From: Victor Nogueira <victor@mojatatu.com>
To: davem@davemloft.net, edumazet@google.com, kuba@kernel.org,
pabeni@redhat.com, jhs@mojatatu.com, jiri@resnulli.us,
netdev@vger.kernel.org
Cc: horms@kernel.org, hybris@mojatatu.ai, sashiko-bot@kernel.org
Subject: [PATCH net-next 3/3] net/sched: act_api: budget TCA_ROOT_EXT_WARN_MSG in notify skbs
Date: Sat, 19 Sep 2026 20:04:29 -0300 [thread overview]
Message-ID: <QDISC-RYTB.v1.20260918093205@mojatatu.com.3> (raw)
In-Reply-To: <QDISC-RYTB.v1.20260918093205@mojatatu.com>
tca_get_fill may emit TCA_ROOT_EXT_WARN_MSG from extack->_msg.
The string is whatever NL_SET_ERR_MSG and friends stored, so its
length is bounded only by the caller, and nothing in the budget that
tcf_add_notify_msg and tcf_del_notify_msg hand to alloc_skb
accounts for it. The notify skb can therefore be sized smaller than
what tca_get_fill goes on to write into it.
The attribute reaches a successful add because tcf_action_init keeps
going when an action that is not skip_sw fails to offload:
err = tcf_action_offload_add(act, extack);
if (tc_act_skip_sw(act->tcfa_flags) && err)
goto err;
The action is created while extack->_msg still holds the offload
diagnostic, and tcf_add_notify echoes it back. A pedit action with mixed
key commands (one SET and one ADD) takes that path: the non-bind
tcf_pedit_offload_act_setup sets "Unsupported pedit command offload" and
returns -EOPNOTSUPP.
In practice, no underbudgeting has been observed because of this, and the
gap is not easy to reach given some other spots account for more than
necessary. However, for correctness, budget the attribute so the size
handed to alloc_skb covers what tca_get_fill can write.
Reported-by: Sashiko <sashiko-bot@kernel.org>
Link: https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260824153903.4143642-1-victor@mojatatu.com
Co-developed-by: Jamal Hadi Salim <jhs@mojatatu.com>
Signed-off-by: Jamal Hadi Salim <jhs@mojatatu.com>
Signed-off-by: Victor Nogueira <victor@mojatatu.com>
---
net/sched/act_api.c | 15 +++++++++++++--
1 file changed, 13 insertions(+), 2 deletions(-)
diff --git a/net/sched/act_api.c b/net/sched/act_api.c
index 3f653721c45f..db06ddcf6ae6 100644
--- a/net/sched/act_api.c
+++ b/net/sched/act_api.c
@@ -475,6 +475,15 @@ static size_t tcf_action_full_attrs_size(size_t sz)
+ sz;
}
+/* tca_get_fill() may append TCA_ROOT_EXT_WARN_MSG from extack->_msg */
+static size_t tcf_action_warn_attr_size(const struct netlink_ext_ack *extack)
+{
+ if (unlikely(extack && extack->_msg))
+ return nla_total_size(strlen(extack->_msg) + 1);
+
+ return 0;
+}
+
static size_t tcf_action_fill_size(const struct tc_action *act)
{
size_t sz = tcf_action_shared_attrs_size(act);
@@ -1980,7 +1989,8 @@ static struct sk_buff *tcf_del_notify_msg(struct net *net, struct nlmsghdr *n,
{
struct sk_buff *skb;
- skb = alloc_skb(max(attr_size, NLMSG_GOODSIZE), GFP_KERNEL);
+ skb = alloc_skb(max(attr_size + tcf_action_warn_attr_size(extack),
+ NLMSG_GOODSIZE), GFP_KERNEL);
if (!skb)
return ERR_PTR(-ENOBUFS);
@@ -2078,7 +2088,8 @@ static struct sk_buff *tcf_add_notify_msg(struct net *net, struct nlmsghdr *n,
{
struct sk_buff *skb;
- skb = alloc_skb(max(attr_size, NLMSG_GOODSIZE), GFP_KERNEL);
+ skb = alloc_skb(max(attr_size + tcf_action_warn_attr_size(extack),
+ NLMSG_GOODSIZE), GFP_KERNEL);
if (!skb)
return ERR_PTR(-ENOBUFS);
--
2.55.0
next prev parent reply other threads:[~2026-09-19 23:04 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-19 23:04 [PATCH net-next 0/3] net/sched: complete action notification accounting Victor Nogueira
2026-09-19 23:04 ` [PATCH net-next 1/3] net/sched: act_mirred: account for TCA_MIRRED_BLOCKID in get_fill_size Victor Nogueira
2026-09-19 23:04 ` [PATCH net-next 2/3] net/sched: add get_fill_size() to the five actions that lack one Victor Nogueira
2026-09-19 23:04 ` Victor Nogueira [this message]
2026-09-21 16:13 ` [PATCH net-next 0/3] net/sched: complete action notification accounting Simon Horman
2026-09-22 11:00 ` patchwork-bot+netdevbpf
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=QDISC-RYTB.v1.20260918093205@mojatatu.com.3 \
--to=victor@mojatatu.com \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=horms@kernel.org \
--cc=hybris@mojatatu.ai \
--cc=jhs@mojatatu.com \
--cc=jiri@resnulli.us \
--cc=kuba@kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=sashiko-bot@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox