Documentation/netlink/netlink-raw.yaml | 31 +++++++++++++++++-------------- 1 file changed, 17 insertions(+), 14 deletions(-)
Currently netlink-raw.yaml contains two if keys and two then keys in a
single mapping that enforces a "len" for "pad" members and a "len" or
"struct" for binary members.
During validation PyYAML resolves duplicate keys last-wins, so only the
binary rule survives. Pad has not been validated since commit
bf08f32c8ced ("tools/net/ynl: Add support for nested structs") added
the second if/then pair in January 2024.
None of the current specs violate this rule, but this validation should
not be parser dependent and unspecified. Strict YAML validators such as
Red Hat's VS Code YAML extension and Adrien Verge's yamllint will
reject the netlink-raw.yaml schema:
Command:
$ yamllint Documentation/netlink/netlink-raw.yaml
Output:
185:13 error duplication of key "if" in mapping (key-duplicates)
189:13 error duplication of key "then" in mapping (key-duplicates)
The following invalid netlink family spec will pass validation in the
current ynl tooling:
# SPDX-License-Identifier: ((GPL-2.0 WITH Linux-syscall-note) OR BSD-3-Clause)
---
name: minimal-raw
doc: Minimal netlink-raw family for schema validation testing.
protocol: netlink-raw
protonum: 0
definitions:
-
name: test-struct
type: struct
members:
-
name: reserved
type: pad
# len intentionally omitted
attribute-sets: []
operations:
list: []
Signed-off-by: Taylor Bates <tmbates12@gmail.com>
---
This is a repost of patch 1 from the "netlink: fix ynl spec tooling
robustness bugs" series, reduced to this single fix as requested.
The netlink-raw spec for the Bridge VLAN family that motivated the
original series will be sent separately once this has landed.
---
Changes in v2:
- Drop patches 2/4, 3/4 and 4/4 from the series; this schema fix stands
on its own.
- Drop the Fixes tag. This is developer tooling only and is not a bug
that needs to reach stable. The offending commit is now cited in the
commit message instead.
- Link to v1: https://patch.msgid.link/20260908-ynl-robustness-v1-0-f255214c0f30@gmail.com
To: Donald Hunter <donald.hunter@gmail.com>
To: Jakub Kicinski <kuba@kernel.org>
To: "David S. Miller" <davem@davemloft.net>
To: Eric Dumazet <edumazet@google.com>
To: Paolo Abeni <pabeni@redhat.com>
To: Simon Horman <horms@kernel.org>
Cc: netdev@vger.kernel.org
Cc: linux-kernel@vger.kernel.org
---
Documentation/netlink/netlink-raw.yaml | 31 +++++++++++++++++--------------
1 file changed, 17 insertions(+), 14 deletions(-)
diff --git a/Documentation/netlink/netlink-raw.yaml b/Documentation/netlink/netlink-raw.yaml
index 4c436b59a34b..18ccfe05048a 100644
--- a/Documentation/netlink/netlink-raw.yaml
+++ b/Documentation/netlink/netlink-raw.yaml
@@ -176,20 +176,23 @@ properties:
struct:
description: Name of the nested struct type.
type: string
- if:
- properties:
- type:
- const: pad
- then:
- required: [ len ]
- if:
- properties:
- type:
- const: binary
- then:
- oneOf:
- - required: [ len ]
- - required: [ struct ]
+ allOf:
+ -
+ if:
+ properties:
+ type:
+ const: pad
+ then:
+ required: [ len ]
+ -
+ if:
+ properties:
+ type:
+ const: binary
+ then:
+ oneOf:
+ - required: [ len ]
+ - required: [ struct ]
# End genetlink-legacy
attribute-sets:
---
base-commit: 043777e948807b5f335f58a0b9f5ed04bba681cf
change-id: 20260907-ynl-robustness-d62d9693cc12
Best regards,
--
Taylor Bates <tmbates12@gmail.com>
Taylor Bates <tmbates12@gmail.com> writes:
> Currently netlink-raw.yaml contains two if keys and two then keys in a
> single mapping that enforces a "len" for "pad" members and a "len" or
> "struct" for binary members.
>
> During validation PyYAML resolves duplicate keys last-wins, so only the
> binary rule survives. Pad has not been validated since commit
> bf08f32c8ced ("tools/net/ynl: Add support for nested structs") added
> the second if/then pair in January 2024.
>
> None of the current specs violate this rule, but this validation should
> not be parser dependent and unspecified. Strict YAML validators such as
> Red Hat's VS Code YAML extension and Adrien Verge's yamllint will
> reject the netlink-raw.yaml schema:
>
> Command:
> $ yamllint Documentation/netlink/netlink-raw.yaml
>
> Output:
> 185:13 error duplication of key "if" in mapping (key-duplicates)
> 189:13 error duplication of key "then" in mapping (key-duplicates)
>
> The following invalid netlink family spec will pass validation in the
> current ynl tooling:
>
> # SPDX-License-Identifier: ((GPL-2.0 WITH Linux-syscall-note) OR BSD-3-Clause)
> ---
> name: minimal-raw
> doc: Minimal netlink-raw family for schema validation testing.
> protocol: netlink-raw
> protonum: 0
>
> definitions:
> -
> name: test-struct
> type: struct
> members:
> -
> name: reserved
> type: pad
> # len intentionally omitted
>
> attribute-sets: []
>
> operations:
> list: []
>
> Signed-off-by: Taylor Bates <tmbates12@gmail.com>
Good catch. We have a lint check on the specs but not the schemas. Maybe
need to add that.
Reviewed-by: Donald Hunter <donald.hunter@gmail.com>
On Thu, 17 Sep 2026 09:35:07 +0100, Donald Hunter wrote:
> Good catch. We have a lint check on the specs but not the schemas. Maybe
> need to add that.
Agreed, there definitely is a gap there, as tools/net/ynl/Makefile is
only pulling in yaml from the specs dir:
SPECDIR=../../../Documentation/netlink/specs
lint:
yamllint $(SPECDIR)
The default profile is rather noisy on the schemas, with both errors
and warnings, mostly brackets, line-length and truthy. With this patch
applied:
$ yamllint -f parsable Documentation/netlink/*.yaml | wc -l
460
$ yamllint -f parsable Documentation/netlink/*.yaml | grep -c '\[error\]'
386
So it'd be worth having a .yamllint config scoped just for the schemas
so we're not chasing a bunch of smaller things, while still checking
for any structure breaking ones (such as the one addressed in this
patch). I'd be happy to put this together as a follow-up if that
sounds useful.
On Mon, Sep 14, 2026 at 09:53:15PM -0400, Taylor Bates wrote:
> Currently netlink-raw.yaml contains two if keys and two then keys in a
> single mapping that enforces a "len" for "pad" members and a "len" or
> "struct" for binary members.
>
> During validation PyYAML resolves duplicate keys last-wins, so only the
> binary rule survives. Pad has not been validated since commit
> bf08f32c8ced ("tools/net/ynl: Add support for nested structs") added
> the second if/then pair in January 2024.
>
> None of the current specs violate this rule, but this validation should
> not be parser dependent and unspecified. Strict YAML validators such as
> Red Hat's VS Code YAML extension and Adrien Verge's yamllint will
> reject the netlink-raw.yaml schema:
>
> Command:
> $ yamllint Documentation/netlink/netlink-raw.yaml
>
> Output:
> 185:13 error duplication of key "if" in mapping (key-duplicates)
> 189:13 error duplication of key "then" in mapping (key-duplicates)
>
> The following invalid netlink family spec will pass validation in the
> current ynl tooling:
>
> # SPDX-License-Identifier: ((GPL-2.0 WITH Linux-syscall-note) OR BSD-3-Clause)
> ---
> name: minimal-raw
> doc: Minimal netlink-raw family for schema validation testing.
> protocol: netlink-raw
> protonum: 0
>
> definitions:
> -
> name: test-struct
> type: struct
> members:
> -
> name: reserved
> type: pad
> # len intentionally omitted
>
> attribute-sets: []
>
> operations:
> list: []
>
> Signed-off-by: Taylor Bates <tmbates12@gmail.com>
> ---
> This is a repost of patch 1 from the "netlink: fix ynl spec tooling
> robustness bugs" series, reduced to this single fix as requested.
>
> The netlink-raw spec for the Bridge VLAN family that motivated the
> original series will be sent separately once this has landed.
> ---
> Changes in v2:
> - Drop patches 2/4, 3/4 and 4/4 from the series; this schema fix stands
> on its own.
> - Drop the Fixes tag. This is developer tooling only and is not a bug
> that needs to reach stable. The offending commit is now cited in the
> commit message instead.
> - Link to v1: https://patch.msgid.link/20260908-ynl-robustness-v1-0-f255214c0f30@gmail.com
>
> To: Donald Hunter <donald.hunter@gmail.com>
> To: Jakub Kicinski <kuba@kernel.org>
> To: "David S. Miller" <davem@davemloft.net>
> To: Eric Dumazet <edumazet@google.com>
> To: Paolo Abeni <pabeni@redhat.com>
> To: Simon Horman <horms@kernel.org>
> Cc: netdev@vger.kernel.org
> Cc: linux-kernel@vger.kernel.org
> ---
> Documentation/netlink/netlink-raw.yaml | 31 +++++++++++++++++--------------
> 1 file changed, 17 insertions(+), 14 deletions(-)
>
> diff --git a/Documentation/netlink/netlink-raw.yaml b/Documentation/netlink/netlink-raw.yaml
> index 4c436b59a34b..18ccfe05048a 100644
> --- a/Documentation/netlink/netlink-raw.yaml
> +++ b/Documentation/netlink/netlink-raw.yaml
> @@ -176,20 +176,23 @@ properties:
> struct:
> description: Name of the nested struct type.
> type: string
> - if:
> - properties:
> - type:
> - const: pad
> - then:
> - required: [ len ]
> - if:
> - properties:
> - type:
> - const: binary
> - then:
> - oneOf:
> - - required: [ len ]
> - - required: [ struct ]
> + allOf:
> + -
> + if:
> + properties:
> + type:
> + const: pad
> + then:
> + required: [ len ]
> + -
> + if:
> + properties:
> + type:
> + const: binary
> + then:
> + oneOf:
> + - required: [ len ]
> + - required: [ struct ]
> # End genetlink-legacy
>
> attribute-sets:
>
> ---
> base-commit: 043777e948807b5f335f58a0b9f5ed04bba681cf
> change-id: 20260907-ynl-robustness-d62d9693cc12
>
> Best regards,
> --
> Taylor Bates <tmbates12@gmail.com>
>
Reviewed-by: Hangbin Liu <liuhangbin@kylinos.cn>
© 2016 - 2026 Red Hat, Inc.