Re: [PATCH net-next] bridge: mrp: fix MRP_Test option TLV length
Nikolay Aleksandrov <[email protected]> Sat, 25 Jul 2026 17:51:21 +0300
| Newsgroups | gmane.linux.network.bridge |
|---|---|
| Message-ID | <amTNacya_ZXLjoDn__46609.8712918878$1784991112$gmane$org@penguin> |
On Fri, Jul 24, 2026 at 05:12:02AM +0000, David Corvaglia wrote: > oui is a pointer, so sizeof(oui) is the pointer size. The MRA > Option TLV thus advertises a wrong length (15 vs 10 on x86_64), > causing misparsing of the frame on peers. Fix is to replace > with sizeof(*oui). > > Signed-off-by: David Corvaglia <[email protected]> > --- > net/bridge/br_mrp.c | 2 +- > 1 file changed, 1 insertion(+), 1 deletion(-) > > diff --git a/net/bridge/br_mrp.c b/net/bridge/br_mrp.c > index 3f7126a7d720..179d2470b724 100644 > --- a/net/bridge/br_mrp.c > +++ b/net/bridge/br_mrp.c > @@ -215,7 +215,7 @@ static struct sk_buff *br_mrp_alloc_test_skb(struct br_mrp *mrp, > struct br_mrp_oui_hdr *oui = NULL; > u8 length; > > - length = sizeof(*sub_opt) + sizeof(*sub_tlv) + sizeof(oui) + > + length = sizeof(*sub_opt) + sizeof(*sub_tlv) + sizeof(*oui) + > MRP_OPT_PADDING; > br_mrp_skb_tlv(skb, BR_MRP_TLV_HEADER_OPTION, length); > > -- > 2.55.0 > This is clearly a fix and looks like it is needed for proper parsing. I think it should be targeted at -net with a fixes tag, probably f7458934b0791 ("net: bridge: mrp: Update the Test frames for MRA") Cheers, Nik