Re: [PATCH net] net/sched: act_gact, act_police: range check the fallback control action

Hyunjung Ko <[email protected]>
Newsgroups org.kernel.vger.netdev,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
On Wed, Aug 5, 2026 at 1:59 PM Jamal Hadi Salim <[email protected]> wrote:
>
> 1) We test almost _everything_, so to get a review - even if it as
> trivial as this: Always, always send a test case to reproduce even if
> it seems as obvious as this. Preferable will be tdc. But you can send
> or point to an AI generated poc as well if you cant ask it to create a
> tdc test. If the issue is sensitive - send the poc to the tc/netdev
> maintainers in a separate email.
>
> 2) If you got assistance from an ai - please add assisted-by tag.
>
> Same goes for your other patch...

Thanks for the review. Both points addressed for both patches; v2 of
each follows shortly.

The act_ct patch now comes with a tdc case (2/2). It uses the scapy
plugin to inject the malformed IPv6 frame and matches on the clsact
drop counter, which turns out to be a clean discriminator: before the
fix act_ct returns TC_ACT_CONSUMED, so tc_run() never reaches its
TC_ACT_SHOT arm and the counter stays at zero while the skbs leak;
after the fix it reads "dropped 10".

To be straight about how far I verified that: I do not have a
scapy-capable tdc setup, so I have not run tdc.py over the case
itself. I ran the equivalent by hand under qemu on both an unpatched
and a patched kernel - same topology, same ten frames, same tc -s
qdisc show - and got "dropped 0" vs "dropped 10". The JSON is modelled
on the existing scapy cases in the same file (3992, 9c2a). Noted below
the --- line of 2/2 as well.

This patch I could not express in tdc. iproute2 only parses symbolic
control-action names, so tc(8) rejects the bad value before it ever
reaches the kernel:

  $ tc actions add action gact drop random determ ok 2
  RTNETLINK answers: Operation not permitted   <- parsed fine
  $ tc actions add action gact drop random determ 9 2
  Bad action type 9                            <- rejected by iproute2

The fallback has to be planted over raw netlink, so I have inlined a
self-contained C reproducer below the --- line of v2 instead. It sets
up the clsact chain, plants TCA_GACT_PROB.paction = 9 and then
TCA_POLICE_RESULT = 9, and reports skbuff_head_cache growth per
injected packet. If you would rather have this as a tdc case anyway I
can write a plugin that does the raw netlink setup, but that looked
like more machinery than a one-line range check warrants - happy to do
it if you disagree.

The AI assistance tag is on both patches now.

Thanks,
Hyunjung
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.