From patchwork Wed Sep 16 08:35:17 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ralf Lici X-Patchwork-Id: 5360 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:6446:b0:8a0:ea1f:253a with SMTP id n6csp5930087mag; Wed, 16 Sep 2026 01:35:51 -0700 (PDT) X-Forwarded-Encrypted: i=2; AKwUvBw1C2DNozkGEwhJD5ZAu0PbyMhdV6hUy9SYp23gf0E2uvKXhA1GznStyrg0LPRDl2WnfFenmJIVKCc=@openvpn.net X-Received: by 2002:a05:6830:2b09:b0:7fb:547f:98bc with SMTP id 46e09a7af769-80b2cbb36a3mr2098864a34.5.1789547750942; Wed, 16 Sep 2026 01:35:50 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1789547750; cv=none; d=google.com; s=arc-20260327; b=ZV/M0jxw5rXf7BH8CDoBkqQClY7MvK3aw++FFx8G7cQ10KnLl2TSP+yVuuoCmJZQpK SfLnIVVesMdiZK9WOFmOpHnCxskiaZUalXWKOT3c5HkYCQ3wgS28pB7O/8I6e/vW/I9H nR372CdZ2ECNfQaioZsri19JPbp6L3TKl5QXSjHRewij1sKe/O6KfGpKRc53qLc6eOVq 4zPPRRnZ+3zVaQlbkhI5HpAMdGohFHEQsJN0gmNJAitrnIhZx+dUL8XgOQJp5r1xHznt rldirFX/5YB0o7pg0YSunYtIUH/KcgqtZohXHEMu+iyNINOqAKq26iCu9H5j6QsLHnk/ GAbw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature:dkim-signature; bh=7S+Ul8Z56nf547WODOD1LZBxk0eHivU+Cl620ao8WzE=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=aH3Kxd5P0qOJwilMnm35HFVtbVMPjMm7WAjym1mdT9QVPtJHPOyrQIrTuqhDL0PvUq vPiwhD+BAjwWbAo0lYDHRO6DuvTlHBFd3PLNrQYXyumM80Kajaex70YCW/rJXsamhcdX yaaIbff96P9g7iG4mbnOEqeBcwIp/Y1b5jAQN1ZYikKDA1/eJnneBvLdLjPvC0P1JDhZ jK6jKR2vNhc4HBeH6sfNk3uuD0vKHRRSTs0ECLvp4DTizLyOPrHiZ/0HAMb8lhMlpQMo MEsWq9vkyQPr1l082lFKXMa/XVqLuY8ITIlwmsWButP5zjl1AvwUPrqaOzTETvk4HmTq OxKQ==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=HYjwubwO; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=PLVRB2Wn; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b="ky/MJgr/"; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b=onGn22K0; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 46e09a7af769-80b07ad8c8dsi3011367a34.46.2026.09.16.01.35.50 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Wed, 16 Sep 2026 01:35:50 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=HYjwubwO; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=PLVRB2Wn; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b="ky/MJgr/"; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b=onGn22K0; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=7S+Ul8Z56nf547WODOD1LZBxk0eHivU+Cl620ao8WzE=; b=HYjwubwOIKmoMN6TVRrGuj1y4X rk07b8ChdopretdMpqtq8a10eIm3apr0BIphXyzsGNMh5ZFs5lpUPLqsKoHkQpKLYQIyZLccL+xxN 82ucIbc5Dt7JeEza3g80YxcvDWd23EDb7JBI8DxHeRRYir2RYX7su1NGjbBGpB1/0D7g=; Received: from [127.0.0.1] (helo=sfs-ml-2.v29.lw.sourceforge.com) by sfs-ml-2.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1x6l7K-0004YO-Ux; Wed, 16 Sep 2026 08:35:47 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-2.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1x6l7I-0004Y1-AB for openvpn-devel@lists.sourceforge.net; Wed, 16 Sep 2026 08:35:45 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=a7gijAAEIUn/Ae6//xolhJZ6xhi2uWt9Sr+GRbs3slk=; b=PLVRB2WnCMTss7ID/yXRuWvE+0 +93LN+1k7GA1q1GsrDfHhHjhCvCDpa9/FkkRarquKWgRGPNjG1a4pbU4taOYdl6TKSi0GOFOvo1BO hFco7HPJLqALHeYxlH5NLEYhLObjfe7P/pJlHyhhxPYpAo6eJeW3G1eoG1YQ/tN1R/MA=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=a7gijAAEIUn/Ae6//xolhJZ6xhi2uWt9Sr+GRbs3slk=; b=ky/MJgr/0bYvhBQi//Y18gKPDR 3ZPKzNX52kzdXsd8aJTJx+vhCk56he7KxHihHKFcGURLwe3D6UfslNsHu3jyknhBiqqfljaM6uVm8 +v+z5nSb5lrF36zlIgcRuFTAqq7Neb3Igu5mAoCx5REopRXIk7Bwu363HvWOrtj2BUpg=; Received: from mout-b-206.mailbox.org ([195.10.208.51]) by sfi-mx-1.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1x6l7H-0000m2-0r for openvpn-devel@lists.sourceforge.net; Wed, 16 Sep 2026 08:35:45 +0000 Received: from smtp2.mailbox.org (smtp2.mailbox.org [IPv6:2001:67c:2050:b231:465::2]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mout-b-206.mailbox.org (Postfix) with ESMTPS id 4hlBzV46HRzS3 for ; Wed, 16 Sep 2026 10:35:34 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mandelbit.com; s=MBO0001; t=1789547734; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=a7gijAAEIUn/Ae6//xolhJZ6xhi2uWt9Sr+GRbs3slk=; b=onGn22K0fOCLlwSuCKJR/0qfZCIkKOecTl84b4pzPjKTJ0d2CXcDnmHc2JEXrrrGXW7thR uU4uzzxIVAvnzePHkcPwcVJAkeUlhKJyPGjVJmmpyX+Ud2zX8mQZF3Cf0b1uoY7sVp17Jg MRGQjB6aoJc7IYDQ9JkCQ4HaVxLoN+nipiIgitExowZK3G/PE977cZ4aebDq1byiaCXzKY MVQPr+R+J4pjRRJPpDo9jpf+CXwS3KsUo6/44Dt+Zyayarc5mijfQ4meBT8B/FCUnhexkI MMvo++xDf5uvZI25xtHntd877Ikqx77HJxayLATHcH30X8NFiKOSka0KO1s/7g== Authentication-Results: outgoing_mbo_mout; dkim=none; spf=pass (outgoing_mbo_mout: domain of ralf@mandelbit.com designates 2001:67c:2050:b231:465::2 as permitted sender) smtp.mailfrom=ralf@mandelbit.com From: Ralf Lici To: openvpn-devel@lists.sourceforge.net Date: Wed, 16 Sep 2026 10:35:17 +0200 Message-ID: In-Reply-To: References: MIME-Version: 1.0 X-Rspamd-Queue-Id: 4hlBzV46HRzS3 X-Spam-Score: -0.2 (/) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-1.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: XFRM's ESP GRO callbacks may consume an skb and return ERR_PTR(-EINPROGRESS) as an ownership marker. dev_gro_receive already recognizes this marker unconditionally and converts it to GRO_CONSUMED, so [...] Content analysis details: (-0.2 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature -0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from envelope-from domain 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid X-Headers-End: 1x6l7H-0000m2-0r Subject: [Openvpn-devel] [RFC ovpn net-next v3 8/9] net: gro: honor skbs consumed by protocol callbacks X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1876476822641166509 X-GMAIL-MSGID: 1876476822641166509 XFRM's ESP GRO callbacks may consume an skb and return ERR_PTR(-EINPROGRESS) as an ownership marker. dev_gro_receive already recognizes this marker unconditionally and converts it to GRO_CONSUMED, so -EINPROGRESS is reserved by the generic GRO callback interface and cannot represent an ordinary callback error. The nested flush helpers currently avoid accessing a consumed skb only when XFRM offload is configured, because XFRM has so far been the sole user of the convention. Make the ownership check unconditional so other protocol callbacks can safely use the existing marker without acquiring an unrelated CONFIG_XFRM_OFFLOAD dependency. Callbacks which do not return the marker are unaffected. Signed-off-by: Ralf Lici --- No changes since v2 https://lore.kernel.org/openvpn-devel/3192bff7d69f958114e5fc9efe0dc5039c5be147.1789540779.git.ralf@mandelbit.com/ No changes since v1 https://lore.kernel.org/openvpn-devel/893f6c2b385f9df3e9617a9b7f547734061df195.1789485693.git.ralf@mandelbit.com/ include/net/gro.h | 19 +++---------------- 1 file changed, 3 insertions(+), 16 deletions(-) diff --git a/include/net/gro.h b/include/net/gro.h index 2300b6da05b2..20ddc5488789 100644 --- a/include/net/gro.h +++ b/include/net/gro.h @@ -361,9 +361,11 @@ static inline void skb_gro_remcsum_cleanup(struct sk_buff *skb, remcsum_unadjust((__sum16 *)ptr, grc->delta); } -#ifdef CONFIG_XFRM_OFFLOAD static inline void skb_gro_flush_final(struct sk_buff *skb, struct sk_buff *pp, int flush) { + /* a GRO callback may consume skb and return this marker to prevent + * accessing the skb while unwinding through the enclosing GRO layers + */ if (PTR_ERR(pp) != -EINPROGRESS) NAPI_GRO_CB(skb)->flush |= flush; } @@ -378,21 +380,6 @@ static inline void skb_gro_flush_final_remcsum(struct sk_buff *skb, skb->remcsum_offload = 0; } } -#else -static inline void skb_gro_flush_final(struct sk_buff *skb, struct sk_buff *pp, int flush) -{ - NAPI_GRO_CB(skb)->flush |= flush; -} -static inline void skb_gro_flush_final_remcsum(struct sk_buff *skb, - struct sk_buff *pp, - int flush, - struct gro_remcsum *grc) -{ - NAPI_GRO_CB(skb)->flush |= flush; - skb_gro_remcsum_cleanup(skb, grc); - skb->remcsum_offload = 0; -} -#endif INDIRECT_CALLABLE_DECLARE(struct sk_buff *ipv6_gro_receive(struct list_head *, struct sk_buff *));