From: Xuanqiang Luo <xuanqiang.luo@linux.dev>
To: Eric Dumazet <edumazet@google.com>
Cc: Simon Horman <horms@kernel.org>,
netdev@vger.kernel.org, eric.dumazet@gmail.com,
syzbot+586af68eb819833c2d91@syzkaller.appspotmail.com,
Allison Henderson <achender@kernel.org>,
rds-devel@oss.oracle.com,
"David S . Miller" <davem@davemloft.net>,
Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>
Subject: Re: [PATCH v2 net] net: skbuff: do not leave stale header offsets after pskb_carve()
Date: Tue, 15 Sep 2026 22:18:17 +0800 [thread overview]
Message-ID: <779472d4-fc73-412f-bae1-d3fb9aa653f8@linux.dev> (raw)
In-Reply-To: <20260915130423.3956471-1-edumazet@google.com>
在 2026/9/15 21:04, Eric Dumazet 写道:
> pskb_carve_inside_header() and pskb_carve_inside_nonlinear() remove
> the first bytes of a packet and reallocate skb->head.
>
> All the headers that were present before the operation are gone,
> but both functions call skb_headers_offset_update(skb, 0), which
> is a no-op : skb->mac_header, skb->network_header,
> skb->transport_header and skb->csum_start keep their old values and
> now describe bytes which are no longer there.
>
> Both helpers size the new head from the old skb_end_offset(), so the
> stale offsets still land inside the new allocation. They point past
> skb_tail_pointer() though, to bytes that were never initialized.
>
> pskb_carve_inside_nonlinear() is the worst case, because it leaves a
> zombie skb with an empty linear part (skb->data ==
> skb_tail_pointer(skb), skb_headlen(skb) == 0), while
> skb_mac_header_was_set() is still true and skb->mac_header is way
> ahead of skb->data.
>
> The only user of pskb_extract() is rds_tcp_data_recv(), and the
> carved skb is queued on tinc->ti_skb_list. When the RDS incoming
> message is released, rds_tcp_inc_free() calls skb_queue_purge(),
> which frees the skbs with SKB_DROP_REASON_QUEUE_PURGE. This is
> visible from drop_monitor, which then tries to pull back to the
> (bogus) mac header :
>
> skbuff: __skb_pull(len=234)
> skb len=6968 data_len=6968 headroom=0 headlen=0 tailroom=0
> end-tail=384 mac=(234,14) mac_len=14 net=(248,40) trans=288
> shinfo(txflags=0 nr_frags=1 gso(size=1428 type=16 segs=5))
> csum(0x100120 start=288 offset=16 ip_summed=3 complete_sw=0 valid=1 level=0)
> hash(0x7b446c6c sw=0 l4=1) proto=0x86dd pkttype=0 iif=60
> ------------[ cut here ]------------
> kernel BUG at ./include/linux/skbuff.h:2847!
>
> Add skb_carve_reset_headers() to mark the mac and transport headers
> as not set, reset the network header, clear skb->mac_len, and drop
> a now meaningless CHECKSUM_PARTIAL (csum_start no longer describes
> anything).
>
> Invalidate the inner offsets as well. Unlike mac_header and
> transport_header they have no "unset" sentinel, so a leftover
> non-zero value still looks like a real header. Zero
> skb->inner_mac_header, skb->inner_network_header,
> skb->inner_transport_header, skb->inner_protocol and
> skb->encapsulation, so that all the header state is invalidated in
> one place.
>
> v2: fixed an inaccurate changelog. The stale offsets stay inside the
> new skb->head, which is never smaller than the old one, they
> simply point past skb_tail_pointer() to bytes that are gone.
> Thanks to Xuanqiang Luo for insisting on this.
> Also invalidate the inner header state, as suggested by the
> netdev AI review :
> https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260911114922.621937-1-edumazet%40google.com
>
> Fixes: 6fa01ccd8830 ("skbuff: Add pskb_extract() helper function")
> Reported-by: syzbot+586af68eb819833c2d91@syzkaller.appspotmail.com
> Closes: https://lore.kernel.org/netdev/6aa3e9d3.f2639fcc.29487d.0028.GAE@google.com/
> Cc: Xuanqiang Luo <xuanqiang.luo@linux.dev>
> Cc: Allison Henderson <achender@kernel.org>
> Cc: rds-devel@oss.oracle.com
> Signed-off-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Xuanqiang Luo <luoxuanqiang@kylinos.cn>
Thanks!
next prev parent reply other threads:[~2026-09-15 14:18 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-15 13:04 [PATCH v2 net] net: skbuff: do not leave stale header offsets after pskb_carve() Eric Dumazet
2026-09-15 14:18 ` Xuanqiang Luo [this message]
2026-09-16 13:05 ` netdev-bot+sashiko
2026-09-17 14:03 ` Paolo Abeni
2026-09-17 14:10 ` patchwork-bot+netdevbpf
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=779472d4-fc73-412f-bae1-d3fb9aa653f8@linux.dev \
--to=xuanqiang.luo@linux.dev \
--cc=achender@kernel.org \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=eric.dumazet@gmail.com \
--cc=horms@kernel.org \
--cc=kuba@kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=rds-devel@oss.oracle.com \
--cc=syzbot+586af68eb819833c2d91@syzkaller.appspotmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox