* [PATCH net v3] net: erspan: set lltx to avoid sch_direct_xmit deadlock
@ 2026-07-30 8:22 Yun Zhou
2026-08-03 15:11 ` Ido Schimmel
0 siblings, 1 reply; 2+ messages in thread
From: Yun Zhou @ 2026-07-30 8:22 UTC (permalink / raw)
To: dsahern, idosch, davem, edumazet, kuba, pabeni, horms
Cc: netdev, linux-kernel, yun.zhou
erspan_xmit() re-enters the network stack via ip_tunnel_xmit(), causing
nested acquisition of _xmit_lock on the underlay device while already
holding the ERSPAN device's _xmit_lock. Both are ARPHRD_ETHER and share
the same lockdep class, creating an ABBA deadlock:
sch_direct_xmit [lock erspan] -> erspan_xmit -> ip_tunnel_xmit ->
ip_output -> __dev_queue_xmit -> sch_direct_xmit [lock underlay]
Set dev->lltx = true so HARD_TX_LOCK() skips the spinlock for ERSPAN.
This is safe as erspan_xmit() has no shared mutable state: o_seqno is
atomic, stats use atomic_long_inc, and dst_cache is per-CPU. GRETAP,
the sibling device with identical xmit structure, already sets lltx.
Closes: https://syzkaller.appspot.com/bug?extid=9bda1b9fbb7fbdf9b62b
Reported-by: syzbot+9bda1b9fbb7fbdf9b62b@syzkaller.appspotmail.com
Fixes: 84e54fe0a5ea ("gre: introduce native tunnel support for ERSPAN")
Fixes: 5a963eb61b7c ("ip6_gre: Add ERSPAN native tunnel support")
Cc: stable@vger.kernel.org
Signed-off-by: Yun Zhou <yun.zhou@windriver.com>
---
v3:
- add fix for IPv6
v2:
- change subject prefix to [PATCH net]
net/ipv4/ip_gre.c | 2 ++
net/ipv6/ip6_gre.c | 2 ++
2 files changed, 4 insertions(+)
diff --git a/net/ipv4/ip_gre.c b/net/ipv4/ip_gre.c
index 0ba1e94e9012..8c5ad8ec8d09 100644
--- a/net/ipv4/ip_gre.c
+++ b/net/ipv4/ip_gre.c
@@ -1363,6 +1363,8 @@ static int erspan_tunnel_init(struct net_device *dev)
dev->features |= GRE_FEATURES;
dev->hw_features |= GRE_FEATURES;
dev->priv_flags |= IFF_LIVE_ADDR_CHANGE;
+ /* Skip TX lock: xmit re-enters stack, risking ABBA with underlay */
+ dev->lltx = true;
netif_keep_dst(dev);
return ip_tunnel_init(dev);
diff --git a/net/ipv6/ip6_gre.c b/net/ipv6/ip6_gre.c
index b843116e9b70..143166e3e586 100644
--- a/net/ipv6/ip6_gre.c
+++ b/net/ipv6/ip6_gre.c
@@ -1870,6 +1870,8 @@ static int ip6erspan_tap_init(struct net_device *dev)
dev->mtu -= 8;
dev->priv_flags |= IFF_LIVE_ADDR_CHANGE;
+ /* Skip TX lock: xmit re-enters stack, risking ABBA with underlay */
+ dev->lltx = true;
ip6erspan_tnl_link_config(tunnel, 1);
netdev_hold(dev, &tunnel->dev_tracker, GFP_KERNEL);
--
2.43.0
^ permalink raw reply related [flat|nested] 2+ messages in thread
* Re: [PATCH net v3] net: erspan: set lltx to avoid sch_direct_xmit deadlock
2026-07-30 8:22 [PATCH net v3] net: erspan: set lltx to avoid sch_direct_xmit deadlock Yun Zhou
@ 2026-08-03 15:11 ` Ido Schimmel
0 siblings, 0 replies; 2+ messages in thread
From: Ido Schimmel @ 2026-08-03 15:11 UTC (permalink / raw)
To: Yun Zhou, edumazet
Cc: dsahern, davem, edumazet, kuba, pabeni, horms, netdev,
linux-kernel
On Thu, Jul 30, 2026 at 04:22:38PM +0800, Yun Zhou wrote:
> erspan_xmit() re-enters the network stack via ip_tunnel_xmit(), causing
> nested acquisition of _xmit_lock on the underlay device while already
> holding the ERSPAN device's _xmit_lock. Both are ARPHRD_ETHER and share
> the same lockdep class, creating an ABBA deadlock:
>
> sch_direct_xmit [lock erspan] -> erspan_xmit -> ip_tunnel_xmit ->
> ip_output -> __dev_queue_xmit -> sch_direct_xmit [lock underlay]
Sashiko complains that this is not accurate. Clarify that both the
overlay and underlay devices are of the same type (both erspan or both
ip6erspan). Not erspan and some Ethernet device in the underlay. See:
https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260730082238.676845-1-yun.zhou%40windriver.com
And:
https://lore.kernel.org/all/83360de7addb13a3b5f4d5e722148f248fdb2ae0.1784884817.git.pabeni@redhat.com/
>
> Set dev->lltx = true so HARD_TX_LOCK() skips the spinlock for ERSPAN.
> This is safe as erspan_xmit() has no shared mutable state: o_seqno is
> atomic, stats use atomic_long_inc, and dst_cache is per-CPU. GRETAP,
> the sibling device with identical xmit structure, already sets lltx.
This is still not safe and in v2 I asked to wait for Eric's patch to be
accepted:
https://lore.kernel.org/netdev/20260720075352.GA2233846@shredder/
And it's still WIP:
https://lore.kernel.org/netdev/20260720135132.3957146-1-edumazet@google.com/
>
> Closes: https://syzkaller.appspot.com/bug?extid=9bda1b9fbb7fbdf9b62b
> Reported-by: syzbot+9bda1b9fbb7fbdf9b62b@syzkaller.appspotmail.com
> Fixes: 84e54fe0a5ea ("gre: introduce native tunnel support for ERSPAN")
> Fixes: 5a963eb61b7c ("ip6_gre: Add ERSPAN native tunnel support")
> Cc: stable@vger.kernel.org
> Signed-off-by: Yun Zhou <yun.zhou@windriver.com>
> ---
> v3:
> - add fix for IPv6
The commit message doesn't mention the ip6erspan fix.
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-08-03 15:12 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-30 8:22 [PATCH net v3] net: erspan: set lltx to avoid sch_direct_xmit deadlock Yun Zhou
2026-08-03 15:11 ` Ido Schimmel
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox