From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id ADE8651C040; Wed, 30 Sep 2026 17:28:26 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790789310; cv=none; b=GIWiR3ad+bpUX/TbHYQvpJ9TOyp2J5Xp0bysB90LPskBGB093Bi2xqUrZ8i31xbw+s6FoNLkq0dXUzVVSifEmYyY5V1mAOiFbqm55riT0EqcE/Awvy2aKk4QLBVSEhQA4CPugA3xoMC6QPK8HzbWpOMlIE4oCsiGFnVzpp3RIEQ= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790789310; c=relaxed/simple; bh=sWMsVfp+2hyDg2oBgPgSZXm5TgSUDSk5yHLAz0OtC/o=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=JBj8TuVJWNteJa9686RjopMyZPFc32hL+x+1vCllA3YjrinAFXmuGLoL9qBTTJd4qQW8m1Chc5Tv085DROltbUd/Tyl/YULMTiISWTEcrfHEg8vmtYO2dBKHTfhvExbhz+npvZj2RtLFZw07Jp7kv6Qbyy1dUrA4+vnTq0wUZjY= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=XnDvRTO4; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="XnDvRTO4" Received: by smtp.kernel.org (Postfix) with ESMTPSA id C78071F000FF; Wed, 30 Sep 2026 17:28:25 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790789306; bh=pXgna3528DGiUpObPKy4IsZMAeOX+yUQvtyi7AT4KBc=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=XnDvRTO4CfOxdRO1xAn6CZ9dVSPlQpAOpqD7f4GZC+WeUIeZUOVm49Kdvnf95wKxs zCECPtZSnXOZlXUsaBZAYk1AYTL/kSV3Z4fRZoV8E3Q/uWaOmgkhjAp+2BUJNqFVqu mWT/GvTF8L1vdOaG/wEJN1CWRTesKsrrQoqVSUHI= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Xuanqiang Luo , Ido Schimmel , Hangbin Liu , Jakub Kicinski , Sasha Levin Subject: [PATCH 6.12 430/877] ip_gre: Reject enabling collect metadata through changelink Date: Wed, 30 Sep 2026 17:22:21 +0200 Message-ID: <20260930152423.967020141@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260930152414.738996857@linuxfoundation.org> References: <20260930152414.738996857@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 6.12-stable review patch. If anyone has any objections, please let me know. ------------------ From: Xuanqiang Luo [ Upstream commit a3f315be9d30eeb6938d11fa17fd4b32d52f7c42 ] ipgre_netlink_parms() can enable collect_md on an existing GRE, GRETAP or ERSPAN device. Unlike newlink, changelink does not enforce metadata tunnel uniqueness. Converting a non-metadata device can therefore replace the metadata receive entry for another device of the same type in the same netns. Deleting either device then clears the shared entry, breaking metadata receive lookup for the surviving device. If parameter validation fails after collect_md is set, deleting the modified device can also clear an entry it never owned. Reject enabling metadata mode in both changelink callbacks before any encapsulation or tunnel parameters are modified. Allow requests that repeat the metadata attribute on an existing metadata device. Fixes: 2e15ea390e6f ("ip_gre: Add support to collect tunnel metadata.") Signed-off-by: Xuanqiang Luo Reviewed-by: Ido Schimmel Reviewed-by: Hangbin Liu Link: https://patch.msgid.link/20260921031859.9283-1-xuanqiang.luo@linux.dev Signed-off-by: Jakub Kicinski Signed-off-by: Sasha Levin --- net/ipv4/ip_gre.c | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/net/ipv4/ip_gre.c b/net/ipv4/ip_gre.c index f344e9bb31fbb..5c5ea36584bf9 100644 --- a/net/ipv4/ip_gre.c +++ b/net/ipv4/ip_gre.c @@ -1449,6 +1449,12 @@ static int ipgre_changelink(struct net_device *dev, struct nlattr *tb[], if (!rtnl_dev_link_net_capable(dev, t->net)) return -EPERM; + if (data && data[IFLA_GRE_COLLECT_METADATA] && !t->collect_md) { + NL_SET_ERR_MSG(extack, + "Enabling collect_md on an existing device is not supported"); + return -EOPNOTSUPP; + } + err = ipgre_newlink_encap_setup(dev, data); if (err) return err; @@ -1481,6 +1487,12 @@ static int erspan_changelink(struct net_device *dev, struct nlattr *tb[], if (!rtnl_dev_link_net_capable(dev, t->net)) return -EPERM; + if (data && data[IFLA_GRE_COLLECT_METADATA] && !t->collect_md) { + NL_SET_ERR_MSG(extack, + "Enabling collect_md on an existing device is not supported"); + return -EOPNOTSUPP; + } + err = ipgre_newlink_encap_setup(dev, data); if (err) return err; -- 2.53.0