Netdev List
 help / color / mirror / Atom feed
* [PATCH net] vrf: Stop corrupting skb->csum when capturing CHECKSUM_COMPLETE packets
@ 2026-09-22 13:12 Ido Schimmel
  2026-09-22 13:55 ` David Ahern
                   ` (2 more replies)
  0 siblings, 3 replies; 5+ messages in thread
From: Ido Schimmel @ 2026-09-22 13:12 UTC (permalink / raw)
  To: netdev
  Cc: davem, kuba, pabeni, edumazet, dsahern, andrew+netdev,
	andrea.mayer, stesasso, Ido Schimmel

The VRF device is an Ethernet device but it can have non-Ethernet ports
such as IP tunnels. Before the cited commit, capturing packets from such
ports on the VRF device resulted in these packets being detected as
malformed since they lack an Ethernet header.

The cited commit fixed it by pushing a dummy Ethernet header to such
packets before the capture and pulling it afterwards. In the case of
CHECKSUM_COMPLETE packets it also updated skb->csum with the checksum of
the dummy Ethernet header. This is wrong as skb->csum should not include
the checksum of the Ethernet header ("checksum of the _whole_ packet as
seen by netif_rx()").

This also means that L4 protocols receive a corrupted skb->csum and
potentially drop the packet, as is the case with UDP packets whose
checksum was completed by software.

Fix by removing the unnecessary call to skb_postpush_rcsum().

Fixes: 048939088220 ("vrf: add mac header for tunneled packets when sniffer is attached")
Reported-by: Stefano Sasso <stesasso@gmail.com>
Closes: https://lore.kernel.org/netdev/CALtE316UtL3x7LL6uxfXzx8rW6AbzYPeDOb478hqJCr_-dj=Wg@mail.gmail.com/
Signed-off-by: Ido Schimmel <idosch@nvidia.com>
---
 drivers/net/vrf.c | 2 --
 1 file changed, 2 deletions(-)

diff --git a/drivers/net/vrf.c b/drivers/net/vrf.c
index a0557a3a7026..d4dc6d690a75 100644
--- a/drivers/net/vrf.c
+++ b/drivers/net/vrf.c
@@ -1175,8 +1175,6 @@ static int vrf_prepare_mac_header(struct sk_buff *skb,
 	skb->protocol = eth->h_proto;
 	skb->pkt_type = PACKET_HOST;
 
-	skb_postpush_rcsum(skb, skb->data, ETH_HLEN);
-
 	skb_pull_inline(skb, ETH_HLEN);
 
 	return 0;
-- 
2.55.0


^ permalink raw reply related	[flat|nested] 5+ messages in thread

* Re: [PATCH net] vrf: Stop corrupting skb->csum when capturing CHECKSUM_COMPLETE packets
  2026-09-22 13:12 [PATCH net] vrf: Stop corrupting skb->csum when capturing CHECKSUM_COMPLETE packets Ido Schimmel
@ 2026-09-22 13:55 ` David Ahern
  2026-09-22 14:23   ` Eric Dumazet
  2026-09-23 19:16 ` Andrea Mayer
  2026-09-24  1:40 ` patchwork-bot+netdevbpf
  2 siblings, 1 reply; 5+ messages in thread
From: David Ahern @ 2026-09-22 13:55 UTC (permalink / raw)
  To: Ido Schimmel, netdev
  Cc: davem, kuba, pabeni, edumazet, andrew+netdev, andrea.mayer,
	stesasso

On 9/22/26 7:12 AM, Ido Schimmel wrote:
> The VRF device is an Ethernet device but it can have non-Ethernet ports
> such as IP tunnels. Before the cited commit, capturing packets from such
> ports on the VRF device resulted in these packets being detected as
> malformed since they lack an Ethernet header.
> 
> The cited commit fixed it by pushing a dummy Ethernet header to such
> packets before the capture and pulling it afterwards. In the case of
> CHECKSUM_COMPLETE packets it also updated skb->csum with the checksum of
> the dummy Ethernet header. This is wrong as skb->csum should not include
> the checksum of the Ethernet header ("checksum of the _whole_ packet as
> seen by netif_rx()").
> 
> This also means that L4 protocols receive a corrupted skb->csum and
> potentially drop the packet, as is the case with UDP packets whose
> checksum was completed by software.
> 
> Fix by removing the unnecessary call to skb_postpush_rcsum().
> 
> Fixes: 048939088220 ("vrf: add mac header for tunneled packets when sniffer is attached")
> Reported-by: Stefano Sasso <stesasso@gmail.com>
> Closes: https://lore.kernel.org/netdev/CALtE316UtL3x7LL6uxfXzx8rW6AbzYPeDOb478hqJCr_-dj=Wg@mail.gmail.com/
> Signed-off-by: Ido Schimmel <idosch@nvidia.com>
> ---
>  drivers/net/vrf.c | 2 --
>  1 file changed, 2 deletions(-)
> 

Reviewed-by: David Ahern <dsahern@kernel.org>

Thanks, Ido.


^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: [PATCH net] vrf: Stop corrupting skb->csum when capturing CHECKSUM_COMPLETE packets
  2026-09-22 13:55 ` David Ahern
@ 2026-09-22 14:23   ` Eric Dumazet
  0 siblings, 0 replies; 5+ messages in thread
From: Eric Dumazet @ 2026-09-22 14:23 UTC (permalink / raw)
  To: David Ahern
  Cc: Ido Schimmel, netdev, davem, kuba, pabeni, andrew+netdev,
	andrea.mayer, stesasso

On Tue, Sep 22, 2026 at 3:55 PM David Ahern <dsahern@kernel.org> wrote:
>
> On 9/22/26 7:12 AM, Ido Schimmel wrote:
> > The VRF device is an Ethernet device but it can have non-Ethernet ports
> > such as IP tunnels. Before the cited commit, capturing packets from such
> > ports on the VRF device resulted in these packets being detected as
> > malformed since they lack an Ethernet header.
> >
> > The cited commit fixed it by pushing a dummy Ethernet header to such
> > packets before the capture and pulling it afterwards. In the case of
> > CHECKSUM_COMPLETE packets it also updated skb->csum with the checksum of
> > the dummy Ethernet header. This is wrong as skb->csum should not include
> > the checksum of the Ethernet header ("checksum of the _whole_ packet as
> > seen by netif_rx()").
> >
> > This also means that L4 protocols receive a corrupted skb->csum and
> > potentially drop the packet, as is the case with UDP packets whose
> > checksum was completed by software.
> >
> > Fix by removing the unnecessary call to skb_postpush_rcsum().
> >
> > Fixes: 048939088220 ("vrf: add mac header for tunneled packets when sniffer is attached")
> > Reported-by: Stefano Sasso <stesasso@gmail.com>
> > Closes: https://lore.kernel.org/netdev/CALtE316UtL3x7LL6uxfXzx8rW6AbzYPeDOb478hqJCr_-dj=Wg@mail.gmail.com/
> > Signed-off-by: Ido Schimmel <idosch@nvidia.com>
> > ---
> >  drivers/net/vrf.c | 2 --
> >  1 file changed, 2 deletions(-)
> >
>
> Reviewed-by: David Ahern <dsahern@kernel.org>

Reviewed-by: Eric Dumazet <edumazet@google.com>

^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: [PATCH net] vrf: Stop corrupting skb->csum when capturing CHECKSUM_COMPLETE packets
  2026-09-22 13:12 [PATCH net] vrf: Stop corrupting skb->csum when capturing CHECKSUM_COMPLETE packets Ido Schimmel
  2026-09-22 13:55 ` David Ahern
@ 2026-09-23 19:16 ` Andrea Mayer
  2026-09-24  1:40 ` patchwork-bot+netdevbpf
  2 siblings, 0 replies; 5+ messages in thread
From: Andrea Mayer @ 2026-09-23 19:16 UTC (permalink / raw)
  To: Ido Schimmel
  Cc: netdev, davem, kuba, pabeni, edumazet, dsahern, andrew+netdev,
	stesasso, Andrea Mayer

On Tue, 22 Sep 2026 16:12:39 +0300
Ido Schimmel <idosch@nvidia.com> wrote:

> The VRF device is an Ethernet device but it can have non-Ethernet ports
> such as IP tunnels. Before the cited commit, capturing packets from such
> ports on the VRF device resulted in these packets being detected as
> malformed since they lack an Ethernet header.
> 
> The cited commit fixed it by pushing a dummy Ethernet header to such
> packets before the capture and pulling it afterwards. In the case of
> CHECKSUM_COMPLETE packets it also updated skb->csum with the checksum of
> the dummy Ethernet header. This is wrong as skb->csum should not include
> the checksum of the Ethernet header ("checksum of the _whole_ packet as
> seen by netif_rx()").
> 
> This also means that L4 protocols receive a corrupted skb->csum and
> potentially drop the packet, as is the case with UDP packets whose
> checksum was completed by software.
> 
> Fix by removing the unnecessary call to skb_postpush_rcsum().
> 
> Fixes: 048939088220 ("vrf: add mac header for tunneled packets when sniffer is attached")
> Reported-by: Stefano Sasso <stesasso@gmail.com>
> Closes: https://lore.kernel.org/netdev/CALtE316UtL3x7LL6uxfXzx8rW6AbzYPeDOb478hqJCr_-dj=Wg@mail.gmail.com/
> Signed-off-by: Ido Schimmel <idosch@nvidia.com>
> ---
>  drivers/net/vrf.c | 2 --
>  1 file changed, 2 deletions(-)
> 

Thanks for taking this, and thanks to Stefano for the report and the
reproducer.

Reviewed-by: Andrea Mayer <andrea.mayer@uniroma2.it>

^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: [PATCH net] vrf: Stop corrupting skb->csum when capturing CHECKSUM_COMPLETE packets
  2026-09-22 13:12 [PATCH net] vrf: Stop corrupting skb->csum when capturing CHECKSUM_COMPLETE packets Ido Schimmel
  2026-09-22 13:55 ` David Ahern
  2026-09-23 19:16 ` Andrea Mayer
@ 2026-09-24  1:40 ` patchwork-bot+netdevbpf
  2 siblings, 0 replies; 5+ messages in thread
From: patchwork-bot+netdevbpf @ 2026-09-24  1:40 UTC (permalink / raw)
  To: Ido Schimmel
  Cc: netdev, davem, kuba, pabeni, edumazet, dsahern, andrew+netdev,
	andrea.mayer, stesasso

Hello:

This patch was applied to netdev/net.git (main)
by Jakub Kicinski <kuba@kernel.org>:

On Tue, 22 Sep 2026 16:12:39 +0300 you wrote:
> The VRF device is an Ethernet device but it can have non-Ethernet ports
> such as IP tunnels. Before the cited commit, capturing packets from such
> ports on the VRF device resulted in these packets being detected as
> malformed since they lack an Ethernet header.
> 
> The cited commit fixed it by pushing a dummy Ethernet header to such
> packets before the capture and pulling it afterwards. In the case of
> CHECKSUM_COMPLETE packets it also updated skb->csum with the checksum of
> the dummy Ethernet header. This is wrong as skb->csum should not include
> the checksum of the Ethernet header ("checksum of the _whole_ packet as
> seen by netif_rx()").
> 
> [...]

Here is the summary with links:
  - [net] vrf: Stop corrupting skb->csum when capturing CHECKSUM_COMPLETE packets
    https://git.kernel.org/netdev/net/c/ab7aa05c06ae

You are awesome, thank you!
-- 
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html



^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2026-09-24  1:41 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-22 13:12 [PATCH net] vrf: Stop corrupting skb->csum when capturing CHECKSUM_COMPLETE packets Ido Schimmel
2026-09-22 13:55 ` David Ahern
2026-09-22 14:23   ` Eric Dumazet
2026-09-23 19:16 ` Andrea Mayer
2026-09-24  1:40 ` patchwork-bot+netdevbpf

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox