Re: [PATCH net v2 2/2] selftests: tc-testing: add act_ct test for malformed header handling

Jamal Hadi Salim <[email protected]>
Newsgroups gmane.linux.kernel,gmane.linux.network
Message-ID <CAM0EoMnMHjq=G0PaHvDs9yJ9Vv0uJP=h69cbV11LNiYG_o-O_Q@mail.gmail.com>
On Thu, Aug 6, 2026 at 2:43 PM Victor Nogueira <[email protected]> wrote:
>
> On 06/08/2026 07:12, Hyunjung Ko wrote:
> > Add a tdc case covering the leak fixed by the previous patch.
> >
> > The test attaches "action ct" to a clsact ingress chain and injects ten
> > IPv6 frames whose nexthdr says hop-by-hop but which carry nothing after
> > the 40-byte header, so ipv6_find_hdr() fails and
> > tcf_ct_ipv6_is_fragment() returns -EPROTO.
> >
> > Before the fix act_ct returned TC_ACT_CONSUMED for these packets, so
> > tc_run() never reached its TC_ACT_SHOT arm and the clsact drop counter
> > stayed at zero while the skbs leaked. After the fix the packets are
> > dropped properly and the counter reflects them, which is what the test
> > matches on:
> >
> >    before:  Sent 476 bytes 11 pkt (dropped 0, overlimits 0 requeues 0)
> >    after:   Sent 400 bytes 10 pkt (dropped 10, overlimits 0 requeues 0)
> >
> > Assisted-by: Anthropic-Claude-Code:Claude-Opus-5
> > Signed-off-by: Hyunjung Ko <[email protected]>
>
> Reviewed-by: Victor Nogueira <[email protected]>

Acked-by: Jamal Hadi Salim <[email protected]>

cheers,
jamal
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.