From nobody Mon Sep 28 22:31:46 2026 Received: from mail-wm1-f53.google.com (mail-wm1-f53.google.com [209.85.128.53]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3A6EF3D9667 for ; Sun, 16 Aug 2026 06:51:46 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.53 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786863108; cv=none; b=ZbABgPaLKrHX7qOPljOgZD9GmRF6umVn/uKDoXT2P2LT8OuLnSpZjFA3FDbsCBi/Ri9xoDRr7LvzZOyop7xi0I3K/Ekh3Ix9qsUNWMc75Ec3rkaaqz9ILmc8I54E0eCavdecj9LkMfLEpR03IkNlH9asoshcvTLtROILyIVyQQI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786863108; c=relaxed/simple; bh=srCYszWAcdgznXWtRfGPPvWPK2RnT/DOB9GIiYtsDbw=; h=Content-Type:Mime-Version:Subject:From:In-Reply-To:Date:Cc: Message-Id:References:To; b=TJpJ7GQpV6gIEDDKz/WLJl3vRv9jA+S/m4Kd3cDw42GUUNQ6CoV2ekTsyO9SLZaaVhHoFphh1wGAiDjXScK8/21LBR4Rie8ZDubZ83yW8TbKadbJTFQMSQ54+VvcJxhqDnfn6qWvG1xd1WlqDDHFct2a0Elh4GH3jDpxMa7B6ME= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=doyensec.com; spf=pass smtp.mailfrom=doyensec.com; dkim=pass (2048-bit key) header.d=doyensec.com header.i=@doyensec.com header.b=RBv/UoFb; arc=none smtp.client-ip=209.85.128.53 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=doyensec.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=doyensec.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=doyensec.com header.i=@doyensec.com header.b="RBv/UoFb" Received: by mail-wm1-f53.google.com with SMTP id 5b1f17b1804b1-49558ce01afso17858475e9.1 for ; Sat, 15 Aug 2026 23:51:46 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=doyensec.com; s=google; t=1786863104; x=1787467904; darn=vger.kernel.org; h=to:references:message-id:content-transfer-encoding:cc:date :in-reply-to:from:subject:mime-version:content-type:from:to:cc :subject:date:message-id:reply-to:content-type; bh=7376kWLfWmn46Je92wOLnlrU4XOrzSlKYQnPz7TuXoc=; b=RBv/UoFbC2+xQq6fwBlbLdKPrbn+jhHlU44VwYFZQGAFMlSvNllTf9RDgH3D+VyzIe A8Y6DGMynzv+YMqSK0b1CnJfWXSw6Cuy+TwMjUqz1dIeCZoQXvRJ4ZrfM4mKAUHscrea Q1nqjl4d3MO18ynANL3UXNsLUw19O0//YiPQ2Ym5ULZBP+R+ksDTk2Ryezr66RJ/Dyjc O+qGVcz6psPlimAhteaXQxjBK73XIwHEX2D3BNccIszZX6okpOujm5W6yMfCg89YAdm2 hoNzZH1nd8gXt47jA28c8dBtyL7Bxuh5QXapnzoJaT9qV6xsIYYGAzC+gCBxSjZNApau RJIQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786863104; x=1787467904; h=to:references:message-id:content-transfer-encoding:cc:date :in-reply-to:from:subject:mime-version:content-type:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=7376kWLfWmn46Je92wOLnlrU4XOrzSlKYQnPz7TuXoc=; b=SDnzIRXDILc+x9Ra4/AxUCo1rbdkkdBWwdmfyPoEKodrIDQmU3SkysuJsr5W93MKqw JsVaXlXx9GpJeudRLx1hpmUAwE+Sk3nITIqxI95h9Clld2Obl3GkXVojPI7ROxK7l9AI GvlSsW/bAJYWor6cya5oJ9RioVn0quaNM5auHsquCfE84OWoAZBNbs0R5Z0r5ZjL3ZK0 3GN06FW/3EBTrZrCjew7LpXcuksqqPpyWMUYFlw8J1IwdF3pZQ4wGtkBxlwjIXrpBnus NoEtgo6CBNdlMgeOiBiXxs3Gcx9Ch6sXwibjglyUoaYrlz8o/atX7RzBfN5gxxV2ggW/ Ybxg== X-Forwarded-Encrypted: i=1; AHgh+Rq+lrJE42IoSbQhshaFdccnwCp2oyZzZrCVcN/HN/D6T/g8RboN7+fYdQmbDPDh9ny96nWHGSJMkvf6N1I=@vger.kernel.org X-Gm-Message-State: AOJu0YyCOps+3lYmMI2WZIqbdUBxfr1YkyArTJlVLm9u9OjcityRhAFf p4tdY4+PuyFqElq10pcMMf10ToKhGy3IvkkgXYWKIx1PI1SXHAnorokoJ7qNzQdXPIc= X-Gm-Gg: AR+sD11Ne+vIdHQONnWxqMagP91BpD/ruGZvzjBSuny3imh84g+o0iUxZrx/kOtdYOQ dtQj2VRkU9kaorYvhhxjjqQcELfetHdHQAEKBXae7ONTxNWVqghgl7+1FZGHv7QneXWB/l5xr8D 3YnX0ik9ZnWYMpvpuO6xC3DZ0QYmS4vkn8GwlGUlFt3lkRqb/MyNABZ/+sbU2bgiLGa59xPgmVZ BmhLQx5udrCD3OpgZMyDLhct7NRtQZ/dq5x9gzMJP3suKXwBu5cZ4B1jNlQ3jzh/G6gpcbDy11M Jq6WqGRuISjkgaM+RMUhg+g0BFFKSqwc5SA5FXIjyCzgcmI/eDFsYM68c0UqWdgxIaUKTiyzaCY h1GFxTfJavvEqtPgSUJXGmw5Xlvjo7DHWCPb8iVXx2SBjgUtpKMXw28I7Mt66ZGD19LxTd4pcN0 Pg7fwxBywDrOLkf1Qsq4Ut+ziARJWo2MYg+rItzNTah9JnyDhaTDNqpP5Ok/4uv/T3MkJDHrGMX Nb7g2uFb9Hdt0Oc4kECGXAKoD/GSBPOl6WVbpzbbz55RQMPY24xKKhQBhHK+KtchizCGSOIa+LC 93L5TENWJTFckM9DOQtjKw== X-Received: by 2002:a05:600c:6a10:b0:499:79ba:a754 with SMTP id 5b1f17b1804b1-49987973094mr211636735e9.11.1786863104314; Sat, 15 Aug 2026 23:51:44 -0700 (PDT) Received: from smtpclient.apple (78-141-71-213.dynamic.orange.sk. [78.141.71.213]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49996128cffsm18511335e9.15.2026.08.15.23.51.43 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Sat, 15 Aug 2026 23:51:43 -0700 (PDT) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3826.700.81.1.4\)) Subject: [PATCH net v2 1/3] openvswitch: only skb_tx_error() a packet we are about to drop From: Norbert Szetei In-Reply-To: Date: Sun, 16 Aug 2026 08:51:32 +0200 Cc: "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , Aaron Conole , Eelco Chaudron , Ilya Maximets , linux-kernel@vger.kernel.org, dev@openvswitch.org Content-Transfer-Encoding: quoted-printable Message-Id: <3766FAA3-D915-4ECD-B51D-DCF390F3C03C@doyensec.com> References: To: netdev@vger.kernel.org X-Mailer: Apple Mail (2.3826.700.81.1.4) Content-Type: text/plain; charset="utf-8" queue_userspace_packet() borrows the packet skb -- it only copies it into a private netlink message (user_skb) and does not own it; on return do_execute_actions() keeps forwarding it through the flow's remaining actions. Its error path nevertheless calls skb_tx_error(skb), which via skb_zcopy_clear() does skb_shinfo(skb)->flags &=3D ~SKBFL_ALL_ZEROCOPY, stripping SKBFL_SHARED_FRAG from that live skb (skb_tx_error()'s kerneldoc says "skb must be freed afterwards"). For a MSG_ZEROCOPY skb carrying page-cache frags, SKBFL_SHARED_FRAG is what makes esp_input() skb_cow_data() before in-place AEAD; once it is stripped a later local ESP-in-UDP delivery decrypts in place over pages the sender does not own -- an unprivileged page-cache write (the "Fragnesia" primitive). do_execute_actions() ignores output_userspace()'s return value, so any action after a failed USERSPACE upcall inherits the stripped skb. Move the skb_tx_error() to the flow-miss drop path - the "default" branch of ovs_dp_process_packet()'s switch(error), before kfree_skb(). The call has been here since commit 36d5fe6a0007 ("core, nfqueue, openvswitch: Orphan frags in skb_zerocopy and handle errors") but was harmless until esp_input() began relying on SKBFL_SHARED_FRAG to gate in-place decrypt; only then did stripping it on a still-forwarded skb become a page-cache write primitive. Fixes: 36d5fe6a0007 ("core, nfqueue, openvswitch: Orphan frags in skb_zeroc= opy and handle errors") Fixes: f4c50a4034e6 ("xfrm: esp: avoid in-place decrypt on shared skb frags= ") Cc: stable@vger.kernel.org Assisted-by: Claude:claude-opus-5 Signed-off-by: Norbert Szetei Reviewed-by: Ilya Maximets Tested-by: Jongmin Jang --- net/openvswitch/datapath.c | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/net/openvswitch/datapath.c b/net/openvswitch/datapath.c index ae69b2cabab9..fff75c3eed11 100644 --- a/net/openvswitch/datapath.c +++ b/net/openvswitch/datapath.c @@ -285,6 +285,7 @@ void ovs_dp_process_packet(struct sk_buff *skb, struct = sw_flow_key *key) consume_skb(skb); break; default: + skb_tx_error(skb); kfree_skb(skb); break; } @@ -601,8 +602,6 @@ static int queue_userspace_packet(struct datapath *dp, = struct sk_buff *skb, err =3D genlmsg_unicast(ovs_dp_get_net(dp), user_skb, upcall_info->portid= ); user_skb =3D NULL; out: - if (err) - skb_tx_error(skb); consume_skb(user_skb); consume_skb(nskb); =20 --=20 2.55.0 From nobody Mon Sep 28 22:31:46 2026 Received: from mail-wm1-f52.google.com (mail-wm1-f52.google.com [209.85.128.52]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7A0AB3D9529 for ; Sun, 16 Aug 2026 06:55:20 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.52 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786863322; cv=none; b=NYzlhPxTtOxmPPCXAFNu++GRipjfft6pFb42PWBengbTVneJfW8u1GkF+LlGc3y+ZdvATZKDQgX66mjhBHqLp8p07or0o5pPKPDw/T8IzmJgCfXPgGOsIUW2wEWC/AsQ9a2cy0JTvrQqBsCHLmfuBck7HURg8BbuiSMa+QYRd2w= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786863322; c=relaxed/simple; bh=GF6Hd3Wu9d+8+v1Ikb5K7KWhUHhKY0lsI7cCBM13xgE=; h=Content-Type:Mime-Version:Subject:From:In-Reply-To:Date:Cc: Message-Id:References:To; b=oi9mR9IbiDArjMn0xsKtHhSpGBGILkauF1SE+GVQzOe8NIjvEfr5UZQ9iBKuPoWtjos32HfisLNIPzui0n4UfJOlc0o+zJ6LEQgaNIXWhH5tEjJG7A2wpcykbUPjBM4XHjBjOOswUHhcLMx6YrPoa6mkGS67CVrM2SL3F8ddtfg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=doyensec.com; spf=pass smtp.mailfrom=doyensec.com; dkim=pass (2048-bit key) header.d=doyensec.com header.i=@doyensec.com header.b=F3YSAOzp; arc=none smtp.client-ip=209.85.128.52 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=doyensec.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=doyensec.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=doyensec.com header.i=@doyensec.com header.b="F3YSAOzp" Received: by mail-wm1-f52.google.com with SMTP id 5b1f17b1804b1-49954b88fffso26966675e9.0 for ; Sat, 15 Aug 2026 23:55:20 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=doyensec.com; s=google; t=1786863319; x=1787468119; darn=vger.kernel.org; h=to:references:message-id:content-transfer-encoding:cc:date :in-reply-to:from:subject:mime-version:content-type:from:to:cc :subject:date:message-id:reply-to:content-type; bh=8MlFAE89dEyHP879JePBDi2+i6NFCJ7ZsUV+zmtCqYo=; b=F3YSAOzp+WAn4HRa8At+q+cvoeGMvtUvemSRNjQMkyxlaQ2O+cpd2goMglN9zzrh8C caCMwQG923UZPs73VyOclMGl7ZnhV8KY9RYgLODnyN7CI94/HcDjdI5zCCVQNpR77yJT C5aIGrmHfPMuMkvVhy5VoPmY04LRv5WBRTnLEzYKQ029G70vYWk3EXbkkHN/RgNcQxCS bMoPV6gjPg4G4owu3cnkRDgwCxf20/7qJiplzyHIgQ0cgFrApK//a6oqqCWpB1eUeAON AaTrifzF/Gy7wonYBRH5KmAT2lKppTbL/6ZGXs3ecj9Ew0wnRAksoX/9BDb6xL1y664G O1Zw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786863319; x=1787468119; h=to:references:message-id:content-transfer-encoding:cc:date :in-reply-to:from:subject:mime-version:content-type:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=8MlFAE89dEyHP879JePBDi2+i6NFCJ7ZsUV+zmtCqYo=; b=aaJGoszGrDXT/Kpb704cW8drNpb1Gr0c9W7LquIrtMwCKkSg4qcVnXklzKSxpCXt9+ cbzh/XcIriy1Cf0UV22zSYqWtc+isJhXXqSEsEn4m5RNRo8o6IQ9FUaFWakTxZc97qrv n99GX5i1BnAwvcOFWCkfE837LtAuFwe4wNcgPDPh1avswrEL+81jTy5XvNtObx7UZ5Ju +8HJ4O8r6RD3AN6QZ37g53/jj45NdKW8zPerQ0Ypq8Mcm/U9kuLahCWfxakmdQpoQFIG I0PVimrXsoqEX6gE6ZIg8FgrRXLJ8JCcbLOEtK9tzJWeCN1RjgBHIyDCP8a5ze9wxZvs LHvg== X-Forwarded-Encrypted: i=1; AHgh+RrQ2Eu5qLaILyeocTRnw4dB2G3MLLh4U6QKyZ4WEGqsW8MjqA0+19ANbWj5URJUluSPA6+ucUw1Oow3SRc=@vger.kernel.org X-Gm-Message-State: AOJu0YxcruqI0RKWMnxK0pYEdNMGSpirz5VB9hocuqUZ6ZFZn0bE1dU9 vY3zjGXgoDP5tgngq66SzbkeiLjksHGfmtoDC5yee8GkNGVUHoC3slI0xgR0bAbovH4= X-Gm-Gg: AR+sD107iA1vtcC202qBA5KEJqXHxWcUIqCG/5xEC7Pr153fTJfmL0OvQrprw2rKtXr jXiITwfToA4cXu3C029pPd9U03leZHmhnV/Ongwa8G6ogjC/nLr5gfPks590IC1QNIUs4lAYvV7 5uI+C4vFsZR3SEG+lcb9peJ/4HAceW+UebD6H7r9vJR3DQRPRv1FX5hP3dCX829dW257md+Ij0u fAlB2V1USsv9C8g73bQzEBpJTib02bGRfWMA8lHDfAKc0K5yi0h56ffEM8WYshHYEZ2Q7skWw9k Y+cDGtRB5fx7PiiZJuzaa3Y/G7+WIgobr9j6vHoiNRtsHygc2PsJys/w/jCICghgYa3Xcg+0dUl OT1Lr27mMflGPebE9xtQWAzkqmRsh2qDkSrGI6+zerA6sP/7oBqTNN7Y/F7LoqWnjRypPa5Z02M iG4IpIfFWIF5rvHLz1iZEdydWlrBh/nCwBTbHJknYAipHMS3F3bdDWOix3HCOv6xfq5FCWXFifI BhD4GQBkW0yK6YlQEdeenuBrGnTYnJUojz+rvgU6Fp8cb3xZGe2iD67Yd2Wgb18XykbiUx+gYrP UOR6E0o3lqBLggqw0ibO6w== X-Received: by 2002:adf:e193:0:b0:47f:25db:8161 with SMTP id ffacd0b85a97d-48160763c02mr26506732f8f.28.1786863318795; Sat, 15 Aug 2026 23:55:18 -0700 (PDT) Received: from smtpclient.apple (78-141-71-213.dynamic.orange.sk. [78.141.71.213]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4815f2b1d9bsm21992046f8f.24.2026.08.15.23.55.17 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Sat, 15 Aug 2026 23:55:17 -0700 (PDT) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3826.700.81.1.4\)) Subject: [PATCH net v2 2/3] net: skbuff: don't skb_tx_error() the source skb in skb_zerocopy() From: Norbert Szetei In-Reply-To: Date: Sun, 16 Aug 2026 08:55:06 +0200 Cc: "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , Aaron Conole , Eelco Chaudron , Ilya Maximets , linux-kernel@vger.kernel.org, dev@openvswitch.org Content-Transfer-Encoding: quoted-printable Message-Id: <807F55C4-1D4E-404F-9564-70639E931A26@doyensec.com> References: To: netdev@vger.kernel.org X-Mailer: Apple Mail (2.3826.700.81.1.4) Content-Type: text/plain; charset="utf-8" skb_zerocopy() copies frags from @from into @to. On an skb_orphan_frags() failure it calls skb_tx_error(@from), a destructive operation on the source skb the copy helper does not own. That completes @from's zerocopy uarg and clears SKBFL_ALL_ZEROCOPY, including the SKBFL_SHARED_FRAG page-ownership marker. Both callers already report the failure on their own drop path. nfnetlink_queue does it at nla_put_failure, and Open vSwitch does it in the flow-miss drop arm of ovs_dp_process_packet(), so nothing is lost by dropping it here. On Open vSwitch's OVS_ACTION_ATTR_USERSPACE path the skb is not freed on this error: do_execute_actions() ignores output_userspace()'s return value and, unless the upcall was the last action, keeps forwarding the same skb through the flow's remaining actions. The uarg is completed while that skb is still in flight, telling the producer its buffers are free, and SKBFL_SHARED_FRAG is cleared on an skb the rest of the stack still handles. That flag is what makes esp_input() call skb_cow_data() instead of decrypting in place, so a later local ESP delivery can decrypt over frags the skb does not own privately. Leave error reporting to the callers. Fixes: 36d5fe6a0007 ("core, nfqueue, openvswitch: Orphan frags in skb_zeroc= opy and handle errors") Cc: stable@vger.kernel.org Suggested-by: Ilya Maximets Signed-off-by: Norbert Szetei Reviewed-by: Ilya Maximets --- net/core/skbuff.c | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/net/core/skbuff.c b/net/core/skbuff.c index ba3dbac80fb4..db62ed6e04b9 100644 --- a/net/core/skbuff.c +++ b/net/core/skbuff.c @@ -3907,10 +3907,9 @@ skb_zerocopy(struct sk_buff *to, struct sk_buff *fro= m, int len, int hlen) =20 skb_len_add(to, len + plen); =20 - if (unlikely(skb_orphan_frags(from, GFP_ATOMIC))) { - skb_tx_error(from); + if (unlikely(skb_orphan_frags(from, GFP_ATOMIC))) return -ENOMEM; - } + skb_zerocopy_clone(to, from, GFP_ATOMIC); =20 for (i =3D 0; i < skb_shinfo(from)->nr_frags; i++) { --=20 2.55.0 From nobody Mon Sep 28 22:31:46 2026 Received: from mail-wr1-f52.google.com (mail-wr1-f52.google.com [209.85.221.52]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 252CA3D954A for ; Sun, 16 Aug 2026 06:57:21 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.221.52 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786863443; cv=none; b=e/z61C7ymrcgJ0w51JFybSz03KSmB3KWmP/gLxkJUdSFVyJIYKpPk33O4IqMOd2uqTNyK/4R6yBEpNI+rA8LhF5UYi1BhVNtLb8hxNl52z8cyaoPkytFZQGY7aXcq9SGmLvT9YyKKQxNFBX4NGeJIh3N6I0dHin2VVCgD8p9W/Q= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786863443; c=relaxed/simple; bh=53qYBlGV55O0oPM6z/iZlmjChX5cBKr1By2eAdAIGzk=; h=Content-Type:Mime-Version:Subject:From:In-Reply-To:Date:Cc: Message-Id:References:To; b=l4RbaCqXJyf/hwKak0ZDAdhFgOomUviGLG/EIOl16ntBDUj9g0W+WzJWlkFfVXKOTt/z2+DvJ7koLOx1oXe7hi1OATw27k88AZbGXSnfl2fvRAdpPk09hf9mMSCReAPVxJsrRWSd8ZrfCTPT/WvR9HrUnx/wORvwFk+mkeG2uqE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=doyensec.com; spf=pass smtp.mailfrom=doyensec.com; dkim=pass (2048-bit key) header.d=doyensec.com header.i=@doyensec.com header.b=HvSzcjwg; arc=none smtp.client-ip=209.85.221.52 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=doyensec.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=doyensec.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=doyensec.com header.i=@doyensec.com header.b="HvSzcjwg" Received: by mail-wr1-f52.google.com with SMTP id ffacd0b85a97d-47fecbb7000so1172936f8f.2 for ; Sat, 15 Aug 2026 23:57:21 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=doyensec.com; s=google; t=1786863440; x=1787468240; darn=vger.kernel.org; h=to:references:message-id:content-transfer-encoding:cc:date :in-reply-to:from:subject:mime-version:content-type:from:to:cc :subject:date:message-id:reply-to:content-type; bh=t7w6rC55cE4ciQbglNZx5NJEoEU8z/3RqBJj8wCuTBw=; b=HvSzcjwgHv+7tKidMzhwWOH/T58GSVTBlCC373z9G8KORGpn7LNcRQududUPry9Ljy KtHTLZ/6lyQLuSddFMO8Qr33WUtCLW+iD5KP3ezi78BikMYb5N/2g+VqEyhujg9j8ZHl B9uk1L1C8wHcQlwvjR3wXEs2l8jp9VxjVWmwX2agWo3QXc/wbr8ZUYTBcsheSFVrSUmF cHuTcRiBnOOkSwCq5H2uuM14X/cn3xWeXRV0Z3UFkXfLgxTwmZapXtFwNOmMWk+TBgF7 flbFfi/HXLjR2/RECo1xCzyDhOHlPMab9SlSOBqax7eVCOnyS4Ir8fz1fZw9VfiGU7ip pyGg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786863440; x=1787468240; h=to:references:message-id:content-transfer-encoding:cc:date :in-reply-to:from:subject:mime-version:content-type:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=t7w6rC55cE4ciQbglNZx5NJEoEU8z/3RqBJj8wCuTBw=; b=KQhqnWw1l++0l2De7yT3wXZdHk1f1z40QvCbpxoJahPBvT55a8LqE5O8ZVChmFHXzS 1txRA7p1zwqF5If8Ro91jrHefIhJm7vsCqQXePX6opCQIAIreNWbNOmBxO2BYgt9HVZm yErnUz2GEcmfTh85s/eiHfVyRpL9e2r+GOhwlEyua48r1IbR7UHeH7aYo6Io4byjxq0s kYsa5jtY5pN4rqnNavWjoabgJV6j9RS4P0dKOoh21ORI+lg6ZRqoYWtf0TWPaG+B6Z2P ucFesobGK7jhkxvfOVMPlUOUtkF7/p4rZpQg8febep63ZnFNGthWn68AAO1VTeHE5eC4 SFGw== X-Forwarded-Encrypted: i=1; AHgh+Romg9v7JgaUnNJObNGJzrlwhhK2CHxeg099uDf/6HnrBZF2v+dwkRbEHA1Rv5NVM9Vs/ApmeeZ/c9bgR2k=@vger.kernel.org X-Gm-Message-State: AOJu0Yw1EnStWDUuz333JK3E6nAkOvcEZ3H99Ic9QvPkOW+CmhbGUU2H 3M0p9xiPtQZY3K/RSXN3eUpux6qcI/vfYWjJGtULqhI2bvGhIV1Iq9wOT4nlGu2gaQQ= X-Gm-Gg: AR+sD10pVaWHEwjaiDSrjV/7NL3EaZS0YfFZnN+cqXZ8PFZ2OWOblYiefay+U4eQ7bu 9zwwLKG8zS6Ev2WH9oODsc9diV1kuuSGMxxJ5lbyFDTtrHq7b9Lc1LJZj7y61Iny3DynGxDKQff x1o5KF1fbZ0S95nQueVVRDbSDdaCfxvBaqYQWYsCKqk7wXFt5mevyxZlSPrQr8IKjMTNivkytg+ BbRrV1QnTf2XO8JIifSDTDf154bYl7lct3TU1NynDRrSpadc7dsCvjuB9QtdPxAuzUhlNyq9IbQ plRRtEN8COMWo0Ngi/+nxJELlAVZQ/24+TllHbIiKTqYAyOVdsWls+t9ushrp6+4NhbvqU4OiL/ LE4BnWv0/4vpZKjUaxyyDOs1Acg6/7G4+bxfCR41oWFPihw3J1UwKp6xDWQfDKBwIFhtwpryPfn uSaeq7j+81Vn8XtHAwTQ5ypnUoNqwBKCgLPPoAfB5QPlAzsa3gFmZhVWg9kEwHax5yK7iK0DVuv lAYlLYwMtB5aLYHEcGgHITYomB6PkxTDIhGC3LZWfSzx24914/b1Wk75j8NvwkHqjojUv3Tq0l0 UsaCzj4zT/w8wlWqRItuIJ4TiqWlxIRtEA== X-Received: by 2002:a05:6000:240c:b0:47f:80d1:be0a with SMTP id ffacd0b85a97d-4816074889bmr21131883f8f.14.1786863440038; Sat, 15 Aug 2026 23:57:20 -0700 (PDT) Received: from smtpclient.apple (78-141-71-213.dynamic.orange.sk. [78.141.71.213]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4815f2b1a91sm21297727f8f.21.2026.08.15.23.57.18 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Sat, 15 Aug 2026 23:57:18 -0700 (PDT) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3826.700.81.1.4\)) Subject: [PATCH net v2 3/3] net: skbuff: don't touch shared zerocopy state in skb_tx_error() From: Norbert Szetei In-Reply-To: Date: Sun, 16 Aug 2026 08:57:07 +0200 Cc: "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , Aaron Conole , Eelco Chaudron , Ilya Maximets , linux-kernel@vger.kernel.org, dev@openvswitch.org Content-Transfer-Encoding: quoted-printable Message-Id: References: To: netdev@vger.kernel.org X-Mailer: Apple Mail (2.3826.700.81.1.4) Content-Type: text/plain; charset="utf-8" skb_tx_error() completes the zerocopy uarg and clears SKBFL_ALL_ZEROCOPY, and skb_zcopy_downgrade_managed() clears SKBFL_MANAGED_FRAG_REFS. Both live in skb_shinfo(), which every clone shares, while the caller only owns the reference it is about to drop. Through a clone it tells the producer its pages are free and drops SKBFL_SHARED_FRAG for an skb that is still in flight. Open vSwitch reaches this with a non-last OVS_ACTION_ATTR_RECIRC: clone_execute() sends a skb_clone() into ovs_dp_process_packet() while do_execute_actions() keeps forwarding the original, and skb_clone() does not privatise the frags here -- skb_orphan_frags() returns early on SKBFL_DONT_ORPHAN. A flow miss on the clone then strips the marker from the packet still being forwarded, and a later local ESP delivery decrypts in place over frags it does not own privately. Skip it for a cloned skb. Nothing is lost: skb_release_data() clears the zerocopy state once the last reference to the shared data goes. Fixes: 36d5fe6a0007 ("core, nfqueue, openvswitch: Orphan frags in skb_zeroc= opy and handle errors") Fixes: f4c50a4034e6 ("xfrm: esp: avoid in-place decrypt on shared skb frags= ") Cc: stable@vger.kernel.org Suggested-by: Ilya Maximets Signed-off-by: Norbert Szetei Tested-by: Jongmin Jang --- net/core/skbuff.c | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/net/core/skbuff.c b/net/core/skbuff.c index db62ed6e04b9..04776a112334 100644 --- a/net/core/skbuff.c +++ b/net/core/skbuff.c @@ -1417,10 +1417,13 @@ EXPORT_SYMBOL(skb_dump); * * Report xmit error if a device callback is tracking this skb. * skb must be freed afterwards. + * + * Does nothing for a cloned skb: the zerocopy state lives in + * skb_shinfo(), which the clones share. */ void skb_tx_error(struct sk_buff *skb) { - if (skb) { + if (skb && !skb_cloned(skb)) { skb_zcopy_downgrade_managed(skb); skb_zcopy_clear(skb, true); } --=20 2.55.0