Netdev List
 help / color / mirror / Atom feed
* [PATCH v2 net 0/2] ipv4: fix IP ID reuse for GSO packets
@ 2026-09-30 14:40 Eric Dumazet
  2026-09-30 14:40 ` [PATCH v2 net 1/2] ipv4: fix IP ID reuse in ip_select_ident_segs() Eric Dumazet
                   ` (2 more replies)
  0 siblings, 3 replies; 6+ messages in thread
From: Eric Dumazet @ 2026-09-30 14:40 UTC (permalink / raw)
  To: David S . Miller, Jakub Kicinski, Paolo Abeni
  Cc: Simon Horman, David Ahern, Ido Schimmel, netdev, edumazet,
	Eric Dumazet

This series fixes two cases where IPv4 GSO packets can reuse the IP IDs
of previous packets:

- Patch 1 fixes ip_select_ident_segs() for non-TCP sockets, which uses
  the first IP ID of the next packet since commit f866fbc842de
  ("ipv4: fix data-races around inet->inet_id"). SCTP GSO is affected.

- Patch 2 makes __ip_make_skb() reserve one IP ID per segment for
  UDP GSO packets, instead of a single one.

Both issues were found by code inspection.

v2: Patch 2: add a sk_is_udp() check (David Ahern)
v1: https://lore.kernel.org/netdev/20260929131247.401104-1-edumazet@kernel.org/

Eric Dumazet (2):
  ipv4: fix IP ID reuse in ip_select_ident_segs()
  ipv4: reserve one IP ID per segment for UDP GSO packets

 include/net/ip.h     |  2 +-
 net/ipv4/ip_output.c | 15 ++++++++++++++-
 2 files changed, 15 insertions(+), 2 deletions(-)

-- 
2.56.0.rc1.315.gc6ed9934b7-goog


^ permalink raw reply	[flat|nested] 6+ messages in thread

* [PATCH v2 net 1/2] ipv4: fix IP ID reuse in ip_select_ident_segs()
  2026-09-30 14:40 [PATCH v2 net 0/2] ipv4: fix IP ID reuse for GSO packets Eric Dumazet
@ 2026-09-30 14:40 ` Eric Dumazet
  2026-09-30 15:11   ` Willem de Bruijn
  2026-09-30 14:40 ` [PATCH v2 net 2/2] ipv4: reserve one IP ID per segment for UDP GSO packets Eric Dumazet
  2026-10-05 22:10 ` [PATCH v2 net 0/2] ipv4: fix IP ID reuse for " patchwork-bot+netdevbpf
  2 siblings, 1 reply; 6+ messages in thread
From: Eric Dumazet @ 2026-09-30 14:40 UTC (permalink / raw)
  To: David S . Miller, Jakub Kicinski, Paolo Abeni
  Cc: Simon Horman, David Ahern, Ido Schimmel, netdev, edumazet,
	Eric Dumazet, Jiayuan Chen

ip_select_ident_segs() must put the first of the @segs reserved IP IDs
in iph->id, as GSO assigns id, id + 1, ..., id + segs - 1 to segments.

Commit f866fbc842de ("ipv4: fix data-races around inet->inet_id")
used atomic_add_return() for non-TCP sockets, which returns the first
ID of the next packet instead. Consecutive GSO packets can then reuse
IP IDs.

SCTP GSO is affected. Other callers use segs == 1, and only see
a harmless off-by-one (UDP GSO has a separate, older issue).

Use atomic_fetch_add() instead, like the TCP path.

Fixes: f866fbc842de ("ipv4: fix data-races around inet->inet_id")
Signed-off-by: Eric Dumazet <edumazet@kernel.org>
Reviewed-by: Jiayuan Chen <jiayuan.chen@linux.dev>
Reviewed-by: David Ahern <dsahern@kernel.org>
---
 include/net/ip.h | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/include/net/ip.h b/include/net/ip.h
index 6f602df72ee621ee4ee45e70beef0a1b5145367f..6a3e8271a73b3669e97c4b389e916dbcbfa9f6ae 100644
--- a/include/net/ip.h
+++ b/include/net/ip.h
@@ -598,7 +598,7 @@ static inline void ip_select_ident_segs(struct net *net, struct sk_buff *skb,
 			val = atomic_read(&inet_sk(sk)->inet_id);
 			atomic_set(&inet_sk(sk)->inet_id, val + segs);
 		} else {
-			val = atomic_add_return(segs, &inet_sk(sk)->inet_id);
+			val = atomic_fetch_add(segs, &inet_sk(sk)->inet_id);
 		}
 		iph->id = htons(val);
 		return;
-- 
2.56.0.rc1.315.gc6ed9934b7-goog


^ permalink raw reply related	[flat|nested] 6+ messages in thread

* [PATCH v2 net 2/2] ipv4: reserve one IP ID per segment for UDP GSO packets
  2026-09-30 14:40 [PATCH v2 net 0/2] ipv4: fix IP ID reuse for GSO packets Eric Dumazet
  2026-09-30 14:40 ` [PATCH v2 net 1/2] ipv4: fix IP ID reuse in ip_select_ident_segs() Eric Dumazet
@ 2026-09-30 14:40 ` Eric Dumazet
  2026-09-30 15:12   ` Willem de Bruijn
  2026-10-05 22:10 ` [PATCH v2 net 0/2] ipv4: fix IP ID reuse for " patchwork-bot+netdevbpf
  2 siblings, 1 reply; 6+ messages in thread
From: Eric Dumazet @ 2026-09-30 14:40 UTC (permalink / raw)
  To: David S . Miller, Jakub Kicinski, Paolo Abeni
  Cc: Simon Horman, David Ahern, Ido Schimmel, netdev, edumazet,
	Eric Dumazet, Jiayuan Chen, Willem de Bruijn

__ip_make_skb() reserves a single IP ID for UDP GSO packets, but GSO
assigns one IP ID per segment. Following packets then reuse these IDs,
either from inet->inet_id or from the shared generator.

Unless IP_PMTUDISC_DO/PROBE is used, DF is not set on UDP GSO packets,
so segments can be fragmented on the path and IP ID reuse can lead to
incorrect reassembly.

Reserve one IP ID per segment, using the same test as udp_send_skb().

Fixes: bec1f6f69736 ("udp: generate gso with UDP_SEGMENT")
Signed-off-by: Eric Dumazet <edumazet@kernel.org>
Reviewed-by: Jiayuan Chen <jiayuan.chen@linux.dev>
Cc: Willem de Bruijn <willemb@google.com>
---
 net/ipv4/ip_output.c | 15 ++++++++++++++-
 1 file changed, 14 insertions(+), 1 deletion(-)

diff --git a/net/ipv4/ip_output.c b/net/ipv4/ip_output.c
index a24cc8ee11d3ea3069bcc0d4d12e6867c2c475f7..47a78f297a7f5f50633c2157b3bcaea3df5fe0b4 100644
--- a/net/ipv4/ip_output.c
+++ b/net/ipv4/ip_output.c
@@ -1410,6 +1410,7 @@ struct sk_buff *__ip_make_skb(struct sock *sk,
 	struct iphdr *iph;
 	u8 pmtudisc, ttl;
 	__be16 df = 0;
+	int segs;
 
 	skb = __skb_dequeue(queue);
 	if (!skb)
@@ -1464,7 +1465,19 @@ struct sk_buff *__ip_make_skb(struct sock *sk,
 	iph->ttl = ttl;
 	iph->protocol = sk->sk_protocol;
 	ip_copy_addrs(iph, fl4);
-	ip_select_ident(net, skb, sk);
+
+	/* UDP GSO packets are segmented later (see udp_send_skb()):
+	 * reserve one IP ID per segment.
+	 */
+	segs = 1;
+	if (cork->gso_size && sk_is_udp(sk)) {
+		int datalen = skb->len - skb_transport_offset(skb) -
+			      sizeof(struct udphdr);
+
+		if (datalen > cork->gso_size)
+			segs = DIV_ROUND_UP(datalen, cork->gso_size);
+	}
+	ip_select_ident_segs(net, skb, sk, segs);
 
 	if (opt) {
 		iph->ihl += opt->optlen >> 2;
-- 
2.56.0.rc1.315.gc6ed9934b7-goog


^ permalink raw reply related	[flat|nested] 6+ messages in thread

* Re: [PATCH v2 net 1/2] ipv4: fix IP ID reuse in ip_select_ident_segs()
  2026-09-30 14:40 ` [PATCH v2 net 1/2] ipv4: fix IP ID reuse in ip_select_ident_segs() Eric Dumazet
@ 2026-09-30 15:11   ` Willem de Bruijn
  0 siblings, 0 replies; 6+ messages in thread
From: Willem de Bruijn @ 2026-09-30 15:11 UTC (permalink / raw)
  To: Eric Dumazet, David S . Miller, Jakub Kicinski, Paolo Abeni
  Cc: Simon Horman, David Ahern, Ido Schimmel, netdev, edumazet,
	Eric Dumazet, Jiayuan Chen

Eric Dumazet wrote:
> ip_select_ident_segs() must put the first of the @segs reserved IP IDs
> in iph->id, as GSO assigns id, id + 1, ..., id + segs - 1 to segments.
> 
> Commit f866fbc842de ("ipv4: fix data-races around inet->inet_id")
> used atomic_add_return() for non-TCP sockets, which returns the first
> ID of the next packet instead. Consecutive GSO packets can then reuse
> IP IDs.
> 
> SCTP GSO is affected. Other callers use segs == 1, and only see
> a harmless off-by-one (UDP GSO has a separate, older issue).
> 
> Use atomic_fetch_add() instead, like the TCP path.
> 
> Fixes: f866fbc842de ("ipv4: fix data-races around inet->inet_id")
> Signed-off-by: Eric Dumazet <edumazet@kernel.org>
> Reviewed-by: Jiayuan Chen <jiayuan.chen@linux.dev>
> Reviewed-by: David Ahern <dsahern@kernel.org>

Reviewed-by: Willem de Bruijn <willemb@google.com>

^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: [PATCH v2 net 2/2] ipv4: reserve one IP ID per segment for UDP GSO packets
  2026-09-30 14:40 ` [PATCH v2 net 2/2] ipv4: reserve one IP ID per segment for UDP GSO packets Eric Dumazet
@ 2026-09-30 15:12   ` Willem de Bruijn
  0 siblings, 0 replies; 6+ messages in thread
From: Willem de Bruijn @ 2026-09-30 15:12 UTC (permalink / raw)
  To: Eric Dumazet, David S . Miller, Jakub Kicinski, Paolo Abeni
  Cc: Simon Horman, David Ahern, Ido Schimmel, netdev, edumazet,
	Eric Dumazet, Jiayuan Chen, Willem de Bruijn

Eric Dumazet wrote:
> __ip_make_skb() reserves a single IP ID for UDP GSO packets, but GSO
> assigns one IP ID per segment. Following packets then reuse these IDs,
> either from inet->inet_id or from the shared generator.
> 
> Unless IP_PMTUDISC_DO/PROBE is used, DF is not set on UDP GSO packets,
> so segments can be fragmented on the path and IP ID reuse can lead to
> incorrect reassembly.
> 
> Reserve one IP ID per segment, using the same test as udp_send_skb().
> 
> Fixes: bec1f6f69736 ("udp: generate gso with UDP_SEGMENT")
> Signed-off-by: Eric Dumazet <edumazet@kernel.org>
> Reviewed-by: Jiayuan Chen <jiayuan.chen@linux.dev>
> Cc: Willem de Bruijn <willemb@google.com>

Reviewed-by: Willem de Bruijn <willemb@google.com>

^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: [PATCH v2 net 0/2] ipv4: fix IP ID reuse for GSO packets
  2026-09-30 14:40 [PATCH v2 net 0/2] ipv4: fix IP ID reuse for GSO packets Eric Dumazet
  2026-09-30 14:40 ` [PATCH v2 net 1/2] ipv4: fix IP ID reuse in ip_select_ident_segs() Eric Dumazet
  2026-09-30 14:40 ` [PATCH v2 net 2/2] ipv4: reserve one IP ID per segment for UDP GSO packets Eric Dumazet
@ 2026-10-05 22:10 ` patchwork-bot+netdevbpf
  2 siblings, 0 replies; 6+ messages in thread
From: patchwork-bot+netdevbpf @ 2026-10-05 22:10 UTC (permalink / raw)
  To: Eric Dumazet
  Cc: davem, kuba, pabeni, horms, dsahern, idosch, netdev, edumazet

Hello:

This series was applied to netdev/net-next.git (main)
by Jakub Kicinski <kuba@kernel.org>:

On Wed, 30 Sep 2026 14:40:16 +0000 you wrote:
> This series fixes two cases where IPv4 GSO packets can reuse the IP IDs
> of previous packets:
> 
> - Patch 1 fixes ip_select_ident_segs() for non-TCP sockets, which uses
>   the first IP ID of the next packet since commit f866fbc842de
>   ("ipv4: fix data-races around inet->inet_id"). SCTP GSO is affected.
> 
> [...]

Here is the summary with links:
  - [v2,net,1/2] ipv4: fix IP ID reuse in ip_select_ident_segs()
    https://git.kernel.org/netdev/net-next/c/fe7ca0c13f7d
  - [v2,net,2/2] ipv4: reserve one IP ID per segment for UDP GSO packets
    https://git.kernel.org/netdev/net-next/c/852c08d6a991

You are awesome, thank you!
-- 
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html



^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2026-10-05 22:10 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-30 14:40 [PATCH v2 net 0/2] ipv4: fix IP ID reuse for GSO packets Eric Dumazet
2026-09-30 14:40 ` [PATCH v2 net 1/2] ipv4: fix IP ID reuse in ip_select_ident_segs() Eric Dumazet
2026-09-30 15:11   ` Willem de Bruijn
2026-09-30 14:40 ` [PATCH v2 net 2/2] ipv4: reserve one IP ID per segment for UDP GSO packets Eric Dumazet
2026-09-30 15:12   ` Willem de Bruijn
2026-10-05 22:10 ` [PATCH v2 net 0/2] ipv4: fix IP ID reuse for " patchwork-bot+netdevbpf

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox