From nobody Thu Sep 24 14:26:46 2026 Received: from mail-pz2-f40.google.com (mail-pz2-f40.google.com [74.125.228.40]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A0DD730ACE6 for ; Wed, 23 Sep 2026 00:37:06 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.228.40 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790123828; cv=none; b=aiIwOKBo3lA5TqGb2ZhdFyt5EgLR3ORhc9saOjr7Q0Mmq6JESoZhfOA+oQDWIxnRf0GFe+0dUWNJmUE+8xA6MrNsc/ukwqBKc6HA6YQBJeDkNlYuWeNM9VWAxObHlaH7KUhl4ijBdpxznYIqlW4wIgXOa15RV95x+ui5Hh/CGiQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790123828; c=relaxed/simple; bh=4GmpNfU3LQJSJpqQsR6/KFUehJWyBgCDEINSJI93IoU=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=F3Q5lvYhkHcEWAEMkliBmNiA2QpqfjPHi/iBjq4ygJ1FgiMjA3aZGxnJYlSwziH1T+4pRZeQuVk9XO1byE9cgvsW8DXfiV82L4yOtpHCnIjEJt8YJ7DP3J9epCHAYKVOvQ7J8Uz1GKhG+4hMxggmJ8TNYu+fIGA894Pquzxo9oA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=aJveOrB0; arc=none smtp.client-ip=74.125.228.40 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="aJveOrB0" Received: by mail-pz2-f40.google.com with SMTP id d2e1a72fcca58-8748f34b1f2so272897b3a.0 for ; Tue, 22 Sep 2026 17:37:06 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790123826; x=1790728626; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=hr/q+PFpOYwfdPGF3n4BjUmiJpuCV+tZ3wvtyOR+SaI=; b=aJveOrB0Mra2DE7rRtm4jSoFHGhSRfwfiHF6IAzvI2+qiUMe2/TqHK1wzPcnGROmDN Yjm4CnDbH9yxAfX87R/bjReLg3lEr09B4M8P7xXt84uGQPvBfAh0CCN+ipdRc5ZPLLIq ahzs0Y69rFMW9b8QpF0GmLKCbhoXoxkkUHZD6J45ncLHYO/rN2Rn5F41pRu4ShJJri9u EafLif2Czzfa4/5OacdWbZMmvrweSQqYazisfeoNVPNcHKK03PfQ4YWBxaFB4OrULJdX Dz0Q8w8MvzRfWNdPMumLqrWaWtfSR4F8ZcA/1RlHAZa/EF2xSly7i2GPbpvAPZIt166n bsNg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790123826; x=1790728626; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=hr/q+PFpOYwfdPGF3n4BjUmiJpuCV+tZ3wvtyOR+SaI=; b=lxTO/1/FQtPVKTajrQVmyPPlCG2zF9GgHiGSumqIvKGkG2I2vIXA+njBo+K7GIk68G Pxi+rIaX0h/eU4EhjzSoQA05kbwMSKczP7aLBLZDKZwo7v2C6eFKaUHwHdKyxBEH4rP8 1KBiS1BCG2pEssqdFpd3Lm1jag4x7Y11IZ1kKOehJ/GA5Q/FseqtAUumRDZEZY/DWNCb /vAe8BSZbmBDIPKNPxJUt5A5WTIEd8zHu8JocOnDFFpx5ZkmTmI1M+bWRHOC018ssRC7 NTA5xxyfNsO745nyPI8Icpy1Fh0lCdeJA2D6bHx1nXfIGuetgPadEyE2zWnzsRUaB4Ci ZVvw== X-Forwarded-Encrypted: i=1; AKwUvBxKI/HHrk+ySPZT1/ziJAhAJ0Y7eidhW9StibhqV9kMjPmOt3lOZtbDXYsmRB4lfXd74ZNZQZwWo95bY0I=@vger.kernel.org X-Gm-Message-State: AFuF++n/ZGHCZLR9gG3nbd68Fr2F+7fNKd1J44C8mMPJJvjaWJGdkLHR xZr+c/646HJPiEBKbJ55QgKNIDzt42zBC4jYgWZy8j+GZXAhraC6ltnO X-Gm-Gg: AYBFou0U0BbN/Pw8U+oV3NksY5kQqDrQDalWidXJ7dCt8WKbvEKhQWzWGVlxFmR6fo4 eqeKMt4IQsR1Ecp3RlATTUw+y3XPbviCBXrUrDTOArw5za0YtbrN+C1fj4MDsvivGZdZ2j6qu8v s2mE5xFbPZpUg1/6n82NaRoa9PSXQc1NtZOaPfwWWNXsm/+BXea7n/uG+5f3nV4urzMcvxXVP9f dNNn+yD0pI3iwQYDQidqM84aQaZ2TP1GOEqg65iPKmahiw19YOGjKpdlb4yddQWwZfAc3hL0KET R/jNqpg+hQj6WWYxWvYuesEI4orSFJl3vaaDV8hGFk9tvSfziA5sPnXLOwcLpIZIWs+AJSiMzmq YbGKNCjDQyvsnBG7wY49tq/K8M1ocY5izgDmMBWFVOj2RmguNhdctMj+BgPVWD1llZ7Yg1252HT gOrRRHLXeb/9aW4gR8MUcY/l9UN4LbTNXKNnKfMMlzMTSAPpIQfrxNedshNis+C+i4mto2+dD2n dSG8SeM0w== X-Received: by 2002:a05:6a21:8209:b0:3cd:61d5:f342 with SMTP id adf61e73a8af0-3ddf7caaa23mr1367384637.9.1790123825606; Tue, 22 Sep 2026 17:37:05 -0700 (PDT) Received: from [163.43.103.131] ([163.43.103.131]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1dff9778sm427895b3a.49.2026.09.22.17.37.02 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 22 Sep 2026 17:37:05 -0700 (PDT) From: Yuya Kusakabe Date: Wed, 23 Sep 2026 09:36:56 +0900 Subject: [PATCH net 1/4] net: lwtunnel: accept RTA_ENCAP without NLA_F_NESTED Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260923-lwt-encap-noflag-v1-1-8de7ab6c86e9@gmail.com> References: <20260923-lwt-encap-noflag-v1-0-8de7ab6c86e9@gmail.com> In-Reply-To: <20260923-lwt-encap-noflag-v1-0-8de7ab6c86e9@gmail.com> To: David Ahern , Ido Schimmel , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , Justin Iurman , Alexander Aring , Steffen Klassert , Herbert Xu , Nikolay Aleksandrov , Eyal Birger , Nicolas Dichtel , Xin Long , Shuah Khan Cc: netdev@vger.kernel.org, linux-kernel@vger.kernel.org, linux-kselftest@vger.kernel.org, Yuya Kusakabe X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=openpgp-sha256; l=4481; i=yuya.kusakabe@gmail.com; h=from:subject:message-id; bh=4GmpNfU3LQJSJpqQsR6/KFUehJWyBgCDEINSJI93IoU=; b=owEBbQKS/ZANAwAIASrX0XUqXRtNAcsmYgBqsx8pyJmi0jAqYRMcjxJXjhNdLthCsldl2TNYY eoZwTVjneuJAjMEAAEIAB0WIQTaB7usAfxNKMeqa6Yq19F1Kl0bTQUCarMfKQAKCRAq19F1Kl0b TblhEACVx9cyL9CTQZ3/LW7LeTj/pABjToLaFkHgZfuwSHVlBzTS3yu2+krdGau9EL0CJLVq188 r59Ar1A4fN6ev/mtkMZTb9m4UFSvhfuQrsbbQ9Zd0LGFxxkkWuJ170XfUk55jGj9oRDhwwSBp7a iuLADGLOepwwxQK8MKiJrvr7lGnEq6Q9C0dia8k8T+eKEhaPKiQsUnXsCZY9MJq3pLZjNhcdNw5 10rk+G6Hl4EHEYcBhJxVyntwoGR2ef6ADM5ih30/hCbD85BnpUkawKwFUgHkwkgy9JHYHQBQRNJ STemUUjI372w6gVbvk3c4sjuxyGn0rOujU09KGmhYa7wJVctO8SX4Ry0lmeXH687Un/dzUdu0Q+ 438+cRsJ3+IPhbkdFjdx0bJuig9BFP75GU0naBgDbpPbi1vCJL9OKz6yGUJN2M6YXnrOQiuyqll eAYAsp5rr9u4yEQmWMbCLjiA0rs6awRsRbGu0jpM04Dvz2grecEaGjWpba3JliD0QFjXzOwexGr v0L3BDfh1TPlLJh1E9aghLCjpGZzg4Hk1N6y5VDou+ZyJeWhwuirNZwA/bI/I7FOqRErShqf+OP 4xIHAxSaMT1DqeWZxWWnvi4HR8Zy5sW2vGYbOZ7SikZV6jM2OeAAXF1KHdZPnOqwH8JLWhp1SoQ ETkdu7NZ992w6Zw== X-Developer-Key: i=yuya.kusakabe@gmail.com; a=openpgp; fpr=DA07BBAC01FC4D28C7AA6BA62AD7D1752A5D1B4D lwtunnel_fill_encap() dumps RTA_ENCAP without NLA_F_NESTED, and "ip route restore" sends the routes saved by "ip route save" back to the kernel unchanged. rpl and ioam6 break on the same path: lwtunnel_build_state() hands the restored RTA_ENCAP to their build_state callbacks, which parse it with nla_parse_nested() and so require the flag. Restoring an rpl route fails as below, and an ioam6 route fails with the same error: # ip -6 route add 2001:db8:1::/64 encap rpl segs 2001:db8::2 dev dummy0 # ip -6 route save 2001:db8:1::/64 > route.bin # ip -6 route del 2001:db8:1::/64 # ip -6 route restore < route.bin Error: NLA_F_NESTED is missing. Setting the flag in the dump is not an option: userspace that does not mask it off the attribute type, such as parse_rtattr() in iproute2, would no longer find RTA_ENCAP. Add lwtunnel_nla_parse(), which validates the nested attributes strictly but does not require the flag on RTA_ENCAP itself, and use it in rpl and ioam6. Switching them to nla_parse_nested_deprecated() instead would also make them accept unknown attributes, which they have rejected since they were added. Fixes: a7a29f9c361f ("net: ipv6: add rpl sr tunnel") Fixes: 3edede08ff37 ("ipv6: ioam: Support for IOAM injection with lwtunnels= ") Assisted-by: LLM Signed-off-by: Yuya Kusakabe --- include/net/lwtunnel.h | 27 +++++++++++++++++++++++++++ net/ipv6/ioam6_iptunnel.c | 4 ++-- net/ipv6/rpl_iptunnel.c | 4 ++-- 3 files changed, 31 insertions(+), 4 deletions(-) diff --git a/include/net/lwtunnel.h b/include/net/lwtunnel.h index 26232f603e33..046978d6224c 100644 --- a/include/net/lwtunnel.h +++ b/include/net/lwtunnel.h @@ -6,6 +6,7 @@ #include #include #include +#include #include =20 #define LWTUNNEL_HASH_BITS 7 @@ -37,6 +38,7 @@ struct lwtunnel_state { }; =20 struct lwtunnel_encap_ops { + /* encap may lack NLA_F_NESTED, parse it with lwtunnel_nla_parse() */ int (*build_state)(struct net *net, struct nlattr *encap, unsigned int family, const void *cfg, struct lwtunnel_state **ts, @@ -53,6 +55,31 @@ struct lwtunnel_encap_ops { struct module *owner; }; =20 +/** + * lwtunnel_nla_parse - parse the attributes nested in an lwtunnel encap + * @tb: destination array with maxtype+1 elements + * @maxtype: maximum attribute type to be expected + * @nla: encap attribute passed to &lwtunnel_encap_ops.build_state, or an + * attribute nested in it + * @policy: validation policy + * @extack: extended ACK report struct + * + * The encap attribute, and some of the attributes nested in it, have alwa= ys + * been dumped without NLA_F_NESTED, and userspace such as "ip route resto= re" + * sends a dump back unchanged, so the flag cannot be required on @nla. + * The attributes nested in @nla are still validated strictly. + * + * Return: 0 on success or a negative error code. + */ +static inline int lwtunnel_nla_parse(struct nlattr *tb[], int maxtype, + const struct nlattr *nla, + const struct nla_policy *policy, + struct netlink_ext_ack *extack) +{ + return nla_parse(tb, maxtype, nla_data(nla), nla_len(nla), policy, + extack); +} + #ifdef CONFIG_LWTUNNEL =20 DECLARE_STATIC_KEY_FALSE(nf_hooks_lwtunnel_enabled); diff --git a/net/ipv6/ioam6_iptunnel.c b/net/ipv6/ioam6_iptunnel.c index cfb2c41634a0..946c360ff214 100644 --- a/net/ipv6/ioam6_iptunnel.c +++ b/net/ipv6/ioam6_iptunnel.c @@ -113,8 +113,8 @@ static int ioam6_build_state(struct net *net, struct nl= attr *nla, if (family !=3D AF_INET6) return -EINVAL; =20 - err =3D nla_parse_nested(tb, IOAM6_IPTUNNEL_MAX, nla, - ioam6_iptunnel_policy, extack); + err =3D lwtunnel_nla_parse(tb, IOAM6_IPTUNNEL_MAX, nla, + ioam6_iptunnel_policy, extack); if (err < 0) return err; =20 diff --git a/net/ipv6/rpl_iptunnel.c b/net/ipv6/rpl_iptunnel.c index 4e10adcd70e8..1861af408bbc 100644 --- a/net/ipv6/rpl_iptunnel.c +++ b/net/ipv6/rpl_iptunnel.c @@ -78,8 +78,8 @@ static int rpl_build_state(struct net *net, struct nlattr= *nla, if (family !=3D AF_INET6) return -EINVAL; =20 - err =3D nla_parse_nested(tb, RPL_IPTUNNEL_MAX, nla, - rpl_iptunnel_policy, extack); + err =3D lwtunnel_nla_parse(tb, RPL_IPTUNNEL_MAX, nla, + rpl_iptunnel_policy, extack); if (err < 0) return err; =20 --=20 2.50.1 From nobody Thu Sep 24 14:26:46 2026 Received: from mail-pz2-f41.google.com (mail-pz2-f41.google.com [74.125.228.41]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 253E72F28FC for ; Wed, 23 Sep 2026 00:37:09 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.228.41 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790123831; cv=none; b=I+JMQ4Aeeu2pxbdknFC7WB8cL+9+dsyBEEf6JmGiq5+i3Z1FYH8g5CycSd5j1XAm4oAu990c9X3oq0WGajbx8E8jW2aX8KxSQ+HGrrfTgvbRozJCjVTUh/1joWr9N257vLrV8B2eXVFHjifJky+TKA7sez1UhFOqGmC65fzaA9A= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790123831; c=relaxed/simple; bh=EbcJkqAUsR125AsGOm6uKZ0BhA9adZV84zXsqa1i6mA=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=i+TQ3adEghKNSt2Rd8O+KS5vIXB0USI98PZNWK4iAA9xaTg2EswjZdjJeg69+gRbkdjj2F7KVXEFr0gdErB8pKpPbNpqLh5Wk0CIBDJSkxVg1dRsutA1p0SnLeNSZqyog891o5eY2yjZnZ1Hm4tNjsEv++CvPkf6S4qxL8FiH6o= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=P98Wr6Xi; arc=none smtp.client-ip=74.125.228.41 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="P98Wr6Xi" Received: by mail-pz2-f41.google.com with SMTP id d2e1a72fcca58-868a9c48f9eso375794b3a.3 for ; Tue, 22 Sep 2026 17:37:09 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790123829; x=1790728629; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=3jWT/lp+R/Tlkfp+3AKgblbjp5barctUrxy33CjiCvo=; b=P98Wr6Xie/MCpG4SEXPluyKf33BZ/UVaBzX3WWsy84oHo6F7sHO3KXt0pjSTUwP7xS 6h9at34tW5lH3Sqg2v2kCFLa+rF/W8qbmMqpt/mXMtmL7iUjHdbzzn4ZZlZCVAYLXvhl BYolK6WOgmE7giXKU1IoIFYJROXKdjMNrHzqIpzg4ZRwwa6POWxAUfErRmubTvwS7+Xc Eeihwjib7V6iSTwvmipyjiINIoYVrWLg9jr61apECLtMeN5JUlw/ruRC662IS9w885mO 0y/wko6H7hvfuu0XP+OtK9R7MlT8nFVvkfxAZEETm7Zy+qwpKfRUzusvXzluFJzE3KEt rF6A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790123829; x=1790728629; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=3jWT/lp+R/Tlkfp+3AKgblbjp5barctUrxy33CjiCvo=; b=HBQilcuP+TjMIir7KQJ8oL6MPCnpA7GPo7dQhjzcPuv7QREOMtyxD2Fl7PwrgNPNto Av8PieiCg8Ddme8gHRN4Dj2ffA/5wiqstWCV5/AjXoWw9FhrgsvVTZ+epVstYux8r6Qp BcGIlpbkiDT7nrJEG4krSrWs0EwmGKCxGVuKk91+GnUypSXJIeKU0yzRiF/7o0+YVi/j pOpGkj0qajVOhPQxgId9y9bxS9lBNNaoQ1tQD1ru4Z+Bs/gmRcl46G5yz82NDvFy4avw 8nV14DW8JxNftoipJB92jVWatSS1bBUrBxqo3j5OTNsbXdlfPWdeeOP1p1lTrAfuKN3G co7g== X-Forwarded-Encrypted: i=1; AKwUvByifU1hBsy6UUhX6JG64lduuF3t5FXU83oxHp/QogvZWaYUO8E9J/UOMqsnfhFFDnWZyCKKPVVoGp7WgLw=@vger.kernel.org X-Gm-Message-State: AFuF++k/d0SPFFUIqk521R1+fJa1E+bMQ/li4XVCCtjpPLZMGepD0d3d 96OEBaojMf1OOfTu0jRiux3mXNKPZCvjCjUUOcMOFmwy+yoHVTGt/2AF X-Gm-Gg: AYBFou2Xtnbp0udj34QLSQl6eojbxMuB5htvM7S4iTMh9l04l2cFihaaNK5wCRhilDx otqFmlfPS9djd9OnNxvP1M1jOsoyG1bUUP9WUOfVVde/0CWH+mOn8zabIADw7QXyVXfI7DlhsUr OaMcwmpYp8737ssLfDXp7xgI98NycNOwphGox2zfGLKlylM6EJiQW+MG1Bt5FXrCpcz+bOS1+iB M1E6w8MsopzbClQKdkpV4dITJBq4uX87FPk59R9KHaIUp3gLqu4mtE4iVBDLWRyt7Z+bzvNY8PH yAN8yG9rkyHxewQkp/7LCoFQCe+dM3uazmRPU8Whf6TqJHH06maN3EMuJtbGOW4qSt8qhY9Qclb lwCqSQNy4wEyEI5w0Eh3/AgyvO7wdLkeKUj6i1AoX+I9k4E8/Houq8raBC4yg1H+xv5DFLCe5uz HrpIDt59PWzYkdLz9QoJxaOwnt9WnVnAudHW9woOYxlYsKMiCrOi4/7uDl9aWDQFiXYPgyLSYmq T3pM/FBE2c= X-Received: by 2002:a05:6a00:3c86:b0:878:3783:8a8a with SMTP id d2e1a72fcca58-87d1dde2ffamr1087891b3a.54.1790123829429; Tue, 22 Sep 2026 17:37:09 -0700 (PDT) Received: from [163.43.103.131] ([163.43.103.131]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1dff9778sm427895b3a.49.2026.09.22.17.37.05 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 22 Sep 2026 17:37:08 -0700 (PDT) From: Yuya Kusakabe Date: Wed, 23 Sep 2026 09:36:57 +0900 Subject: [PATCH net 2/4] xfrm: lwtunnel: accept RTA_ENCAP without NLA_F_NESTED Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260923-lwt-encap-noflag-v1-2-8de7ab6c86e9@gmail.com> References: <20260923-lwt-encap-noflag-v1-0-8de7ab6c86e9@gmail.com> In-Reply-To: <20260923-lwt-encap-noflag-v1-0-8de7ab6c86e9@gmail.com> To: David Ahern , Ido Schimmel , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , Justin Iurman , Alexander Aring , Steffen Klassert , Herbert Xu , Nikolay Aleksandrov , Eyal Birger , Nicolas Dichtel , Xin Long , Shuah Khan Cc: netdev@vger.kernel.org, linux-kernel@vger.kernel.org, linux-kselftest@vger.kernel.org, Yuya Kusakabe X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=openpgp-sha256; l=1299; i=yuya.kusakabe@gmail.com; h=from:subject:message-id; bh=EbcJkqAUsR125AsGOm6uKZ0BhA9adZV84zXsqa1i6mA=; b=owEBbQKS/ZANAwAIASrX0XUqXRtNAcsmYgBqsx8pbycS0xTOF+rGUkGurYGp4Ki+GssAR/lwC wNJEjCLWGGJAjMEAAEIAB0WIQTaB7usAfxNKMeqa6Yq19F1Kl0bTQUCarMfKQAKCRAq19F1Kl0b Tf7QD/0bfigNdYJ/Eb5oQOcvab12OHdvsLB2IgXftugNDtbYezhZfzSwybDssg+ldzqjhFOOA1P pNzC6A0y1wPGFffcMepDjYH+RdH631eA8ce3cbckRsN02ncQBqkhvGSWkjyubId+NI6MQDN9zhK ZcE9DEiQDkLeXugF2oxz4qXQ7dlU5cGWd50td4B8DCs4jrttrn12Ipa+IIenHnVA9GJ+97c3po+ hOmHk0WmDkboteJ+GAXVtq1m7WyOdz5ievXSUs24lQSJ2yHNk14LpdYihIIO+OpqfD9RFc3sfms 8/g0DswPc4ufeeaBQGcp9ze13NG51lZPnayx/PQa2+PZ6tCQve95Ukz/OAcvpOT199N8LYL9Pb8 6pDZlzU0ueBHBkxMVtVNZSh/rtcfQmcw5rybotR75+9CqjULhjNumQ5nwrjm/JHrwsOxrP2K5Xe +YSvXnr1jhBjtizuoONPUrl/EMXZYxenSgMq9G3lqRiU//B15Iilh0SUFziSHuk9FI7uoP5ZiWr F1ASWbOGXHNbgZH8r+CH+AkYvedy89dKtd9jmjDdsfSabt4EH5R50PpqUJ9knlNvMlsgdaGXMJl SkIL8pp5Un2Dnrr4bQjWKBwNp5zDnxJAfn0DQKPnbvXyv0n15klTCqli91MaJdALHfnx5rC4KvQ I8I5SANjcjWiIRA== X-Developer-Key: i=yuya.kusakabe@gmail.com; a=openpgp; fpr=DA07BBAC01FC4D28C7AA6BA62AD7D1752A5D1B4D xfrmi_build_state() parses RTA_ENCAP with nla_parse_nested(), which requires NLA_F_NESTED, but lwtunnel_fill_encap() dumps RTA_ENCAP without it. As a result, "ip route restore" cannot restore the routes saved by "ip route save": # ip -6 route add 2001:db8:3::/64 dev ipsec0 encap xfrm if_id 1 # ip -6 route save 2001:db8:3::/64 > route.bin # ip -6 route del 2001:db8:3::/64 # ip -6 route restore < route.bin Error: NLA_F_NESTED is missing. Use lwtunnel_nla_parse(). Fixes: 2c2493b9da91 ("xfrm: lwtunnel: add lwtunnel support for xfrm interfa= ces in collect_md mode") Assisted-by: LLM Signed-off-by: Yuya Kusakabe --- net/xfrm/xfrm_interface_core.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/net/xfrm/xfrm_interface_core.c b/net/xfrm/xfrm_interface_core.c index 688306bf62c5..2fcfbfac315a 100644 --- a/net/xfrm/xfrm_interface_core.c +++ b/net/xfrm/xfrm_interface_core.c @@ -80,7 +80,8 @@ static int xfrmi_build_state(struct net *net, struct nlat= tr *nla, struct xfrm_md_info *info; int ret; =20 - ret =3D nla_parse_nested(tb, LWT_XFRM_MAX, nla, xfrm_lwt_policy, extack); + ret =3D lwtunnel_nla_parse(tb, LWT_XFRM_MAX, nla, xfrm_lwt_policy, + extack); if (ret < 0) return ret; =20 --=20 2.50.1 From nobody Thu Sep 24 14:26:46 2026 Received: from mail-pz2-f40.google.com (mail-pz2-f40.google.com [74.125.228.40]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id F26063019BA for ; Wed, 23 Sep 2026 00:37:13 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.228.40 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790123835; cv=none; b=sKqyJ9bg2ixOghd8MtuD+twS0/g4tQY2ajwUd3jnQL4deYb/8c9i0joUhBDJBQMD7yQJEoSEELZzIM3VLwCLxaOaYMu/gOv0UBCpFL8fVDWs65S6VwVB0xqhTrf32CGrslcfIOcoRDoN5QovYnEhpXNdwJNpWm5mxO2ahfgG4rY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790123835; c=relaxed/simple; bh=oqaPlCUSuLMmmge376HFkC5mCq37bzKmEex5ZULPFT4=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=rb76F+xBn/2s7qFXyJSOQtJREVOsuYXXUB+TO+7eMLXCGWldh/46goAyTuhEiSApy6jsUELY1P+QDbjFkhyTC2ECSIyN4SxeFlv6ciNUV+tUQW0Byziqkgkt47kww9ody19uqUFlnETw5bcIoLgK7G/4jVr2675Ni6U+MDqCl3M= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=VHGoCGgE; arc=none smtp.client-ip=74.125.228.40 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="VHGoCGgE" Received: by mail-pz2-f40.google.com with SMTP id d2e1a72fcca58-8748f34b1f2so272919b3a.0 for ; Tue, 22 Sep 2026 17:37:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790123833; x=1790728633; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=cs5VDXaWa10EO+BljqB1eCOQjDMrGLKA7eDZKUXCtZc=; b=VHGoCGgEujli+1bSIlAWuKuIN1iEd9b4+DiFFpqvHtHOdVxf/yW22SJApdxQhIlRQ8 DgXaVOUipfDnRjy1w3lSH01LQ2nmgraOGwErFYz920GVsIoFNmrMUCHiijOjiemu3aHI XUPSf2bQJpaqmir5lvatuWNoVTRUI8yDepabVn5GVLiS0KvwQXiOOxmLCs30tRS5qGZi bGhtuQEWON/18vyPjCHndfy/gU42rdJkcDBqowXBtUhREAwMw89cEGJ2LJDEaKhRXEom 2aKh47yvUvT9MzredN0yPpDgYXwxmQaie870QcCHvblrB3PTtBexWeS2UIGN2psLoAFS H3kw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790123833; x=1790728633; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=cs5VDXaWa10EO+BljqB1eCOQjDMrGLKA7eDZKUXCtZc=; b=sC3FdZP7UasSSOnEtkJjNJeTJWNmmGoDsjJfGHtG81pAC0MK3ekH3jwBIgFEgzICYl WDnaMyNNIrpf7Blc6XsG6+q6OT6G5JBhZQ9oQPdARKsJG/x2wqo+0ugQ6W3liickHlDd 9zfI8Fj8veh28pdef/AvuiiqqOCm1IajGNOFMdc5DF+1A+YiOG6apMWWYm4W82tffCPt 2ix1Hp04j+Thb9hdTK+wpW8megjic2DZO9CDZ9wQc2ZL6RFT3Wi46sz2vYLZ5RZh9Kak eRpq7j27KwBgSYwwhVivmyTCjsu7KXJ8gyV4GtSaKN3T1iCHaB8d4NpnXDPpasxxXQps rWeg== X-Forwarded-Encrypted: i=1; AKwUvBy0aPj5Fmv+/2YYfCU9oIIMAE7FGXrLOpGo+8lryJZqwZBMlfH7+bmRZlY7IWbN5e3dSGVSqpNp+shiMZw=@vger.kernel.org X-Gm-Message-State: AFuF++lI29dIYjVYDYu3ZXnfxxTk6GFO85haw5Z3+Rp11GmLlaJLeh8W YPanv/7xK5DlRqUh1Een2dwUs50tfp3/rr3Z1ScBjLDbOOQOXyGDRQTm X-Gm-Gg: AYBFou2SiErLmqM/7pIpgcqemUa7pC+NkS/kMZviSuMwcuLVgS9BlWQsVNrx4kFnnHW RVHIn9UybuN1J3Y0C2qvY0gTsUe6HzY0++E3sMsaSogYfG3RsDEKIvZZWK57t+nCzJC1Fx3mbk4 rw7HhHhPn0AnaAw7C1YZIM95B3154E4KbxfJSEr42GPLYQoS9YgxIwHB6Tt8DR/vJkMdfJPp9Tf Fju9C/3/IIdgUSHYnmPp6k/SQAkFX5fKr7JlCk34dHDez1YkpgJCCAH859Gy6H/0cLj2PjSm0mf UzVHWKCZsMjnBnwCQGRK0rTWt0BxAtO0KS/Ki0oV5dmXNZjvlvN9Em8WUDUBnZ27IOn5LrMKoJF oOOMKzNkOqyOi5hKKg8eLUowncDytQJLtGZVpJej9ph5mTixSsYWrFkV8eCkNy1QyHbR3Q+isEO wxcQ0+fi+J7fBBtdFt6Y2Ky8BYaG5ESnwWiwcWpOK4luOGX5m0w5JNywAf+QEM3yBg6e2LijAk5 5CY0J6ZcxQJwUAxprNn X-Received: by 2002:a05:6a00:a489:b0:857:72ba:ff12 with SMTP id d2e1a72fcca58-87d19da1c6amr1197615b3a.26.1790123833293; Tue, 22 Sep 2026 17:37:13 -0700 (PDT) Received: from [163.43.103.131] ([163.43.103.131]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1dff9778sm427895b3a.49.2026.09.22.17.37.09 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 22 Sep 2026 17:37:12 -0700 (PDT) From: Yuya Kusakabe Date: Wed, 23 Sep 2026 09:36:58 +0900 Subject: [PATCH net 3/4] net: ip_tunnel: accept tunnel options without NLA_F_NESTED Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260923-lwt-encap-noflag-v1-3-8de7ab6c86e9@gmail.com> References: <20260923-lwt-encap-noflag-v1-0-8de7ab6c86e9@gmail.com> In-Reply-To: <20260923-lwt-encap-noflag-v1-0-8de7ab6c86e9@gmail.com> To: David Ahern , Ido Schimmel , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , Justin Iurman , Alexander Aring , Steffen Klassert , Herbert Xu , Nikolay Aleksandrov , Eyal Birger , Nicolas Dichtel , Xin Long , Shuah Khan Cc: netdev@vger.kernel.org, linux-kernel@vger.kernel.org, linux-kselftest@vger.kernel.org, Yuya Kusakabe X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=openpgp-sha256; l=6146; i=yuya.kusakabe@gmail.com; h=from:subject:message-id; bh=oqaPlCUSuLMmmge376HFkC5mCq37bzKmEex5ZULPFT4=; b=owEBbQKS/ZANAwAIASrX0XUqXRtNAcsmYgBqsx8qoZ9UvQxTNKyzWBK4DXc+hGQf0Ml3ZHx0p +tAt2uuOZuJAjMEAAEIAB0WIQTaB7usAfxNKMeqa6Yq19F1Kl0bTQUCarMfKgAKCRAq19F1Kl0b TcjcEACpcfZ9JEJkn4O6lUv8wQ6QicwbBE8oiwLchoHGyxzunTObvQO0XZ/CKYQ3qtFFLOWjCaQ joZa3hLwY5PcuD4QqsB+V0i9t+zhVgVqIyRb4pv/MgJvoO/kihCgePgKzY9uCNM2gYMM+ClUxgI cNeAT7ee9R1UbuLqe/EnUjIpecZGi/YdHGzA8EEon7K3Rwumb5K1GmJlYAy1A2EGYWriGYQJiWz dr1lf4qWLGgsmO8Gi/WCNGgETtkUmYGiGqaEnNqDHIybcKaN5LFC1eorCXXdx8lkSOJGiZze0gU /9rNWFSJisqX11KlR5q+C8zEYR2wqtZ+FA+9VWV5QCSkXpSuj3jOOm/vCkjqp1SLhicTHreWo4/ LpDn6S/H2FhcDJRrV0PGtH0Gb6ft87r1tVyaV/Te1aFwdDFXFM3hp5+OPjaR6Kd6V1ci25eYE8e uxh4XoDu+Hqcgcd9l8/9+hZdEDQEHvt2sffMd4W2/mOtrS/4CGyKab/AsNC3HRty8DEAGVwhBPD SThiw1a9q66pzbja0gp9Kvo+BsqNJx4pRmlIL1yFZEPxbM3tswQHEUql0t4B+xQTcE96jRCs+Ut rdDnd7340H4URrbmtt8sgSw42QY9NP+MyMMSfELOiMyM7dUN/Vf4yrxb8G+cf9ps7dWXAVgZXK6 uPzH0YDZpLdgXrg== X-Developer-Key: i=yuya.kusakabe@gmail.com; a=openpgp; fpr=DA07BBAC01FC4D28C7AA6BA62AD7D1752A5D1B4D ip_tun_fill_encap_opts() and its helpers dump LWTUNNEL_IP_OPTS, LWTUNNEL_IP6_OPTS and the geneve, vxlan and erspan options nested in them without NLA_F_NESTED. Commit ed02551f58b9 ("lwtunnel: change to use nla_parse_nested on new options") made the parsing of all of them strict, on the grounds that new attributes should be strict from the start, but left the dump as it was, and the two sides have disagreed ever since. So "ip route restore" cannot send back the ip and ip6 encap routes with tunnel options saved by "ip route save": # ip route add 192.0.2.0/24 encap ip id 1 dst 198.51.100.2 \ geneve_opts 0:0:12121212 dev dummy0 # ip route save 192.0.2.0/24 > route.bin # ip route del 192.0.2.0/24 # ip route restore < route.bin Error: NLA_F_NESTED is missing. The flag is required at three levels: - ip_tun_policy and ip6_tun_policy validate LWTUNNEL_IP_OPTS and LWTUNNEL_IP6_OPTS strictly through .strict_start_type. - ip_tun_parse_opts() validates the options nested in them with nla_validate(), which is strict as well. - ip_tun_parse_opts_geneve(), ip_tun_parse_opts_vxlan() and ip_tun_parse_opts_erspan() parse each option with nla_parse_nested(). Start the strict validation after LWTUNNEL_IP(6)_OPTS, validate the options with lwtunnel_nla_validate(), which is nla_validate() without the NLA_F_NESTED check, and parse each option with lwtunnel_nla_parse(). netlink has no validation level that keeps the other strict checks and drops that one, so lwtunnel_nla_validate() clears the flag when calling __nla_validate(). Nothing else is relaxed: unknown option types and trailing bytes after the last option are still rejected, and attributes added to ip_tun_policy and ip6_tun_policy later are still validated strictly. Fixes: ed02551f58b9 ("lwtunnel: change to use nla_parse_nested on new optio= ns") Fixes: 2f1d370b997a ("lwtunnel: add support for multiple geneve opts") Fixes: 7b6a70f73764 ("lwtunnel: be STRICT to validate the new LWTUNNEL_IP(6= )_OPTS") Assisted-by: LLM Signed-off-by: Yuya Kusakabe --- include/net/lwtunnel.h | 22 ++++++++++++++++++++++ net/ipv4/ip_tunnel_core.c | 24 ++++++++++++++---------- 2 files changed, 36 insertions(+), 10 deletions(-) diff --git a/include/net/lwtunnel.h b/include/net/lwtunnel.h index 046978d6224c..59d7ec7b04f2 100644 --- a/include/net/lwtunnel.h +++ b/include/net/lwtunnel.h @@ -80,6 +80,28 @@ static inline int lwtunnel_nla_parse(struct nlattr *tb[]= , int maxtype, extack); } =20 +/** + * lwtunnel_nla_validate - validate the attributes nested in an lwtunnel e= ncap + * @nla: encap attribute passed to &lwtunnel_encap_ops.build_state, or an + * attribute nested in it + * @maxtype: maximum attribute type to be expected + * @policy: validation policy + * @extack: extended ACK report struct + * + * Like nla_validate(), except that NLA_F_NESTED is not required on the + * attributes nested in @nla, for the reason given for lwtunnel_nla_parse(= ). + * + * Return: 0 on success or a negative error code. + */ +static inline int lwtunnel_nla_validate(const struct nlattr *nla, int maxt= ype, + const struct nla_policy *policy, + struct netlink_ext_ack *extack) +{ + return __nla_validate(nla_data(nla), nla_len(nla), maxtype, policy, + NL_VALIDATE_STRICT & ~NL_VALIDATE_NESTED, + extack); +} + #ifdef CONFIG_LWTUNNEL =20 DECLARE_STATIC_KEY_FALSE(nf_hooks_lwtunnel_enabled); diff --git a/net/ipv4/ip_tunnel_core.c b/net/ipv4/ip_tunnel_core.c index bab42b9e277f..c87827ffc347 100644 --- a/net/ipv4/ip_tunnel_core.c +++ b/net/ipv4/ip_tunnel_core.c @@ -466,7 +466,9 @@ int skb_tunnel_check_pmtu(struct sk_buff *skb, struct d= st_entry *encap_dst, EXPORT_SYMBOL(skb_tunnel_check_pmtu); =20 static const struct nla_policy ip_tun_policy[LWTUNNEL_IP_MAX + 1] =3D { - [LWTUNNEL_IP_UNSPEC] =3D { .strict_start_type =3D LWTUNNEL_IP_OPTS }, + [LWTUNNEL_IP_UNSPEC] =3D { + .strict_start_type =3D LWTUNNEL_IP_OPTS + 1 + }, [LWTUNNEL_IP_ID] =3D { .type =3D NLA_U64 }, [LWTUNNEL_IP_DST] =3D { .type =3D NLA_U32 }, [LWTUNNEL_IP_SRC] =3D { .type =3D NLA_U32 }, @@ -509,8 +511,8 @@ static int ip_tun_parse_opts_geneve(struct nlattr *attr, struct nlattr *tb[LWTUNNEL_IP_OPT_GENEVE_MAX + 1]; int data_len, err; =20 - err =3D nla_parse_nested(tb, LWTUNNEL_IP_OPT_GENEVE_MAX, attr, - geneve_opt_policy, extack); + err =3D lwtunnel_nla_parse(tb, LWTUNNEL_IP_OPT_GENEVE_MAX, attr, + geneve_opt_policy, extack); if (err) return err; =20 @@ -546,8 +548,8 @@ static int ip_tun_parse_opts_vxlan(struct nlattr *attr, struct nlattr *tb[LWTUNNEL_IP_OPT_VXLAN_MAX + 1]; int err; =20 - err =3D nla_parse_nested(tb, LWTUNNEL_IP_OPT_VXLAN_MAX, attr, - vxlan_opt_policy, extack); + err =3D lwtunnel_nla_parse(tb, LWTUNNEL_IP_OPT_VXLAN_MAX, attr, + vxlan_opt_policy, extack); if (err) return err; =20 @@ -575,8 +577,8 @@ static int ip_tun_parse_opts_erspan(struct nlattr *attr, int err; u8 ver; =20 - err =3D nla_parse_nested(tb, LWTUNNEL_IP_OPT_ERSPAN_MAX, attr, - erspan_opt_policy, extack); + err =3D lwtunnel_nla_parse(tb, LWTUNNEL_IP_OPT_ERSPAN_MAX, attr, + erspan_opt_policy, extack); if (err) return err; =20 @@ -626,8 +628,8 @@ static int ip_tun_parse_opts(struct nlattr *attr, struc= t ip_tunnel_info *info, if (!attr) return 0; =20 - err =3D nla_validate(nla_data(attr), nla_len(attr), LWTUNNEL_IP_OPTS_MAX, - ip_opts_policy, extack); + err =3D lwtunnel_nla_validate(attr, LWTUNNEL_IP_OPTS_MAX, + ip_opts_policy, extack); if (err) return err; =20 @@ -975,7 +977,9 @@ static const struct lwtunnel_encap_ops ip_tun_lwt_ops = =3D { }; =20 static const struct nla_policy ip6_tun_policy[LWTUNNEL_IP6_MAX + 1] =3D { - [LWTUNNEL_IP6_UNSPEC] =3D { .strict_start_type =3D LWTUNNEL_IP6_OPTS }, + [LWTUNNEL_IP6_UNSPEC] =3D { + .strict_start_type =3D LWTUNNEL_IP6_OPTS + 1 + }, [LWTUNNEL_IP6_ID] =3D { .type =3D NLA_U64 }, [LWTUNNEL_IP6_DST] =3D { .len =3D sizeof(struct in6_addr) }, [LWTUNNEL_IP6_SRC] =3D { .len =3D sizeof(struct in6_addr) }, --=20 2.50.1 From nobody Thu Sep 24 14:26:46 2026 Received: from mail-pz2-f43.google.com (mail-pz2-f43.google.com [74.125.228.43]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 91C8D30596F for ; Wed, 23 Sep 2026 00:37:18 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.228.43 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790123841; cv=none; b=oL7MnBNT3bNXFzq85o6WCuDRMOXV9Nv99zdek7Rr2REgMh5fzRZiizwB/mdMEbNY7rRpIdc3jWTdIOrXyQ9dDek5JEy4sgo74t4qKNxyBjpKwngZfD8rcJFJfHl3GVq5qtv/HPLUtwyVcqlOu+9T9IjXP7zgfZuoeQxXMuNjm9U= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790123841; c=relaxed/simple; bh=qkeQzWOWaxxISsl4uCQPDbfJ2pwDKTr/UDzPD99oQ98=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=QBheg9Ju0lpgF0s0PJJhYg8OCWjbZNGvh+R1Mstgx3XPktC6WcMmcEmByNfk7upKKmDwoZcjhqTLRsEt+RvCoqJM0cwZgZejdUI6XObbcuizIU3g8MSfFseGMGvpcoxSAGttigjGGDKV4KQCG1OkWhFcpSyIVoyOg+uWK/RnWls= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=haUnb6/u; arc=none smtp.client-ip=74.125.228.43 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="haUnb6/u" Received: by mail-pz2-f43.google.com with SMTP id d2e1a72fcca58-8623e5d435cso140015b3a.1 for ; Tue, 22 Sep 2026 17:37:18 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790123838; x=1790728638; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=vQQTGO16FXbzJluwZGxhoyxw7BVm8s40aDo/D7gXx7E=; b=haUnb6/umygpdhvmg/IzQrNUoYsT83fOZ3GTKlimFvLPhVNNle57N6zvV5U/XEHStV uIE7NXWgbFDP7jLarAU3vuyqbKWlmtcQtkhRzmHJ3CcijaM0xF5f+TCaE8voDLpJohkZ bUOjCBWthkD7SacGPtnpeJpqoPJR1Qf5hPvq1QXbiYBX5BsxPrsFeQauA0szqG3LYKlj W41AI2YMjXtRB20OW8ja+yqZwV9LMho69z7VqAxiGwEjlyehXJlf3BMF4LBlAZJXdJ8j 1DpO3Juo9ElGk9lmZmrfKfwRcA6RCL4AAgKYRpf1s28hU1vJvNo3czb1Pf1J/h+UVWLQ uxiw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790123838; x=1790728638; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=vQQTGO16FXbzJluwZGxhoyxw7BVm8s40aDo/D7gXx7E=; b=LUk0d12OQJ71csC0LULjjGo/qTEdHlbyEuh80FF9rwI5NfItl6nPh0nXPDW9aL3RPk APnzuKheVM5w4FP+dynVEcIzCWTs5UBM5B3DcZobos/wgbrlo5b9oRRLY3U3DdrS+SJh jDG/VCAHTGdW+kvbIx188YXH7mZfv09cmWBZxlcbZzrvYFEXFoaZ/HjImYxafKTzuLod hvSwSDaHOZWelZ+DOjUD/BNguvdytfHZDNSRqxMYN/AcRXHrZFKd8rxEZVLTuHTy6Mwh nS0RNfccx5VoDP4sMdz/gvVM1GzAwVwYIq1cJtQN9PLhtbEbiFPoVHVjgw9Ex4wLvE5Q 5RUw== X-Forwarded-Encrypted: i=1; AKwUvBxdfDrWTPwBKMXOtbQzcSTscKwZU3qPO0YbKZ/6fRxcm/FFuQJXBqs/wwOjs2GRB+tKBgSykcyw74S6ZME=@vger.kernel.org X-Gm-Message-State: AFuF++lisGzYrbb+eg8nVQ3Y4Y4G0z4XQuWByzujOoDOh451SsdZ0BLv sBXcVcG10DPRJkJMMWf1idlCxm+0QPaEP46dNPJ3bfpk2sr1QpKlaVGT X-Gm-Gg: AYBFou1zhs/ADs1wDoY1G5SBOU9zUw3Dgm4tKimePKZwmDvvbcXpkGMkuft2C312yg0 q9GENHDdBlIlXF9G6nAwCOHdN3DxokNZ0St9NGY0U4CS8vft+yiQoFSdmqxUJ7ttoIwA/ZBm2VO IQbVHdCpPOwyB3ZwcCrU2pCbAEbEMukL9KUgzavXbQibRr/ZEORFMPwZkPCy2aNJppyEPyZXb3a Nf/qqYD6nU1/kGfgkCI2M/PAmcL4Vab37xCSyJ93lkO6q3o5byDESEaC4G0/Ize4boj88gZqk6O fhzph6Qs4eC9j2NJ3fL6BcNO7CWGzab93qXE83k5u4dsfvirvd9ZEkWVEVLD+WNEzVh2p3/nuQC MyJezustuVLl2Qn3i9O1+aX1nhQPmHQwLQP4cUr9IzfPETFLmou+Y/dM+wHBOxkN3VH40bGOBmL BfsHM6EWe1SpnN7lys70AOsjr4VzOPSXzkQocBozox0AhlaHJ+JXkrguvUtAQeUEUF7lzjvjRj0 kyieQGxGlQ= X-Received: by 2002:a05:6a21:1398:b0:3dd:a196:ffcd with SMTP id adf61e73a8af0-3ddf8354fd9mr736411637.29.1790123837960; Tue, 22 Sep 2026 17:37:17 -0700 (PDT) Received: from [163.43.103.131] ([163.43.103.131]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-87d1dff9778sm427895b3a.49.2026.09.22.17.37.13 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 22 Sep 2026 17:37:16 -0700 (PDT) From: Yuya Kusakabe Date: Wed, 23 Sep 2026 09:36:59 +0900 Subject: [PATCH net 4/4] selftests: net: add lwtunnel route save and restore test Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260923-lwt-encap-noflag-v1-4-8de7ab6c86e9@gmail.com> References: <20260923-lwt-encap-noflag-v1-0-8de7ab6c86e9@gmail.com> In-Reply-To: <20260923-lwt-encap-noflag-v1-0-8de7ab6c86e9@gmail.com> To: David Ahern , Ido Schimmel , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , Justin Iurman , Alexander Aring , Steffen Klassert , Herbert Xu , Nikolay Aleksandrov , Eyal Birger , Nicolas Dichtel , Xin Long , Shuah Khan Cc: netdev@vger.kernel.org, linux-kernel@vger.kernel.org, linux-kselftest@vger.kernel.org, Yuya Kusakabe X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=openpgp-sha256; l=4135; i=yuya.kusakabe@gmail.com; h=from:subject:message-id; bh=qkeQzWOWaxxISsl4uCQPDbfJ2pwDKTr/UDzPD99oQ98=; b=owEBbQKS/ZANAwAIASrX0XUqXRtNAcsmYgBqsx8qGYKDa+Moa334x7rJOG8r+GdYWjOJwUmhN grU+ne16wCJAjMEAAEIAB0WIQTaB7usAfxNKMeqa6Yq19F1Kl0bTQUCarMfKgAKCRAq19F1Kl0b TeNREACzYs5nzq43SdXpSUP7sd70DgWFhqYY2j6yuqOeQuMUnL1l8Ns2/hYo8bUe1LyfpRm1Uys G+vTYT9fpVAdhWAuDzB9EX7W9HJIzC8lqj/ft831DL1Clj7q2ZidVRMhaBkTUxB8vSHMQIUuNuN Ahger3YtSbcD2GspOweoLVGUcQIzksNKxtfVs+O9RHcLjuq4FYwiR+XtyIixehGvDbl0doOeGc1 b6ksWyKalDqCsuBzD+XekRBVAyo1i2jGUNp156DU+XQ4hJWbsInJpMWngR6nM66UrTuP+5vFUKI Pc8i1hchxqENQfggrd7/ThhXcMTZiZnQJtPllFk3UEXTgw1wn8RjRniDSUz4SJJYRKVWLLS7g8m snB/FZl1sOtj1oyjQyrTYCUgcgHRlgxSGBZxj03qTVTmXGr1QE+CK+8yNoCFO5V1DwWeDp0EXy0 5YwmH7TYib1kGb09ODRkG4j7lTvP2E7x9+REmMrDFsT09pqnQJ5G4zK24Y5nMlvH4edHotm1pt1 rj4mpvNwUuVTQVFprgKWLFKlG2M5mCojH2eTKL2IbVSRgVj239y/y4n1gkhroIq7WQ0Y77hLJ4Y VFkoTvY6uwO2RGp6Lq/a4L/tY+Fos5FM5QbZ3A/1dH2t1axGFw287r16snDgGh+ktF8LFIMkUQS 0ph8PWetfqEVV5A== X-Developer-Key: i=yuya.kusakabe@gmail.com; a=openpgp; fpr=DA07BBAC01FC4D28C7AA6BA62AD7D1752A5D1B4D Add an encap route, save it with "ip route save", delete it and send the dump back with "ip route restore". The restored route must match the original one. The test covers the rpl, ioam6 and xfrm encaps and the ip encap with geneve, vxlan and erspan options. A case is skipped when the kernel or iproute2 does not support its encap. Assisted-by: LLM Signed-off-by: Yuya Kusakabe --- tools/testing/selftests/net/Makefile | 1 + tools/testing/selftests/net/lwt_save_restore.sh | 116 ++++++++++++++++++++= ++++ 2 files changed, 117 insertions(+) diff --git a/tools/testing/selftests/net/Makefile b/tools/testing/selftests= /net/Makefile index 3ee3378f8b26..496aed9ca57b 100644 --- a/tools/testing/selftests/net/Makefile +++ b/tools/testing/selftests/net/Makefile @@ -62,6 +62,7 @@ TEST_PROGS :=3D \ l2tp.sh \ link_netns.py \ lwt_dst_cache_ref_loop.sh \ + lwt_save_restore.sh \ macvlan_mcast_shared_mac.sh \ msg_zerocopy.sh \ nat6to4.sh \ diff --git a/tools/testing/selftests/net/lwt_save_restore.sh b/tools/testin= g/selftests/net/lwt_save_restore.sh new file mode 100755 index 000000000000..9666386c622d --- /dev/null +++ b/tools/testing/selftests/net/lwt_save_restore.sh @@ -0,0 +1,116 @@ +#!/bin/bash +# SPDX-License-Identifier: GPL-2.0 +# +# Check that routes with a lightweight tunnel encap survive "ip route save" +# followed by "ip route restore", which sends the dumped RTA_ENCAP back to +# the kernel unchanged. + +# shellcheck disable=3DSC1091,SC2034,SC2154,SC2317 +source lib.sh + +ALL_TESTS=3D" + save_restore_rpl + save_restore_ioam6 + save_restore_xfrm + save_restore_geneve_opts + save_restore_vxlan_opts + save_restore_erspan_opts +" + +setup_prepare() +{ + setup_ns NS + defer cleanup_all_ns + + ip -n "$NS" link add name dummy0 up type dummy +} + +# save_restore +# +# The description starts with the encap type. +save_restore() +{ + local desc=3D$1; shift + local prefix=3D$1 + local encap=3D${desc%% *} + local before after dump out rc + local family=3D-4 + + [[ $prefix =3D=3D *:* ]] && family=3D-6 + + RET=3D0 + + if ! ip route help 2>&1 | grep "^ENCAPTYPE" | grep -qw "$encap"; then + log_test_skip "$desc" "iproute2 lacks the encap" + return + fi + + out=3D$(ip -n "$NS" "$family" route add "$@" 2>&1) + rc=3D$? + if ((rc)) && [[ $out =3D=3D *"encapsulation type"* || + $out =3D=3D *CONFIG_LWTUNNEL* ]]; then + log_test_skip "$desc" "kernel lacks the encap" + return + fi + check_err "$rc" "Failed to add route: $out" + + dump=3D$(mktemp) + defer rm -f "$dump" + + before=3D$(ip -n "$NS" "$family" route show "$prefix") + ip -n "$NS" "$family" route save "$prefix" > "$dump" + check_err $? "Failed to save route" + + ip -n "$NS" "$family" route del "$prefix" + ip -n "$NS" "$family" route restore < "$dump" + check_err $? "Failed to restore route" + + after=3D$(ip -n "$NS" "$family" route show "$prefix") + [ "$before" =3D "$after" ] + check_err $? "Restored route differs from the saved one" + + log_test "encap $desc route save and restore" +} + +save_restore_rpl() +{ + save_restore rpl 2001:db8:1::/64 \ + encap rpl segs 2001:db8::2 dev dummy0 +} + +save_restore_ioam6() +{ + save_restore ioam6 2001:db8:2::/64 \ + encap ioam6 trace prealloc type 0x800000 ns 1 size 12 dev dummy0 +} + +save_restore_xfrm() +{ + # iproute2 takes every argument after "encap xfrm" as an xfrm one + save_restore xfrm 2001:db8:3::/64 dev dummy0 encap xfrm if_id 1 +} + +save_restore_geneve_opts() +{ + save_restore "ip geneve_opts" 192.0.2.0/26 \ + encap ip id 1 dst 198.51.100.2 geneve_opts 0:0:12121212 \ + dev dummy0 +} + +save_restore_vxlan_opts() +{ + save_restore "ip vxlan_opts" 192.0.2.64/26 \ + encap ip id 1 dst 198.51.100.2 vxlan_opts 456 dev dummy0 +} + +save_restore_erspan_opts() +{ + save_restore "ip erspan_opts" 192.0.2.128/26 \ + encap ip id 1 dst 198.51.100.2 erspan_opts 1:123:0:0 dev dummy0 +} + +trap defer_scopes_cleanup EXIT +setup_prepare +tests_run + +exit "$EXIT_STATUS" --=20 2.50.1