Netdev List
 help / color / mirror / Atom feed
From: Wang Zhan <wang.zhan@smartx.com>
To: netdev@vger.kernel.org,
	Joas Antonio dos Santos <joasantonio108@gmail.com>
Cc: Wang Zhan <wang.zhan@smartx.com>,
	Paul Moore <paul@paul-moore.com>,
	Eric Dumazet <edumazet@kernel.org>,
	"David S. Miller" <davem@davemloft.net>,
	Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
	Simon Horman <horms@kernel.org>,
	linux-security-module@vger.kernel.org,
	Alice Mikityanska <alice.kernel@fastmail.im>
Subject: Re: [PATCH net v2] calipso: keep BIG TCP payload_len in calipso_skbuff_setattr()
Date: Sat, 10 Oct 2026 17:05:34 +0800	[thread overview]
Message-ID: <20261010090534.317149-1-wang.zhan@smartx.com> (raw)
In-Reply-To: <179156155963.36253.400481753322266658@gmail.com>

On Fri, 09 Oct 2026 12:59:19 -0300 Joas Antonio dos Santos wrote:
> calipso_skbuff_setattr() adjusts payload_len by the length of the
> option it inserts or resizes:
>
> 	payload = ntohs(ip6_hdr->payload_len);
> 	ip6_hdr->payload_len = htons(payload + len_delta);
>
> GRO can build BIG TCP packets larger than IPV6_MAXPLEN, and stores
> payload_len == 0 for them; ipv6_payload_len() then falls back to
> skb->len.  For such a packet forwarded to a destination mapped to
> CALIPSO, the code above writes len_delta (or 65536 + len_delta when
> shrinking) into payload_len, and ipv6_payload_len() no longer falls
> back to skb->len.  nf_tables, conntrack and sch_cake rely on it.
>
> The same arithmetic also wraps when a packet grows past IPV6_MAXPLEN,
> and a BIG TCP packet that shrinks below IPV6_MAXPLEN should get its
> real length back.
>
> Set payload_len from the skb length with ipv6_set_payload_len(), which
> stores 0 above IPV6_MAXPLEN and the real length otherwise, as
> ipv6_gro_complete() does.  The network header was just reset to
> skb->data, so skb->len - sizeof(*ip6_hdr) is the payload length.
>
> Tested on one kernel (arm64, QEMU) with SELinux permissive, a minimal
> mdp-generated policy (network_peer_controls=1), "netlabelctl calipso
> add pass doi:16" and a NetLabel mapping of fd00:2::/64 to CALIPSO
> DOI 16.  calipso_skbuff_setattr() was called through
> netlbl_skbuff_setattr() from a test-only debugfs hook (not part of
> this patch) adding a level-only label; payload_len after the call:
>
>   case                         before fix   after fix   real length
>   1000, unlabeled                    1016        1016          1016
>   70000 GSO, payload_len 0             16           0         70016
>   65530 GSO, grows past MAXPLEN        10           0         65546
>   65540 GSO with a 24 byte hop
>   header, shrinks below MAXPLEN     65528       65532         65532
>   1000 with a 24 byte hop header      992         992           992
>
> (0 means ipv6_payload_len() returns the real length.)  On the forward
> path, with a client injecting unlabeled UDP through a router to a
> server, the router adds the CALIPSO option and the server delivers all
> datagrams (Udp6InDatagrams 5, Ip6InTruncatedPkts 0) with this patch.
>
> Fixes: 81fbc812132c ("ipv6/gro: insert temporary HBH/jumbo header")
> Suggested-by: Eric Dumazet <edumazet@kernel.org>
> Suggested-by: Wang Zhan <wang.zhan@smartx.com>
> Signed-off-by: Joas Antonio dos Santos <joasantonio108@gmail.com>
> Assisted-by: Claude:claude-opus-5-5

Reviewed-by: Wang Zhan <wang.zhan@smartx.com>

> @@ -1357,8 +1357,8 @@ static int calipso_skbuff_setattr(struct sk_buff *skb,
>  			sizeof(*ip6_hdr) + start);
>  		skb_reset_network_header(skb);
>  		ip6_hdr = ipv6_hdr(skb);
> -		payload = ntohs(ip6_hdr->payload_len);
> -		ip6_hdr->payload_len = htons(payload + len_delta);
> +		/* 0 above IPV6_MAXPLEN (BIG TCP), the real length otherwise */

nit: consider dropping the comment, it just repeats what
ipv6_set_payload_len() does.

      reply	other threads:[~2026-10-10  9:06 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-09 15:59 [PATCH net v2] calipso: keep BIG TCP payload_len in calipso_skbuff_setattr() Joas Antonio dos Santos
2026-10-10  9:05 ` Wang Zhan [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261010090534.317149-1-wang.zhan@smartx.com \
    --to=wang.zhan@smartx.com \
    --cc=alice.kernel@fastmail.im \
    --cc=davem@davemloft.net \
    --cc=edumazet@kernel.org \
    --cc=horms@kernel.org \
    --cc=joasantonio108@gmail.com \
    --cc=kuba@kernel.org \
    --cc=linux-security-module@vger.kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    --cc=paul@paul-moore.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox