mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
synced 2026-09-22 09:34:56 +02:00
vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets
[ Upstream commit34a71f5361] vmxnet3_get_hdr_len() assumes gdesc->rcd.v4/v6/tcp always describe the outer header, but for a Geneve-encapsulated packet the device can set them based on the inner header instead, signalled by the VMXNET3_RCD_HDR_INNER_SHIFT bit in the completion descriptor. Since the function never skips the outer encapsulation, this mismatch triggers: - BUG_ON(hdr.ipv4->protocol != IPPROTO_TCP), because the outer protocol is UDP (Geneve), not TCP. - BUG_ON(hdr.eth->h_proto != ...), when the tunnel's outer and inner IP versions differ (e.g. outer IPv6/inner IPv4 or vice versa). Check VMXNET3_RCD_HDR_INNER_SHIFT up front and bail out, since the function cannot locate the inner header it would need to parse. Also convert the remaining BUG_ON()s in this function to return 0 defensively. Fixes:45dac1d6ea("vmxnet3: Changes for vmxnet3 adapter version 2 (fwd)") Signed-off-by: Harshaka Narayana <harshaka.narayana@broadcom.com> Reviewed-by: Ronak Doshi <ronak.doshi@broadcom.com> Reviewed-by: Sankararaman Jayaraman <sankararaman.jayaraman@broadcom.com> Reviewed-by: Simon Horman <horms@kernel.org> Link: https://patch.msgid.link/20260713140915.3381715-1-harshaka.narayana@broadcom.com Signed-off-by: Jakub Kicinski <kuba@kernel.org> Signed-off-by: Sasha Levin <sashal@kernel.org>
This commit is contained in:
committed by
Greg Kroah-Hartman
parent
ec2e157fc9
commit
667b6e5204
@@ -1457,7 +1457,11 @@ vmxnet3_get_hdr_len(struct vmxnet3_adapter *adapter, struct sk_buff *skb,
|
||||
struct ipv6hdr *ipv6;
|
||||
struct tcphdr *tcp;
|
||||
} hdr;
|
||||
BUG_ON(gdesc->rcd.tcp == 0);
|
||||
|
||||
/* v4/v6/tcp then describe the inner header, which we can't locate. */
|
||||
if ((le32_to_cpu(gdesc->dword[0]) & (1UL << VMXNET3_RCD_HDR_INNER_SHIFT)) ||
|
||||
gdesc->rcd.tcp == 0)
|
||||
return 0;
|
||||
|
||||
maplen = skb_headlen(skb);
|
||||
if (unlikely(sizeof(struct iphdr) + sizeof(struct tcphdr) > maplen))
|
||||
@@ -1471,15 +1475,21 @@ vmxnet3_get_hdr_len(struct vmxnet3_adapter *adapter, struct sk_buff *skb,
|
||||
|
||||
hdr.eth = eth_hdr(skb);
|
||||
if (gdesc->rcd.v4) {
|
||||
BUG_ON(hdr.eth->h_proto != htons(ETH_P_IP) &&
|
||||
hdr.veth->h_vlan_encapsulated_proto != htons(ETH_P_IP));
|
||||
if (hdr.eth->h_proto != htons(ETH_P_IP) &&
|
||||
hdr.veth->h_vlan_encapsulated_proto != htons(ETH_P_IP))
|
||||
return 0;
|
||||
|
||||
hdr.ptr += hlen;
|
||||
BUG_ON(hdr.ipv4->protocol != IPPROTO_TCP);
|
||||
if (hdr.ipv4->protocol != IPPROTO_TCP)
|
||||
return 0;
|
||||
|
||||
hlen = hdr.ipv4->ihl << 2;
|
||||
hdr.ptr += hdr.ipv4->ihl << 2;
|
||||
} else if (gdesc->rcd.v6) {
|
||||
BUG_ON(hdr.eth->h_proto != htons(ETH_P_IPV6) &&
|
||||
hdr.veth->h_vlan_encapsulated_proto != htons(ETH_P_IPV6));
|
||||
if (hdr.eth->h_proto != htons(ETH_P_IPV6) &&
|
||||
hdr.veth->h_vlan_encapsulated_proto != htons(ETH_P_IPV6))
|
||||
return 0;
|
||||
|
||||
hdr.ptr += hlen;
|
||||
/* Use an estimated value, since we also need to handle
|
||||
* TSO case.
|
||||
|
||||
Reference in New Issue
Block a user