From: Eric Dumazet <edumazet@kernel.org>
To: "David S . Miller" <davem@davemloft.net>,
Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>
Cc: Simon Horman <horms@kernel.org>,
netdev@vger.kernel.org, Eric Dumazet <edumazet@kernel.org>
Subject: [PATCH net-next] net: remove IPX raw 802.3 detection from eth_type_trans()
Date: Fri, 2 Oct 2026 20:55:09 +0200 [thread overview]
Message-ID: <20261002185509.17226-1-edumazet@kernel.org> (raw)
eth_type_trans() and vlan_set_encap_proto() still carry a "magic hack"
to spot Novell raw 802.3 frames (IPX directly over 802.3, without
an 802.2 LLC header) by looking for 0xFFFF in the first two bytes
of the payload, and report them as ETH_P_802_3.
IPX was removed in commit 7a2e838d28cf ("staging: ipx: delete it
from the tree") and there is no in-kernel packet handler for
ETH_P_802_3 on the Ethernet receive path anymore.
Simply classify all frames using a length field as ETH_P_802_2,
which is what the remaining LLC users (STP, GARP, SNAP) register for.
This removes a skb_header_pointer() call (and the skb->dev scratch
trick used to avoid a stack canary) from eth_type_trans(), and lets
skb_vlan_untag() only pull VLAN_HLEN bytes, as the extra two bytes
were only needed for this check since commit 55eff0eb7460
("net: Fix potential wrong skb->protocol in skb_vlan_untag()").
Note that such frames are now reported to AF_PACKET, tc, BPF and
nftables with skb->protocol == ETH_P_802_2 instead of ETH_P_802_3.
$ scripts/bloat-o-meter -t vmlinux.old vmlinux.new
add/remove: 0/0 grow/shrink: 2/5 up/down: 33/-187 (-154)
Function old new delta
skb_shift 1736 1768 +32
eth_type_trans.cold 45 46 +1
skb_vlan_untag 690 678 -12
__skb_vlan_pop 489 477 -12
nf_flow_encap_pop 462 449 -13
eth_type_trans 354 220 -134
Total: Before=31212910, After=31212756, chg -0.00%
Signed-off-by: Eric Dumazet <edumazet@kernel.org>
---
include/linux/if_vlan.h | 18 ++----------------
net/core/skbuff.c | 3 +--
net/ethernet/eth.c | 18 ++----------------
3 files changed, 5 insertions(+), 34 deletions(-)
diff --git a/include/linux/if_vlan.h b/include/linux/if_vlan.h
index 4846032bf4ffc80e55a8aafd1814bbcc27233599..97589236713668179dee21da6b3572edffe51404 100644
--- a/include/linux/if_vlan.h
+++ b/include/linux/if_vlan.h
@@ -698,7 +698,6 @@ static inline void vlan_set_encap_proto(struct sk_buff *skb,
struct vlan_hdr *vhdr)
{
__be16 proto;
- unsigned short *rawp;
/*
* Was a VLAN packet, grab the encapsulated protocol, which the layer
@@ -711,21 +710,8 @@ static inline void vlan_set_encap_proto(struct sk_buff *skb,
return;
}
- rawp = (unsigned short *)(vhdr + 1);
- if (*rawp == 0xFFFF)
- /*
- * This is a magic hack to spot IPX packets. Older Novell
- * breaks the protocol design and runs IPX over 802.3 without
- * an 802.2 LLC layer. We look for FFFF which isn't a used
- * 802.2 SSAP/DSAP. This won't work for fault tolerant netware
- * but does for the rest.
- */
- skb->protocol = htons(ETH_P_802_3);
- else
- /*
- * Real 802.2 LLC
- */
- skb->protocol = htons(ETH_P_802_2);
+ /* No ethertype: this is an 802.2 LLC frame (length field). */
+ skb->protocol = htons(ETH_P_802_2);
}
/**
diff --git a/net/core/skbuff.c b/net/core/skbuff.c
index 5c4024a03e10550d22dd926410c4fada35f69641..43ebe61c7fc481e91cf560f7e21b5a9dd02bbbc5 100644
--- a/net/core/skbuff.c
+++ b/net/core/skbuff.c
@@ -6355,8 +6355,7 @@ struct sk_buff *skb_vlan_untag(struct sk_buff *skb)
skb = skb_share_check(skb, GFP_ATOMIC);
if (unlikely(!skb))
goto err_free;
- /* We may access the two bytes after vlan_hdr in vlan_set_encap_proto(). */
- if (unlikely(!pskb_may_pull(skb, VLAN_HLEN + sizeof(unsigned short))))
+ if (unlikely(!pskb_may_pull(skb, VLAN_HLEN)))
goto err_free;
vhdr = (struct vlan_hdr *)skb->data;
diff --git a/net/ethernet/eth.c b/net/ethernet/eth.c
index d9faadbe9b6c86a746cace6d7a7cfffdb84e4519..39aab0f8035ad9fc99a7dd81b397050a719ecc25 100644
--- a/net/ethernet/eth.c
+++ b/net/ethernet/eth.c
@@ -154,9 +154,7 @@ EXPORT_SYMBOL(eth_get_headlen);
*/
__be16 eth_type_trans(struct sk_buff *skb, struct net_device *dev)
{
- const unsigned short *sap;
const struct ethhdr *eth;
- __be16 res;
skb->dev = dev;
skb_reset_mac_header(skb);
@@ -176,20 +174,8 @@ __be16 eth_type_trans(struct sk_buff *skb, struct net_device *dev)
if (likely(eth_proto_is_802_3(eth->h_proto)))
return eth->h_proto;
- /*
- * This is a magic hack to spot IPX packets. Older Novell breaks
- * the protocol design and runs IPX over 802.3 without an 802.2 LLC
- * layer. We look for FFFF which isn't a used 802.2 SSAP/DSAP. This
- * won't work for fault tolerant netware but does for the rest.
- * We use skb->dev as temporary storage to not hit
- * CONFIG_STACKPROTECTOR_STRONG=y costs on some platforms.
- */
- sap = skb_header_pointer(skb, 0, sizeof(*sap), &skb->dev);
- res = (sap && *sap == 0xFFFF) ? htons(ETH_P_802_3) : htons(ETH_P_802_2);
-
- /* restore skb->dev in case it was mangled by skb_header_pointer(). */
- skb->dev = dev;
- return res;
+ /* No ethertype: this is an 802.2 LLC frame (length field). */
+ return htons(ETH_P_802_2);
}
EXPORT_SYMBOL(eth_type_trans);
--
2.53.0
next reply other threads:[~2026-10-02 18:55 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-02 18:55 Eric Dumazet [this message]
2026-10-06 0:40 ` [PATCH net-next] net: remove IPX raw 802.3 detection from eth_type_trans() patchwork-bot+netdevbpf
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261002185509.17226-1-edumazet@kernel.org \
--to=edumazet@kernel.org \
--cc=davem@davemloft.net \
--cc=horms@kernel.org \
--cc=kuba@kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox