Netdev List
 help / color / mirror / Atom feed
From: Xuanqiang Luo <xuanqiang.luo@linux.dev>
To: Eric Dumazet <edumazet@google.com>
Cc: Simon Horman <horms@kernel.org>,
	netdev@vger.kernel.org, eric.dumazet@gmail.com,
	syzbot+586af68eb819833c2d91@syzkaller.appspotmail.com,
	Allison Henderson <achender@kernel.org>,
	rds-devel@oss.oracle.com,
	"David S . Miller" <davem@davemloft.net>,
	Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>
Subject: Re: [PATCH v2 net] net: skbuff: do not leave stale header offsets after pskb_carve()
Date: Tue, 15 Sep 2026 22:18:17 +0800	[thread overview]
Message-ID: <779472d4-fc73-412f-bae1-d3fb9aa653f8@linux.dev> (raw)
In-Reply-To: <20260915130423.3956471-1-edumazet@google.com>

在 2026/9/15 21:04, Eric Dumazet 写道:
> pskb_carve_inside_header() and pskb_carve_inside_nonlinear() remove
> the first bytes of a packet and reallocate skb->head.
> 
> All the headers that were present before the operation are gone,
> but both functions call skb_headers_offset_update(skb, 0), which
> is a no-op : skb->mac_header, skb->network_header,
> skb->transport_header and skb->csum_start keep their old values and
> now describe bytes which are no longer there.
> 
> Both helpers size the new head from the old skb_end_offset(), so the
> stale offsets still land inside the new allocation. They point past
> skb_tail_pointer() though, to bytes that were never initialized.
> 
> pskb_carve_inside_nonlinear() is the worst case, because it leaves a
> zombie skb with an empty linear part (skb->data ==
> skb_tail_pointer(skb), skb_headlen(skb) == 0), while
> skb_mac_header_was_set() is still true and skb->mac_header is way
> ahead of skb->data.
> 
> The only user of pskb_extract() is rds_tcp_data_recv(), and the
> carved skb is queued on tinc->ti_skb_list. When the RDS incoming
> message is released, rds_tcp_inc_free() calls skb_queue_purge(),
> which frees the skbs with SKB_DROP_REASON_QUEUE_PURGE. This is
> visible from drop_monitor, which then tries to pull back to the
> (bogus) mac header :
> 
> skbuff: __skb_pull(len=234)
> skb len=6968 data_len=6968 headroom=0 headlen=0 tailroom=0
> end-tail=384 mac=(234,14) mac_len=14 net=(248,40) trans=288
> shinfo(txflags=0 nr_frags=1 gso(size=1428 type=16 segs=5))
> csum(0x100120 start=288 offset=16 ip_summed=3 complete_sw=0 valid=1 level=0)
> hash(0x7b446c6c sw=0 l4=1) proto=0x86dd pkttype=0 iif=60
> ------------[ cut here ]------------
> kernel BUG at ./include/linux/skbuff.h:2847!
> 
> Add skb_carve_reset_headers() to mark the mac and transport headers
> as not set, reset the network header, clear skb->mac_len, and drop
> a now meaningless CHECKSUM_PARTIAL (csum_start no longer describes
> anything).
> 
> Invalidate the inner offsets as well. Unlike mac_header and
> transport_header they have no "unset" sentinel, so a leftover
> non-zero value still looks like a real header. Zero
> skb->inner_mac_header, skb->inner_network_header,
> skb->inner_transport_header, skb->inner_protocol and
> skb->encapsulation, so that all the header state is invalidated in
> one place.
> 
> v2: fixed an inaccurate changelog. The stale offsets stay inside the
>      new skb->head, which is never smaller than the old one, they
>      simply point past skb_tail_pointer() to bytes that are gone.
>      Thanks to Xuanqiang Luo for insisting on this.
>      Also invalidate the inner header state, as suggested by the
>      netdev AI review :
>      https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260911114922.621937-1-edumazet%40google.com
> 
> Fixes: 6fa01ccd8830 ("skbuff: Add pskb_extract() helper function")
> Reported-by: syzbot+586af68eb819833c2d91@syzkaller.appspotmail.com
> Closes: https://lore.kernel.org/netdev/6aa3e9d3.f2639fcc.29487d.0028.GAE@google.com/
> Cc: Xuanqiang Luo <xuanqiang.luo@linux.dev>
> Cc: Allison Henderson <achender@kernel.org>
> Cc: rds-devel@oss.oracle.com
> Signed-off-by: Eric Dumazet <edumazet@google.com>

Reviewed-by: Xuanqiang Luo <luoxuanqiang@kylinos.cn>

Thanks!

  reply	other threads:[~2026-09-15 14:18 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-15 13:04 [PATCH v2 net] net: skbuff: do not leave stale header offsets after pskb_carve() Eric Dumazet
2026-09-15 14:18 ` Xuanqiang Luo [this message]
2026-09-16 13:05 ` netdev-bot+sashiko
2026-09-17 14:03   ` Paolo Abeni
2026-09-17 14:10 ` patchwork-bot+netdevbpf

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=779472d4-fc73-412f-bae1-d3fb9aa653f8@linux.dev \
    --to=xuanqiang.luo@linux.dev \
    --cc=achender@kernel.org \
    --cc=davem@davemloft.net \
    --cc=edumazet@google.com \
    --cc=eric.dumazet@gmail.com \
    --cc=horms@kernel.org \
    --cc=kuba@kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    --cc=rds-devel@oss.oracle.com \
    --cc=syzbot+586af68eb819833c2d91@syzkaller.appspotmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox