netdev.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* sending VLAN packets via packet_mmap
@ 2010-09-30 19:24 Phil Sutter
  2010-10-07  6:53 ` David Miller
  0 siblings, 1 reply; 11+ messages in thread
From: Phil Sutter @ 2010-09-30 19:24 UTC (permalink / raw)
  To: netdev; +Cc: Johann Baudy, Eric Dumazet

Hi,

support for VLAN tags in af_packet.c seems to be incomplete. While it's
possible to receive a full packet using SOCK_RAW, sending one will fail
due to size constraints. tpacket_snd() does not account for the
additional four bytes.

There are a few possible solutions to this problem. When searching for
the most appropriate one, I've been looking at tpacket_rcv() which
simply writes the whole frame out, setting tpacket2_hdr.tp_vlan_tci on
the go. So from a user's point of view, information is redundantly
available.

The actual problem in tpacket_snd() is this:

| reserve = dev->hard_header_len;
| [...]
| if (size_max > dev->mtu + reserve)
| 	size_max = dev->mtu + reserve;

I guess the check is there to avoid skb overflows on malicious data
input. Is this correct? Are there other reasons for it's existence?

As af_packet.c has no knowledge about VLANs (other than a call to
vlan_tx_tag_get()), I guess avoiding expensive parsing of the inserted
data for the VLAN tag should be appropriate. Nevertheless the check from
above needs to account for the additional VLAN_HLEN when the tag exists.

So a rather trivial solution would be to drop the check completely
(given no other constraints, of course), thereby giving the user a
little more ability to break things. Alternatively, one could require
that tpacket2_hdr.tp_vlan_tci be set (at least non-zero) to identify
packets containing a VLAN tag and allow the additional size (probably
mostly consistent to the logic inside tpacket_rcv()).

A third solution could be like the second one, but not accepting
prebuilt packets including VLAN header at all and using
tpacket2_hdr.tp_vlan_tci together with vlan_put_tag() to instead insert
it from inside the kernel.

Hopefully I didn't overlook something crucial. Feel free to flame me if
that's the case! :)

Greetings, Phil

^ permalink raw reply	[flat|nested] 11+ messages in thread

end of thread, other threads:[~2010-10-27 15:48 UTC | newest]

Thread overview: 11+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2010-09-30 19:24 sending VLAN packets via packet_mmap Phil Sutter
2010-10-07  6:53 ` David Miller
2010-10-11 13:15   ` Phil Sutter
2010-10-11 13:25     ` [PATCH] af_packet: account for VLAN when checking packet size Phil Sutter
2010-10-11 14:03       ` Eric Dumazet
2010-10-11 16:01         ` David Miller
2010-10-11 17:29           ` Phil Sutter
2010-10-12 17:19             ` Michael S. Tsirkin
2010-10-12 17:40               ` David Miller
2010-10-22  8:41                 ` Simon Horman
2010-10-27 15:48                   ` David Miller

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).