From: Eric Dumazet <edumazet@kernel.org>
To: "David S . Miller" <davem@davemloft.net>,
Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>
Cc: Simon Horman <horms@kernel.org>, David Ahern <dsahern@kernel.org>,
Ido Schimmel <idosch@nvidia.com>,
netdev@vger.kernel.org, edumazet@google.com,
Eric Dumazet <edumazet@kernel.org>,
Jiayuan Chen <jiayuan.chen@linux.dev>,
Willem de Bruijn <willemb@google.com>
Subject: [PATCH v2 net 2/2] ipv4: reserve one IP ID per segment for UDP GSO packets
Date: Wed, 30 Sep 2026 14:40:18 +0000 [thread overview]
Message-ID: <20260930144018.1174068-3-edumazet@kernel.org> (raw)
In-Reply-To: <20260930144018.1174068-1-edumazet@kernel.org>
__ip_make_skb() reserves a single IP ID for UDP GSO packets, but GSO
assigns one IP ID per segment. Following packets then reuse these IDs,
either from inet->inet_id or from the shared generator.
Unless IP_PMTUDISC_DO/PROBE is used, DF is not set on UDP GSO packets,
so segments can be fragmented on the path and IP ID reuse can lead to
incorrect reassembly.
Reserve one IP ID per segment, using the same test as udp_send_skb().
Fixes: bec1f6f69736 ("udp: generate gso with UDP_SEGMENT")
Signed-off-by: Eric Dumazet <edumazet@kernel.org>
Reviewed-by: Jiayuan Chen <jiayuan.chen@linux.dev>
Cc: Willem de Bruijn <willemb@google.com>
---
net/ipv4/ip_output.c | 15 ++++++++++++++-
1 file changed, 14 insertions(+), 1 deletion(-)
diff --git a/net/ipv4/ip_output.c b/net/ipv4/ip_output.c
index a24cc8ee11d3ea3069bcc0d4d12e6867c2c475f7..47a78f297a7f5f50633c2157b3bcaea3df5fe0b4 100644
--- a/net/ipv4/ip_output.c
+++ b/net/ipv4/ip_output.c
@@ -1410,6 +1410,7 @@ struct sk_buff *__ip_make_skb(struct sock *sk,
struct iphdr *iph;
u8 pmtudisc, ttl;
__be16 df = 0;
+ int segs;
skb = __skb_dequeue(queue);
if (!skb)
@@ -1464,7 +1465,19 @@ struct sk_buff *__ip_make_skb(struct sock *sk,
iph->ttl = ttl;
iph->protocol = sk->sk_protocol;
ip_copy_addrs(iph, fl4);
- ip_select_ident(net, skb, sk);
+
+ /* UDP GSO packets are segmented later (see udp_send_skb()):
+ * reserve one IP ID per segment.
+ */
+ segs = 1;
+ if (cork->gso_size && sk_is_udp(sk)) {
+ int datalen = skb->len - skb_transport_offset(skb) -
+ sizeof(struct udphdr);
+
+ if (datalen > cork->gso_size)
+ segs = DIV_ROUND_UP(datalen, cork->gso_size);
+ }
+ ip_select_ident_segs(net, skb, sk, segs);
if (opt) {
iph->ihl += opt->optlen >> 2;
--
2.56.0.rc1.315.gc6ed9934b7-goog
next prev parent reply other threads:[~2026-09-30 14:40 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-30 14:40 [PATCH v2 net 0/2] ipv4: fix IP ID reuse for GSO packets Eric Dumazet
2026-09-30 14:40 ` [PATCH v2 net 1/2] ipv4: fix IP ID reuse in ip_select_ident_segs() Eric Dumazet
2026-09-30 15:11 ` Willem de Bruijn
2026-09-30 14:40 ` Eric Dumazet [this message]
2026-09-30 15:12 ` [PATCH v2 net 2/2] ipv4: reserve one IP ID per segment for UDP GSO packets Willem de Bruijn
2026-10-05 22:10 ` [PATCH v2 net 0/2] ipv4: fix IP ID reuse for " patchwork-bot+netdevbpf
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260930144018.1174068-3-edumazet@kernel.org \
--to=edumazet@kernel.org \
--cc=davem@davemloft.net \
--cc=dsahern@kernel.org \
--cc=edumazet@google.com \
--cc=horms@kernel.org \
--cc=idosch@nvidia.com \
--cc=jiayuan.chen@linux.dev \
--cc=kuba@kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=willemb@google.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox