From nobody Mon Sep 28 11:40:32 2026 Received: from mail-ed1-f54.google.com (mail-ed1-f54.google.com [209.85.208.54]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8D7D22F1FED for ; Sat, 22 Aug 2026 09:12:25 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.208.54 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787389947; cv=none; b=g096c+1oX4A0OLtXTQd4SO9w4HpAFk49Ptks5FY1uQA6xvpF+tJjnQlaolaBxalGvZ2MSG3UkRRcYlTUv/q2ASRrTtiJRPVlJ7d/dCheG387CMg2cekTXGse7g6EPoisJ3PuKo5DcFZriEw8NAorAnguomx83MO32bQ7DlkTSmg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787389947; c=relaxed/simple; bh=XT5S148/6y5PD2abIdBJGe7naJ1gCbCR2/WdiwBaWPg=; h=Content-Type:Mime-Version:Subject:From:In-Reply-To:Date:Cc: Message-Id:References:To; b=NFvtgLIyVxPWndpR2eQYVdxVj64qOSuEhAN4gMZQfW8yPBaRVSvkdSyMbRBwNwfOrUm5b8/H9agZ8nCBOrTpY9tuA0/pV6G9ezTHWH6+4N5M05rzgWvaa7hUqK51IPNriP3QpuS88B+yODksvVN33x2tlc1sIsfur5uNsBo7dRc= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=doyensec.com; spf=pass smtp.mailfrom=doyensec.com; dkim=pass (2048-bit key) header.d=doyensec.com header.i=@doyensec.com header.b=iEG0di0y; arc=none smtp.client-ip=209.85.208.54 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=doyensec.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=doyensec.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=doyensec.com header.i=@doyensec.com header.b="iEG0di0y" Received: by mail-ed1-f54.google.com with SMTP id 4fb4d7f45d1cf-6a0de062db5so3394988a12.1 for ; Sat, 22 Aug 2026 02:12:25 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=doyensec.com; s=google; t=1787389944; x=1787994744; darn=vger.kernel.org; h=to:references:message-id:content-transfer-encoding:cc:date :in-reply-to:from:subject:mime-version:content-type:from:to:cc :subject:date:message-id:reply-to:content-type; bh=uQFsMzRQ7qJG+O1uCjBI7iyW2F5zaHwuZq7leRaTSoY=; b=iEG0di0yoPIKluDXmcb1o0tKC0u8Xe/Gf9JGClCuRdkOeXKx3rVcLnZeaOIiJoPHVA Y0K/xUDsI/UeBjz6EDhpksaIk/eBpwXu5TpKzWv+DYu8frS+IeQJGmzGqO+GlhYWFXJt t67OaeFiR5q5r/Uxjw/Dl6eQkfP7e+DAY+Jq3u52TPU8nfGL+R2MXQ+2ay5et1sNLzBY bU9W8kSZYZPXb7m+ONKSEG+W0MWNm4kKz2oJ4juCS8loUDejgTlbGB+rToxetuZyziwD DKCExU/88ffZHQq6TYg7paZxuTGupCTPyYEvbyek60EgEplxgdqIfI15K2VnjeMxcKyi 7uKQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787389944; x=1787994744; h=to:references:message-id:content-transfer-encoding:cc:date :in-reply-to:from:subject:mime-version:content-type:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=uQFsMzRQ7qJG+O1uCjBI7iyW2F5zaHwuZq7leRaTSoY=; b=Tsxcwl9uWJbBbI/8HwTroElrnooRrnQi/nzsSNgdUBh9R4Rv6ThzZacFmLBRFOz1Bf ahyKSHRPVDktQxDPqyomQgLbeoAmCLMUz0xXQaKE4AEOp+7ewbVZNP62RggAdfdzo72g fCrBU7HrpkrJrznJv7+1wrpcz1SIoUb9ivfcsvmyNV5VKeGKg75jinGPjKmhHTdRBerj r42hJzyL1GrDBqZU3BGmwBQZA537j7siFGWmTwDdEds+4SOcqPucg0r6Qy6DVlh4YdLf nX7zppSN0MaGZYanqqw8v0tYrhN+Xi3Cgpkp70aXfa2WooPhdt2Z5mPHm8kalAKTvKqA KU+A== X-Forwarded-Encrypted: i=1; AHgh+Rpc9bgpmlyqODOiIcMpsd+Ee3q0DwRsXCtzX/dl2Z4D/dC8+bfyPtLKJaWOZz1zD7TZ4oJBtQU9UK+Wj1M=@vger.kernel.org X-Gm-Message-State: AFuF++m/FfYoqElVPNlnAW6mYdVhVe04I9WzQJbYMy7n5DabFf2lgzth NbGurZ1xb9xmRujrVd5/6ZeyAtUhgLiYlyJsnJ0ibteuvNHT8/m5oVLTOs6F9QmqEeI= X-Gm-Gg: AR+sD103DLcxHcT/x5JvnJ1LhwQmn2XdiipJODuzX4Eo2Y1oqFrugE6tRv52gMScZ3Q dhD2+ZSpfOz4UNPSj1/ur14kw55e4R6ZDg38eH5GPxm11WoxXB87/ghV6BzCXqdU6WR43GdcjXH wuSpUtXYFE/khWqHi/cT7YpEi/j3YUpTmrOTWMAl0JV0YiN8tG3ryAIVQOOcvUNCoLkhtW9R1ak Yr/7V4AQDQg3nYQMHKXkY11OXZQwLQL1J1OoAlLoGCjk5ArDY0E5F58poRKAXpxwET46OIxDNBk t8YLoA8im/lAnqdxK1g+NkWsPXpFuDRhqOA02yvpzNJZ2Vzvvfe4n3T8Aj5q21lno7zDaGxNvgD n+tbsg7XXMVysSQ/JtFwzALpmv7oxA4XvEp4VpV22ozChj6AfNoGTAiW2NtmB151aYigngR50++ vaxTa96GMv+EIQsxyyuehzRQsIYiWb5JhVk+tPUgZqBtmYYrU+KVhPy0jwWePX5uAium5p+c4xN AsLbMW2UspE9qoMqCRGvJLSqPveRmNXQGiov10dbFPFXiCKjXSAq9SOWVCverEIWM0M7N6DfEG0 ghh6tZEHWfszfBMFt+4aeCGMmV/NDi5Xafe4Dg== X-Received: by 2002:a05:6402:3784:b0:6a0:eb:ae41 with SMTP id 4fb4d7f45d1cf-6a42f2096a5mr14464320a12.10.1787389943816; Sat, 22 Aug 2026 02:12:23 -0700 (PDT) Received: from smtpclient.apple (78-141-71-213.dynamic.orange.sk. [78.141.71.213]) by smtp.gmail.com with ESMTPSA id 4fb4d7f45d1cf-6a3ff16c546sm10836738a12.21.2026.08.22.02.12.21 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Sat, 22 Aug 2026 02:12:23 -0700 (PDT) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3826.700.81.1.4\)) Subject: [PATCH net v4 1/3] openvswitch: only skb_tx_error() a packet we are about to drop From: Norbert Szetei In-Reply-To: <4B5CCA6E-2C49-4F86-8C4E-E1BE15C16C0A@doyensec.com> Date: Sat, 22 Aug 2026 11:12:11 +0200 Cc: "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , Aaron Conole , Eelco Chaudron , Ilya Maximets , Steffen Klassert , Kuan-Ting Chen , "Michael S. Tsirkin" , Willem de Bruijn , linux-kernel@vger.kernel.org, dev@openvswitch.org, Jongmin Jang Content-Transfer-Encoding: quoted-printable Message-Id: <55A52703-7548-4A55-A9CE-2A37145BDCAD@doyensec.com> References: <4B5CCA6E-2C49-4F86-8C4E-E1BE15C16C0A@doyensec.com> To: netdev@vger.kernel.org X-Mailer: Apple Mail (2.3826.700.81.1.4) Content-Type: text/plain; charset="utf-8" queue_userspace_packet() borrows the packet skb -- it only copies it into a private netlink message (user_skb) and does not own it; on return do_execute_actions() keeps forwarding it through the flow's remaining actions. Its error path nevertheless calls skb_tx_error(skb), which via skb_zcopy_clear() does skb_shinfo(skb)->flags &=3D ~SKBFL_ALL_ZEROCOPY, stripping SKBFL_SHARED_FRAG from that live skb (skb_tx_error()'s kerneldoc says "skb must be freed afterwards"). For a MSG_ZEROCOPY skb carrying page-cache frags, SKBFL_SHARED_FRAG is what makes esp_input() skb_cow_data() before in-place AEAD; once it is stripped a later local ESP-in-UDP delivery decrypts in place over pages the sender does not own -- an unprivileged page-cache write (the "Fragnesia" primitive). do_execute_actions() ignores output_userspace()'s return value, so any action after a failed USERSPACE upcall inherits the stripped skb. Move the skb_tx_error() to the flow-miss drop path - the "default" branch of ovs_dp_process_packet()'s switch(error), before kfree_skb(). The call has been here since commit 36d5fe6a0007 ("core, nfqueue, openvswitch: Orphan frags in skb_zerocopy and handle errors") but was harmless until esp_input() began relying on SKBFL_SHARED_FRAG to gate in-place decrypt; only then did stripping it on a still-forwarded skb become a page-cache write primitive. Fixes: 36d5fe6a0007 ("core, nfqueue, openvswitch: Orphan frags in skb_zeroc= opy and handle errors") Fixes: f4c50a4034e6 ("xfrm: esp: avoid in-place decrypt on shared skb frags= ") Cc: stable@vger.kernel.org Assisted-by: Claude:claude-opus-5 Signed-off-by: Norbert Szetei Reviewed-by: Ilya Maximets Tested-by: Jongmin Jang --- net/openvswitch/datapath.c | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/net/openvswitch/datapath.c b/net/openvswitch/datapath.c index f2d5b5ab38de..2fc9ef6c321f 100644 --- a/net/openvswitch/datapath.c +++ b/net/openvswitch/datapath.c @@ -285,6 +285,7 @@ void ovs_dp_process_packet(struct sk_buff *skb, struct = sw_flow_key *key) consume_skb(skb); break; default: + skb_tx_error(skb); kfree_skb(skb); break; } @@ -604,8 +605,6 @@ static int queue_userspace_packet(struct datapath *dp, = struct sk_buff *skb, err =3D genlmsg_unicast(ovs_dp_get_net(dp), user_skb, upcall_info->portid= ); user_skb =3D NULL; out: - if (err) - skb_tx_error(skb); consume_skb(user_skb); consume_skb(nskb); =20 --=20 2.55.0 From nobody Mon Sep 28 11:40:32 2026 Received: from mail-ej1-f48.google.com (mail-ej1-f48.google.com [209.85.218.48]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D08473859E0 for ; Sat, 22 Aug 2026 09:14:01 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.218.48 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787390043; cv=none; b=rOcekJPM2dhb8Abn4gMYtFNKvDtVSE9XYFB1fLNcFcCSxmYjA3HdeXpI0bpFqdRyj0TNLON4xuv96HwTA5AbTduIoOwL6xqNcEinIY+cqTyhY2uzCsStOrsb9+kapdcYfgGYZVCmy3WwE6IMu93Ii6+dooBM0rqsItVCWAtchUc= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787390043; c=relaxed/simple; bh=YGQckMbqnllO9cEfuF+Zcd1aPYYBxFpLUZxJ3rmbmKE=; h=Content-Type:Mime-Version:Subject:From:In-Reply-To:Date:Cc: Message-Id:References:To; b=SpHI1Nr3d/dQA29T5hGe7tQI2qoCi7lrJRUbZCJ6rCwz+4HCdk09lRhGrP0N2pcUVnuWZUAEU4bJA3W+/uQj4GDRN+xMkz1lEBDJ6RJjYxeqGSzJr7R1cdBqKV3ooqt/4/CKmT2QIfYoUUPLHS+ENjh8VDNMQDVAWnBBp1S0HEo= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=doyensec.com; spf=pass smtp.mailfrom=doyensec.com; dkim=pass (2048-bit key) header.d=doyensec.com header.i=@doyensec.com header.b=WKsdCzsD; arc=none smtp.client-ip=209.85.218.48 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=doyensec.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=doyensec.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=doyensec.com header.i=@doyensec.com header.b="WKsdCzsD" Received: by mail-ej1-f48.google.com with SMTP id a640c23a62f3a-c15ca7a7ca9so209035166b.0 for ; Sat, 22 Aug 2026 02:14:01 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=doyensec.com; s=google; t=1787390040; x=1787994840; darn=vger.kernel.org; h=to:references:message-id:content-transfer-encoding:cc:date :in-reply-to:from:subject:mime-version:content-type:from:to:cc :subject:date:message-id:reply-to:content-type; bh=syWMrXd3oOZ7WIz9yPYxecNXYsjgH/7HiK2KDpGXAks=; b=WKsdCzsD+lxlKTtc9t9c6GC2Ou312UX6tPe3J5ZTgMQGEevB1KUMjZgy+Vskywmwss lJl4CZpixQSAnuDEKUtzrpJ6aQ0H1dNTO0w6DJGWvWNuf/oVHrylDz4aUYPq7y+MO3Cv 1RWWb1fYU2i8+FrCULOwn9ifJE/rmcnQMeVe+7cWdHrDHldOg3qUFhjMlaHoxQSZATEL ixSou0eTTik6Yv6enZrcQINWV1RTBJIV3XCAfU+krRkCK6rNSeP5j1F+YdJLdXXEc0UI 69Ey81ZsRT7uEcX6F4WuknB61u86qHgbIH5gOU4oTcrXeU1oq/M3uR+/wty4gBRi0d4w Hreg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787390040; x=1787994840; h=to:references:message-id:content-transfer-encoding:cc:date :in-reply-to:from:subject:mime-version:content-type:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=syWMrXd3oOZ7WIz9yPYxecNXYsjgH/7HiK2KDpGXAks=; b=H4cmLJ8wm5iPBbhT8QgG2+3K8kPQToQYbezSnYyTWr6qvVSx/L4Kim/+d6+2EaQJtt OpXSemKArf9cMH8unJ+HTeUNrYsd038aUXk42wgCcBLZMCNFealeeZmHCemH3Y9JKoIy Ttp7J4emBjR7JfW2cb8B7mUVSmWXUawyKKC+/Cla0R6VyLuUzycXX4l94in63Iy5QY+q TqWHU8hUQgi0BBpbVXMW4BnmwCur7XnaebZegcInB2/UEU0B0vrt+4pWIv+VcswriYde iHUg5jiCxHzN2H2ld7d5k07XQMq2pdqeNwJJ5dxjhp0xrRCxJHPQ75wObr9aUhqHKF1Y iWxg== X-Forwarded-Encrypted: i=1; AHgh+RowyAqMLK+8FEUWEmyccIOeqKbUbFQJEK/4O0nSD4YT6RLDYts0YPzavA+kT4XYOtQT09PpDmheCsI+//A=@vger.kernel.org X-Gm-Message-State: AFuF++nnpq3PA1g5eoi5mFAofo0/3/V6o6wvwqaK1STLsvQOkH22USz/ P/l5J8YOZf9I+T8exHhLYucJDFht8ejW6xFxJMINU72r4Mi9/dDOPib8O7rnZCw5MfY= X-Gm-Gg: AR+sD10xJ6oF02gg/uRbkJhD1fdJAAkwkQ2HuDqR5WZBDoVgvO51C7lqRpwWM9X5dq8 2IAHlDEh1cXigxFh8ECSIIIVsKD2iupqqZI3HcvMqRIO1O8S4CptclXMSyN5/Is92NoGbPYGCUY e2thMel8bD4MMIMYk5q1G84WtdUOPM0bXwCnzv+U0a93bD4ntgCHr0apIDxup3GKTLZ6pRdEDfY aEaAHPiOMxH0VyPj2cj7kLBerqOniqoKdKtvXRK+B0snSNrHC+CtIy3xdQ56491CvD13JJFEVp6 8k+FCvfs9HQN8GFIwA4W6bL7Do1wEw/Crs/gOSETH4w12AIkR0nyIJza3BhMjGonJJrXyJrBW3d Yv+Sll6pWiKF6SikIwAvz2tVWbtJqpBmFYnZA1zZCRlXyJkbfWLKdLQa++97nIIztQ3zMosfRUg rtJpC+UssSMN+dQKq2QJsOq1YamkoxpW9mTgO9xFeR1VoGLWXtra5RWB3ljZYvMS/5BzVheYgBq jRJP/isOg0S+hELbf878Bwv6BnRkZHWb9L4/rX1oQlypsL/Nz5so3Mt/GnyDqO3eAK94m5ah3zU h9zMtUPwfY+Yg5cpad9dYAJsW6RJ X-Received: by 2002:a17:907:3d0a:b0:c20:83b1:396c with SMTP id a640c23a62f3a-c246a62b68fmr1266504466b.17.1787390039880; Sat, 22 Aug 2026 02:13:59 -0700 (PDT) Received: from smtpclient.apple (78-141-71-213.dynamic.orange.sk. [78.141.71.213]) by smtp.gmail.com with ESMTPSA id 4fb4d7f45d1cf-6a3ff1565fesm11013626a12.17.2026.08.22.02.13.57 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Sat, 22 Aug 2026 02:13:58 -0700 (PDT) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3826.700.81.1.4\)) Subject: [PATCH net v4 2/3] net: skbuff: don't skb_tx_error() the source skb in skb_zerocopy() From: Norbert Szetei In-Reply-To: <4B5CCA6E-2C49-4F86-8C4E-E1BE15C16C0A@doyensec.com> Date: Sat, 22 Aug 2026 11:13:47 +0200 Cc: "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , Aaron Conole , Eelco Chaudron , Ilya Maximets , Steffen Klassert , Kuan-Ting Chen , "Michael S. Tsirkin" , Willem de Bruijn , linux-kernel@vger.kernel.org, dev@openvswitch.org, Jongmin Jang Content-Transfer-Encoding: quoted-printable Message-Id: <6E3A780D-FB87-421F-9964-B1D457D7D106@doyensec.com> References: <4B5CCA6E-2C49-4F86-8C4E-E1BE15C16C0A@doyensec.com> To: netdev@vger.kernel.org X-Mailer: Apple Mail (2.3826.700.81.1.4) Content-Type: text/plain; charset="utf-8" skb_zerocopy() copies frags from @from into @to. On an skb_orphan_frags() failure it calls skb_tx_error(@from), a destructive operation on the source skb the copy helper does not own. That completes @from's zerocopy uarg and clears SKBFL_ALL_ZEROCOPY, including the SKBFL_SHARED_FRAG page-ownership marker. Both callers already report the failure on their own drop path. nfnetlink_queue does it at nla_put_failure, and Open vSwitch does it in the flow-miss drop arm of ovs_dp_process_packet(), so nothing is lost by dropping it here. On Open vSwitch's OVS_ACTION_ATTR_USERSPACE path the skb is not freed on this error: do_execute_actions() ignores output_userspace()'s return value and, unless the upcall was the last action, keeps forwarding the same skb through the flow's remaining actions. The uarg is completed while that skb is still in flight, telling the producer its buffers are free, and SKBFL_SHARED_FRAG is cleared on an skb the rest of the stack still handles. That flag is what makes esp_input() call skb_cow_data() instead of decrypting in place, so a later local ESP delivery can decrypt over frags the skb does not own privately. Leave error reporting to the callers. Fixes: 36d5fe6a0007 ("core, nfqueue, openvswitch: Orphan frags in skb_zeroc= opy and handle errors") Cc: stable@vger.kernel.org Suggested-by: Ilya Maximets Signed-off-by: Norbert Szetei Reviewed-by: Ilya Maximets Reviewed-by: Willem de Bruijn --- net/core/skbuff.c | 1 - 1 file changed, 1 deletion(-) diff --git a/net/core/skbuff.c b/net/core/skbuff.c index d4382b68d56e..ab3d161247b9 100644 --- a/net/core/skbuff.c +++ b/net/core/skbuff.c @@ -3914,7 +3914,6 @@ skb_zerocopy(struct sk_buff *to, struct sk_buff *from= , int len, int hlen) skb_len_add(to, len + plen); =20 if (unlikely(skb_orphan_frags(from, GFP_ATOMIC))) { - skb_tx_error(from); if (j > 0) put_page(virt_to_head_page(from->head)); return -ENOMEM; --=20 2.55.0 From nobody Mon Sep 28 11:40:32 2026 Received: from mail-ed1-f44.google.com (mail-ed1-f44.google.com [209.85.208.44]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4B3362C21E8 for ; Sat, 22 Aug 2026 09:15:22 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.208.44 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787390123; cv=none; b=OrxcWRNgOrDa+TBF/GNufzi8ApW+XgJ7GGlP2JaYiCXN6Hd978XGI5IuHEOVY4twIbGHRtIgcQbURzNeIEcqjLT7zXBc7hAaL1csyQ2GhvgulitRCaMN4Y5N4OXDT9jYbFfoE0vSr40mAIUnXTu+hGYLazrdTFOx+1M7DvCk6KI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787390123; c=relaxed/simple; bh=ppRIomUQhBNFC3z0nFKkGR0Lp8EWpbYgo5TTz3do1Xc=; h=Content-Type:Mime-Version:Subject:From:In-Reply-To:Date:Cc: Message-Id:References:To; b=keRTToI1xj/i9CwLpOGhBJ4R0GDhWGRi5ZJ855s2711GzcMs8O87SiLVhvCFKp9vfiJKDtRlIEjG5XydYcZQfXztTyOE4Ub3ilzKyGn1hQ79un9KtLKGL9fEDvVV159jbMqZkIK0aJ8Xu1KnsLu/JAsxdtrSUdIPeZ6Smj4q7sQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=doyensec.com; spf=pass smtp.mailfrom=doyensec.com; dkim=pass (2048-bit key) header.d=doyensec.com header.i=@doyensec.com header.b=Ncr+v2Fw; arc=none smtp.client-ip=209.85.208.44 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=doyensec.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=doyensec.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=doyensec.com header.i=@doyensec.com header.b="Ncr+v2Fw" Received: by mail-ed1-f44.google.com with SMTP id 4fb4d7f45d1cf-6a18840e2abso3374920a12.0 for ; Sat, 22 Aug 2026 02:15:22 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=doyensec.com; s=google; t=1787390120; x=1787994920; darn=vger.kernel.org; h=to:references:message-id:content-transfer-encoding:cc:date :in-reply-to:from:subject:mime-version:content-type:from:to:cc :subject:date:message-id:reply-to:content-type; bh=e2WiQ+y65OMTsDA3Cve1BDKJD3PESaPf/ssJwSf9IjM=; b=Ncr+v2FwZhJzshJsmMbQm8xlfSRab8PWPD6rocWDegFdcf7+f88YmLdO03ZAue88nn tGCZqe49lEquZUdNaKVOSz1BaNH6L1b4p9oeBqAykZGjn2cmy1WwQpdoyqk1aLGOO438 t52U2Ju/TtPmFxkMhsRvglEHfXF6lIKk7y48zR3qd9pqWD7gogpTHYXXWryQn/CuZnbe k3eSAIsFEA/6qagSPJNA3UGyPTzELbUTjXrltZ+gaCuf4JJJ1XFid9TzipchJ4IIFAB2 Anqt6GSypa9xwK2Lwg1vepWBA7A/nQgwK3BV9t8O0wxHr1JrOMPudk9Fydd/QS+WVI+5 AbXA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787390120; x=1787994920; h=to:references:message-id:content-transfer-encoding:cc:date :in-reply-to:from:subject:mime-version:content-type:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=e2WiQ+y65OMTsDA3Cve1BDKJD3PESaPf/ssJwSf9IjM=; b=RQPMKoVwB9F5YrSvlM6RTBZVQrJLwDYbxHyPb3yll8hOD0Ymy9/hSQ1uStrFXrEzpS i/eHhjznyzxxHk8mgMtzxl6eVSqMMyzSNuM65R7CCOVc39vwWd63NYBhBZOt3VnU8vM+ d6z0XRfh/rvU4AVYsoL8BRlAOqjg6zTU+pCpzzWWb3Wv5lKR4dtXR8MeQ30h10HoB5mZ /+to7eUZoga96PSjWOWD+sm48t8iNliWun5U++MjZnPIVxX9lJUQ0EKnthFW/g93ED1w 5Qe6J1gJIx9ML/W10Ug3q31B302EvG5xTnmdX/UqU49/WwQAYWYCnCOiSdS3FjAdXX1r OHmg== X-Forwarded-Encrypted: i=1; AHgh+Rr3sw2OzvbwTwuDJJk0dsfanGoq38AtfzURn4dNJtJHu1AsWRjV1BkQAFkYKIonOI8OyGCAsRxQfX72bKk=@vger.kernel.org X-Gm-Message-State: AFuF++mD9aQzQha241xedVhP/hYnZpe2QD+4LqqwQIm/gm9f6ApOGJti AgeCBpyGnNTK7wL/EQQMpBldHZAY48uxNXF6nP9A2Y2CH02Hi43Sg3AqQ0PgRAFKr30= X-Gm-Gg: AR+sD11HnKWR4QmOAsAxCZbHllEXU0TpYH+V+mBJhUGJ1jkmttWbVcpK6g/qmrxHG+/ T4P/R3rcDoWSSTYvmXCGyg5hKrnA7nGpz3TyJvZ1u66zdyJTMp5vq8gEsCsf6tmgyhPY5P2tlkM A7TlbjN19f98ChL/RkjImeMHw/B+2engUBoV6CI6z3oIP5GtDhlfxKWS6XmWXB06RMiaqsKbIpb VzMckmTBMifQOHrhJiYTSSDIbJ2FqXK9bD1oOGRFV1gALa6A7V5+SKi3cYdyODCA+7jNY0x3b3K MYKGsDViVxDRxwmZzyDvO6m78OpfGIl/DrUD0a9WCOiOM4GSQukh4EbONY6McESxJwHBRBrlYb4 uQeSjRgsV36JOJC68X402/TsRyYfNzAHDBD7n3Yyt+nwTkg+ONZmTTgHUJ+ZhPmEZBkGOVHExZI MwfQ3XcH8DNs0LAPwyXlgI6PMRTKgVBkWLvJaWXV2aweZ8I9wlsopsktJ2ytXtFIEiQKBx22rXg hgF/IO3KJRcJNvLYLVbxy4KTjxQW4mR+cnDVRxEzJQ2Tf+aanM+i6Fx2+U9zI81jY0WkGNovf38 Z7OHRPVGY7Irj6TCz1U1BDQtWQc= X-Received: by 2002:a05:6402:354c:b0:6a1:b0b:bc2 with SMTP id 4fb4d7f45d1cf-6a582b7daedmr5038325a12.10.1787390120108; Sat, 22 Aug 2026 02:15:20 -0700 (PDT) Received: from smtpclient.apple (78-141-71-213.dynamic.orange.sk. [78.141.71.213]) by smtp.gmail.com with ESMTPSA id 4fb4d7f45d1cf-6a3ff177b1esm11330272a12.29.2026.08.22.02.15.18 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Sat, 22 Aug 2026 02:15:19 -0700 (PDT) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3826.700.81.1.4\)) Subject: [PATCH net v4 3/3] net: skbuff: don't touch shared zerocopy state in skb_tx_error() From: Norbert Szetei In-Reply-To: <4B5CCA6E-2C49-4F86-8C4E-E1BE15C16C0A@doyensec.com> Date: Sat, 22 Aug 2026 11:15:08 +0200 Cc: "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , Aaron Conole , Eelco Chaudron , Ilya Maximets , Steffen Klassert , Kuan-Ting Chen , "Michael S. Tsirkin" , Willem de Bruijn , linux-kernel@vger.kernel.org, dev@openvswitch.org, Jongmin Jang Content-Transfer-Encoding: quoted-printable Message-Id: References: <4B5CCA6E-2C49-4F86-8C4E-E1BE15C16C0A@doyensec.com> To: netdev@vger.kernel.org X-Mailer: Apple Mail (2.3826.700.81.1.4) Content-Type: text/plain; charset="utf-8" skb_tx_error() completes the zerocopy uarg and clears SKBFL_ALL_ZEROCOPY, and skb_zcopy_downgrade_managed() clears SKBFL_MANAGED_FRAG_REFS. Both live in skb_shinfo(), which every clone shares, while the caller only owns the reference it is about to drop. Through a clone it tells the producer its pages are free and drops SKBFL_SHARED_FRAG for an skb that is still in flight. Open vSwitch reaches this with a non-last OVS_ACTION_ATTR_RECIRC: clone_execute() sends a skb_clone() into ovs_dp_process_packet() while do_execute_actions() keeps forwarding the original, and skb_clone() does not privatise the frags here -- skb_orphan_frags() returns early on SKBFL_DONT_ORPHAN. A flow miss on the clone then strips the marker from the packet still being forwarded, and a later local ESP delivery decrypts in place over frags it does not own privately. Skip it for a cloned skb. Nothing is lost: skb_release_data() clears the zerocopy state once the last reference to the shared data goes. Fixes: 25121173f7b1 ("skb: api to report errors for zero copy skbs") Cc: stable@vger.kernel.org Suggested-by: Ilya Maximets Signed-off-by: Norbert Szetei Reviewed-by: Ilya Maximets Tested-by: Jongmin Jang Reviewed-by: Willem de Bruijn --- net/core/skbuff.c | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/net/core/skbuff.c b/net/core/skbuff.c index ab3d161247b9..b9541329f1a7 100644 --- a/net/core/skbuff.c +++ b/net/core/skbuff.c @@ -1417,10 +1417,13 @@ EXPORT_SYMBOL(skb_dump); * * Report xmit error if a device callback is tracking this skb. * skb must be freed afterwards. + * + * Does nothing for a cloned skb: the zerocopy state lives in + * skb_shinfo(), which the clones share. */ void skb_tx_error(struct sk_buff *skb) { - if (skb) { + if (skb && !skb_cloned(skb)) { skb_zcopy_downgrade_managed(skb); skb_zcopy_clear(skb, true); } --=20 2.55.0