From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-1.0 required=3.0 tests=HEADER_FROM_DIFFERENT_DOMAINS, MAILING_LIST_MULTI,SPF_PASS autolearn=ham autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 137BDC43387 for ; Wed, 16 Jan 2019 17:30:46 +0000 (UTC) Received: from vger.kernel.org (vger.kernel.org [209.132.180.67]) by mail.kernel.org (Postfix) with ESMTP id C542A20675 for ; Wed, 16 Jan 2019 17:30:45 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1727268AbfAPRao (ORCPT ); Wed, 16 Jan 2019 12:30:44 -0500 Received: from mx1.redhat.com ([209.132.183.28]:39330 "EHLO mx1.redhat.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1727237AbfAPRao (ORCPT ); Wed, 16 Jan 2019 12:30:44 -0500 Received: from smtp.corp.redhat.com (int-mx05.intmail.prod.int.phx2.redhat.com [10.5.11.15]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by mx1.redhat.com (Postfix) with ESMTPS id 806DF7970E; Wed, 16 Jan 2019 17:30:44 +0000 (UTC) Received: from localhost.localdomain (unknown [10.32.181.77]) by smtp.corp.redhat.com (Postfix) with ESMTP id 42B7A5D77A; Wed, 16 Jan 2019 17:30:29 +0000 (UTC) Message-ID: Subject: Re: [PATCH net] net: ip6_gre: use erspan key field for tunnel lookup From: Davide Caratti To: Lorenzo Bianconi Cc: davem@davemloft.net, netdev@vger.kernel.org, u9012063@gmail.com, Jiri Benc In-Reply-To: <20190116164003.GC2454@localhost.localdomain> References: <044b51ecc8d0bc21faf8755e2f3014e8b65d71ec.1547569872.git.lorenzo.bianconi@redhat.com> <568fc3d4505d6a1725a4e1e59f43f0af0ac10f8c.camel@redhat.com> <20190116164003.GC2454@localhost.localdomain> Organization: red hat Content-Type: text/plain; charset="UTF-8" Date: Wed, 16 Jan 2019 18:30:28 +0100 Mime-Version: 1.0 User-Agent: Evolution 3.30.3 (3.30.3-1.fc29) Content-Transfer-Encoding: 7bit X-Scanned-By: MIMEDefang 2.79 on 10.5.11.15 X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.5.16 (mx1.redhat.com [10.5.110.25]); Wed, 16 Jan 2019 17:30:44 +0000 (UTC) Sender: netdev-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: netdev@vger.kernel.org On Wed, 2019-01-16 at 17:40 +0100, Lorenzo Bianconi wrote: > Does '((*(u8 *)options & 0xF0) != 0x40)' have the same issue? (cc-ing Jiri Benc, he probably knows more on this part) in my opinion, yes, theoretically there might be situations where the above line reads 1 byte outside the linear area of the skb. Probably the fix for this is unrelated, and needs to be done in another patch. For the record, git annotate on this line shows 00b203402984 ("gre: remove superfluous pskb_may_pull") but I think it was reading out of the linear area also before that commit, and that commit is correct, because pskb_may_pull() is called later using the return value of gre_parse_header(). (other eyes over here are welcome :) ) -- davide