From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pf1-f181.google.com (mail-pf1-f181.google.com [209.85.210.181]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A14AC43C7DF for ; Thu, 6 Aug 2026 10:12:50 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.181 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786011171; cv=none; b=YcdrA0mYjvov4+/N/AJdBHvqhlOvejMenlzsVHOtdKnxJIOd0oA2i2akl+5AfWpsEN/ILntb1gO1RS52JoAyGosNNnoUTUUN0g8iYo52zyfQ/lt9VNGaxyqf5wqMgc48L00bn2Wnuw0RDE2OF2cpkuiA2XXnrAn1EY86iyNbBLM= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786011171; c=relaxed/simple; bh=VrzyduWAQBp2atZUJGEwneCO6VgDa36h9AzGxsS+y70=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=TNsMf31pR76EMy5gLLn7n8ZEnv4atY3lH5On2sk6tvXz9oS7d2+O5HY5LvTE240J7Ztk/9QckfEJwzth3lGyPh3hsdbmR+dg8mPWvG2F11qc3ZMbXwBhdW0K0UQPV0507kzkJY6+EnB/GPUWR8sD4DBCOiEo9TWBWwvWV5J4qc4= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=LXjH1Zid; arc=none smtp.client-ip=209.85.210.181 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="LXjH1Zid" Received: by mail-pf1-f181.google.com with SMTP id d2e1a72fcca58-84867f07d63so2397667b3a.2 for ; Thu, 06 Aug 2026 03:12:50 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786011170; x=1786615970; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=A5pZPZKOV8wB+qQsGx++/PxBsNUpy69jm91FCX96JKg=; b=LXjH1ZidmOFQfXJ6UmjVjmp+UbeyaPQNdSV5MvvDJNFi61sXGaYUBZcJNtEJlxFmk+ bCKRGMOohajw9cjvvuUN9wT5ivqH8D4cloa9FtZNFuam5f23Z09DO3eMN0mXGZw7NzSw MleWkPIcR6p4C2n/JArNJ9m9E7ZuzIiGybWn108EY/9PwinhlaUXGjmwaN2YWMqZyUhV G6RoH6D7wYL8gWMSYbjposUJjZDXu2weADuaopn/G7mUaqHYJ027h76wiPgFmakG1N05 z22zU8e/XsRb2CALqAO/MZe34ZV/hYXwTLviz2fuL/qSbNFMvoF7G97j5HBkMd4ro9bs Y8gw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786011170; x=1786615970; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=A5pZPZKOV8wB+qQsGx++/PxBsNUpy69jm91FCX96JKg=; b=HMeTOYjbpVQGYbevI7UkvkASqZrY4nBxHkyvXbuE/4yGYJUBeQ5/cLE8t9q13COtyB jzHav1yCQQamaHeyQzFuNrc9HA+z8R+rpi5ZLZjqih+bGw7x+3Gd32cFTdMzH3Uybe2j pDinRmTdVQiL9JYw5deCIfPIPXw/xJNyYOefO0p0ABVNn3Be4yEYBBymLQ4DtcH/l16+ 1riUiC3OP6g5CGBihlsWwarNHKhjnd2y5NLHgPpYs0jxN8TDLMXiefkdxw0RC35JgSvH ezMbJ4E6AWpbzun7pVRxIl0UQ+ScOR8fgYb9ebGnZVkdcKAXAXRmO4X4jMxLYe/cRVDx qF4g== X-Forwarded-Encrypted: i=1; AHgh+RrB+9rKzSIjLmWqbGvQ602lB8lSxLhjrFVj7otleVzAVCeYsuKpA3zWz2NrFcW6qySydk2d8QugUP137i0=@vger.kernel.org X-Gm-Message-State: AOJu0YykCGjXBbU5lNoQvFN8H/ad2oPTouEXvRor0JPGX/Vspg50A6yi O4SEIdaDlbyt0JZlOrBG6Gp1Nn6GwBOb1xKxWes8ikZI0ITJkHGSyZna X-Gm-Gg: AR+sD109DO+eXCm/DXdWmXFpC1kSsG4n/opYMcqxorWP8ANR3u+DWiEXk5m9vQ9R1Qh KkQVZcpCjZGS0X+VH+DvO1Dhikg5wi/evC4WbjTHNZWULNr1OhCe+KDdy23RSOMRc1RXq66IbjE cvI5SmFEqXgfyx6dwXgHjQ/Rdo7/XLUtQAGBu54dFiM655Ue0lwus9yKi/uLVCrDzukFLkGAh2w PwFusPYgDDJPAdSwRdJolVYFNjP2AhjlpL1HgYGeewb5+TlY6Lrw881WFYqgLpa1rNsr9ArmPMH HliryEAMjeCCkqa4SO82Cz+tPhx8Q7OYDKJen0w9y1EFwoO9qMdrLkPVRbmFckWjWpGVE91AUOT RBnLCAyy7uN18FrjhfEvzzmVlNeABU+ImptE/Sti00m0Jj7fXwQTLfhebSzKZ/uMqPMjXY5Oq2b 6CP5qQl/SIFxHhRH7RB0L2r5lLyN1J2ZAeNeM5K9agmdmR1hwkFxymGakoxpoIFGuW5Ba/be5uU Y9yEdfUAMf8w1Ll+XOL1/W0GcL6/1sAlJ4ft06CnIetrsjw1Q== X-Received: by 2002:a05:6a00:4294:b0:83e:b443:965e with SMTP id d2e1a72fcca58-84f2dfc5413mr15446711b3a.3.1786011169755; Thu, 06 Aug 2026 03:12:49 -0700 (PDT) Received: from BOOK-P74QMIQ7E8.localdomain ([220.73.18.179]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-84f45bc9cffsm1090371b3a.59.2026.08.06.03.12.46 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 06 Aug 2026 03:12:49 -0700 (PDT) From: Hyunjung Ko To: Jamal Hadi Salim , Jiri Pirko , "David S . Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , Shuah Khan , Tao Liu Cc: netdev@vger.kernel.org, linux-kselftest@vger.kernel.org, linux-kernel@vger.kernel.org, Hyunjung Ko Subject: [PATCH net v2 2/2] selftests: tc-testing: add act_ct test for malformed header handling Date: Thu, 6 Aug 2026 19:12:35 +0900 Message-Id: <20260806101235.809370-2-hj351016@gmail.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260806101235.809370-1-hj351016@gmail.com> References: <20260806101235.809370-1-hj351016@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Add a tdc case covering the leak fixed by the previous patch. The test attaches "action ct" to a clsact ingress chain and injects ten IPv6 frames whose nexthdr says hop-by-hop but which carry nothing after the 40-byte header, so ipv6_find_hdr() fails and tcf_ct_ipv6_is_fragment() returns -EPROTO. Before the fix act_ct returned TC_ACT_CONSUMED for these packets, so tc_run() never reached its TC_ACT_SHOT arm and the clsact drop counter stayed at zero while the skbs leaked. After the fix the packets are dropped properly and the counter reflects them, which is what the test matches on: before: Sent 476 bytes 11 pkt (dropped 0, overlimits 0 requeues 0) after: Sent 400 bytes 10 pkt (dropped 10, overlimits 0 requeues 0) Assisted-by: Anthropic-Claude-Code:Claude-Opus-5 Signed-off-by: Hyunjung Ko --- .../selftests/tc-testing/tc-tests/actions/ct.json | 40 ++++++++++++++++++++++ 1 file changed, 40 insertions(+) New in v2, requested by Jamal. Caveat on how far I verified it: I do not have a scapy-capable tdc environment set up, so I have not run tdc.py over this case itself. What I did run, on both an unpatched and a patched v7.2-rc6 under qemu, is exactly what the case does - clsact ingress plus "matchall action ct" on a veth pair, ten of the same malformed frames injected on the peer, then "tc -s qdisc show dev clsact": unpatched: Sent 476 bytes 11 pkt (dropped 0, overlimits 0 requeues 0) patched: Sent 400 bytes 10 pkt (dropped 10, overlimits 0 requeues 0) so the matchPattern does discriminate. The JSON itself is modelled on the existing scapy cases in the same file (3992, 9c2a). A run through tdc.py proper before this is applied would be welcome. diff --git a/tools/testing/selftests/tc-testing/tc-tests/actions/ct.json b/tools/testing/selftests/tc-testing/tc-tests/actions/ct.json index da65f838bd52..8ab48def89b6 100644 --- a/tools/testing/selftests/tc-testing/tc-tests/actions/ct.json +++ b/tools/testing/selftests/tc-testing/tc-tests/actions/ct.json @@ -702,5 +702,45 @@ "$TC qdisc del dev $DUMMY clsact", "$TC qdisc del dev $DUMMY root handle 1:" ] + }, + { + "id": "c7a3", + "name": "Verify act_ct drops a packet whose header checks fail", + "category": [ + "actions", + "ct", + "scapy" + ], + "plugins": { + "requires": [ + "nsPlugin", + "scapyPlugin" + ] + }, + "setup": [ + [ + "$TC qdisc del dev $DEV1 clsact", + 0, + 1, + 2, + 255 + ], + "$TC qdisc add dev $DEV1 clsact" + ], + "cmdUnderTest": "$TC filter add dev $DEV1 ingress protocol all prio 1 matchall action ct", + "scapy": [ + { + "iface": "$DEV0", + "count": 10, + "packet": "Ether(type=0x86dd)/IPv6(nh=0, plen=0, src='::1', dst='::2')" + } + ], + "expExitCode": "0", + "verifyCmd": "$TC -s qdisc show dev $DEV1 clsact", + "matchPattern": "dropped 10", + "matchCount": "1", + "teardown": [ + "$TC qdisc del dev $DEV1 clsact" + ] } ] -- 2.43.0