From nobody Mon Sep 28 19:23:42 2026 Received: from mail-wm1-f46.google.com (mail-wm1-f46.google.com [209.85.128.46]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6FBCF42D763 for ; Tue, 18 Aug 2026 08:45:20 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.46 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787042723; cv=none; b=cdACNI+ph52em2j3oTdaByn6wfyaGKWBg166zuwq4uRARmZvOVmRq6VwB29CGlpsiJCA5ya6hhpvo/8g4cmv9wUYZe6h96kKeCBCUffzRDGddwio9Uyehj+XKP5OcK3KQldkFRQuBfp47Vq1bGK+Sruw+ramJ3RkLobHw+xbC2c= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787042723; c=relaxed/simple; bh=1Hak+sK1AObHRlfR/O9TAETWPHGKoELjxohYzABOdLc=; h=Content-Type:Mime-Version:Subject:From:In-Reply-To:Date:Cc: Message-Id:References:To; b=kCVMP/nlX6bPmS8pralYllsKKTXxhqgcou9AxBboBWseRePvH7Ojp5hk3YaOCCpy6jsl4PuozfZOUkB3qhOBcxqgzvovhBoCHL2gijOo3RKV/IaEdkkDpaGj4Hl3c/k4LLKdnFkDA9XdxbpF9YxWOjCeICrg9WyH5f11DctqZ3o= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=doyensec.com; spf=pass smtp.mailfrom=doyensec.com; dkim=pass (2048-bit key) header.d=doyensec.com header.i=@doyensec.com header.b=TATUfMV6; arc=none smtp.client-ip=209.85.128.46 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=doyensec.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=doyensec.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=doyensec.com header.i=@doyensec.com header.b="TATUfMV6" Received: by mail-wm1-f46.google.com with SMTP id 5b1f17b1804b1-496bb7cdf51so53926695e9.2 for ; Tue, 18 Aug 2026 01:45:20 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=doyensec.com; s=google; t=1787042718; x=1787647518; darn=vger.kernel.org; h=to:references:message-id:content-transfer-encoding:cc:date :in-reply-to:from:subject:mime-version:content-type:from:to:cc :subject:date:message-id:reply-to:content-type; bh=mRqu1Yx5HorjqSemdAiIQulC/QDv6fmNzSHtkTVqTB4=; b=TATUfMV60VcCrllqYNWQNUpHmWWNj2ESP5Sroym/wpZBLZpFZmuSm/dhT3KVAjhQS2 ucYQKqPTTqKsjeWeRj9S4ITs9hrgQmkr1loatoaCyTw/jfehnQJatF/mOjQ0wbkgfsSD a69Xod6ITCeM2ve46OVcjioHB3Qqe83iaHFmb3bDu9qxmG2iHyU4wihxZufsMBkxeC+L AZpKLtbAMTfo+p/PlSv9iz22N+X6uWY8sNE1tUb3deZbm5CBqWl8FMkFszxz323elIyJ LnUS94I8DV8HTbtwzIBV5lcWgDuiWg9/rhf0wya+xLi1cj/dFYHOtB2ox+urLYuEAPSO 0s7Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787042718; x=1787647518; h=to:references:message-id:content-transfer-encoding:cc:date :in-reply-to:from:subject:mime-version:content-type:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=mRqu1Yx5HorjqSemdAiIQulC/QDv6fmNzSHtkTVqTB4=; b=Mf2uCZvZ62oH951juagXu1oepriBQGxb31yEcrD8pQTI42RsYRGqlH+XbP8DjdFmCH r22o4DFvGXDfPxaCo8hMZZfUhb/um/55MUhmBW+6CH+xAuv+jQco/mZCRchzURGRsRmg fmRCoNrpjIBDMD6Ej3wwkGEb/9uK+6naGc4g++a1CBkElubB+wBm7WGJxqGxRjYYOMR6 /KfY88sHGttbyj27BuW7Sco4nQfmArXNZYl7RvloNUTHtC1OSxYIo8teTAzror10Vfyj om+F9AD1+7ISVvgqGEG02veIv7FIFjWZh5MuGrskpP0LTusgIN99cJM2JpWMn1gGxJem xP5g== X-Forwarded-Encrypted: i=1; AHgh+RokiTdgASULBBIqClnZ8iu1zCPW4gxesNt830mOqigZeUvCZeTF9rH0z+A3dXJBeaMYmZeB+Go2cX6UljA=@vger.kernel.org X-Gm-Message-State: AOJu0YzbPJQS0cNUSjy2aYgWkDVxfbOJ+n7BKznD1gO+6+5ai5mAwH5d ZmRs/90DD2pIQVk53RQKUz1QFm4/+JuOhb1EFc+GHfiAMsG4d89hEkzlcyp9mU19HeA= X-Gm-Gg: AR+sD10z+OJIgdFyWiOpuJqPVP2dB9F3mng+MXnQUDKAy731e88GRL3lSVUiqSUIbXl IY8hZ7fSHipcaFXMl32V2ZfxmwcLGsv3nEBst23zg3wJ31CkdRxGa/YgXTkFk7OKBh6bRoHSgyb j3F4e+0g6xh3dw2yUeD+mBOGbWqsCk0/QngsRTjuCxrczkmJqsF1goUQjgJcH/NS2PQtD1e7lZr x3KzKTNCpv1aWe5MLbWDPs5pun2aqvvYaa7cGPnqNuDO+O/OFBA78lCC2R/87ogv4/6aSW2dM91 A5jCCBM/gPnKETGR7epW5GCCTP8OxZQlYb3mnNC2BpUOVIpHWan5Fn5o5YOazLDZmMMsAhAuTnx ZUns9nbL6D2JmFxd+qkCY4wxAfgLERAwVaRp4AW9fSPTGXZ1B9/achMkLVEn7ghdmQNFDEiqbxh MRi7nuETqGIFPU0f3zqGJjUiqWqPb0jx4ylns03j/+3aJVzLFmz/XOuEf6v9lO/Zo/9tEjrmdzd wqySwYaC6RFIVhqi8x5plX+zAJTOTKndu7hXsKTJlrtsf+g8t6zBY1P0homV3yc/HfZq2soVIp0 xgm09EXydbyv8j+XJa0kbQ== X-Received: by 2002:a05:600c:34d1:b0:499:83f1:398 with SMTP id 5b1f17b1804b1-4999fb6d598mr111856735e9.9.1787042717752; Tue, 18 Aug 2026 01:45:17 -0700 (PDT) Received: from smtpclient.apple (78-141-71-213.dynamic.orange.sk. [78.141.71.213]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49996188217sm512122605e9.13.2026.08.18.01.45.16 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Tue, 18 Aug 2026 01:45:17 -0700 (PDT) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3826.700.81.1.4\)) Subject: [PATCH net v3 1/3] openvswitch: only skb_tx_error() a packet we are about to drop From: Norbert Szetei In-Reply-To: Date: Tue, 18 Aug 2026 10:45:05 +0200 Cc: "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , Aaron Conole , Eelco Chaudron , Ilya Maximets , Steffen Klassert , Kuan-Ting Chen , "Michael S. Tsirkin" , linux-kernel@vger.kernel.org, dev@openvswitch.org, Jongmin Jang Content-Transfer-Encoding: quoted-printable Message-Id: <5C0BEBF6-AF95-4045-8ED4-C6081C51E40B@doyensec.com> References: To: netdev@vger.kernel.org X-Mailer: Apple Mail (2.3826.700.81.1.4) Content-Type: text/plain; charset="utf-8" queue_userspace_packet() borrows the packet skb -- it only copies it into a private netlink message (user_skb) and does not own it; on return do_execute_actions() keeps forwarding it through the flow's remaining actions. Its error path nevertheless calls skb_tx_error(skb), which via skb_zcopy_clear() does skb_shinfo(skb)->flags &=3D ~SKBFL_ALL_ZEROCOPY, stripping SKBFL_SHARED_FRAG from that live skb (skb_tx_error()'s kerneldoc says "skb must be freed afterwards"). For a MSG_ZEROCOPY skb carrying page-cache frags, SKBFL_SHARED_FRAG is what makes esp_input() skb_cow_data() before in-place AEAD; once it is stripped a later local ESP-in-UDP delivery decrypts in place over pages the sender does not own -- an unprivileged page-cache write (the "Fragnesia" primitive). do_execute_actions() ignores output_userspace()'s return value, so any action after a failed USERSPACE upcall inherits the stripped skb. Move the skb_tx_error() to the flow-miss drop path - the "default" branch of ovs_dp_process_packet()'s switch(error), before kfree_skb(). The call has been here since commit 36d5fe6a0007 ("core, nfqueue, openvswitch: Orphan frags in skb_zerocopy and handle errors") but was harmless until esp_input() began relying on SKBFL_SHARED_FRAG to gate in-place decrypt; only then did stripping it on a still-forwarded skb become a page-cache write primitive. Fixes: 36d5fe6a0007 ("core, nfqueue, openvswitch: Orphan frags in skb_zeroc= opy and handle errors") Fixes: f4c50a4034e6 ("xfrm: esp: avoid in-place decrypt on shared skb frags= ") Cc: stable@vger.kernel.org Assisted-by: Claude:claude-opus-5 Signed-off-by: Norbert Szetei Reviewed-by: Ilya Maximets Tested-by: Jongmin Jang --- net/openvswitch/datapath.c | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/net/openvswitch/datapath.c b/net/openvswitch/datapath.c index ae69b2cabab9..fff75c3eed11 100644 --- a/net/openvswitch/datapath.c +++ b/net/openvswitch/datapath.c @@ -285,6 +285,7 @@ void ovs_dp_process_packet(struct sk_buff *skb, struct = sw_flow_key *key) consume_skb(skb); break; default: + skb_tx_error(skb); kfree_skb(skb); break; } @@ -601,8 +602,6 @@ static int queue_userspace_packet(struct datapath *dp, = struct sk_buff *skb, err =3D genlmsg_unicast(ovs_dp_get_net(dp), user_skb, upcall_info->portid= ); user_skb =3D NULL; out: - if (err) - skb_tx_error(skb); consume_skb(user_skb); consume_skb(nskb); =20 --=20 2.55.0 From nobody Mon Sep 28 19:23:42 2026 Received: from mail-wm1-f41.google.com (mail-wm1-f41.google.com [209.85.128.41]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 135DD43B3DA for ; Tue, 18 Aug 2026 08:46:43 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.41 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787042807; cv=none; b=WMatuMlJX8aObYfYGJxmTb2IynuYc2AN2c8yjZS2IP7OSraqD1/lQsPkhft+stjJYkmF7xw68d00ip921wEHzq6c6ehvWbhX4ErzdydjCL0XIOhDIDy8+t0nC0C4Ip56yuZF211xQvj0Xq0F3QpKJpw2F+R/FlAZ4+RAi1AIpl0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787042807; c=relaxed/simple; bh=GF6Hd3Wu9d+8+v1Ikb5K7KWhUHhKY0lsI7cCBM13xgE=; h=Content-Type:Mime-Version:Subject:From:In-Reply-To:Date:Cc: Message-Id:References:To; b=CmP28RRWSfSpczu+eHVBac/I0xNIbVb+xbj62GgNqK4nvSIxySERvQX60XErHdRB7OLCZ8nMvc6fPb78+bgS3ePs6J8tLum/NDD/m2Seb08e7wI2cuy4JfHTyiO7v/95oO93626db7LqJZnNzx3KA7GsZvMWG7teB3uSzxn+W8Y= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=doyensec.com; spf=pass smtp.mailfrom=doyensec.com; dkim=pass (2048-bit key) header.d=doyensec.com header.i=@doyensec.com header.b=PzejMekq; arc=none smtp.client-ip=209.85.128.41 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=doyensec.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=doyensec.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=doyensec.com header.i=@doyensec.com header.b="PzejMekq" Received: by mail-wm1-f41.google.com with SMTP id 5b1f17b1804b1-4956242332dso45687675e9.2 for ; Tue, 18 Aug 2026 01:46:43 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=doyensec.com; s=google; t=1787042802; x=1787647602; darn=vger.kernel.org; h=to:references:message-id:content-transfer-encoding:cc:date :in-reply-to:from:subject:mime-version:content-type:from:to:cc :subject:date:message-id:reply-to:content-type; bh=8MlFAE89dEyHP879JePBDi2+i6NFCJ7ZsUV+zmtCqYo=; b=PzejMekqjwnk05Fr6dSZlEeQp2cwK5qsQyUiRjitGCwIaZLD8EA7/LJwq5EBlEG0tF 3n/bvdDUGO6zTwkdw6BWzpj23rzGzXCV0wHskG5NEFgC5Z4E5Z8WYfnfBniZ+qEKcm+q 4VryrRYLAdjH/pO/GuuDwncdk/oWBJRNEpul3pxbAqZfy7UtdV2eu+soGx+u7R9LxUgh VP1fWxsM5JpO7mbg7tPO6McIBTSUgM2L7BtGAq4Sxu+zm4IE5jGjz2SJCISRbIhrW0N/ R2UEl3pwt+SbMm+AR8UEppLTN0HbfhPUD8RDrMJyjogUuUVMUGAFuQI3iw4PPeDgyUTM NTjQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787042802; x=1787647602; h=to:references:message-id:content-transfer-encoding:cc:date :in-reply-to:from:subject:mime-version:content-type:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=8MlFAE89dEyHP879JePBDi2+i6NFCJ7ZsUV+zmtCqYo=; b=SrJcuiK6v4z7YI8Ff2WNRVfXGzpFvFVLVVa33WIo0FLmA4rdfgfE6PInRCSW99aT+w NH7jxtNlI0mxnPcXOt3fiI89DSsgICeZ2UqYKu1KzZ3+HGYhFIm1Dbqdqwz2m14Gzwkv cWOFhVI5/PtXtwMYfDu/RJVfuLU3zhs3jBt7+JjhSJgnwKAy/ZjaN0wdvLUQD0C2koJG qziXVnyyIpb7d7Rz/w3Jkl1w8ozLgITbLNwU2Em6OL5kdtYqkpXuWrq8s8bii9XlOnKL a2tn3ADF9L6L5ARH+hsx2gv4BnfdfHk+GJ12fclUUkELowY/okaC2BsjppOBLw4Av9bg t1Ug== X-Forwarded-Encrypted: i=1; AHgh+Rpe7cWB8o93/Q5aKM1Yc0YYuiFwt04Nz4HxFEmbp7agAjr0yZV3hY/YM+RtrBO8NrlILgtrAStjx/tqc5Y=@vger.kernel.org X-Gm-Message-State: AOJu0Yxqk67YMKDVDKnHEISW5w+1yN/b8+a//6kYg38A3thXhD4/+hpG LMTgYdGHzF/kn2DLmaFg0Gy1ivO9SiqQJybMt3Jj517OO5pvSiFFZ7DVrTE90VnpcL0= X-Gm-Gg: AR+sD12Te+4AJtMechkIQ3bxBJmsjiqkWNOieLFRtHif+Et3JlAlKXSTXq0gBBBlUrT 7ANRaCyr6znH6RMaoU3/nawEzrX+Inwe/vN4b50FJkb9Z06xgEcmCoPD5kkD5MBzpF0Nlpk5nLb AG/j7k63ADst1ijv5anLFPzllMTdqDAjAF2u5CFwSYwA0v/oMQPeRi/j4pNEdriykviaCT93arQ Vj8WykYF1lpVOGx9gvZkAaa0OL57TDSR2Hj1p2PMY+X/daBfUUe+vuUfXMAB40IUVtkQCOsvGcy +G0aB+s7HGzWfwlrJI0BkMyWxA7PdheoBePme2VIBawKFWtBh9OQ0A9XKD11UwTaRIRpY9v5IEe sJk7WyA+VcvWyCjZlhSv9GDA4psTGtqafLiOXAbgDu392f4lDGFNqVIBr8GFxPEIDljij11dt2F EhK/ytWfDDmvVExfU/n1YiyYw0BHWG505OIXZ//WnPFQyQ8DWcfW/hWzdmmxHhKS8BxL5z1n3sQ 9QVeTK+j5/AS8smtKWfpww90DgrOjit08BoyXSm3zKeG3wSqoGKmV5zAPAJCwF98Gg5pswMREyj RyZ1s5Lh1mcmCORsHZB9CA== X-Received: by 2002:a05:600d:10e:b0:495:4572:21af with SMTP id 5b1f17b1804b1-499879809b7mr341093675e9.9.1787042801837; Tue, 18 Aug 2026 01:46:41 -0700 (PDT) Received: from smtpclient.apple (78-141-71-213.dynamic.orange.sk. [78.141.71.213]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4999d086c6dsm109435105e9.7.2026.08.18.01.46.40 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Tue, 18 Aug 2026 01:46:41 -0700 (PDT) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3826.700.81.1.4\)) Subject: [PATCH net v3 2/3] net: skbuff: don't skb_tx_error() the source skb in skb_zerocopy() From: Norbert Szetei In-Reply-To: Date: Tue, 18 Aug 2026 10:46:29 +0200 Cc: "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , Aaron Conole , Eelco Chaudron , Ilya Maximets , Steffen Klassert , Kuan-Ting Chen , "Michael S. Tsirkin" , linux-kernel@vger.kernel.org, dev@openvswitch.org, Jongmin Jang Content-Transfer-Encoding: quoted-printable Message-Id: References: To: netdev@vger.kernel.org X-Mailer: Apple Mail (2.3826.700.81.1.4) Content-Type: text/plain; charset="utf-8" skb_zerocopy() copies frags from @from into @to. On an skb_orphan_frags() failure it calls skb_tx_error(@from), a destructive operation on the source skb the copy helper does not own. That completes @from's zerocopy uarg and clears SKBFL_ALL_ZEROCOPY, including the SKBFL_SHARED_FRAG page-ownership marker. Both callers already report the failure on their own drop path. nfnetlink_queue does it at nla_put_failure, and Open vSwitch does it in the flow-miss drop arm of ovs_dp_process_packet(), so nothing is lost by dropping it here. On Open vSwitch's OVS_ACTION_ATTR_USERSPACE path the skb is not freed on this error: do_execute_actions() ignores output_userspace()'s return value and, unless the upcall was the last action, keeps forwarding the same skb through the flow's remaining actions. The uarg is completed while that skb is still in flight, telling the producer its buffers are free, and SKBFL_SHARED_FRAG is cleared on an skb the rest of the stack still handles. That flag is what makes esp_input() call skb_cow_data() instead of decrypting in place, so a later local ESP delivery can decrypt over frags the skb does not own privately. Leave error reporting to the callers. Fixes: 36d5fe6a0007 ("core, nfqueue, openvswitch: Orphan frags in skb_zeroc= opy and handle errors") Cc: stable@vger.kernel.org Suggested-by: Ilya Maximets Signed-off-by: Norbert Szetei Reviewed-by: Ilya Maximets --- net/core/skbuff.c | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/net/core/skbuff.c b/net/core/skbuff.c index ba3dbac80fb4..db62ed6e04b9 100644 --- a/net/core/skbuff.c +++ b/net/core/skbuff.c @@ -3907,10 +3907,9 @@ skb_zerocopy(struct sk_buff *to, struct sk_buff *fro= m, int len, int hlen) =20 skb_len_add(to, len + plen); =20 - if (unlikely(skb_orphan_frags(from, GFP_ATOMIC))) { - skb_tx_error(from); + if (unlikely(skb_orphan_frags(from, GFP_ATOMIC))) return -ENOMEM; - } + skb_zerocopy_clone(to, from, GFP_ATOMIC); =20 for (i =3D 0; i < skb_shinfo(from)->nr_frags; i++) { --=20 2.55.0 From nobody Mon Sep 28 19:23:42 2026 Received: from mail-wm1-f47.google.com (mail-wm1-f47.google.com [209.85.128.47]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 759E831E852 for ; Tue, 18 Aug 2026 08:47:52 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.47 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787042874; cv=none; b=ah0D0s4wjnasbSsYhx5D0I/JYS+44FbV8lWaFF6BeMAV+uXwdGmhyOtjmm8q9zo6sQIXKhXtHkB5DJlRF5He7diaxRAv5GaINVS/a9vqrMVOHbbNMhQXx0963k5KRxhDbpmLL+v6A0M195O4iPICmIUJtlj4W5g76kHCwFWudB4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787042874; c=relaxed/simple; bh=jq44illgW0PY8H3areDJs61Qx3jgTr2nLguNWng4mwE=; h=Content-Type:Mime-Version:Subject:From:In-Reply-To:Date:Cc: Message-Id:References:To; b=lJxLj4T3HIXsPXBqRMZGk/75B6R2iFTzvLYkXLndCgNPNG0/t4u8W4ADrM571m0g1lomsMHRUphNJWMupWsTnG/CJyhAiv1nYETmyLdAY5N8sVZ5/BR7U1zw6bAHlWQWV/60vJ/n2qamA92WzUOLwyHGTVR5eTQQSAWIjGgfpwM= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=doyensec.com; spf=pass smtp.mailfrom=doyensec.com; dkim=pass (2048-bit key) header.d=doyensec.com header.i=@doyensec.com header.b=fK+K7cYI; arc=none smtp.client-ip=209.85.128.47 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=doyensec.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=doyensec.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=doyensec.com header.i=@doyensec.com header.b="fK+K7cYI" Received: by mail-wm1-f47.google.com with SMTP id 5b1f17b1804b1-490cf322ed0so41656215e9.1 for ; Tue, 18 Aug 2026 01:47:51 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=doyensec.com; s=google; t=1787042870; x=1787647670; darn=vger.kernel.org; h=to:references:message-id:content-transfer-encoding:cc:date :in-reply-to:from:subject:mime-version:content-type:from:to:cc :subject:date:message-id:reply-to:content-type; bh=1F67UUCLxuWMVKHEvlzFMLbN/5jPWi3pvGWjATgGVJA=; b=fK+K7cYIVx78gsFO1lWSOchujkMtohupSSGzDi3C2Sl/vFTBx4yC0j08NjV+si3guB 6XoudAnNxIc6AnfiIcWeLPq8EDbO7Ytr8jqrdV1yFb4flZBoZOJZH1PG9cQE6dgcTBHp JkRHPlKZhbTiOrX7nVl/2iwJKWwxGaZhXQbTV/SHwKHEm2FlBWbyRcPSl6ZVsPJsRkj/ r5uc/JiXvOYyUjH6FRWPmZOcBov+zqFUlQbhgAEH1NH5WglZH31TgMqOwRa5ETiwDV85 YmCJB3Mlvx2/6HvRWnt5RtzWJ4ewXa6XC+K8iVhvoee1MGihiU//hrNBDV4oNvlUPHY8 PtWA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787042870; x=1787647670; h=to:references:message-id:content-transfer-encoding:cc:date :in-reply-to:from:subject:mime-version:content-type:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=1F67UUCLxuWMVKHEvlzFMLbN/5jPWi3pvGWjATgGVJA=; b=fZFluuBwhre5cy1VmXN48v2STikyYlIj7O4Zxypu5DPfpx6JsNhctjuqUjsPuMErJX 422OoKxIYZDnvlcGt4RmURWoLtQJC6Eao0eKtjgCn9O5UgPpCPu18W0A0aTVX6z8NnWl S9EP12/rwfI23vxoVhiOeoR5fyU3/gsGBRyqxAfes/u46fZOyi1QRYGjqZ1ef5egABg/ yQ0rtAf9r7Oz1+hVSdpjtj+/8RKyPKThMC5UFrPSzAWrzWi5HR+12wGKwsilu8jBdgG7 Utxh6puBRHwyB6CeMfDMaHG/T7IMiMKrr2DqiG81jOVaoiHcaUqqZSe1Ct+qM/e0GGs9 WXlA== X-Forwarded-Encrypted: i=1; AHgh+RqejFxaephdsFt4Q2tRM3PbAkFHx8V8aL0uZUGpNFb84uU+L2GDhfZEnjqY/w4uscOxyBCGdqjPYA6kDlg=@vger.kernel.org X-Gm-Message-State: AOJu0YyJIMfB+p+RMEfZF7kTw+XtRQc9uydphLp9HlnTwwCdVuw5vKmE 0DUEBOFQQ31bRDv02DuEsQ3PhEsw26VEYdgHg5rK7gRnjh+8Wx4FRMK0OVEU/v4O5yQ= X-Gm-Gg: AR+sD12Nd+KuJ3ZCHxEcop/1o9eo/jSSXteu9oMW1NTGJ4uCjPtYUR2arEPwPQZuxI+ EmCQ7gmPT1q6KSgfAk8ryEkkaTdU5OYYj8zZes6TVpQZAa84b0JskVjEkU10wITGuv9tSI9V/Ic f/NHXyWu80g2XHc1Uc63iJh0SJ6oFqO3N/cxlX4ohRa9fc2yfANbfilv+xnO+PPiLSRB/UQGV0F xmum4zmzArPrtknCHRdkGFH1t9mfkTvFF6Hc+7fcKTtCd+SK/+AldSyWgTJiZ0Gycyl4W1vTEq0 i2NJ0eBJKTC+gVvVpUHgtygFEqSR3mykJNGkVWGNRlNJQgc7SxQa23kwDmViiQuBg63fRJybYi1 2sTgFJOXnugx4GTNvtZm5ED3+SkjDk6DLQUrgKeSUpwrF9aH4kfVtbueMOhOUjL4VbQEy+kn7Fk LDp4f8Bmad109oBadLtU/tw0ym2CA7Pu0myC+iu2h5+9bqOhNwl5YKZ8gE4wlGCVzK0AQJYiG6Z fRDdUQq1MHliwLwQVIR4FJvu07WKAVSoVDAGlcT1wOriTs3G0W0IPOFoKHih4S1QFADQ8xiZT3R GbE0erYlhfuJJ+w1RyZjvw== X-Received: by 2002:a05:600c:4e56:b0:499:a69d:e14b with SMTP id 5b1f17b1804b1-499a69de2fbmr11541395e9.4.1787042870069; Tue, 18 Aug 2026 01:47:50 -0700 (PDT) Received: from smtpclient.apple (78-141-71-213.dynamic.orange.sk. [78.141.71.213]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4999d078517sm103942915e9.5.2026.08.18.01.47.48 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Tue, 18 Aug 2026 01:47:49 -0700 (PDT) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3826.700.81.1.4\)) Subject: [PATCH net v3 3/3] net: skbuff: don't touch shared zerocopy state in skb_tx_error() From: Norbert Szetei In-Reply-To: Date: Tue, 18 Aug 2026 10:47:37 +0200 Cc: "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , Aaron Conole , Eelco Chaudron , Ilya Maximets , Steffen Klassert , Kuan-Ting Chen , "Michael S. Tsirkin" , linux-kernel@vger.kernel.org, dev@openvswitch.org, Jongmin Jang Content-Transfer-Encoding: quoted-printable Message-Id: <45B00A1C-A331-4982-8317-592EEA59426A@doyensec.com> References: To: netdev@vger.kernel.org X-Mailer: Apple Mail (2.3826.700.81.1.4) Content-Type: text/plain; charset="utf-8" skb_tx_error() completes the zerocopy uarg and clears SKBFL_ALL_ZEROCOPY, and skb_zcopy_downgrade_managed() clears SKBFL_MANAGED_FRAG_REFS. Both live in skb_shinfo(), which every clone shares, while the caller only owns the reference it is about to drop. Through a clone it tells the producer its pages are free and drops SKBFL_SHARED_FRAG for an skb that is still in flight. Open vSwitch reaches this with a non-last OVS_ACTION_ATTR_RECIRC: clone_execute() sends a skb_clone() into ovs_dp_process_packet() while do_execute_actions() keeps forwarding the original, and skb_clone() does not privatise the frags here -- skb_orphan_frags() returns early on SKBFL_DONT_ORPHAN. A flow miss on the clone then strips the marker from the packet still being forwarded, and a later local ESP delivery decrypts in place over frags it does not own privately. Skip it for a cloned skb. Nothing is lost: skb_release_data() clears the zerocopy state once the last reference to the shared data goes. Fixes: 25121173f7b1 ("skb: api to report errors for zero copy skbs") Cc: stable@vger.kernel.org Suggested-by: Ilya Maximets Signed-off-by: Norbert Szetei Tested-by: Jongmin Jang Reviewed-by: Ilya Maximets --- net/core/skbuff.c | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/net/core/skbuff.c b/net/core/skbuff.c index db62ed6e04b9..04776a112334 100644 --- a/net/core/skbuff.c +++ b/net/core/skbuff.c @@ -1417,10 +1417,13 @@ EXPORT_SYMBOL(skb_dump); * * Report xmit error if a device callback is tracking this skb. * skb must be freed afterwards. + * + * Does nothing for a cloned skb: the zerocopy state lives in + * skb_shinfo(), which the clones share. */ void skb_tx_error(struct sk_buff *skb) { - if (skb) { + if (skb && !skb_cloned(skb)) { skb_zcopy_downgrade_managed(skb); skb_zcopy_clear(skb, true); } --=20 2.55.0