From: "Jörg Willmann" <joe@clnt.de>
To: linux-can@vger.kernel.org
Cc: socketcan@hartkopp.net, mkl@pengutronix.de, netdev@vger.kernel.org
Subject: [BUG] can: RX frames silently dropped in raw_rcv() with RPS enabled since d4fb6514ff8e
Date: Mon, 28 Sep 2026 13:55:01 +0200 [thread overview]
Message-ID: <2859AD3D-C805-41A0-9036-C5E8EE152419@clnt.de> (raw)
In-Reply-To: <VI1P18901MB0640EC60F0E40E18EED92A0AAA8D2@VI1P18901MB0640.EURP189.PROD.OUTLOOK.COM>
Hi Oliver, hi Marc,
since commit d4fb6514ff8e ("can: use skb hash instead of private
variable in headroom") we are losing received CAN frames on raw sockets
when RPS is enabled on the CAN interface. The problem also shows up in
the stable backports (seen on [6.12.109]).
Setup:
- Kernel: 6.12.109
- Platform: OpenWrt 25.12.5, 4 CPU cores
- CAN controller / driver: mcp251xfd
- OpenWrt enables packet steering (RPS) by default on multi-core
systems, so rps_cpus is non-zero on can0
Symptom:
The application on a CAN_RAW socket misses frames. /proc/net/can/stats
counts more RX frames than the application receives. With
echo 0 > /sys/class/net/can0/queues/rx-0/rps_cpus
the losses disappear completely. [Optional: rate/amount of loss, number
of filters on the socket, whether join_filters is used.]
Analysis (as far as I understand it):
1. RX skbs from the driver start with skb->hash == 0.
2. With RPS enabled, get_rps_cpu() calls skb_get_hash() in the
netif_rx() path before can_rcv() is reached. The flow dissector
finds no L3/L4 headers in CAN skbs, so every CAN frame gets the
same non-zero hash with sw_hash = 1.
3. can_set_skb_uid() only assigns a new counter value while
skb->hash is 0, so the RPS hash is kept and the frame gets no
unique identifier.
4. raw_rcv() treats a frame as a duplicate when both the skb pointer
and skb->hash match the per-CPU uniq entry. Since the slab
allocator often returns the same address for the next skb, a new
frame with the same (constant) hash is dropped as a duplicate.
Before d4fb6514ff8e this could not happen because the unique id was
kept in can_skb_priv::skbcnt, independent of skb->hash.
Thanks,
Joerg
next parent reply other threads:[~2026-09-28 11:55 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <VI1P18901MB0640EC60F0E40E18EED92A0AAA8D2@VI1P18901MB0640.EURP189.PROD.OUTLOOK.COM>
2026-09-28 11:55 ` Jörg Willmann [this message]
2026-09-28 12:16 ` [BUG] can: RX frames silently dropped in raw_rcv() with RPS enabled since d4fb6514ff8e Oliver Hartkopp
2026-09-28 17:48 ` Oliver Hartkopp
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=2859AD3D-C805-41A0-9036-C5E8EE152419@clnt.de \
--to=joe@clnt.de \
--cc=linux-can@vger.kernel.org \
--cc=mkl@pengutronix.de \
--cc=netdev@vger.kernel.org \
--cc=socketcan@hartkopp.net \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox