From: Nikolay Aleksandrov <razor@blackwall.org>
To: Artem Lytkin <iprintercanon@gmail.com>, netdev@vger.kernel.org
Cc: bridge@lists.linux.dev, idosch@nvidia.com, davem@davemloft.net,
edumazet@google.com, kuba@kernel.org, pabeni@redhat.com,
horms@kernel.org, andrew+netdev@lunn.ch, kuniyu@google.com,
michael.chan@broadcom.com, pavan.chebbi@broadcom.com,
ajit.khaparde@broadcom.com, sriharsha.basavapatna@broadcom.com,
anthony.l.nguyen@intel.com, przemyslaw.kitszel@intel.com,
intel-wired-lan@lists.osuosl.org, saeedm@nvidia.com,
tariqt@nvidia.com, mbloch@nvidia.com, oss-drivers@corigine.com,
wintera@linux.ibm.com, aswin@linux.ibm.com,
linux-s390@vger.kernel.org
Subject: Re: [PATCH net-next v3 2/2] net: bridge: fail link info that does not fit in a netlink attribute
Date: Sun, 20 Sep 2026 10:06:32 +0300 [thread overview]
Message-ID: <ed1de95e-e112-4076-93f0-6f7668e657ad@blackwall.org> (raw)
In-Reply-To: <20260919134333.49379-3-iprintercanon@gmail.com>
On 19/09/2026 16:43, Artem Lytkin wrote:
> nla_len is a u16, and a port with enough VLANs, tunnels or MST entries
> makes the IFLA_AF_SPEC nest wrap, so userspace reads garbage. Same for
> the inner MST and CFM nests.
>
> Use nla_nest_end_safe() for all three and return -E2BIG with an extack
> on overflow. Dumps end with that error, notifications go through
> rtnl_set_sk_err() so listeners resync.
>
> Assisted-by: Claude:claude-opus-5
> Signed-off-by: Artem Lytkin <iprintercanon@gmail.com>
> ---
> net/bridge/br_netlink.c | 25 +++++++++++++++++--------
> 1 file changed, 17 insertions(+), 8 deletions(-)
>
You can add specific extack messages to the different dumping parts of br_fill_ifinfo
so the user can identify exactly which one doesn't fit and get a more accurate error.
More below...
> diff --git a/net/bridge/br_netlink.c b/net/bridge/br_netlink.c
> index 855a46aec3a89..fbd91b86d4268 100644
> --- a/net/bridge/br_netlink.c
> +++ b/net/bridge/br_netlink.c
> @@ -459,7 +459,7 @@ static int br_fill_ifinfo(struct sk_buff *skb,
> const struct net_bridge_port *port,
> u32 pid, u32 seq, int event, unsigned int flags,
> u32 filter_mask, const struct net_device *dev,
> - bool getlink)
> + bool getlink, struct netlink_ext_ack *extack)
> {
> u8 operstate = netif_running(dev) ? READ_ONCE(dev->operstate) :
> IF_OPER_DOWN;
> @@ -588,7 +588,8 @@ static int br_fill_ifinfo(struct sk_buff *skb,
> goto nla_put_failure;
> }
>
Before these you can call if (nla_nest_end_safe(skb, af) < 0) { }
in the vlan block and set a vlan-specific extack error message, in fact
you can do that after vlan info is dumped, then after vlan tunnels are dumped
and set specific messages depending on which one didn't fit.
nla_nest_end_safe updates nla_len but you can still append attributes
after it has been called
Then you have MRP, you can do the same there and so on.
> - nla_nest_end(skb, cfm_nest);
> + if (nla_nest_end_safe(skb, cfm_nest) < 0)
> + goto nla_nest_too_large;
This can set its own extack err message, e.g.
CFM information exceeds the netlink attribute size limit
> }
>
> if ((filter_mask & RTEXT_FILTER_MST) &&
> @@ -608,20 +609,27 @@ static int br_fill_ifinfo(struct sk_buff *skb,
> if (err)
> goto nla_put_failure;
>
> - nla_nest_end(skb, mst_nest);
> + if (nla_nest_end_safe(skb, mst_nest) < 0)
> + goto nla_nest_too_large;
Same here but with MST
> }
>
> done:
> if (af) {
> - if (nlmsg_get_pos(skb) - (void *)af > nla_attr_size(0))
> - nla_nest_end(skb, af);
> - else
> + if (nla_nest_end_safe(skb, af) < 0)
> + goto nla_nest_too_large;
> + if (!nla_len(af))
> nla_nest_cancel(skb, af);
> }
>
> nlmsg_end(skb, nlh);
> return 0;
>
> +nla_nest_too_large:
> + NL_SET_ERR_MSG_MOD(extack,
> + "AF_SPEC info too large, use per-object dumps (e.g. RTM_GETVLAN)");
Just make sure here to use NL_SET_ERR_MSG_WEAK_MOD() so extack doesn't get overwritten
> + nlmsg_cancel(skb, nlh);
> + return -E2BIG;
> +
> nla_put_failure:
> nlmsg_cancel(skb, nlh);
> return -EMSGSIZE;
> @@ -654,7 +662,8 @@ void br_info_notify(int event, const struct net_bridge *br,
> if (skb == NULL)
> goto errout;
>
> - err = br_fill_ifinfo(skb, port, 0, 0, event, 0, filter, dev, false);
> + err = br_fill_ifinfo(skb, port, 0, 0, event, 0, filter, dev, false,
> + NULL);
> if (err < 0) {
> /* -EMSGSIZE implies BUG in br_nlmsg_size() */
> WARN_ON(err == -EMSGSIZE);
> @@ -693,7 +702,7 @@ int br_getlink(struct sk_buff *skb, u32 pid, u32 seq,
> return 0;
>
> return br_fill_ifinfo(skb, port, pid, seq, RTM_NEWLINK, nlflags,
> - filter_mask, dev, true);
> + filter_mask, dev, true, extack);
> }
>
> static int br_vlan_info(struct net_bridge *br, struct net_bridge_port *p,
next prev parent reply other threads:[~2026-09-20 7:06 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-19 13:43 [PATCH net-next v3 0/2] bridge: report an oversized IFLA_AF_SPEC nest instead of truncating Artem Lytkin
2026-09-19 13:43 ` [PATCH net-next v3 1/2] rtnetlink: pass extack to ndo_bridge_getlink() Artem Lytkin
2026-09-19 13:55 ` sashiko-bot
2026-09-20 7:08 ` Nikolay Aleksandrov
2026-09-22 18:44 ` netdev-bot+sashiko
2026-09-19 13:43 ` [PATCH net-next v3 2/2] net: bridge: fail link info that does not fit in a netlink attribute Artem Lytkin
2026-09-19 13:55 ` sashiko-bot
2026-09-20 7:06 ` Nikolay Aleksandrov [this message]
2026-09-22 18:44 ` netdev-bot+sashiko
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=ed1de95e-e112-4076-93f0-6f7668e657ad@blackwall.org \
--to=razor@blackwall.org \
--cc=ajit.khaparde@broadcom.com \
--cc=andrew+netdev@lunn.ch \
--cc=anthony.l.nguyen@intel.com \
--cc=aswin@linux.ibm.com \
--cc=bridge@lists.linux.dev \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=horms@kernel.org \
--cc=idosch@nvidia.com \
--cc=intel-wired-lan@lists.osuosl.org \
--cc=iprintercanon@gmail.com \
--cc=kuba@kernel.org \
--cc=kuniyu@google.com \
--cc=linux-s390@vger.kernel.org \
--cc=mbloch@nvidia.com \
--cc=michael.chan@broadcom.com \
--cc=netdev@vger.kernel.org \
--cc=oss-drivers@corigine.com \
--cc=pabeni@redhat.com \
--cc=pavan.chebbi@broadcom.com \
--cc=przemyslaw.kitszel@intel.com \
--cc=saeedm@nvidia.com \
--cc=sriharsha.basavapatna@broadcom.com \
--cc=tariqt@nvidia.com \
--cc=wintera@linux.ibm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox