From: Eric Dumazet <edumazet@google.com>
To: "David S . Miller" <davem@davemloft.net>,
Jakub Kicinski <kuba@kernel.org>,
Paolo Abeni <pabeni@redhat.com>
Cc: Simon Horman <horms@kernel.org>,
Kuniyuki Iwashima <kuniyu@google.com>,
netdev@vger.kernel.org, eric.dumazet@gmail.com,
William Tu <u9012063@gmail.com>,
Eric Dumazet <edumazet@google.com>,
stable@vger.kernel.org
Subject: [PATCH net v3 4/5] ip_gre: recompute erspan header lengths after a change
Date: Wed, 23 Sep 2026 03:52:16 +0000 [thread overview]
Message-ID: <20260923035217.179102-5-edumazet@google.com> (raw)
In-Reply-To: <20260923035217.179102-1-edumazet@google.com>
erspan_tunnel_init() is the only place computing tunnel->tun_hlen and
tunnel->hlen, but erspan_changelink() can change both: tunnel->erspan_ver
selects a 4 or 8 byte GRE header and feeds erspan_hdr_len(), while
ip_tunnel_encap_setup() recomputes tunnel->hlen without the ERSPAN part.
dev->needed_headroom is not refreshed either, since ip_tunnel_update()
only rebinds when the link or the fwmark changes.
erspan_xmit() then pushes an ERSPAN header sized from the new
tunnel->erspan_ver, while __gre_xmit() lays the GRE header out from the
stale tunnel->tun_hlen. After a version 0 -> 2 change, tun_hlen is still
4 and gre_build_header() writes the sequence number at
greh + tun_hlen - 4, that is over greh->flags and greh->protocol. The
MTU keeps the value derived from the old header length.
Also reject non-zero IFLA_GRE_OFLAGS/IFLA_GRE_IFLAGS when erspan_ver is 0
or IFLA_GRE_COLLECT_METADATA is set, and ensure IP_TUNNEL_SEQ_BIT in
erspan_xmit() matches tunnel->erspan_ver.
There is no memory safety issue: dev->needed_headroom is at least
tunnel->hlen + sizeof(struct iphdr), and erspan_xmit() pushes at most
12 + 8 bytes before ip_tunnel_xmit() takes over and cows again.
Move the computation into erspan_set_hlen() and add
erspan_link_update(), refreshing the lengths as the previous patch does
for plain GRE. Commit gparms alongside i_flags/o_flags after
ip_tunnel_changelink() succeeds, and run erspan_link_update() at the end
of erspan_changelink(), including on the ip_tunnel_changelink() error
path, as ipgre_changelink() does.
Fixes: f551c91de262 ("net: erspan: introduce erspan v2 for ip_gre")
Cc: stable@vger.kernel.org
Signed-off-by: Eric Dumazet <edumazet@google.com>
---
net/ipv4/ip_gre.c | 81 +++++++++++++++++++++++++++++++++++++----------
1 file changed, 64 insertions(+), 17 deletions(-)
diff --git a/net/ipv4/ip_gre.c b/net/ipv4/ip_gre.c
index 27b3b4c584b1e1b4f1c9c9f42b5585b28101ece0..7385d66a94bf49c84bc674ded51ed3f9f5352e28 100644
--- a/net/ipv4/ip_gre.c
+++ b/net/ipv4/ip_gre.c
@@ -733,7 +733,6 @@ static netdev_tx_t erspan_xmit(struct sk_buff *skb,
/* Push ERSPAN header */
if (tunnel->erspan_ver == 0) {
proto = htons(ETH_P_ERSPAN);
- __clear_bit(IP_TUNNEL_SEQ_BIT, flags);
} else if (tunnel->erspan_ver == 1) {
erspan_build_header(skb, ntohl(tunnel->parms.o_key),
tunnel->index,
@@ -748,6 +747,7 @@ static netdev_tx_t erspan_xmit(struct sk_buff *skb,
goto free_skb;
}
+ __assign_bit(IP_TUNNEL_SEQ_BIT, flags, tunnel->erspan_ver != 0);
__clear_bit(IP_TUNNEL_KEY_BIT, flags);
__gre_xmit(skb, dev, &tunnel->parms.iph, proto, flags);
return NETDEV_TX_OK;
@@ -1169,17 +1169,18 @@ static int erspan_validate(struct nlattr *tb[], struct nlattr *data[],
if (ret)
return ret;
- if (data[IFLA_GRE_ERSPAN_VER] &&
- nla_get_u8(data[IFLA_GRE_ERSPAN_VER]) == 0)
- return 0;
-
- /* ERSPAN type II/III should only have GRE sequence and key flag */
if (data[IFLA_GRE_OFLAGS])
flags |= nla_get_be16(data[IFLA_GRE_OFLAGS]);
if (data[IFLA_GRE_IFLAGS])
flags |= nla_get_be16(data[IFLA_GRE_IFLAGS]);
- if (!data[IFLA_GRE_COLLECT_METADATA] &&
- flags != (GRE_SEQ | GRE_KEY))
+
+ if ((data[IFLA_GRE_ERSPAN_VER] &&
+ nla_get_u8(data[IFLA_GRE_ERSPAN_VER]) == 0) ||
+ data[IFLA_GRE_COLLECT_METADATA])
+ return flags ? -EINVAL : 0;
+
+ /* ERSPAN type II/III should only have GRE sequence and key flag */
+ if (flags != (GRE_SEQ | GRE_KEY))
return -EINVAL;
/* ERSPAN Session ID only has 10-bit. Since we reuse
@@ -1317,7 +1318,11 @@ static int erspan_netlink_parms(struct net_device *dev,
return -EINVAL;
}
- if (gparms->erspan_ver == 1) {
+ if (gparms->erspan_ver == 0) {
+ if (!ip_tunnel_flags_empty(parms->i_flags) ||
+ !ip_tunnel_flags_empty(parms->o_flags))
+ return -EINVAL;
+ } else if (gparms->erspan_ver == 1) {
if (data[IFLA_GRE_ERSPAN_INDEX]) {
gparms->index = nla_get_u32(data[IFLA_GRE_ERSPAN_INDEX]);
if (gparms->index & ~INDEX_MASK)
@@ -1394,18 +1399,43 @@ static const struct net_device_ops gre_tap_netdev_ops = {
.ndo_fill_metadata_dst = gre_fill_metadata_dst,
};
+static void erspan_set_hlen(struct ip_tunnel *tunnel)
+{
+ /* Version 0 uses a 4-byte GRE header, other versions use 8 bytes. */
+ tunnel->tun_hlen = tunnel->erspan_ver == 0 ? 4 : 8;
+
+ tunnel->hlen = tunnel->tun_hlen + tunnel->encap_hlen +
+ erspan_hdr_len(tunnel->erspan_ver);
+}
+
+/* Both tunnel->erspan_ver and tunnel->encap_hlen can be changed from
+ * erspan_changelink(), and both feed tunnel->hlen. Recompute it, then let
+ * ip_tunnel_bind_dev() derive the device lengths from it.
+ *
+ * As in ipgre_link_update(), @old_hlen only tells whether the MTU became
+ * stale and must be sampled before ip_tunnel_encap_setup(), which
+ * recomputes tunnel->hlen without the ERSPAN part.
+ */
+static void erspan_link_update(struct net_device *dev, bool set_mtu,
+ int old_hlen)
+{
+ struct ip_tunnel *tunnel = netdev_priv(dev);
+
+ erspan_set_hlen(tunnel);
+
+ /* Only reset a MTU that the header length just invalidated, so that
+ * a MTU configured by the user survives an unrelated change.
+ */
+ ip_tunnel_refresh_lengths(dev, set_mtu && tunnel->hlen != old_hlen);
+}
+
static int erspan_tunnel_init(struct net_device *dev)
{
struct ip_tunnel *tunnel = netdev_priv(dev);
- if (tunnel->erspan_ver == 0)
- tunnel->tun_hlen = 4; /* 4-byte GRE hdr. */
- else
- tunnel->tun_hlen = 8; /* 8-byte GRE hdr. */
+ erspan_set_hlen(tunnel);
tunnel->parms.iph.protocol = IPPROTO_GRE;
- tunnel->hlen = tunnel->tun_hlen + tunnel->encap_hlen +
- erspan_hdr_len(tunnel->erspan_ver);
dev->features |= GRE_FEATURES;
dev->hw_features |= GRE_FEATURES;
@@ -1562,6 +1592,8 @@ static int erspan_changelink(struct net_device *dev, struct nlattr *tb[],
struct ip_tunnel *t = netdev_priv(dev);
struct ip_tunnel_parm_kern p;
struct ip_gre_parm gparms;
+ int old_hlen = t->hlen;
+ bool link_changed;
int err;
if (!rtnl_dev_link_net_capable(dev, t->net))
@@ -1575,15 +1607,30 @@ static int erspan_changelink(struct net_device *dev, struct nlattr *tb[],
if (err)
return err;
+ link_changed = t->parms.link != p.link || t->fwmark != gparms.fwmark;
+
err = ip_tunnel_changelink(dev, tb, &p, gparms.fwmark);
if (err < 0)
- return err;
+ goto link_update;
+
+ if (link_changed)
+ old_hlen = t->hlen;
ipgre_commit_parms(t, &gparms);
ip_tunnel_flags_copy(t->parms.i_flags, p.i_flags);
ip_tunnel_flags_copy(t->parms.o_flags, p.o_flags);
- return 0;
+link_update:
+ /* ipgre_newlink_encap_setup() has published a new encapsulation
+ * without the ERSPAN header length even if ip_tunnel_changelink()
+ * failed, so the lengths must be refreshed on that error path too.
+ *
+ * As in ipgre_changelink(), IFLA_MTU must not hold the MTU back if we
+ * return an error, because do_setlink() will not apply it then.
+ */
+ erspan_link_update(dev, err || !tb[IFLA_MTU], old_hlen);
+
+ return err;
}
static size_t ipgre_get_size(const struct net_device *dev)
--
2.55.0.1082.g2b9226bbc0-goog
next prev parent reply other threads:[~2026-09-23 3:52 UTC|newest]
Thread overview: 14+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-23 3:52 [PATCH net v3 0/5] ip_tunnel, ip_gre: fix header length and validation bugs Eric Dumazet
2026-09-23 3:52 ` [PATCH net v3 1/5] ip_tunnel: do not clear the active encap before validating the new one Eric Dumazet
2026-09-25 6:52 ` netdev-bot+sashiko
2026-09-25 9:27 ` Eric Dumazet
2026-09-23 3:52 ` [PATCH net v3 2/5] ip_gre: validate netlink attributes before changing the tunnel Eric Dumazet
2026-09-25 6:52 ` netdev-bot+sashiko
2026-09-23 3:52 ` [PATCH net v3 3/5] ip_gre: compute tunnel lengths absolutely instead of by delta Eric Dumazet
2026-09-25 6:53 ` netdev-bot+sashiko
2026-09-25 9:28 ` Eric Dumazet
2026-09-23 3:52 ` Eric Dumazet [this message]
2026-09-25 6:53 ` [PATCH net v3 4/5] ip_gre: recompute erspan header lengths after a change netdev-bot+sashiko
2026-09-25 9:31 ` Eric Dumazet
2026-09-23 3:52 ` [PATCH net v3 5/5] gre: do not read inner frame as erspan metadata in collect_md mode Eric Dumazet
2026-09-25 6:53 ` netdev-bot+sashiko
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260923035217.179102-5-edumazet@google.com \
--to=edumazet@google.com \
--cc=davem@davemloft.net \
--cc=eric.dumazet@gmail.com \
--cc=horms@kernel.org \
--cc=kuba@kernel.org \
--cc=kuniyu@google.com \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=stable@vger.kernel.org \
--cc=u9012063@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox