From nobody Sat Jul 25 21:21:08 2026 Received: from mail-pj1-f99.google.com (mail-pj1-f99.google.com [209.85.216.99]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 027F427FB2A for ; Mon, 13 Jul 2026 14:11:21 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.99 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783951883; cv=none; b=F9J/xeyQPN/7Ed7YeFXTF2eXbGBUQdElvIpI+aW0GhahXeCub4bYCVAvCea4oQno9f10pR73CG0vzLOZrPd/+3+LQ1Yd9pl7xa5XBcQac4f6+ElOUGF0awPflj0sNT/kMkX8lsxenxbd7Mjq4vaoccSVM6AWWJEwWUlASip7zrY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783951883; c=relaxed/simple; bh=ky8a078BzuCeIqNQ3LW+dhReUhSCYk+x7jWpvgUSciU=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=Z61lsEWieXSRp1WmBHTe5gIismNyYCM628hok6PXzVmpcjGCw1eHVAW2mORjOQ2i6ojlFIb7eQ5V3h4B5fT5Lbpy8HQUUZ00sBbCM/SujTIwTpFJsBxVWTsu0SvgQZbCBKRYAYfJTZlzbrpBVBsAACaLun2gpAEClVb5+5JhgYk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=broadcom.com; spf=fail smtp.mailfrom=broadcom.com; dkim=pass (1024-bit key) header.d=broadcom.com header.i=@broadcom.com header.b=GizbaxR6; arc=none smtp.client-ip=209.85.216.99 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=broadcom.com Authentication-Results: smtp.subspace.kernel.org; spf=fail smtp.mailfrom=broadcom.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=broadcom.com header.i=@broadcom.com header.b="GizbaxR6" Received: by mail-pj1-f99.google.com with SMTP id 98e67ed59e1d1-38e041ea211so715500a91.0 for ; Mon, 13 Jul 2026 07:11:21 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783951881; x=1784556681; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:dkim-signature:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to:content-type; bh=hIl1om5v05Us/yKSHOl5DicDdbxl/J4daUVgzU7kfHw=; b=CJIjIVkOcAftTxacz6Kvl38aUxmy1oZINrdZ6GRg4SQjNZ10xIK4R4NW+opp6naY0X bJNRk5+BwaULfhweTknGOd2YG6fnqVP1Tnp5h6JrKgXcgwQddcXN17OpRwlY97BvIXKr D1CIcSTXUH4j5s2LF/Cts0J28BVqLHII4Fl0xHSBj1PkXUk0FzJhrygxE0g3txtoNuke nejQQCJd1PW2uv+AWJBbJ/Wm0qmgNxFhEoB3dQ+usTG50YE4V51jPkhY37RH8ngWDMTN S+Q2bwl8OcxEQXXL/Frf539Q5Z7qkM0cICCnUzn32sZTuExFIBUiGCexywhbizy7lY8l GSvQ== X-Forwarded-Encrypted: i=1; AHgh+RoxEleJV5Y97pPKNhQ+oPJwNCtYv92Azypi40Vsxc4uTTRYQx3xrhr5uoXaC+DPiPdwO/aXMi4QI4OwgWY=@vger.kernel.org X-Gm-Message-State: AOJu0YyOTBLL4QS9SJNf5mUigPxj2WMQ34nP1jM05VSdFjF4q7+kTILL XevEbD8AKrZDPj//UV4JQZcdIACXKxMSei82acA8+lJM2zXf6YQclbvywDypsRiYjHcoqbG6tBE HDX2rZ0QD+8kwVsrSIZbUN0bYQ1/qP422tCncE+3Ko4e0WaKyINfAjmUXUIRNkC6qHT3yPRrgWZ 9vHe8T7U4KWvtI/KAtUQpl+Jkr6MxqkS97S0DjY52GXb2Kj/qaux95UxlPdzX3gdVqqr60JabXo BL+dVq+5KWBDZ1E5Srw4mSYupFK X-Gm-Gg: AfdE7cl7DSMhIjroxd3K0HF3/Az8cx6Dw0ju7iwYvjch5MNaZNsZvZR39HDBB6lCsKB YOpP3yeglzIUp7KsWWkxb8QL8RW6mM/NWAuTOquLKQ9R4QczsoCRYnN8l0DaB/TunDHh5D/W8OQ hkcUFKi0ql3EX0ten/WzcHRj35fjimkVotudtqq4zHaksr69vpz7m4dNGbYZfhAQFNio/y3FVyi VIpbYOYLgUMi+T05xcZNXLSgcJ6R78IZ6UUpDXH2R4TNhctJPpQHITh1PUNInqq/UHk3PbCxQrr zk430MORw09OrSpUOWyCGmbLKuL+i5W0sp09AK5VPJBBmqEDDyLfeEktaFQzjmafFOOrNPH8jj8 jeY4DNl+NI13lmlMaA5dkZwuxljwxtJgyjo6u1G0zCsNym1hFWx5pjEmiZ1gUZ/+yY7QBrVz8b6 kbpTC9jSSSPGkBabe4hUpdKyuty22nmazMxI3r75BSvwCON3nVCQ== X-Received: by 2002:a17:90a:ec8e:b0:387:e0bb:57fa with SMTP id 98e67ed59e1d1-38dc77b59e2mr8862419a91.43.1783951881187; Mon, 13 Jul 2026 07:11:21 -0700 (PDT) Received: from smtp-us-east1-p01-i01-si01.dlp.protect.broadcom.com (address-144-49-247-0.dlp.protect.broadcom.com. [144.49.247.0]) by smtp-relay.gmail.com with ESMTPS id 98e67ed59e1d1-38dea1f1684sm408243a91.7.2026.07.13.07.11.20 for (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Mon, 13 Jul 2026 07:11:21 -0700 (PDT) X-Relaying-Domain: broadcom.com X-CFilter-Loop: Reflected Received: by mail-pg1-f200.google.com with SMTP id 41be03b00d2f7-c9667280edeso4205744a12.2 for ; Mon, 13 Jul 2026 07:11:20 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=broadcom.com; s=google; t=1783951880; x=1784556680; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=hIl1om5v05Us/yKSHOl5DicDdbxl/J4daUVgzU7kfHw=; b=GizbaxR6YOZfxAtjKOqUsxVb6Ni4Ljzxrztzyel3tRGdvvXqntf5VSy3XV3pOS6LGC zTBSYdgAbQHxUa0lCgOK2C9F6Edsv1yCbOTP6g1LKaM9HCyPFQ9ZdWLDRC++LXDAWHjq YFTt4p9OwMv5T3xyQHk9etnSsNkDSn797NGIw= X-Forwarded-Encrypted: i=1; AHgh+RrGJJaKqrntsiLwXRIzpQW1N9OAOSos7xkqMxwpAGEGZuLfEF48lO3t75Mgsdd5uzZkM88wkPCCzd0PwV8=@vger.kernel.org X-Received: by 2002:a05:6a21:9216:b0:3bf:9142:ba3a with SMTP id adf61e73a8af0-3c110a77446mr10555422637.26.1783951879491; Mon, 13 Jul 2026 07:11:19 -0700 (PDT) X-Received: by 2002:a05:6a21:9216:b0:3bf:9142:ba3a with SMTP id adf61e73a8af0-3c110a77446mr10555376637.26.1783951879034; Mon, 13 Jul 2026 07:11:19 -0700 (PDT) Received: from lvn-dbc2448.lvn.broadcom.net ([192.19.161.250]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-13b93ae3b45sm19650511c88.15.2026.07.13.07.11.18 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 13 Jul 2026 07:11:18 -0700 (PDT) From: Harshaka Narayana To: davem@davemloft.net, kuba@kernel.org, pabeni@redhat.com, netdev@vger.kernel.org Cc: ronak.doshi@broadcom.com, bcm-kernel-feedback-list@broadcom.com, andrew+netdev@lunn.ch, edumazet@google.com, linux-kernel@vger.kernel.org, guolin.yang@broadcom.com, harshaka.narayana@broadcom.com, sankararaman.jayaraman@broadcom.com Subject: [PATCH net v3] vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets Date: Mon, 13 Jul 2026 07:09:15 -0700 Message-ID: <20260713140915.3381715-1-harshaka.narayana@broadcom.com> X-Mailer: git-send-email 2.52.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-DetectorID-Processed: b00c1d49-9d2e-4205-b15f-d015386d3d5e Content-Type: text/plain; charset="utf-8" vmxnet3_get_hdr_len() assumes gdesc->rcd.v4/v6/tcp always describe the outer header, but for a Geneve-encapsulated packet the device can set them based on the inner header instead, signalled by the VMXNET3_RCD_HDR_INNER_SHIFT bit in the completion descriptor. Since the function never skips the outer encapsulation, this mismatch triggers: - BUG_ON(hdr.ipv4->protocol !=3D IPPROTO_TCP), because the outer protocol is UDP (Geneve), not TCP. - BUG_ON(hdr.eth->h_proto !=3D ...), when the tunnel's outer and inner IP versions differ (e.g. outer IPv6/inner IPv4 or vice versa). Check VMXNET3_RCD_HDR_INNER_SHIFT up front and bail out, since the function cannot locate the inner header it would need to parse. Also convert the remaining BUG_ON()s in this function to return 0 defensively. Fixes: 45dac1d6ea04 ("vmxnet3: Changes for vmxnet3 adapter version 2 (fwd)") Signed-off-by: Harshaka Narayana Reviewed-by: Ronak Doshi Reviewed-by: Sankararaman Jayaraman Reviewed-by: Simon Horman --- v3: - Combined the two early return-0 checks into one condition - Replaced stacked Signed-off-by tags with Reviewed-by for Ronak Doshi and Sankararaman Jayaraman v2: https://lore.kernel.org/netdev/20260709201654.4108084-1-harshaka.naraya= na@broadcom.com/ - Check VMXNET3_RCD_HDR_INNER_SHIFT up front to catch the Geneve inner-header case directly, and convert the remaining BUG_ON(hdr.eth->h_proto !=3D ...) checks to return 0 - Reworded commit message to describe the root cause via VMXNET3_RCD_HDR_INNER_SHIFT v1: https://lore.kernel.org/netdev/20260707165248.1859188-1-harshaka.naraya= na@broadcom.com/ --- drivers/net/vmxnet3/vmxnet3_drv.c | 22 ++++++++++++++++------ 1 file changed, 16 insertions(+), 6 deletions(-) diff --git a/drivers/net/vmxnet3/vmxnet3_drv.c b/drivers/net/vmxnet3/vmxnet= 3_drv.c index 40522afc0532..f8df83f9965d 100644 --- a/drivers/net/vmxnet3/vmxnet3_drv.c +++ b/drivers/net/vmxnet3/vmxnet3_drv.c @@ -1530,7 +1530,11 @@ vmxnet3_get_hdr_len(struct vmxnet3_adapter *adapter,= struct sk_buff *skb, struct ipv6hdr *ipv6; struct tcphdr *tcp; } hdr; - BUG_ON(gdesc->rcd.tcp =3D=3D 0); + + /* v4/v6/tcp then describe the inner header, which we can't locate. */ + if ((le32_to_cpu(gdesc->dword[0]) & (1UL << VMXNET3_RCD_HDR_INNER_SHIFT))= || + gdesc->rcd.tcp =3D=3D 0) + return 0; =20 maplen =3D skb_headlen(skb); if (unlikely(sizeof(struct iphdr) + sizeof(struct tcphdr) > maplen)) @@ -1544,15 +1548,21 @@ vmxnet3_get_hdr_len(struct vmxnet3_adapter *adapter= , struct sk_buff *skb, =20 hdr.eth =3D eth_hdr(skb); if (gdesc->rcd.v4) { - BUG_ON(hdr.eth->h_proto !=3D htons(ETH_P_IP) && - hdr.veth->h_vlan_encapsulated_proto !=3D htons(ETH_P_IP)); + if (hdr.eth->h_proto !=3D htons(ETH_P_IP) && + hdr.veth->h_vlan_encapsulated_proto !=3D htons(ETH_P_IP)) + return 0; + hdr.ptr +=3D hlen; - BUG_ON(hdr.ipv4->protocol !=3D IPPROTO_TCP); + if (hdr.ipv4->protocol !=3D IPPROTO_TCP) + return 0; + hlen =3D hdr.ipv4->ihl << 2; hdr.ptr +=3D hdr.ipv4->ihl << 2; } else if (gdesc->rcd.v6) { - BUG_ON(hdr.eth->h_proto !=3D htons(ETH_P_IPV6) && - hdr.veth->h_vlan_encapsulated_proto !=3D htons(ETH_P_IPV6)); + if (hdr.eth->h_proto !=3D htons(ETH_P_IPV6) && + hdr.veth->h_vlan_encapsulated_proto !=3D htons(ETH_P_IPV6)) + return 0; + hdr.ptr +=3D hlen; /* Use an estimated value, since we also need to handle * TSO case. --=20 2.52.0