From: Jiayuan Chen <jiayuan.chen@linux.dev>
To: Eric Dumazet <edumazet@kernel.org>,
"David S . Miller" <davem@davemloft.net>,
Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>
Cc: Simon Horman <horms@kernel.org>,
Willem de Bruijn <willemb@google.com>,
David Ahern <dsahern@kernel.org>,
Ido Schimmel <idosch@nvidia.com>,
netdev@vger.kernel.org, edumazet@google.com
Subject: Re: [PATCH net 2/2] ipv4: reserve one IP ID per segment for UDP GSO packets
Date: Wed, 30 Sep 2026 14:18:38 +0800 [thread overview]
Message-ID: <a988ac49-d701-4588-9e66-85bf3d6d0e12@linux.dev> (raw)
In-Reply-To: <20260929131247.401104-3-edumazet@kernel.org>
On 9/29/26 9:12 PM, Eric Dumazet wrote:
> __ip_make_skb() reserves a single IP ID for UDP GSO packets, but GSO
> assigns one IP ID per segment. Following packets then reuse these IDs,
> either from inet->inet_id or from the shared generator.
>
> Unless IP_PMTUDISC_DO/PROBE is used, DF is not set on UDP GSO packets,
> so segments can be fragmented on the path and IP ID reuse can lead to
> incorrect reassembly.
>
> Reserve one IP ID per segment, using the same test as udp_send_skb().
>
> Fixes: bec1f6f69736 ("udp: generate gso with UDP_SEGMENT")
> Signed-off-by: Eric Dumazet <edumazet@kernel.org>
Reviewed-by: Jiayuan Chen <jiayuan.chen@linux.dev>
> ---
> net/ipv4/ip_output.c | 15 ++++++++++++++-
> 1 file changed, 14 insertions(+), 1 deletion(-)
>
> diff --git a/net/ipv4/ip_output.c b/net/ipv4/ip_output.c
> index a24cc8ee11d3ea3069bcc0d4d12e6867c2c475f7..b1cf0c6bfc79c8d234cc81ff32332116c1ee3401 100644
> --- a/net/ipv4/ip_output.c
> +++ b/net/ipv4/ip_output.c
> @@ -1410,6 +1410,7 @@ struct sk_buff *__ip_make_skb(struct sock *sk,
> struct iphdr *iph;
> u8 pmtudisc, ttl;
> __be16 df = 0;
> + int segs;
>
> skb = __skb_dequeue(queue);
> if (!skb)
> @@ -1464,7 +1465,19 @@ struct sk_buff *__ip_make_skb(struct sock *sk,
> iph->ttl = ttl;
> iph->protocol = sk->sk_protocol;
> ip_copy_addrs(iph, fl4);
> - ip_select_ident(net, skb, sk);
> +
> + /* UDP GSO packets are segmented later (see udp_send_skb()):
> + * reserve one IP ID per segment.
> + */
> + segs = 1;
> + if (cork->gso_size) {
> + int datalen = skb->len - skb_transport_offset(skb) -
> + sizeof(struct udphdr);
> +
> + if (datalen > cork->gso_size)
> + segs = DIV_ROUND_UP(datalen, cork->gso_size);
> + }
> + ip_select_ident_segs(net, skb, sk, segs);
>
> if (opt) {
> iph->ihl += opt->optlen >> 2;
next prev parent reply other threads:[~2026-09-30 6:18 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-29 13:12 [PATCH net 0/2] ipv4: fix IP ID reuse for GSO packets Eric Dumazet
2026-09-29 13:12 ` [PATCH net 1/2] ipv4: fix IP ID reuse in ip_select_ident_segs() Eric Dumazet
2026-09-30 6:20 ` Jiayuan Chen
2026-09-30 12:30 ` David Ahern
2026-09-29 13:12 ` [PATCH net 2/2] ipv4: reserve one IP ID per segment for UDP GSO packets Eric Dumazet
2026-09-30 6:18 ` Jiayuan Chen [this message]
2026-09-30 12:28 ` David Ahern
2026-09-30 12:58 ` Eric Dumazet
2026-09-30 13:50 ` David Ahern
2026-09-30 14:24 ` Eric Dumazet
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=a988ac49-d701-4588-9e66-85bf3d6d0e12@linux.dev \
--to=jiayuan.chen@linux.dev \
--cc=davem@davemloft.net \
--cc=dsahern@kernel.org \
--cc=edumazet@google.com \
--cc=edumazet@kernel.org \
--cc=horms@kernel.org \
--cc=idosch@nvidia.com \
--cc=kuba@kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=willemb@google.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox