Skip to content

Commit 667b6e5

Browse files
Harshaka Narayanagregkh
authored andcommitted
vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets
[ Upstream commit 34a71f5 ] vmxnet3_get_hdr_len() assumes gdesc->rcd.v4/v6/tcp always describe the outer header, but for a Geneve-encapsulated packet the device can set them based on the inner header instead, signalled by the VMXNET3_RCD_HDR_INNER_SHIFT bit in the completion descriptor. Since the function never skips the outer encapsulation, this mismatch triggers: - BUG_ON(hdr.ipv4->protocol != IPPROTO_TCP), because the outer protocol is UDP (Geneve), not TCP. - BUG_ON(hdr.eth->h_proto != ...), when the tunnel's outer and inner IP versions differ (e.g. outer IPv6/inner IPv4 or vice versa). Check VMXNET3_RCD_HDR_INNER_SHIFT up front and bail out, since the function cannot locate the inner header it would need to parse. Also convert the remaining BUG_ON()s in this function to return 0 defensively. Fixes: 45dac1d ("vmxnet3: Changes for vmxnet3 adapter version 2 (fwd)") Signed-off-by: Harshaka Narayana <harshaka.narayana@broadcom.com> Reviewed-by: Ronak Doshi <ronak.doshi@broadcom.com> Reviewed-by: Sankararaman Jayaraman <sankararaman.jayaraman@broadcom.com> Reviewed-by: Simon Horman <horms@kernel.org> Link: https://patch.msgid.link/20260713140915.3381715-1-harshaka.narayana@broadcom.com Signed-off-by: Jakub Kicinski <kuba@kernel.org> Signed-off-by: Sasha Levin <sashal@kernel.org>
1 parent ec2e157 commit 667b6e5

1 file changed

Lines changed: 16 additions & 6 deletions

File tree

drivers/net/vmxnet3/vmxnet3_drv.c

Lines changed: 16 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1457,7 +1457,11 @@ vmxnet3_get_hdr_len(struct vmxnet3_adapter *adapter, struct sk_buff *skb,
14571457
struct ipv6hdr *ipv6;
14581458
struct tcphdr *tcp;
14591459
} hdr;
1460-
BUG_ON(gdesc->rcd.tcp == 0);
1460+
1461+
/* v4/v6/tcp then describe the inner header, which we can't locate. */
1462+
if ((le32_to_cpu(gdesc->dword[0]) & (1UL << VMXNET3_RCD_HDR_INNER_SHIFT)) ||
1463+
gdesc->rcd.tcp == 0)
1464+
return 0;
14611465

14621466
maplen = skb_headlen(skb);
14631467
if (unlikely(sizeof(struct iphdr) + sizeof(struct tcphdr) > maplen))
@@ -1471,15 +1475,21 @@ vmxnet3_get_hdr_len(struct vmxnet3_adapter *adapter, struct sk_buff *skb,
14711475

14721476
hdr.eth = eth_hdr(skb);
14731477
if (gdesc->rcd.v4) {
1474-
BUG_ON(hdr.eth->h_proto != htons(ETH_P_IP) &&
1475-
hdr.veth->h_vlan_encapsulated_proto != htons(ETH_P_IP));
1478+
if (hdr.eth->h_proto != htons(ETH_P_IP) &&
1479+
hdr.veth->h_vlan_encapsulated_proto != htons(ETH_P_IP))
1480+
return 0;
1481+
14761482
hdr.ptr += hlen;
1477-
BUG_ON(hdr.ipv4->protocol != IPPROTO_TCP);
1483+
if (hdr.ipv4->protocol != IPPROTO_TCP)
1484+
return 0;
1485+
14781486
hlen = hdr.ipv4->ihl << 2;
14791487
hdr.ptr += hdr.ipv4->ihl << 2;
14801488
} else if (gdesc->rcd.v6) {
1481-
BUG_ON(hdr.eth->h_proto != htons(ETH_P_IPV6) &&
1482-
hdr.veth->h_vlan_encapsulated_proto != htons(ETH_P_IPV6));
1489+
if (hdr.eth->h_proto != htons(ETH_P_IPV6) &&
1490+
hdr.veth->h_vlan_encapsulated_proto != htons(ETH_P_IPV6))
1491+
return 0;
1492+
14831493
hdr.ptr += hlen;
14841494
/* Use an estimated value, since we also need to handle
14851495
* TSO case.

0 commit comments

Comments
 (0)