[PATCH net-next v2] netlink: specs: fix duplicate if/then keys in netlink-raw schema

Taylor Bates posted 1 patch 1 week, 3 days ago
Documentation/netlink/netlink-raw.yaml | 31 +++++++++++++++++--------------
1 file changed, 17 insertions(+), 14 deletions(-)
[PATCH net-next v2] netlink: specs: fix duplicate if/then keys in netlink-raw schema
Posted by Taylor Bates 1 week, 3 days ago
Currently netlink-raw.yaml contains two if keys and two then keys in a
single mapping that enforces a "len" for "pad" members and a "len" or
"struct" for binary members.

During validation PyYAML resolves duplicate keys last-wins, so only the
binary rule survives. Pad has not been validated since commit
bf08f32c8ced ("tools/net/ynl: Add support for nested structs") added
the second if/then pair in January 2024.

None of the current specs violate this rule, but this validation should
not be parser dependent and unspecified. Strict YAML validators such as
Red Hat's VS Code YAML extension and Adrien Verge's yamllint will
reject the netlink-raw.yaml schema:

Command:
  $ yamllint Documentation/netlink/netlink-raw.yaml

Output:
  185:13    error    duplication of key "if" in mapping  (key-duplicates)
  189:13    error    duplication of key "then" in mapping  (key-duplicates)

The following invalid netlink family spec will pass validation in the
current ynl tooling:

  # SPDX-License-Identifier: ((GPL-2.0 WITH Linux-syscall-note) OR BSD-3-Clause)
  ---
  name: minimal-raw
  doc: Minimal netlink-raw family for schema validation testing.
  protocol: netlink-raw
  protonum: 0

  definitions:
    -
      name: test-struct
      type: struct
      members:
        -
          name: reserved
          type: pad
          # len intentionally omitted

  attribute-sets: []

  operations:
    list: []

Signed-off-by: Taylor Bates <tmbates12@gmail.com>
---
This is a repost of patch 1 from the "netlink: fix ynl spec tooling
robustness bugs" series, reduced to this single fix as requested.

The netlink-raw spec for the Bridge VLAN family that motivated the
original series will be sent separately once this has landed.
---
Changes in v2:
- Drop patches 2/4, 3/4 and 4/4 from the series; this schema fix stands
  on its own.
- Drop the Fixes tag. This is developer tooling only and is not a bug
  that needs to reach stable. The offending commit is now cited in the
  commit message instead.
- Link to v1: https://patch.msgid.link/20260908-ynl-robustness-v1-0-f255214c0f30@gmail.com

To: Donald Hunter <donald.hunter@gmail.com>
To: Jakub Kicinski <kuba@kernel.org>
To: "David S. Miller" <davem@davemloft.net>
To: Eric Dumazet <edumazet@google.com>
To: Paolo Abeni <pabeni@redhat.com>
To: Simon Horman <horms@kernel.org>
Cc: netdev@vger.kernel.org
Cc: linux-kernel@vger.kernel.org
---
 Documentation/netlink/netlink-raw.yaml | 31 +++++++++++++++++--------------
 1 file changed, 17 insertions(+), 14 deletions(-)

diff --git a/Documentation/netlink/netlink-raw.yaml b/Documentation/netlink/netlink-raw.yaml
index 4c436b59a34b..18ccfe05048a 100644
--- a/Documentation/netlink/netlink-raw.yaml
+++ b/Documentation/netlink/netlink-raw.yaml
@@ -176,20 +176,23 @@ properties:
               struct:
                 description: Name of the nested struct type.
                 type: string
-            if:
-              properties:
-                type:
-                  const: pad
-            then:
-              required: [ len ]
-            if:
-              properties:
-                type:
-                  const: binary
-            then:
-              oneOf:
-                - required: [ len ]
-                - required: [ struct ]
+            allOf:
+              -
+                if:
+                  properties:
+                    type:
+                      const: pad
+                then:
+                  required: [ len ]
+              -
+                if:
+                  properties:
+                    type:
+                      const: binary
+                then:
+                  oneOf:
+                    - required: [ len ]
+                    - required: [ struct ]
         # End genetlink-legacy
 
   attribute-sets:

---
base-commit: 043777e948807b5f335f58a0b9f5ed04bba681cf
change-id: 20260907-ynl-robustness-d62d9693cc12

Best regards,
--  
Taylor Bates <tmbates12@gmail.com>
Re: [PATCH net-next v2] netlink: specs: fix duplicate if/then keys in netlink-raw schema
Posted by Donald Hunter 1 week ago
Taylor Bates <tmbates12@gmail.com> writes:

> Currently netlink-raw.yaml contains two if keys and two then keys in a
> single mapping that enforces a "len" for "pad" members and a "len" or
> "struct" for binary members.
>
> During validation PyYAML resolves duplicate keys last-wins, so only the
> binary rule survives. Pad has not been validated since commit
> bf08f32c8ced ("tools/net/ynl: Add support for nested structs") added
> the second if/then pair in January 2024.
>
> None of the current specs violate this rule, but this validation should
> not be parser dependent and unspecified. Strict YAML validators such as
> Red Hat's VS Code YAML extension and Adrien Verge's yamllint will
> reject the netlink-raw.yaml schema:
>
> Command:
>   $ yamllint Documentation/netlink/netlink-raw.yaml
>
> Output:
>   185:13    error    duplication of key "if" in mapping  (key-duplicates)
>   189:13    error    duplication of key "then" in mapping  (key-duplicates)
>
> The following invalid netlink family spec will pass validation in the
> current ynl tooling:
>
>   # SPDX-License-Identifier: ((GPL-2.0 WITH Linux-syscall-note) OR BSD-3-Clause)
>   ---
>   name: minimal-raw
>   doc: Minimal netlink-raw family for schema validation testing.
>   protocol: netlink-raw
>   protonum: 0
>
>   definitions:
>     -
>       name: test-struct
>       type: struct
>       members:
>         -
>           name: reserved
>           type: pad
>           # len intentionally omitted
>
>   attribute-sets: []
>
>   operations:
>     list: []
>
> Signed-off-by: Taylor Bates <tmbates12@gmail.com>

Good catch. We have a lint check on the specs but not the schemas. Maybe
need to add that.

Reviewed-by: Donald Hunter <donald.hunter@gmail.com>
Re: [PATCH net-next v2] netlink: specs: fix duplicate if/then keys in netlink-raw schema
Posted by tmbates12 1 week ago
On Thu, 17 Sep 2026 09:35:07 +0100, Donald Hunter wrote:
> Good catch. We have a lint check on the specs but not the schemas. Maybe
> need to add that.

Agreed, there definitely is a gap there, as tools/net/ynl/Makefile is
only pulling in yaml from the specs dir:

  SPECDIR=../../../Documentation/netlink/specs
  lint:
      yamllint $(SPECDIR)

The default profile is rather noisy on the schemas, with both errors
and warnings, mostly brackets, line-length and truthy. With this patch
applied:

  $ yamllint -f parsable Documentation/netlink/*.yaml | wc -l
  460
  $ yamllint -f parsable Documentation/netlink/*.yaml | grep -c '\[error\]'
  386

So it'd be worth having a .yamllint config scoped just for the schemas
so we're not chasing a bunch of smaller things, while still checking
for any structure breaking ones (such as the one addressed in this
patch). I'd be happy to put this together as a follow-up if that
sounds useful.
Re: [PATCH net-next v2] netlink: specs: fix duplicate if/then keys in netlink-raw schema
Posted by Hangbin Liu 1 week, 3 days ago
On Mon, Sep 14, 2026 at 09:53:15PM -0400, Taylor Bates wrote:
> Currently netlink-raw.yaml contains two if keys and two then keys in a
> single mapping that enforces a "len" for "pad" members and a "len" or
> "struct" for binary members.
> 
> During validation PyYAML resolves duplicate keys last-wins, so only the
> binary rule survives. Pad has not been validated since commit
> bf08f32c8ced ("tools/net/ynl: Add support for nested structs") added
> the second if/then pair in January 2024.
> 
> None of the current specs violate this rule, but this validation should
> not be parser dependent and unspecified. Strict YAML validators such as
> Red Hat's VS Code YAML extension and Adrien Verge's yamllint will
> reject the netlink-raw.yaml schema:
> 
> Command:
>   $ yamllint Documentation/netlink/netlink-raw.yaml
> 
> Output:
>   185:13    error    duplication of key "if" in mapping  (key-duplicates)
>   189:13    error    duplication of key "then" in mapping  (key-duplicates)
> 
> The following invalid netlink family spec will pass validation in the
> current ynl tooling:
> 
>   # SPDX-License-Identifier: ((GPL-2.0 WITH Linux-syscall-note) OR BSD-3-Clause)
>   ---
>   name: minimal-raw
>   doc: Minimal netlink-raw family for schema validation testing.
>   protocol: netlink-raw
>   protonum: 0
> 
>   definitions:
>     -
>       name: test-struct
>       type: struct
>       members:
>         -
>           name: reserved
>           type: pad
>           # len intentionally omitted
> 
>   attribute-sets: []
> 
>   operations:
>     list: []
> 
> Signed-off-by: Taylor Bates <tmbates12@gmail.com>
> ---
> This is a repost of patch 1 from the "netlink: fix ynl spec tooling
> robustness bugs" series, reduced to this single fix as requested.
> 
> The netlink-raw spec for the Bridge VLAN family that motivated the
> original series will be sent separately once this has landed.
> ---
> Changes in v2:
> - Drop patches 2/4, 3/4 and 4/4 from the series; this schema fix stands
>   on its own.
> - Drop the Fixes tag. This is developer tooling only and is not a bug
>   that needs to reach stable. The offending commit is now cited in the
>   commit message instead.
> - Link to v1: https://patch.msgid.link/20260908-ynl-robustness-v1-0-f255214c0f30@gmail.com
> 
> To: Donald Hunter <donald.hunter@gmail.com>
> To: Jakub Kicinski <kuba@kernel.org>
> To: "David S. Miller" <davem@davemloft.net>
> To: Eric Dumazet <edumazet@google.com>
> To: Paolo Abeni <pabeni@redhat.com>
> To: Simon Horman <horms@kernel.org>
> Cc: netdev@vger.kernel.org
> Cc: linux-kernel@vger.kernel.org
> ---
>  Documentation/netlink/netlink-raw.yaml | 31 +++++++++++++++++--------------
>  1 file changed, 17 insertions(+), 14 deletions(-)
> 
> diff --git a/Documentation/netlink/netlink-raw.yaml b/Documentation/netlink/netlink-raw.yaml
> index 4c436b59a34b..18ccfe05048a 100644
> --- a/Documentation/netlink/netlink-raw.yaml
> +++ b/Documentation/netlink/netlink-raw.yaml
> @@ -176,20 +176,23 @@ properties:
>                struct:
>                  description: Name of the nested struct type.
>                  type: string
> -            if:
> -              properties:
> -                type:
> -                  const: pad
> -            then:
> -              required: [ len ]
> -            if:
> -              properties:
> -                type:
> -                  const: binary
> -            then:
> -              oneOf:
> -                - required: [ len ]
> -                - required: [ struct ]
> +            allOf:
> +              -
> +                if:
> +                  properties:
> +                    type:
> +                      const: pad
> +                then:
> +                  required: [ len ]
> +              -
> +                if:
> +                  properties:
> +                    type:
> +                      const: binary
> +                then:
> +                  oneOf:
> +                    - required: [ len ]
> +                    - required: [ struct ]
>          # End genetlink-legacy
>  
>    attribute-sets:
> 
> ---
> base-commit: 043777e948807b5f335f58a0b9f5ed04bba681cf
> change-id: 20260907-ynl-robustness-d62d9693cc12
> 
> Best regards,
> --  
> Taylor Bates <tmbates12@gmail.com>
> 

Reviewed-by: Hangbin Liu <liuhangbin@kylinos.cn>