From: Chenguang Zhao <chenguang.zhao@linux.dev>
To: Ido Schimmel <idosch@nvidia.com>
Cc: davem@davemloft.net, edumazet@google.com, kuba@kernel.org,
pabeni@redhat.com, horms@kernel.org, dsahern@kernel.org,
kerneljasonxing@gmail.com, netdev@vger.kernel.org,
Chenguang Zhao <zhaochenguang@kylinos.cn>,
syzbot+2b120190d9e54ad8c65d@syzkaller.appspotmail.com, ja@ssi.bg
Subject: Re: [PATCH net] ipvs: fix infinite loop with ipvlan L3 from unconditional ipvs_property clear
Date: Mon, 28 Sep 2026 14:55:50 +0800 [thread overview]
Message-ID: <20260928065550.GA620427@pc> (raw)
In-Reply-To: <20260925124242.GA112355@shredder>
On Fri, Sep 25, 2026 at 03:42:42PM +0300, Ido Schimmel wrote:
> On Thu, Sep 24, 2026 at 02:33:12PM +0800, Chenguang Zhao wrote:
> > From: Chenguang Zhao <zhaochenguang@kylinos.cn>
> >
> > Commit de2c211868b9 ("ipvs: Always clear ipvs_property flag in
> > skb_scrub_packet()") moved ipvs_reset() before the xnet check, making
> > the call unconditional. The intent was to fix a bpf_redirect case where
> > stale ipvs_property on an skb re-entering the RX path caused the SNAT
> > hook to be skipped. However the change is too broad: when IPVS NAT
> > sits above an ipvlan L3 interface in the same netns, the following
> > loop happens:
> >
> > LOCAL_OUT -> IPVS DNAT (sets ipvs_property=1) -> dst_output -> ipvlan
> > -> skb_scrub_packet() -> ipvs_reset() clears the flag
> > -> ipvlan_process_v4_outbound() -> ip_local_out() -> LOCAL_OUT
> > -> IPVS sees ipvs_property=0, processes again -> infinite recursion
> >
> > syzbot reported this as a stack overflow on a KASAN kernel where each
> > level burns ~3.3 KB of stack and XMIT_RECURSION_LIMIT falls short. On
> > non-KASAN kernels the dead-loop detector catches it and prints "Dead
> > loop on virtual device", but traffic is still broken.
> >
> > Fixes: de2c211868b9 ("ipvs: Always clear ipvs_property flag in skb_scrub_packet()")
> > Reported-by: syzbot+2b120190d9e54ad8c65d@syzkaller.appspotmail.com
> > Closes: https://syzkaller.appspot.com/bug?extid=2b120190d9e54ad8c65d
> > Signed-off-by: Chenguang Zhao <zhaochenguang@kylinos.cn>
>
> 1. You need to copy IPVS maintainers on patches related to IPVS. Added
> Julian.
Thanks, will add Julian to CC in v2.
>
> 2. Does it reproduce with commit 7f1de03e3103 ("net: reduce
> XMIT_RECURSION_LIMIT under KASAN") in net-next?
The dead loop itself still reproduces — dmesg shows "Dead loop on virtual device" for
every connection, and IPVS InPkts keeps climbing. But the stack overflow crash does not
reproduce with 7f1de03e3103 on KASAN, since the lower recursion limit catches the loop
before the stack blows up. So 7f1de03e3103 turns the panic into a packet drop,
which is expected, but doesn't fix the underlying issue (ipvs_property being cleared
unconditionally in skb_scrub_packet).
Thanks
Chenguang
next prev parent reply other threads:[~2026-09-28 6:55 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-24 6:33 [PATCH net] ipvs: fix infinite loop with ipvlan L3 from unconditional ipvs_property clear Chenguang Zhao
2026-09-25 12:42 ` Ido Schimmel
2026-09-28 6:55 ` Chenguang Zhao [this message]
2026-09-28 8:10 ` Julian Anastasov
2026-09-26 20:12 ` [syzbot ci] " syzbot ci
2026-09-28 6:58 ` [PATCH net] " netdev-bot+sashiko
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260928065550.GA620427@pc \
--to=chenguang.zhao@linux.dev \
--cc=davem@davemloft.net \
--cc=dsahern@kernel.org \
--cc=edumazet@google.com \
--cc=horms@kernel.org \
--cc=idosch@nvidia.com \
--cc=ja@ssi.bg \
--cc=kerneljasonxing@gmail.com \
--cc=kuba@kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=syzbot+2b120190d9e54ad8c65d@syzkaller.appspotmail.com \
--cc=zhaochenguang@kylinos.cn \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox