to both xdp and bpf (at least initially)