* [PATCH v2 net 0/2] ipv4: fix IP ID reuse for GSO packets
@ 2026-09-30 14:40 Eric Dumazet
2026-09-30 14:40 ` [PATCH v2 net 1/2] ipv4: fix IP ID reuse in ip_select_ident_segs() Eric Dumazet
` (2 more replies)
0 siblings, 3 replies; 6+ messages in thread
From: Eric Dumazet @ 2026-09-30 14:40 UTC (permalink / raw)
To: David S . Miller, Jakub Kicinski, Paolo Abeni
Cc: Simon Horman, David Ahern, Ido Schimmel, netdev, edumazet,
Eric Dumazet
This series fixes two cases where IPv4 GSO packets can reuse the IP IDs
of previous packets:
- Patch 1 fixes ip_select_ident_segs() for non-TCP sockets, which uses
the first IP ID of the next packet since commit f866fbc842de
("ipv4: fix data-races around inet->inet_id"). SCTP GSO is affected.
- Patch 2 makes __ip_make_skb() reserve one IP ID per segment for
UDP GSO packets, instead of a single one.
Both issues were found by code inspection.
v2: Patch 2: add a sk_is_udp() check (David Ahern)
v1: https://lore.kernel.org/netdev/20260929131247.401104-1-edumazet@kernel.org/
Eric Dumazet (2):
ipv4: fix IP ID reuse in ip_select_ident_segs()
ipv4: reserve one IP ID per segment for UDP GSO packets
include/net/ip.h | 2 +-
net/ipv4/ip_output.c | 15 ++++++++++++++-
2 files changed, 15 insertions(+), 2 deletions(-)
--
2.56.0.rc1.315.gc6ed9934b7-goog
^ permalink raw reply [flat|nested] 6+ messages in thread
* [PATCH v2 net 1/2] ipv4: fix IP ID reuse in ip_select_ident_segs()
2026-09-30 14:40 [PATCH v2 net 0/2] ipv4: fix IP ID reuse for GSO packets Eric Dumazet
@ 2026-09-30 14:40 ` Eric Dumazet
2026-09-30 15:11 ` Willem de Bruijn
2026-09-30 14:40 ` [PATCH v2 net 2/2] ipv4: reserve one IP ID per segment for UDP GSO packets Eric Dumazet
2026-10-05 22:10 ` [PATCH v2 net 0/2] ipv4: fix IP ID reuse for " patchwork-bot+netdevbpf
2 siblings, 1 reply; 6+ messages in thread
From: Eric Dumazet @ 2026-09-30 14:40 UTC (permalink / raw)
To: David S . Miller, Jakub Kicinski, Paolo Abeni
Cc: Simon Horman, David Ahern, Ido Schimmel, netdev, edumazet,
Eric Dumazet, Jiayuan Chen
ip_select_ident_segs() must put the first of the @segs reserved IP IDs
in iph->id, as GSO assigns id, id + 1, ..., id + segs - 1 to segments.
Commit f866fbc842de ("ipv4: fix data-races around inet->inet_id")
used atomic_add_return() for non-TCP sockets, which returns the first
ID of the next packet instead. Consecutive GSO packets can then reuse
IP IDs.
SCTP GSO is affected. Other callers use segs == 1, and only see
a harmless off-by-one (UDP GSO has a separate, older issue).
Use atomic_fetch_add() instead, like the TCP path.
Fixes: f866fbc842de ("ipv4: fix data-races around inet->inet_id")
Signed-off-by: Eric Dumazet <edumazet@kernel.org>
Reviewed-by: Jiayuan Chen <jiayuan.chen@linux.dev>
Reviewed-by: David Ahern <dsahern@kernel.org>
---
include/net/ip.h | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/include/net/ip.h b/include/net/ip.h
index 6f602df72ee621ee4ee45e70beef0a1b5145367f..6a3e8271a73b3669e97c4b389e916dbcbfa9f6ae 100644
--- a/include/net/ip.h
+++ b/include/net/ip.h
@@ -598,7 +598,7 @@ static inline void ip_select_ident_segs(struct net *net, struct sk_buff *skb,
val = atomic_read(&inet_sk(sk)->inet_id);
atomic_set(&inet_sk(sk)->inet_id, val + segs);
} else {
- val = atomic_add_return(segs, &inet_sk(sk)->inet_id);
+ val = atomic_fetch_add(segs, &inet_sk(sk)->inet_id);
}
iph->id = htons(val);
return;
--
2.56.0.rc1.315.gc6ed9934b7-goog
^ permalink raw reply related [flat|nested] 6+ messages in thread
* [PATCH v2 net 2/2] ipv4: reserve one IP ID per segment for UDP GSO packets
2026-09-30 14:40 [PATCH v2 net 0/2] ipv4: fix IP ID reuse for GSO packets Eric Dumazet
2026-09-30 14:40 ` [PATCH v2 net 1/2] ipv4: fix IP ID reuse in ip_select_ident_segs() Eric Dumazet
@ 2026-09-30 14:40 ` Eric Dumazet
2026-09-30 15:12 ` Willem de Bruijn
2026-10-05 22:10 ` [PATCH v2 net 0/2] ipv4: fix IP ID reuse for " patchwork-bot+netdevbpf
2 siblings, 1 reply; 6+ messages in thread
From: Eric Dumazet @ 2026-09-30 14:40 UTC (permalink / raw)
To: David S . Miller, Jakub Kicinski, Paolo Abeni
Cc: Simon Horman, David Ahern, Ido Schimmel, netdev, edumazet,
Eric Dumazet, Jiayuan Chen, Willem de Bruijn
__ip_make_skb() reserves a single IP ID for UDP GSO packets, but GSO
assigns one IP ID per segment. Following packets then reuse these IDs,
either from inet->inet_id or from the shared generator.
Unless IP_PMTUDISC_DO/PROBE is used, DF is not set on UDP GSO packets,
so segments can be fragmented on the path and IP ID reuse can lead to
incorrect reassembly.
Reserve one IP ID per segment, using the same test as udp_send_skb().
Fixes: bec1f6f69736 ("udp: generate gso with UDP_SEGMENT")
Signed-off-by: Eric Dumazet <edumazet@kernel.org>
Reviewed-by: Jiayuan Chen <jiayuan.chen@linux.dev>
Cc: Willem de Bruijn <willemb@google.com>
---
net/ipv4/ip_output.c | 15 ++++++++++++++-
1 file changed, 14 insertions(+), 1 deletion(-)
diff --git a/net/ipv4/ip_output.c b/net/ipv4/ip_output.c
index a24cc8ee11d3ea3069bcc0d4d12e6867c2c475f7..47a78f297a7f5f50633c2157b3bcaea3df5fe0b4 100644
--- a/net/ipv4/ip_output.c
+++ b/net/ipv4/ip_output.c
@@ -1410,6 +1410,7 @@ struct sk_buff *__ip_make_skb(struct sock *sk,
struct iphdr *iph;
u8 pmtudisc, ttl;
__be16 df = 0;
+ int segs;
skb = __skb_dequeue(queue);
if (!skb)
@@ -1464,7 +1465,19 @@ struct sk_buff *__ip_make_skb(struct sock *sk,
iph->ttl = ttl;
iph->protocol = sk->sk_protocol;
ip_copy_addrs(iph, fl4);
- ip_select_ident(net, skb, sk);
+
+ /* UDP GSO packets are segmented later (see udp_send_skb()):
+ * reserve one IP ID per segment.
+ */
+ segs = 1;
+ if (cork->gso_size && sk_is_udp(sk)) {
+ int datalen = skb->len - skb_transport_offset(skb) -
+ sizeof(struct udphdr);
+
+ if (datalen > cork->gso_size)
+ segs = DIV_ROUND_UP(datalen, cork->gso_size);
+ }
+ ip_select_ident_segs(net, skb, sk, segs);
if (opt) {
iph->ihl += opt->optlen >> 2;
--
2.56.0.rc1.315.gc6ed9934b7-goog
^ permalink raw reply related [flat|nested] 6+ messages in thread
* Re: [PATCH v2 net 1/2] ipv4: fix IP ID reuse in ip_select_ident_segs()
2026-09-30 14:40 ` [PATCH v2 net 1/2] ipv4: fix IP ID reuse in ip_select_ident_segs() Eric Dumazet
@ 2026-09-30 15:11 ` Willem de Bruijn
0 siblings, 0 replies; 6+ messages in thread
From: Willem de Bruijn @ 2026-09-30 15:11 UTC (permalink / raw)
To: Eric Dumazet, David S . Miller, Jakub Kicinski, Paolo Abeni
Cc: Simon Horman, David Ahern, Ido Schimmel, netdev, edumazet,
Eric Dumazet, Jiayuan Chen
Eric Dumazet wrote:
> ip_select_ident_segs() must put the first of the @segs reserved IP IDs
> in iph->id, as GSO assigns id, id + 1, ..., id + segs - 1 to segments.
>
> Commit f866fbc842de ("ipv4: fix data-races around inet->inet_id")
> used atomic_add_return() for non-TCP sockets, which returns the first
> ID of the next packet instead. Consecutive GSO packets can then reuse
> IP IDs.
>
> SCTP GSO is affected. Other callers use segs == 1, and only see
> a harmless off-by-one (UDP GSO has a separate, older issue).
>
> Use atomic_fetch_add() instead, like the TCP path.
>
> Fixes: f866fbc842de ("ipv4: fix data-races around inet->inet_id")
> Signed-off-by: Eric Dumazet <edumazet@kernel.org>
> Reviewed-by: Jiayuan Chen <jiayuan.chen@linux.dev>
> Reviewed-by: David Ahern <dsahern@kernel.org>
Reviewed-by: Willem de Bruijn <willemb@google.com>
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [PATCH v2 net 2/2] ipv4: reserve one IP ID per segment for UDP GSO packets
2026-09-30 14:40 ` [PATCH v2 net 2/2] ipv4: reserve one IP ID per segment for UDP GSO packets Eric Dumazet
@ 2026-09-30 15:12 ` Willem de Bruijn
0 siblings, 0 replies; 6+ messages in thread
From: Willem de Bruijn @ 2026-09-30 15:12 UTC (permalink / raw)
To: Eric Dumazet, David S . Miller, Jakub Kicinski, Paolo Abeni
Cc: Simon Horman, David Ahern, Ido Schimmel, netdev, edumazet,
Eric Dumazet, Jiayuan Chen, Willem de Bruijn
Eric Dumazet wrote:
> __ip_make_skb() reserves a single IP ID for UDP GSO packets, but GSO
> assigns one IP ID per segment. Following packets then reuse these IDs,
> either from inet->inet_id or from the shared generator.
>
> Unless IP_PMTUDISC_DO/PROBE is used, DF is not set on UDP GSO packets,
> so segments can be fragmented on the path and IP ID reuse can lead to
> incorrect reassembly.
>
> Reserve one IP ID per segment, using the same test as udp_send_skb().
>
> Fixes: bec1f6f69736 ("udp: generate gso with UDP_SEGMENT")
> Signed-off-by: Eric Dumazet <edumazet@kernel.org>
> Reviewed-by: Jiayuan Chen <jiayuan.chen@linux.dev>
> Cc: Willem de Bruijn <willemb@google.com>
Reviewed-by: Willem de Bruijn <willemb@google.com>
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [PATCH v2 net 0/2] ipv4: fix IP ID reuse for GSO packets
2026-09-30 14:40 [PATCH v2 net 0/2] ipv4: fix IP ID reuse for GSO packets Eric Dumazet
2026-09-30 14:40 ` [PATCH v2 net 1/2] ipv4: fix IP ID reuse in ip_select_ident_segs() Eric Dumazet
2026-09-30 14:40 ` [PATCH v2 net 2/2] ipv4: reserve one IP ID per segment for UDP GSO packets Eric Dumazet
@ 2026-10-05 22:10 ` patchwork-bot+netdevbpf
2 siblings, 0 replies; 6+ messages in thread
From: patchwork-bot+netdevbpf @ 2026-10-05 22:10 UTC (permalink / raw)
To: Eric Dumazet
Cc: davem, kuba, pabeni, horms, dsahern, idosch, netdev, edumazet
Hello:
This series was applied to netdev/net-next.git (main)
by Jakub Kicinski <kuba@kernel.org>:
On Wed, 30 Sep 2026 14:40:16 +0000 you wrote:
> This series fixes two cases where IPv4 GSO packets can reuse the IP IDs
> of previous packets:
>
> - Patch 1 fixes ip_select_ident_segs() for non-TCP sockets, which uses
> the first IP ID of the next packet since commit f866fbc842de
> ("ipv4: fix data-races around inet->inet_id"). SCTP GSO is affected.
>
> [...]
Here is the summary with links:
- [v2,net,1/2] ipv4: fix IP ID reuse in ip_select_ident_segs()
https://git.kernel.org/netdev/net-next/c/fe7ca0c13f7d
- [v2,net,2/2] ipv4: reserve one IP ID per segment for UDP GSO packets
https://git.kernel.org/netdev/net-next/c/852c08d6a991
You are awesome, thank you!
--
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html
^ permalink raw reply [flat|nested] 6+ messages in thread
end of thread, other threads:[~2026-10-05 22:10 UTC | newest]
Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-30 14:40 [PATCH v2 net 0/2] ipv4: fix IP ID reuse for GSO packets Eric Dumazet
2026-09-30 14:40 ` [PATCH v2 net 1/2] ipv4: fix IP ID reuse in ip_select_ident_segs() Eric Dumazet
2026-09-30 15:11 ` Willem de Bruijn
2026-09-30 14:40 ` [PATCH v2 net 2/2] ipv4: reserve one IP ID per segment for UDP GSO packets Eric Dumazet
2026-09-30 15:12 ` Willem de Bruijn
2026-10-05 22:10 ` [PATCH v2 net 0/2] ipv4: fix IP ID reuse for " patchwork-bot+netdevbpf
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox