* [PATCH net v3 0/4] net: hsr: fix GRO/GSO super-packet handling
@ 2026-07-31 9:02 Xin Xie
2026-07-31 9:02 ` [PATCH net v3 1/4] net: hsr: fix packet drops caused by GRO superpackets Xin Xie
` (3 more replies)
0 siblings, 4 replies; 5+ messages in thread
From: Xin Xie @ 2026-07-31 9:02 UTC (permalink / raw)
To: netdev, linux-kselftest, linux-kernel
Cc: davem, edumazet, kuba, pabeni, horms, andrew+netdev, shuah, kees,
petr.wozniak, qingfang.deng, fmaurer, luka.gejak, bigeasy,
xiaoliang.yang_1, skhawaja, stable, Xin Xie
HSR/PRP forward frames one by one: each wire frame gets its own tag
or RCT and sequence number, and duplicate discard is per frame. Two
aggregation mechanisms break that per-frame assumption:
* On RX, a lower device that aggregates frames into a GRO
super-packet feeds the HSR receive and forward paths a single
skb instead of the individual frames. Depending on the lower
device, that super-skb is then either rejected outright (for
example when it exceeds the lower MTU at egress), or forwarded
without valid per-wire-frame HSR/PRP processing: its single
trailing HSR tag / PRP RCT cannot represent the per-frame
trailers and sequence numbers of the aggregated frames. On
memory-constrained devices processing super-skbs in softirq
context also pressures atomic allocation.
* At the forward entry, a GSO super-packet (locally generated on
the master, or delivered intact by software NICs such as veth)
would be tagged and forwarded as a single frame, violating
per-frame wire semantics.
Patch 1 adds netif_disable_gro() and dev_disable_gro() alongside
the existing LRO helpers. HSR calls the public wrapper at
enslavement time, while the networking core handles the generic
feature update and recursive lower-device traversal. Enslavement to
an HSR/PRP master therefore strips NETIF_F_GRO and NETIF_F_GRO_HW
on the lower device. Disabling GRO on our own lowers is the cheap,
always-correct default for this problem: unlike the bridge,
HSR/PRP must attach a tag or RCT and a sequence number to every
wire frame, so leaving GRO enabled and re-segmenting later (the
bridge pattern) would add per-packet segmentation cost and still
could not recover per-frame trailer state from a super-skb. This
is a setup-time default, not an immutable feature policy: a later
privileged feature override, or a lower newly attached below a
stacked slave, can re-enable GRO without re-walking the HSR
enslavement path.
Patch 2 is a preparatory locking change: it shrinks
hsr->seqnr_lock from whole hsr_forward_skb() calls to the
individual sequence counter updates, so that the segmentation work
of patch 3 (per-segment allocation, checksums and forwarding)
never runs with BH disabled under the global sequence lock.
Patch 3 depends on patch 2; their automatic stable selection is
limited to 7.0 and newer, where sparse-bitmap duplicate discard
accepts out-of-order arrival. Older stable branches require an
adapted backport.
Patch 3 unfolds the remaining GSO super-packets at the forward
entry with the top-level GSO dispatch (__skb_gso_segment()), so
each wire frame still gets its own tag and sequence number. Patch 1
and patch 3 cover different sources and neither is redundant:
patch 1 establishes the safe default on our own enslaved lowers at
setup time (a later privileged override can re-enable GRO, and
patch 3 is the fail-safe for that case), while patch 3 handles GSO
super-packets that legitimately arise from locally generated
master traffic or from untagged SAN ingress on the interlink.
Segmentation is offered only for those two roles, whose frames are
known to be plain Ethernet. A super-packet from a LAN slave may
carry per-frame HSR tags or PRP RCT trailers that software
segmentation cannot recover, and an already-tagged HSR/PRP
super-packet violates per-frame wire semantics; both are rejected
by ingress-port policy. The HSR master also stops advertising
NETIF_F_GSO_MASK so locally generated traffic is segmented as
early as possible.
Patch 4 adds a kselftest covering the above: GRO disabled on
enslaved devices, no GSO/TSO advertised by the HSR master, and a
TCP stream from a TSO-enabled SAN through an HSR DUT. The stream
evidence is direct: the SAN's TX frame-size average must exceed a
fixed super-packet threshold while the DUT LAN legs' averages stay
below a fixed per-frame guard, which is aggregate evidence that
super-packets entered the forward path and bulk output was
segmented (not a per-frame maximum proof); zero retransmits is
reported as a secondary health signal. The one-shot iperf3 server
is confined to a private mktemp workdir with its real exit status
propagated, so on every path exercised by the test itself (normal
completion, server startup failure, client failure,
never-published PID, and baseline/final counter-snapshot parse
failures) no process or directory can leak.
Validation:
* build: W=1 allmodconfig and allyesconfig, base vs patched - no
new warnings (final run on this frozen v3 candidate: all four
builds RC=0; 342/342 normalized warnings in allmodconfig and
345/345 in allyesconfig, base-vs-patched diffs empty).
* selftests (all on this exact v3 kernel, QEMU x86_64):
hsr_gro_superpacket passes (GRO stripped on enslaved devices; SAN
TX frame-size average ~38k bytes > super-packet threshold; DUT
LAN legs ~1.5k bytes < per-frame guard; 0 retransmits) and fails
on the base kernel: the LAN per-frame-average guard fails at
approximately 1.9 kB on a veth lower device (aggregate evidence;
not a universal MTU-drop or per-frame-maximum proof); hsr_ping,
hsr_redbox, link_faults and
prp_ping all pass.
* functional: IPv4, IPv6 and VLAN-tagged SAN TSO streams unfold
per-frame through an HSR DUT with clean dmesg; the counter
assertions show super-packets entering the forward path and
per-frame output on both LAN legs. LAN-side aggregates and
already-tagged super-packets are dropped by ingress-port policy
(supplementary, reused v1/v2 evidence per the same patch-id
argument).
* concurrency: parallel interlink-RX (GSO) and master-TX streams
with supervision timers running, under a PROVE_LOCKING kernel
built from this candidate: both streams 0 retransmits, no
lockdep/WARN/BUG/sleep-atomic findings.
* lifecycle: normal completion, server startup failure, client
failure, a never-published server PID (live-but-unpublished
proven), and forced baseline/final counter-snapshot parse
failures all exit bounded with no leftover iperf3 process,
workdir, or namespace (all re-run on this exact v3 script; the
parse-failure paths are new v3 evidence: a baseline-snapshot
parse failure aborts before the iperf3 client workload, a
final-snapshot parse failure aborts before any counter-delta
verdict, and both leave no process or workdir).
* physical igb lower devices (supplementary, reused v1 evidence:
patches 1-3 are patch-id identical and the only upstream delta
in the touched files is an unrelated 2-line hsr_del_port()
change): GRO stripped at enslavement; force-enabled generic GRO
super-packets unfold at line rate with a clean dmesg.
---
Changes in v3:
- Fix the selftest's early-abort path: both TX counter snapshot
blocks now validate their values as decimal counters. Previously
the error flag was lost in a command-substitution subshell: a
baseline-snapshot parse failure let the test continue into the
iperf3 client workload, and a final-snapshot parse failure was
only caught indirectly. Now a baseline failure aborts before the
client workload, and a final failure aborts before any
counter-delta evaluation.
- Wrap the remaining lines that exceed 80 columns (tab-expanded)
in the selftest.
- Make the selftest's network namespaces instance-unique via
setup_ns()/cleanup_all_ns(): the previous hard-coded namespace
names were deleted unconditionally at setup, which could destroy
unrelated host namespaces and made concurrent instances collide.
Also re-prove that pre-existing namespaces survive and that two
instances run in parallel.
- Patch 2 message: state explicitly that the lock shrink removes
the old allocation-through-forward ordering guarantee and why
current sparse-bitmap duplicate discard accepts that; correct
the seqnr_lock history to its actual branch shape.
- Patch 1 message and the failure description: the outcome of a
GRO aggregate is driver-dependent (rejected by a constrained
lower device, or forwarded without valid per-frame processing),
not a universal MTU drop. Also spell out the enforcement
contract: the enslavement-time GRO disable is a setup-time
default, not an immutable feature policy, and patch 3 is the
fail-safe for traffic that still arrives aggregated.
- Stable floor: patches 2 and 3 are marked for 7.0 and newer
(sparse-bitmap duplicate discard); patch 1's eligibility is
unchanged; older branches need adapted backports.
- Rebase onto current net; patches 1-3 code payloads are unchanged
(stable patch-ids).
- Cover clarifications: the concrete RX failure site, the patch 1
vs patch 3 layering, and why disabling GRO is preferred over
re-segmenting later.
Note on the v2 contest report: the v2 series conflicts in net-next
with our own PRP RedBox series now merged there
(https://lore.kernel.org/netdev/20260717201457.54-1-xiexinet@gmail.com/).
On current net it applies cleanly (re-verified by a full-series
git am). A tested net-next merge resolution is available on
request.
Previous postings (newest first):
v2: https://lore.kernel.org/netdev/20260724161253.79-1-xiexinet@gmail.com/
v1: https://lore.kernel.org/netdev/20260722171836.196-1-xiexinet@gmail.com/
Xin Xie (4):
net: hsr: fix packet drops caused by GRO superpackets
net: hsr: shrink seqnr_lock to sequence counter updates
net: hsr: unfold GSO super-packets at the forward entry
selftests: net: hsr: add GRO super-packet forwarding test
include/linux/netdevice.h | 2 +
net/core/dev.c | 18 +
net/core/dev_api.c | 16 +
net/hsr/hsr_device.c | 17 +-
net/hsr/hsr_forward.c | 53 +-
net/hsr/hsr_slave.c | 12 +-
tools/testing/selftests/net/hsr/Makefile | 1 +
.../selftests/net/hsr/hsr_gro_superpacket.sh | 462 ++++++++++++++++++
8 files changed, 557 insertions(+), 24 deletions(-)
create mode 100755 tools/testing/selftests/net/hsr/hsr_gro_superpacket.sh
base-commit: 51b093a7ba27476e1f639455f005e8d2e75390e4
--
2.43.0
^ permalink raw reply [flat|nested] 5+ messages in thread
* [PATCH net v3 1/4] net: hsr: fix packet drops caused by GRO superpackets
2026-07-31 9:02 [PATCH net v3 0/4] net: hsr: fix GRO/GSO super-packet handling Xin Xie
@ 2026-07-31 9:02 ` Xin Xie
2026-07-31 9:02 ` [PATCH net v3 2/4] net: hsr: shrink seqnr_lock to sequence counter updates Xin Xie
` (2 subsequent siblings)
3 siblings, 0 replies; 5+ messages in thread
From: Xin Xie @ 2026-07-31 9:02 UTC (permalink / raw)
To: netdev, linux-kselftest, linux-kernel
Cc: davem, edumazet, kuba, pabeni, horms, andrew+netdev, shuah, kees,
petr.wozniak, qingfang.deng, fmaurer, luka.gejak, bigeasy,
xiaoliang.yang_1, skhawaja, stable, Xin Xie
HSR/PRP append a 6-byte tag/RCT to every forwarded frame and process
each frame individually (sequence numbering, duplicate discard). When
a lower device aggregates received frames into a GRO super-packet --
in software, or in hardware on GRO_HW-capable NICs -- the HSR
receive/forward path sees a single skb instead of the individual
frames. Depending on the lower device, that super-skb is then either
rejected outright (for example when it exceeds the lower MTU at
egress), or forwarded without valid per-wire-frame HSR/PRP
processing: its single trailing tag/RCT cannot represent the
per-frame trailers and sequence numbers of the aggregated frames. On
memory-constrained devices, processing super-skbs in softirq context
can also pressure atomic memory allocation.
The HSR/PRP stack already disables LRO on enslaved devices for the
same reason. Extend that treatment to GRO: add netif_disable_gro()
and dev_disable_gro() mirroring netif_disable_lro()/dev_disable_lro(),
and call dev_disable_gro() from hsr_portdev_setup() so enslavement to
an HSR/PRP master automatically strips NETIF_F_GRO and NETIF_F_GRO_HW
on the lower device (recursively on its own lowers, as with LRO).
This is a setup-time default, not an immutable feature policy: a
later privileged feature override, or a lower newly attached below a
stacked slave, can re-enable GRO without re-walking the HSR
enslavement path. Patch 3 is the fail-safe for that case: a GSO skb
that nevertheless reaches the forward entry is segmented on the
plain master/interlink paths or rejected on the LAN/tagged paths, so
invalid aggregates are never forwarded as-is -- though a later
override can still cost traffic on a LAN ingress.
Fixes: f421436a591d ("net/hsr: Add support for the High-availability Seamless Redundancy protocol (HSRv0)")
Cc: stable@vger.kernel.org
Signed-off-by: Xin Xie <xiexinet@gmail.com>
---
include/linux/netdevice.h | 2 ++
net/core/dev.c | 18 ++++++++++++++++++
net/core/dev_api.c | 16 ++++++++++++++++
net/hsr/hsr_slave.c | 1 +
4 files changed, 37 insertions(+)
diff --git a/include/linux/netdevice.h b/include/linux/netdevice.h
index 9981d637f8b5..eba2c26a49ba 100644
--- a/include/linux/netdevice.h
+++ b/include/linux/netdevice.h
@@ -3434,6 +3434,8 @@ void dev_close(struct net_device *dev);
void netif_close_many(struct list_head *head, bool unlink);
void netif_disable_lro(struct net_device *dev);
void dev_disable_lro(struct net_device *dev);
+void netif_disable_gro(struct net_device *dev);
+void dev_disable_gro(struct net_device *dev);
int dev_loopback_xmit(struct net *net, struct sock *sk, struct sk_buff *newskb);
u16 dev_pick_tx_zero(struct net_device *dev, struct sk_buff *skb,
struct net_device *sb_dev);
diff --git a/net/core/dev.c b/net/core/dev.c
index 5933c5dab09e..a6cf2adc8625 100644
--- a/net/core/dev.c
+++ b/net/core/dev.c
@@ -1840,6 +1840,24 @@ void netif_disable_lro(struct net_device *dev)
}
}
+void netif_disable_gro(struct net_device *dev)
+{
+ struct net_device *lower_dev;
+ struct list_head *iter;
+
+ dev->wanted_features &= ~(NETIF_F_GRO | NETIF_F_GRO_HW);
+ netdev_update_features(dev);
+
+ if (unlikely(dev->features & (NETIF_F_GRO | NETIF_F_GRO_HW)))
+ netdev_WARN(dev, "failed to disable GRO!\n");
+
+ netdev_for_each_lower_dev(dev, lower_dev, iter) {
+ netdev_lock_ops(lower_dev);
+ netif_disable_gro(lower_dev);
+ netdev_unlock_ops(lower_dev);
+ }
+}
+
/**
* dev_disable_gro_hw - disable HW Generic Receive Offload on a device
* @dev: device
diff --git a/net/core/dev_api.c b/net/core/dev_api.c
index 437947dd08ed..02fb21629512 100644
--- a/net/core/dev_api.c
+++ b/net/core/dev_api.c
@@ -269,6 +269,22 @@ void dev_disable_lro(struct net_device *dev)
}
EXPORT_SYMBOL(dev_disable_lro);
+/**
+ * dev_disable_gro() - disable Generic Receive Offload on a device
+ * @dev: device
+ *
+ * Disable Generic Receive Offload (GRO) on a net device. Must be
+ * called under RTNL. This is needed if received packets may be
+ * forwarded to another interface.
+ */
+void dev_disable_gro(struct net_device *dev)
+{
+ netdev_lock_ops(dev);
+ netif_disable_gro(dev);
+ netdev_unlock_ops(dev);
+}
+EXPORT_SYMBOL(dev_disable_gro);
+
/**
* dev_set_promiscuity() - update promiscuity count on a device
* @dev: device
diff --git a/net/hsr/hsr_slave.c b/net/hsr/hsr_slave.c
index 01c73b4b50dd..da06b21cdf51 100644
--- a/net/hsr/hsr_slave.c
+++ b/net/hsr/hsr_slave.c
@@ -170,6 +170,7 @@ static int hsr_portdev_setup(struct hsr_priv *hsr, struct net_device *dev,
if (res)
goto fail_rx_handler;
dev_disable_lro(dev);
+ dev_disable_gro(dev);
return 0;
--
2.43.0
^ permalink raw reply related [flat|nested] 5+ messages in thread
* [PATCH net v3 2/4] net: hsr: shrink seqnr_lock to sequence counter updates
2026-07-31 9:02 [PATCH net v3 0/4] net: hsr: fix GRO/GSO super-packet handling Xin Xie
2026-07-31 9:02 ` [PATCH net v3 1/4] net: hsr: fix packet drops caused by GRO superpackets Xin Xie
@ 2026-07-31 9:02 ` Xin Xie
2026-07-31 9:02 ` [PATCH net v3 3/4] net: hsr: unfold GSO super-packets at the forward entry Xin Xie
2026-07-31 9:02 ` [PATCH net v3 4/4] selftests: net: hsr: add GRO super-packet forwarding test Xin Xie
3 siblings, 0 replies; 5+ messages in thread
From: Xin Xie @ 2026-07-31 9:02 UTC (permalink / raw)
To: netdev, linux-kselftest, linux-kernel
Cc: davem, edumazet, kuba, pabeni, horms, andrew+netdev, shuah, kees,
petr.wozniak, qingfang.deng, fmaurer, luka.gejak, bigeasy,
xiaoliang.yang_1, skhawaja, stable, Xin Xie
hsr->seqnr_lock is currently held across entire hsr_forward_skb()
calls: master TX (hsr_dev_xmit()), interlink RX (hsr_handle_frame()),
and both supervision frame builders hold it while frames are built,
classified, duplicated and forwarded on every port. The only state
that actually needs the lock is the sequence counters themselves
(hsr->sequence_nr / hsr->sup_sequence_nr).
Shrink the locking to the individual counter updates:
handle_std_frame() now takes the lock around its sequence number
allocation (replacing the lockdep assertion), the master TX and
interlink RX paths drop their outer lock, and the supervision
builders release the lock right after updating their counter instead
of holding it across frame construction and forwarding.
Ordering: with IFF_NO_QUEUE and dev->lltx, hsr_dev_xmit() is
concurrently callable, and this change removes the old
allocation-through-forward ordering guarantee there: master-TX frames
may now be emitted out of sequence-allocation order. On the current
tree this is safe because duplicate discard tracks individual
sequence numbers in sparse bitmaps (commit aae9d6b616b5 ("hsr:
Implement more robust duplicate discard for HSR") and
commit 415e6367512b ("hsr: Implement more robust duplicate discard
for PRP")) rather than requiring monotonic arrival. Sequence numbers
remain unique and monotonically allocated per counter.
This is a latency/critical-section prerequisite for unfolding GSO
super-packets at the forward entry (not a functional prerequisite):
the segmentation work should not extend the global sequence lock's
critical section. Patch 3 depends on this change; their automatic
stable selection is limited to 7.0 and newer, where sparse-bitmap
duplicate discard accepts out-of-order arrival. Older stable branches
require an adapted backport.
History of the lock being narrowed: it was introduced by
commit 06afd2c31d33 ("hsr: Synchronize sending frames to have always
incremented outgoing seq nr.") and briefly removed by
commit b3c9e65eb227 ("net: hsr: remove seqnr_lock") in net. Merge
commit 46ae4d0a4897 ("Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net")
reverted that removal because
commit 430d67bdcb04 ("net: hsr: Use the seqnr lock for frames
received via interlink port.") in net-next had already superseded it
by adding locking for the interlink RX path. All sequence counter
updates remain protected; only the forwarding work moves out of the
critical section.
Cc: <stable@vger.kernel.org> # 7.0.x
Signed-off-by: Xin Xie <xiexinet@gmail.com>
---
net/hsr/hsr_device.c | 15 ++++-----------
net/hsr/hsr_forward.c | 3 ++-
net/hsr/hsr_slave.c | 11 +----------
3 files changed, 7 insertions(+), 22 deletions(-)
diff --git a/net/hsr/hsr_device.c b/net/hsr/hsr_device.c
index 5555b71ab19b..3fd1762d8916 100644
--- a/net/hsr/hsr_device.c
+++ b/net/hsr/hsr_device.c
@@ -232,9 +232,7 @@ static netdev_tx_t hsr_dev_xmit(struct sk_buff *skb, struct net_device *dev)
skb->dev = master->dev;
skb_reset_mac_header(skb);
skb_reset_mac_len(skb);
- spin_lock_bh(&hsr->seqnr_lock);
hsr_forward_skb(skb, master);
- spin_unlock_bh(&hsr->seqnr_lock);
} else {
dev_core_stats_tx_dropped_inc(dev);
dev_kfree_skb_any(skb);
@@ -335,6 +333,7 @@ static void send_hsr_supervision_frame(struct hsr_port *port,
hsr_stag->sequence_nr = htons(hsr->sequence_nr);
hsr->sequence_nr++;
}
+ spin_unlock_bh(&hsr->seqnr_lock);
hsr_stag->tlv.HSR_TLV_type = type;
/* HSRv0 has 6 unused bytes after the MAC */
@@ -356,14 +355,10 @@ static void send_hsr_supervision_frame(struct hsr_port *port,
ether_addr_copy(hsr_sp->macaddress_A, hsr->macaddress_redbox);
}
- if (skb_put_padto(skb, ETH_ZLEN)) {
- spin_unlock_bh(&hsr->seqnr_lock);
+ if (skb_put_padto(skb, ETH_ZLEN))
return;
- }
hsr_forward_skb(skb, port);
- spin_unlock_bh(&hsr->seqnr_lock);
- return;
}
static void send_prp_supervision_frame(struct hsr_port *master,
@@ -390,6 +385,7 @@ static void send_prp_supervision_frame(struct hsr_port *master,
spin_lock_bh(&hsr->seqnr_lock);
hsr_stag->sequence_nr = htons(hsr->sup_sequence_nr);
hsr->sup_sequence_nr++;
+ spin_unlock_bh(&hsr->seqnr_lock);
hsr_stag->tlv.HSR_TLV_type = PRP_TLV_LIFE_CHECK_DD;
hsr_stag->tlv.HSR_TLV_length = sizeof(struct hsr_sup_payload);
@@ -397,13 +393,10 @@ static void send_prp_supervision_frame(struct hsr_port *master,
hsr_sp = skb_put(skb, sizeof(struct hsr_sup_payload));
ether_addr_copy(hsr_sp->macaddress_A, master->dev->dev_addr);
- if (skb_put_padto(skb, ETH_ZLEN)) {
- spin_unlock_bh(&hsr->seqnr_lock);
+ if (skb_put_padto(skb, ETH_ZLEN))
return;
- }
hsr_forward_skb(skb, master);
- spin_unlock_bh(&hsr->seqnr_lock);
}
/* Announce (supervision frame) timer function
diff --git a/net/hsr/hsr_forward.c b/net/hsr/hsr_forward.c
index 0774981a65c1..8e4158a9b57c 100644
--- a/net/hsr/hsr_forward.c
+++ b/net/hsr/hsr_forward.c
@@ -621,9 +621,10 @@ static void handle_std_frame(struct sk_buff *skb,
if (port->type == HSR_PT_MASTER ||
port->type == HSR_PT_INTERLINK) {
/* Sequence nr for the master/interlink node */
- lockdep_assert_held(&hsr->seqnr_lock);
+ spin_lock_bh(&hsr->seqnr_lock);
frame->sequence_nr = hsr->sequence_nr;
hsr->sequence_nr++;
+ spin_unlock_bh(&hsr->seqnr_lock);
}
}
diff --git a/net/hsr/hsr_slave.c b/net/hsr/hsr_slave.c
index da06b21cdf51..0ca55d9323c5 100644
--- a/net/hsr/hsr_slave.c
+++ b/net/hsr/hsr_slave.c
@@ -73,16 +73,7 @@ static rx_handler_result_t hsr_handle_frame(struct sk_buff **pskb)
}
skb_reset_mac_len(skb);
- /* Only the frames received over the interlink port will assign a
- * sequence number and require synchronisation vs other sender.
- */
- if (port->type == HSR_PT_INTERLINK) {
- spin_lock_bh(&hsr->seqnr_lock);
- hsr_forward_skb(skb, port);
- spin_unlock_bh(&hsr->seqnr_lock);
- } else {
- hsr_forward_skb(skb, port);
- }
+ hsr_forward_skb(skb, port);
finish_consume:
return RX_HANDLER_CONSUMED;
--
2.43.0
^ permalink raw reply related [flat|nested] 5+ messages in thread
* [PATCH net v3 3/4] net: hsr: unfold GSO super-packets at the forward entry
2026-07-31 9:02 [PATCH net v3 0/4] net: hsr: fix GRO/GSO super-packet handling Xin Xie
2026-07-31 9:02 ` [PATCH net v3 1/4] net: hsr: fix packet drops caused by GRO superpackets Xin Xie
2026-07-31 9:02 ` [PATCH net v3 2/4] net: hsr: shrink seqnr_lock to sequence counter updates Xin Xie
@ 2026-07-31 9:02 ` Xin Xie
2026-07-31 9:02 ` [PATCH net v3 4/4] selftests: net: hsr: add GRO super-packet forwarding test Xin Xie
3 siblings, 0 replies; 5+ messages in thread
From: Xin Xie @ 2026-07-31 9:02 UTC (permalink / raw)
To: netdev, linux-kselftest, linux-kernel
Cc: davem, edumazet, kuba, pabeni, horms, andrew+netdev, shuah, kees,
petr.wozniak, qingfang.deng, fmaurer, luka.gejak, bigeasy,
xiaoliang.yang_1, skhawaja, stable, Xin Xie
HSR/PRP forward frames one by one: each wire frame gets its own tag
and sequence number, and duplicate discard is per frame. A GSO
super-packet reaching hsr_forward_skb() breaks that per-frame
semantics: it would be tagged and forwarded as a single frame.
Unfold such super-packets at the forward entry with the top-level GSO
dispatch: __skb_gso_segment() initializes SKB_GSO_CB() and performs
the L2->L3->L4 protocol dispatch (calling the low-level skb_segment()
helper directly is not allowed here -- it reads SKB_GSO_CB(skb) state
that only __skb_gso_segment() sets up). features = 0 requests full
software segmentation; tx_path is selected by ingress port (master =
locally generated TX, interlink = RX) to get the right checksum
semantics. Each segment then runs through the existing per-frame
path, which is split out as hsr_forward_skb_one() so that no GSO skb
can reach it.
Segmentation is only offered for the ingress roles whose frames are
known to be plain Ethernet: the master (locally generated) and the
interlink (SAN side, untagged). A super-packet received from a LAN
slave may carry per-frame HSR tags or PRP RCT trailers that software
segmentation cannot recover, and an already-tagged HSR/PRP
super-packet violates per-frame wire semantics; both are rejected by
ingress-port policy. (ETH_P_PRP identifies supervision traffic only;
a PRP data frame keeps its payload EtherType, so RCT carriage cannot
be tested by protocol.)
Also drop NETIF_F_GSO_MASK from the HSR master's hw_features so
locally generated traffic is segmented before reaching the forward
path whenever possible.
Patch 2 (seqnr_lock shrink) is a latency/critical-section
prerequisite for this change; their automatic stable selection is
limited to 7.0 and newer. Older stable branches require an adapted
backport.
Fixes: f421436a591d ("net/hsr: Add support for the High-availability Seamless Redundancy protocol (HSRv0)")
Cc: <stable@vger.kernel.org> # 7.0.x
Signed-off-by: Xin Xie <xiexinet@gmail.com>
---
net/hsr/hsr_device.c | 2 +-
net/hsr/hsr_forward.c | 50 ++++++++++++++++++++++++++++++++++++++++++-
2 files changed, 50 insertions(+), 2 deletions(-)
diff --git a/net/hsr/hsr_device.c b/net/hsr/hsr_device.c
index 3fd1762d8916..248cbb142e21 100644
--- a/net/hsr/hsr_device.c
+++ b/net/hsr/hsr_device.c
@@ -652,7 +652,7 @@ void hsr_dev_setup(struct net_device *dev)
dev->needs_free_netdev = true;
dev->hw_features = NETIF_F_SG | NETIF_F_FRAGLIST | NETIF_F_HIGHDMA |
- NETIF_F_GSO_MASK | NETIF_F_HW_CSUM |
+ NETIF_F_HW_CSUM |
NETIF_F_HW_VLAN_CTAG_TX |
NETIF_F_HW_VLAN_CTAG_FILTER;
diff --git a/net/hsr/hsr_forward.c b/net/hsr/hsr_forward.c
index 8e4158a9b57c..3fcdbac49c59 100644
--- a/net/hsr/hsr_forward.c
+++ b/net/hsr/hsr_forward.c
@@ -12,6 +12,7 @@
#include <linux/skbuff.h>
#include <linux/etherdevice.h>
#include <linux/if_vlan.h>
+#include <net/gso.h>
#include "hsr_main.h"
#include "hsr_framereg.h"
@@ -732,7 +733,7 @@ static int fill_frame_info(struct hsr_frame_info *frame,
}
/* Must be called holding rcu read lock (because of the port parameter) */
-void hsr_forward_skb(struct sk_buff *skb, struct hsr_port *port)
+static void hsr_forward_skb_one(struct sk_buff *skb, struct hsr_port *port)
{
struct hsr_frame_info frame;
@@ -761,3 +762,50 @@ void hsr_forward_skb(struct sk_buff *skb, struct hsr_port *port)
port->dev->stats.tx_dropped++;
kfree_skb(skb);
}
+
+/* GSO fan-out funnel: unfold super-packets before per-frame processing so
+ * each wire frame gets its own HSR/PRP tag and sequence number.
+ */
+void hsr_forward_skb(struct sk_buff *skb, struct hsr_port *port)
+{
+ struct sk_buff *segs, *next;
+
+ if (likely(!skb_is_gso(skb))) {
+ hsr_forward_skb_one(skb, port);
+ return;
+ }
+
+ /* Unfold only plain-Ethernet GSO super-packets: locally generated
+ * on the master, or arriving untagged from the SAN side on the
+ * interlink. A super-packet from a LAN slave may carry per-frame
+ * HSR tags / PRP RCT trailers that software segmentation cannot
+ * recover; an already-tagged HSR/PRP super-packet violates
+ * per-frame wire semantics. Drop both.
+ */
+ if (port->type != HSR_PT_MASTER && port->type != HSR_PT_INTERLINK)
+ goto drop_gso;
+ if (skb->protocol == htons(ETH_P_HSR) ||
+ skb->protocol == htons(ETH_P_PRP))
+ goto drop_gso;
+
+ /* features = 0: request full software segmentation. tx_path is true
+ * only for locally generated traffic on the master; ingress from
+ * the interlink follows RX checksum semantics.
+ */
+ segs = __skb_gso_segment(skb, 0, port->type == HSR_PT_MASTER);
+ if (IS_ERR(segs) || unlikely(!segs))
+ goto drop_gso;
+
+ consume_skb(skb);
+ while (segs) {
+ next = segs->next;
+ segs->next = NULL;
+ hsr_forward_skb_one(segs, port);
+ segs = next;
+ }
+ return;
+
+drop_gso:
+ port->dev->stats.tx_dropped++;
+ kfree_skb(skb);
+}
--
2.43.0
^ permalink raw reply related [flat|nested] 5+ messages in thread
* [PATCH net v3 4/4] selftests: net: hsr: add GRO super-packet forwarding test
2026-07-31 9:02 [PATCH net v3 0/4] net: hsr: fix GRO/GSO super-packet handling Xin Xie
` (2 preceding siblings ...)
2026-07-31 9:02 ` [PATCH net v3 3/4] net: hsr: unfold GSO super-packets at the forward entry Xin Xie
@ 2026-07-31 9:02 ` Xin Xie
3 siblings, 0 replies; 5+ messages in thread
From: Xin Xie @ 2026-07-31 9:02 UTC (permalink / raw)
To: netdev, linux-kselftest, linux-kernel
Cc: davem, edumazet, kuba, pabeni, horms, andrew+netdev, shuah, kees,
petr.wozniak, qingfang.deng, fmaurer, luka.gejak, bigeasy,
xiaoliang.yang_1, skhawaja, stable, Xin Xie
Add a test exercising the HSR forward path with GSO super-packets:
a TSO-enabled SAN behind the interlink streams TCP through an HSR
DUT to a peer node. The test verifies that:
* enslaved devices have GRO and HW-GRO disabled automatically,
* the HSR master does not advertise GSO/TSO features (including
tx-tcp6/udp/gso-list, to catch future hw_features leaks),
* super-packets really leave the SAN (TX average frame size above a
fixed threshold) while bulk output on the DUT's LAN legs stays at
per-frame size — aggregate counter evidence that GSO enters the
forward path and is unfolded at the forward entry. Zero TCP
retransmits is reported as a secondary health signal.
The one-shot iperf3 server lives in a private mktemp -d workdir
(mode 0700): its exact PID is retained only after numeric, alive,
comm==iperf3 and netns-membership checks, its real exit status is
propagated through an rc file, and cleanup kills by exact PID with a
bounded wrapper reap plus a namespace-scoped iperf3 sweep. Server
startup failure, client failure and a never-published PID are all
bounded exits with no process or directory leaks. Environments whose
iproute2 lacks the HSR interlink syntax are skipped with ksft_skip.
Without this series the feature checks fail, and on drivers that hand
GRO super-packets to the HSR receive path the stream degrades or
stalls.
Signed-off-by: Xin Xie <xiexinet@gmail.com>
---
tools/testing/selftests/net/hsr/Makefile | 1 +
.../selftests/net/hsr/hsr_gro_superpacket.sh | 462 ++++++++++++++++++
2 files changed, 463 insertions(+)
create mode 100755 tools/testing/selftests/net/hsr/hsr_gro_superpacket.sh
diff --git a/tools/testing/selftests/net/hsr/Makefile b/tools/testing/selftests/net/hsr/Makefile
index 31fb9326cf53..0d105476e7c5 100644
--- a/tools/testing/selftests/net/hsr/Makefile
+++ b/tools/testing/selftests/net/hsr/Makefile
@@ -3,6 +3,7 @@
top_srcdir = ../../../../..
TEST_PROGS := \
+ hsr_gro_superpacket.sh \
hsr_ping.sh \
hsr_redbox.sh \
link_faults.sh \
diff --git a/tools/testing/selftests/net/hsr/hsr_gro_superpacket.sh b/tools/testing/selftests/net/hsr/hsr_gro_superpacket.sh
new file mode 100755
index 000000000000..288de3a60b89
--- /dev/null
+++ b/tools/testing/selftests/net/hsr/hsr_gro_superpacket.sh
@@ -0,0 +1,462 @@
+#!/bin/bash
+# SPDX-License-Identifier: GPL-2.0
+#
+# Test HSR handling of GRO/GSO super-packets:
+#
+# 1. Enslaving a device to an HSR master disables GRO on it
+# (dev_disable_gro()).
+# 2. The HSR master does not advertise GSO/TSO features.
+# 3. A TCP stream from a TSO-enabled SAN (which therefore emits GSO
+# super-packets) is unfolded at the HSR forward entry. Evidence:
+# interface-counter deltas show super-packet-sized frames leaving
+# the SAN and per-frame-sized traffic leaving the DUT's LAN ports.
+#
+# Topology (100.64.0.0/24):
+#
+# ns_san ns_dut ns_peer
+# +-----------+ interlink +---------------+ LAN A/B +-----------+
+# | s0 [0.1] |-------------| d_il hsr0 |-----------| hsr1 [0.3]|
+# +-----------+ | d_a / d_b | | p_a / p_b |
+# +---------------+ +-----------+
+#
+# SAN traffic reaches ns_peer only through hsr0's forward path
+# (interlink RX -> LAN A/B TX), so every SAN frame is tagged and
+# forwarded by the DUT.
+
+source ./hsr_common.sh
+
+san_ip="100.64.0.1"
+peer_ip="100.64.0.3"
+
+# Aggregate counter thresholds for the stream test (bytes/packets):
+# SAN_AVG_MIN proves GSO super-packets left the SAN; LAN_AVG_MAX is a
+# guard with margin, not the protocol maximum (see do_tso_stream_test).
+SAN_AVG_MIN=2048
+LAN_AVG_MAX=1514
+
+iperf_pid=""
+server_wrapper=""
+workdir=""
+pidfile=""
+rcfile=""
+
+cleanup()
+{
+ # exact-PID kill only after RE-validating identity (guards against
+ # PID reuse between publication and cleanup)
+ if [ -n "${iperf_pid}" ] && valid_server_pid "${iperf_pid}"; then
+ kill "${iperf_pid}" 2>/dev/null
+ fi
+ iperf_pid=""
+ if [ -n "${server_wrapper}" ]; then
+ # the wrapper waits on the server; reap it with a 5s bound so a
+ # live-but-unpublished server can never hang cleanup
+ for _ in $(seq 1 50); do
+ kill -0 "${server_wrapper}" 2>/dev/null || break
+ sleep 0.1
+ done
+ kill "${server_wrapper}" 2>/dev/null
+ wait "${server_wrapper}" 2>/dev/null
+ server_wrapper=""
+ fi
+ # last resort, namespace-scoped only: TERM the iperf3 processes that
+ # actually live in the peer netns, poll for bounded exit, then
+ # SIGKILL any survivor before touching the namespace name. A blind
+ # pkill would scan the host PID space and hit unrelated tests.
+ local _p _still
+ for _p in $(ip netns pids "$ns_peer" 2>/dev/null); do
+ if is_iperf3_pid "$_p"; then
+ kill "$_p" 2>/dev/null
+ fi
+ done
+ for _ in $(seq 1 50); do
+ _still=0
+ for _p in $(ip netns pids "$ns_peer" 2>/dev/null); do
+ if is_iperf3_pid "$_p"; then
+ _still=1
+ break
+ fi
+ done
+ [ "$_still" -eq 0 ] && break
+ sleep 0.1
+ done
+ for _p in $(ip netns pids "$ns_peer" 2>/dev/null); do
+ if is_iperf3_pid "$_p"; then
+ kill -9 "$_p" 2>/dev/null
+ fi
+ done
+ # remove only the known non-empty private directory
+ if [ -n "${workdir}" ] && [ -d "${workdir}" ]; then
+ rm -rf "${workdir}"
+ fi
+ workdir=""
+ pidfile=""
+ rcfile=""
+ cleanup_all_ns
+}
+
+trap cleanup EXIT
+
+check_tool()
+{
+ if ! command -v "$1" > /dev/null 2>&1; then
+ echo "SKIP: Could not run test without $1"
+ exit $ksft_skip
+ fi
+}
+
+nsx()
+{
+ ip netns exec "$1" bash -c "$2"
+}
+
+is_iperf3_pid()
+{
+ [ "$(cat /proc/"$1"/comm 2>/dev/null)" = "iperf3" ]
+}
+
+# Decimal-counter validation for the snapshot blocks: every value must
+# be a plain decimal number. A parse failure in read_tx_counters yields
+# empty/garbled fields, which this check turns into an immediate FAIL.
+valid_decimals()
+{
+ local v
+
+ for v in "$@"; do
+ [[ "$v" =~ ^[0-9]+$ ]] || return 1
+ done
+ return 0
+}
+
+setup_topo()
+{
+ setup_ns ns_dut ns_san ns_peer || exit $?
+
+ ip link add d_a netns "$ns_dut" type veth peer name p_a netns "$ns_peer"
+ ip link add d_b netns "$ns_dut" type veth peer name p_b netns "$ns_peer"
+ ip link add d_il netns "$ns_dut" type veth peer name s0 netns "$ns_san"
+
+ # HSR tags add 6 bytes per frame; give the LAN legs headroom.
+ for iface in d_a d_b; do
+ nsx "$ns_dut" "ip link set $iface mtu 1600; \
+ ip link set $iface up"
+ done
+ for iface in p_a p_b; do
+ nsx "$ns_peer" "ip link set $iface mtu 1600; \
+ ip link set $iface up"
+ done
+
+ nsx "$ns_dut" "ip link set d_il up"
+ nsx "$ns_san" "ip link set s0 up; ip addr add $san_ip/24 dev s0"
+
+ nsx "$ns_dut" "ip link add hsr0 type hsr \
+ slave1 d_a slave2 d_b interlink d_il proto 0; \
+ ip link set hsr0 up"
+ nsx "$ns_peer" "ip link add hsr1 type hsr \
+ slave1 p_a slave2 p_b proto 0; \
+ ip link set hsr1 up; ip addr add $peer_ip/24 dev hsr1"
+
+ # Let the nodes see each other's supervision frames.
+ sleep 2
+}
+
+check_feature()
+{
+ local ns="$1"
+ local iface="$2"
+ local feature="$3"
+ local want="$4"
+
+ if nsx "$ns" "ethtool -k $iface" | grep -q "^$feature: $want"; then
+ echo "INFO: $ns/$iface $feature is $want [ OK ]"
+ else
+ echo "FAIL: $ns/$iface $feature is not $want" 1>&2
+ ret=1
+ fi
+}
+
+# Off-or-absent variant: fails only when the feature is present AND on,
+# so devices that simply do not list the feature do not fail it.
+check_feature_not_on()
+{
+ local ns="$1"
+ local iface="$2"
+ local feature="$3"
+
+ if nsx "$ns" "ethtool -k $iface" | grep -q "^$feature: on"; then
+ echo "FAIL: $ns/$iface $feature is on" 1>&2
+ ret=1
+ else
+ echo "INFO: $ns/$iface $feature not on [ OK ]"
+ fi
+}
+
+do_gro_feature_checks()
+{
+ echo "INFO: Checking that enslavement disabled GRO."
+ check_feature "$ns_dut" d_a generic-receive-offload off
+ check_feature "$ns_dut" d_b generic-receive-offload off
+ check_feature "$ns_dut" d_il generic-receive-offload off
+ stop_if_error "GRO not disabled on enslaved devices."
+
+ echo "INFO: Checking that enslavement disabled HW-GRO."
+ check_feature "$ns_dut" d_a rx-gro-hw off
+ check_feature "$ns_dut" d_b rx-gro-hw off
+ check_feature "$ns_dut" d_il rx-gro-hw off
+ stop_if_error "HW-GRO not disabled on enslaved devices."
+
+ echo "INFO: Checking that the HSR master does not advertise GSO/TSO."
+ check_feature "$ns_dut" hsr0 generic-segmentation-offload off
+ check_feature "$ns_dut" hsr0 tcp-segmentation-offload off
+ check_feature_not_on "$ns_dut" hsr0 tx-tcp6-segmentation
+ check_feature_not_on "$ns_dut" hsr0 tx-udp-segmentation
+ check_feature_not_on "$ns_dut" hsr0 tx-gso-list
+ stop_if_error "HSR master still advertises GSO-family features."
+}
+
+alloc_workdir()
+{
+ # Allocated only here, long after the initial topology cleanup, so
+ # cleanup() at setup_topo() time can never remove it. mktemp failure
+ # is a hard test failure.
+ workdir=$(mktemp -d /tmp/hsr_gro_test.XXXXXX) || {
+ echo "FAIL: mktemp -d failed" 1>&2
+ exit 1
+ }
+ chmod 700 "${workdir}"
+ pidfile="${workdir}/iperf.pid"
+ rcfile="${workdir}/iperf.rc"
+}
+
+# Numeric, alive, comm == iperf3, and really owned by the peer netns.
+valid_server_pid()
+{
+ local p="$1"
+
+ [[ "$p" =~ ^[0-9]+$ ]] || return 1
+ kill -0 "$p" 2>/dev/null || return 1
+ [ "$(cat /proc/"$p"/comm 2>/dev/null)" = "iperf3" ] || return 1
+ ip netns pids "$ns_peer" 2>/dev/null | grep -qx "$p"
+}
+
+start_iperf_server()
+{
+ local candidate_pid
+
+ # One-shot server, no -D: the wrapper records its exact PID and its
+ # real exit status (netns shares the PID namespace and the host fs).
+ alloc_workdir
+ ( nsx "$ns_peer" "iperf3 -s -1 > /dev/null 2>&1 & \
+ echo \$! > ${pidfile}; \
+ wait \$!; \
+ echo \$? > ${rcfile}" ) &
+ server_wrapper=$!
+ # the wrapper writes the pidfile asynchronously; wait for it to
+ # appear instead of racing the read
+ for _ in $(seq 1 50); do
+ [ -s "${pidfile}" ] && break
+ sleep 0.1
+ done
+ if [ ! -s "${pidfile}" ]; then
+ echo "FAIL: iperf3 server did not publish a pid" \
+ "(no pidfile)" 1>&2
+ ret=1
+ return 1
+ fi
+ candidate_pid=$(<"${pidfile}")
+ if ! valid_server_pid "${candidate_pid}"; then
+ echo "FAIL: iperf3 server pid '${candidate_pid}'" \
+ "failed validation" 1>&2
+ ret=1
+ return 1
+ fi
+ # publish only after full validation
+ iperf_pid="${candidate_pid}"
+ sleep 1
+ return 0
+}
+
+# Print "<bytes> <packets>" for exactly one TX record of ns/dev; anything
+# else (missing, duplicated, non-numeric) is a hard FAIL.
+read_tx_counters()
+{
+ local ns="$1" dev="$2"
+ local out cnt
+
+ out=$(nsx "$ns" "ip -s link show $dev" | \
+ awk '/^ +TX:/{getline; print $1, $2}')
+ cnt=$(echo "$out" | grep -c '^[0-9]* [0-9]*$')
+ if [ "$cnt" -ne 1 ]; then
+ echo "FAIL: cannot parse TX counters of $ns/$dev" \
+ "(records=$cnt)" 1>&2
+ return 1
+ fi
+ echo "$out"
+ return 0
+}
+
+eval_counter_delta()
+{
+ local name="$1" b0="$2" p0="$3" b1="$4" p1="$5" op="$6" limit="$7"
+ local bd pd
+
+ if ! [[ "$b0" =~ ^[0-9]+$ && "$b1" =~ ^[0-9]+$ && \
+ "$p0" =~ ^[0-9]+$ && "$p1" =~ ^[0-9]+$ ]]; then
+ echo "FAIL: non-numeric counter input for $name" 1>&2
+ ret=1
+ return 1
+ fi
+ bd=$((b1 - b0))
+ pd=$((p1 - p0))
+ if [ "$bd" -lt 0 ] || [ "$pd" -le 0 ]; then
+ echo "FAIL: counter delta invalid for $name" \
+ "(bytes=$bd pkts=$pd)" 1>&2
+ ret=1
+ return 1
+ fi
+ if [ "$op" = "gt" ]; then
+ if [ "$bd" -le $((pd * limit)) ]; then
+ echo "FAIL: $name bytes/packets $bd/$pd <= $limit" 1>&2
+ ret=1
+ return 1
+ fi
+ else
+ if [ "$bd" -gt $((pd * limit)) ]; then
+ echo "FAIL: $name bytes/packets $bd/$pd > $limit" 1>&2
+ ret=1
+ return 1
+ fi
+ fi
+ echo "INFO: $name counter delta bytes=$bd packets=$pd" \
+ "(op $op limit $limit) [ OK ]"
+ return 0
+}
+
+do_tso_stream_test()
+{
+ local out sender_retr server_rc
+ local san_b0 san_p0 san_b1 san_p1
+ local a_b0 a_p0 a_b1 a_p1 b_b0 b_p0 b_b1 b_p1
+
+ echo "INFO: Enabling TSO/GSO on the SAN interface."
+ nsx "$ns_san" "ethtool -K s0 tso on gso on"
+ check_feature "$ns_san" s0 tcp-segmentation-offload on
+ stop_if_error "Could not enable TSO on the SAN interface."
+
+ echo "INFO: Running 10s TCP stream SAN -> peer through the HSR DUT."
+ start_iperf_server || return
+
+ # Counter snapshots around the stream window. The SAN-side average
+ # must exceed SAN_AVG_MIN (aggregate proof that GSO super-packets
+ # really left the SAN); each DUT LAN leg must stay under LAN_AVG_MAX
+ # (aggregate proof that bulk output was segmented per-frame). These
+ # are aggregate discriminators, not a per-frame maximum proof.
+ san_b0=0; san_p0=0; a_b0=0; a_p0=0; b_b0=0; b_p0=0
+ read -r san_b0 san_p0 <<EOF
+$(read_tx_counters "$ns_san" s0)
+EOF
+ read -r a_b0 a_p0 <<EOF
+$(read_tx_counters "$ns_dut" d_a)
+EOF
+ read -r b_b0 b_p0 <<EOF
+$(read_tx_counters "$ns_dut" d_b)
+EOF
+ if ! valid_decimals "$san_b0" "$san_p0" "$a_b0" "$a_p0" \
+ "$b_b0" "$b_p0"; then
+ echo "FAIL: baseline TX counter snapshot invalid" 1>&2
+ ret=1
+ return 1
+ fi
+
+ # rate-capped: the PRIMARY discriminator is the counter inequality
+ # above, not max throughput; retransmits are informational only.
+ # Uncapped runs flap at VM/CI edge rates without indicating a
+ # functional problem.
+ if ! out=$(nsx "$ns_san" "timeout 60 iperf3 -c $peer_ip -M 1446 \
+ -b 2G -t 10" 2>&1); then
+ echo "FAIL: iperf3 client failed:" 1>&2
+ echo "$out" 1>&2
+ ret=1
+ return
+ fi
+
+ read -r san_b1 san_p1 <<EOF
+$(read_tx_counters "$ns_san" s0)
+EOF
+ read -r a_b1 a_p1 <<EOF
+$(read_tx_counters "$ns_dut" d_a)
+EOF
+ read -r b_b1 b_p1 <<EOF
+$(read_tx_counters "$ns_dut" d_b)
+EOF
+ if ! valid_decimals "$san_b1" "$san_p1" "$a_b1" "$a_p1" \
+ "$b_b1" "$b_p1"; then
+ echo "FAIL: final TX counter snapshot invalid" 1>&2
+ ret=1
+ return 1
+ fi
+
+ eval_counter_delta "SAN s0 TX" "$san_b0" "$san_p0" "$san_b1" "$san_p1" \
+ gt "$SAN_AVG_MIN"
+ eval_counter_delta "DUT d_a TX" "$a_b0" "$a_p0" "$a_b1" "$a_p1" \
+ le "$LAN_AVG_MAX"
+ eval_counter_delta "DUT d_b TX" "$b_b0" "$b_p0" "$b_b1" "$b_p1" \
+ le "$LAN_AVG_MAX"
+ [ "${ret:-0}" -eq 0 ] || return
+
+ # success path: the one-shot server exits by itself; reap the
+ # wrapper, then REQUIRE the rcfile with the server's real status
+ wait "${server_wrapper}"
+ server_wrapper=""
+ if [ ! -s "${rcfile}" ]; then
+ echo "FAIL: iperf3 server status file missing (${rcfile})" 1>&2
+ ret=1
+ return
+ fi
+ server_rc=$(cat "${rcfile}")
+ if ! [[ "$server_rc" =~ ^[0-9]+$ ]] || [ "$server_rc" -ne 0 ]; then
+ echo "FAIL: iperf3 server exited with rc='${server_rc}'" 1>&2
+ ret=1
+ return
+ fi
+ iperf_pid=""
+
+ # secondary health signal only: anchored, single-match, numeric —
+ # any parse anomaly is a loud FAIL, but the value itself no longer
+ # gates (the counter inequalities above are the primary evidence).
+ sender_retr=$(echo "$out" | awk '/sec .* sender$/ {print $(NF-1)}')
+ if [ "$(echo "$sender_retr" | grep -Ec '^[0-9]+$')" -ne 1 ]; then
+ echo "FAIL: cannot parse sender retransmits reliably" 1>&2
+ echo "$out" 1>&2
+ ret=1
+ return
+ fi
+ echo "INFO: TCP stream done;" \
+ "sender retransmits=$sender_retr (secondary signal)"
+ echo "$out" | grep -E "sender|receiver"
+}
+
+check_prerequisites
+check_tool ethtool
+check_tool iperf3
+check_tool timeout
+
+# iproute2 must know the HSR interlink syntax.
+if ! ip link help hsr 2>&1 | grep -qi interlink; then
+ echo "SKIP: iproute2 has no HSR interlink support"
+ exit $ksft_skip
+fi
+
+setup_topo
+
+echo "INFO: Initial validation ping (SAN -> peer through the DUT)."
+do_ping "$ns_san" "$peer_ip"
+stop_if_error "Initial validation failed."
+
+do_gro_feature_checks
+do_tso_stream_test
+stop_if_error "GSO super-packet stream test failed."
+
+echo "INFO: All good."
+cleanup
+exit $ret
--
2.43.0
^ permalink raw reply related [flat|nested] 5+ messages in thread
end of thread, other threads:[~2026-07-31 9:02 UTC | newest]
Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-31 9:02 [PATCH net v3 0/4] net: hsr: fix GRO/GSO super-packet handling Xin Xie
2026-07-31 9:02 ` [PATCH net v3 1/4] net: hsr: fix packet drops caused by GRO superpackets Xin Xie
2026-07-31 9:02 ` [PATCH net v3 2/4] net: hsr: shrink seqnr_lock to sequence counter updates Xin Xie
2026-07-31 9:02 ` [PATCH net v3 3/4] net: hsr: unfold GSO super-packets at the forward entry Xin Xie
2026-07-31 9:02 ` [PATCH net v3 4/4] selftests: net: hsr: add GRO super-packet forwarding test Xin Xie
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox