Netdev List
 help / color / mirror / Atom feed
From: Jean-Paul Sergent <jpsergent@gmail.com>
To: Sasha Levin <sashal@kernel.org>
Cc: Jean-Paul Sergent <jpsergent@gmail.com>,
	netdev@vger.kernel.org, stable@vger.kernel.org,
	Ilya Maximets <i.maximets@ovn.org>, Kees Cook <kees@kernel.org>,
	Jakub Kicinski <kuba@kernel.org>,
	"David S. Miller" <davem@davemloft.net>,
	Eric Dumazet <edumazet@kernel.org>,
	Paolo Abeni <pabeni@redhat.com>, Simon Horman <horms@kernel.org>,
	Sridhar Samudrala <sridhar.samudrala@intel.com>
Subject: Re: [Bug Report] fortify false-positive + real overread in skb_metadata_dst_cmp (geneve, gro_cell_poll)
Date: Sat,  3 Oct 2026 16:05:33 -0700	[thread overview]
Message-ID: <20261003230533.1650829-1-jpsergent@gmail.com> (raw)
In-Reply-To: <2026-10-03-1-daily-reply-0028-re-skb-metadata-dst-cmp-fixes-tag@kernel.org>

On Sat, Oct 03, 2026 at 06:33:09PM -0400, Sasha Levin wrote:
> I've queued that one for 6.18: 6.18 has the counted_by annotation it trips on.

Thanks for queueing the tun_dst_unclone fix for 6.18.

> For your skb_metadata_dst_cmp() patch, the Fixes: tag should be ce87fc6ce3f9
> ("gro: Make GRO aware of lightweight tunnels."), not 69050f8d6d07 ("treewide:
> Replace kmalloc with kmalloc_obj for non-scalar types"). The overread predates
> kmalloc_flex, and 6.18 has no kmalloc_flex at all, so with the current tag the
> fix would miss 6.18, which is the tree that panics for you, and the older
> trees, where the overread is silent.

Agreed that 69050f8d6d07 is wrong - Ilya pointed that out earlier today as
well (our messages crossed in flight).

Looking at the git history, the options_len equality check that prevents the
overread was actually present in ce87fc6ce3f9 itself. It was dropped later by
commit 3fcece12bc1b ("net: store port/representator id in metadata_dst") when
skb_metadata_dst_cmp() was refactored into a type switch.

So the overread was introduced in 3fcece12bc1b (2017). v3 carries:

  Fixes: 3fcece12bc1b ("net: store port/representator id in metadata_dst")

Since 3fcece12bc1b is present in 6.18 and all active stable trees, this reaches
both 6.18 and the older trees. It also means the patch applies cleanly exactly
on the trees that have the bug - in 4.5-4.12 the check is still present and the
patch would not apply there.

Unless you see any issue with using 3fcece12bc1b, I will post v3 with that tag
once the 24-hour waiting window from v2 closes.

-- 
Jean-Paul Sergent

  reply	other threads:[~2026-10-03 23:05 UTC|newest]

Thread overview: 11+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-03  1:22 [Bug Report] fortify false-positive + real overread in skb_metadata_dst_cmp (geneve, gro_cell_poll) Jean-Paul Sergent
2026-10-03  1:24 ` [PATCH] net: dst_metadata: fix fortify trap + overread in skb_metadata_dst_cmp Jean-Paul Sergent
2026-10-03  1:24   ` [PATCH net v2] " Jean-Paul Sergent
2026-10-03 13:31     ` Ilya Maximets
2026-10-03 22:50       ` Jean-Paul Sergent
2026-10-04  1:23       ` Jean-Paul Sergent
2026-10-04  1:26     ` netdev-bot+sashiko
2026-10-04  1:26   ` [PATCH] " netdev-bot+sashiko
2026-10-03 22:33 ` [Bug Report] fortify false-positive + real overread in skb_metadata_dst_cmp (geneve, gro_cell_poll) Sasha Levin
2026-10-03 23:05   ` Jean-Paul Sergent [this message]
2026-10-04 16:29     ` Sasha Levin

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261003230533.1650829-1-jpsergent@gmail.com \
    --to=jpsergent@gmail.com \
    --cc=davem@davemloft.net \
    --cc=edumazet@kernel.org \
    --cc=horms@kernel.org \
    --cc=i.maximets@ovn.org \
    --cc=kees@kernel.org \
    --cc=kuba@kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    --cc=sashal@kernel.org \
    --cc=sridhar.samudrala@intel.com \
    --cc=stable@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox