netdev.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
From: "Michael S. Tsirkin" <mst@redhat.com>
To: David Ahern <dahern@digitalocean.com>
Cc: Jason Wang <jasowang@redhat.com>,
	"netdev@vger.kernel.org" <netdev@vger.kernel.org>
Subject: Re: virtio_net: can change MTU after installing program
Date: Wed, 26 Feb 2020 02:07:04 -0500	[thread overview]
Message-ID: <20200226015113-mutt-send-email-mst@kernel.org> (raw)
In-Reply-To: <7df5bb7f-ea69-7673-642b-f174e45a1e64@digitalocean.com>

On Tue, Feb 25, 2020 at 08:32:14PM -0700, David Ahern wrote:
> Another issue is that virtio_net checks the MTU when a program is
> installed, but does not restrict an MTU change after:
> 
> # ip li sh dev eth0
> 2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 xdp qdisc fq_codel
> state UP mode DEFAULT group default qlen 1000
>     link/ether 5a:39:e6:01:a5:36 brd ff:ff:ff:ff:ff:ff
>     prog/xdp id 13 tag c5595e4590d58063 jited
> 
> # ip li set dev eth0 mtu 8192
> 
> # ip li sh dev eth0
> 2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 8192 xdp qdisc fq_codel
> state UP mode DEFAULT group default qlen 1000

Well the reason XDP wants to limit MTU is this:
    the MTU must be less than a page
    size to avoid having to handle XDP across multiple pages

however device mtu basically comes from dhcp.
it is assumed that whoever configured it knew
what he's doing and configured mtu to match
what's going on on the underlying backend.
So we are trusting the user already.

But yes, one can configure mtu later and then it's too late
as xdp was attached.


> 
> 
> The simple solution is:
> 
> @@ -2489,6 +2495,8 @@ static int virtnet_xdp_set(struct net_device *dev,
> struct bpf_prog *prog,
>                 }
>         }
> 
> +       dev->max_mtu = prog ? max_sz : MAX_MTU;
> +
>         return 0;
> 
>  err:


Well max MTU comes from the device ATM and supplies the limit
of the underlying backend. Why is it OK to set it to MAX_MTU?
That's just asking for trouble IMHO, traffic will not
be packetized properly.


> The complicated solution is to implement ndo_change_mtu.
> 
> The simple solution causes a user visible change with 'ip -d li sh' by
> showing a changing max mtu, but the ndo has a poor user experience in
> that it just fails EINVAL (their is no extack) which is confusing since,
> for example, 8192 is a totally legit MTU. Changing the max does return a
> nice extack message.

Just fail with EBUSY instead?

-- 
MST


  parent reply	other threads:[~2020-02-26  7:07 UTC|newest]

Thread overview: 24+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2020-02-26  9:33 Michael S. Tsirkin
2020-02-26  3:32 ` virtio_net: can change MTU after installing program David Ahern
2020-02-26  4:02   ` Jason Wang
2020-02-26  4:31     ` David Ahern
2020-02-26  5:53       ` Jason Wang
2020-02-26 16:04         ` David Ahern
2020-02-26  7:07   ` Michael S. Tsirkin [this message]
2020-02-26  7:37     ` Jason Wang
2020-02-26  8:39       ` Michael S. Tsirkin
2020-02-26  9:30         ` Jason Wang
2020-02-26  9:36           ` Michael S. Tsirkin
2020-02-26 16:08     ` David Ahern
2020-02-26 16:56       ` Michael S. Tsirkin
2020-02-26  9:51   ` Toke Høiland-Jørgensen
2020-02-26 16:03     ` David Ahern
2020-02-26 16:55       ` Michael S. Tsirkin
2020-02-26 16:58         ` David Ahern
2020-02-26 17:02           ` Michael S. Tsirkin
2020-02-27  1:37             ` Jakub Kicinski
2020-02-27  8:14               ` Michael S. Tsirkin
2020-02-27 17:16                 ` Jakub Kicinski
2020-02-27 19:26               ` Michael Chan
2020-02-27 19:45                 ` Jakub Kicinski
2020-02-27 21:37                 ` David Ahern

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20200226015113-mutt-send-email-mst@kernel.org \
    --to=mst@redhat.com \
    --cc=dahern@digitalocean.com \
    --cc=jasowang@redhat.com \
    --cc=netdev@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).