From: Wang Zhan <wang.zhan@smartx.com>
To: netdev@vger.kernel.org,
Joas Antonio dos Santos <joasantonio108@gmail.com>
Cc: Wang Zhan <wang.zhan@smartx.com>,
Paul Moore <paul@paul-moore.com>,
Eric Dumazet <edumazet@kernel.org>,
"David S. Miller" <davem@davemloft.net>,
Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
Simon Horman <horms@kernel.org>,
linux-security-module@vger.kernel.org,
Alice Mikityanska <alice.kernel@fastmail.im>
Subject: Re: [PATCH net v2] calipso: keep BIG TCP payload_len in calipso_skbuff_setattr()
Date: Sat, 10 Oct 2026 17:05:34 +0800 [thread overview]
Message-ID: <20261010090534.317149-1-wang.zhan@smartx.com> (raw)
In-Reply-To: <179156155963.36253.400481753322266658@gmail.com>
On Fri, 09 Oct 2026 12:59:19 -0300 Joas Antonio dos Santos wrote:
> calipso_skbuff_setattr() adjusts payload_len by the length of the
> option it inserts or resizes:
>
> payload = ntohs(ip6_hdr->payload_len);
> ip6_hdr->payload_len = htons(payload + len_delta);
>
> GRO can build BIG TCP packets larger than IPV6_MAXPLEN, and stores
> payload_len == 0 for them; ipv6_payload_len() then falls back to
> skb->len. For such a packet forwarded to a destination mapped to
> CALIPSO, the code above writes len_delta (or 65536 + len_delta when
> shrinking) into payload_len, and ipv6_payload_len() no longer falls
> back to skb->len. nf_tables, conntrack and sch_cake rely on it.
>
> The same arithmetic also wraps when a packet grows past IPV6_MAXPLEN,
> and a BIG TCP packet that shrinks below IPV6_MAXPLEN should get its
> real length back.
>
> Set payload_len from the skb length with ipv6_set_payload_len(), which
> stores 0 above IPV6_MAXPLEN and the real length otherwise, as
> ipv6_gro_complete() does. The network header was just reset to
> skb->data, so skb->len - sizeof(*ip6_hdr) is the payload length.
>
> Tested on one kernel (arm64, QEMU) with SELinux permissive, a minimal
> mdp-generated policy (network_peer_controls=1), "netlabelctl calipso
> add pass doi:16" and a NetLabel mapping of fd00:2::/64 to CALIPSO
> DOI 16. calipso_skbuff_setattr() was called through
> netlbl_skbuff_setattr() from a test-only debugfs hook (not part of
> this patch) adding a level-only label; payload_len after the call:
>
> case before fix after fix real length
> 1000, unlabeled 1016 1016 1016
> 70000 GSO, payload_len 0 16 0 70016
> 65530 GSO, grows past MAXPLEN 10 0 65546
> 65540 GSO with a 24 byte hop
> header, shrinks below MAXPLEN 65528 65532 65532
> 1000 with a 24 byte hop header 992 992 992
>
> (0 means ipv6_payload_len() returns the real length.) On the forward
> path, with a client injecting unlabeled UDP through a router to a
> server, the router adds the CALIPSO option and the server delivers all
> datagrams (Udp6InDatagrams 5, Ip6InTruncatedPkts 0) with this patch.
>
> Fixes: 81fbc812132c ("ipv6/gro: insert temporary HBH/jumbo header")
> Suggested-by: Eric Dumazet <edumazet@kernel.org>
> Suggested-by: Wang Zhan <wang.zhan@smartx.com>
> Signed-off-by: Joas Antonio dos Santos <joasantonio108@gmail.com>
> Assisted-by: Claude:claude-opus-5-5
Reviewed-by: Wang Zhan <wang.zhan@smartx.com>
> @@ -1357,8 +1357,8 @@ static int calipso_skbuff_setattr(struct sk_buff *skb,
> sizeof(*ip6_hdr) + start);
> skb_reset_network_header(skb);
> ip6_hdr = ipv6_hdr(skb);
> - payload = ntohs(ip6_hdr->payload_len);
> - ip6_hdr->payload_len = htons(payload + len_delta);
> + /* 0 above IPV6_MAXPLEN (BIG TCP), the real length otherwise */
nit: consider dropping the comment, it just repeats what
ipv6_set_payload_len() does.
prev parent reply other threads:[~2026-10-10 9:06 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-09 15:59 [PATCH net v2] calipso: keep BIG TCP payload_len in calipso_skbuff_setattr() Joas Antonio dos Santos
2026-10-10 9:05 ` Wang Zhan [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261010090534.317149-1-wang.zhan@smartx.com \
--to=wang.zhan@smartx.com \
--cc=alice.kernel@fastmail.im \
--cc=davem@davemloft.net \
--cc=edumazet@kernel.org \
--cc=horms@kernel.org \
--cc=joasantonio108@gmail.com \
--cc=kuba@kernel.org \
--cc=linux-security-module@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=paul@paul-moore.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox