Re: [PATCH net] ipvlan: inherit needed_headroom from phy_dev

Eric Dumazet <[email protected]>
Newsgroups org.kernel.vger.netdev
Message-ID <CANn89iLr4EQxBAKikZCeXbXEk-pjmT4mq3d=D2P01MtNSUgwrg@mail.gmail.com>
On Tue, Aug 4, 2026 at 5:54 PM Eric Dumazet <[email protected]> wrote:
>
> ipvlan devices inherit hard_header_len from phy_dev during ipvlan_init(),
> but leave needed_headroom set to 0.
>
> When the underlying phy_dev (or stacked lower device) requires extra headroom
> for headers (e.g. macsec, ipsec, wireguard, tunnels, or veth with rx headroom),
> upper layers calculating packet headroom via LL_RESERVED_SPACE(dev) fail to
> reserve sufficient headroom.
>
> This can result in reallocation failures, skb headroom underflows, or KASAN
> slab-use-after-free crashes when dev_hard_header() / ipvlan_hard_header()
> prepends header data.
>
> Fix this by:
> 1. Inheriting needed_headroom from phy_dev in ipvlan_init().
> 2. Propagating needed_headroom updates to attached ipvlans in
>    ipvlan_device_event() when receiving NETDEV_FEAT_CHANGE events.
>
> Note that a similar issue exists in macvlan and will be handled in another
> patch.
>
> Fixes: 2ad7bfab3016 ("ipvlan: Initial check-in of the IPVLAN driver.")
> Reported-by: [email protected]
> Closes: https://lore.kernel.org/netdev/[email protected]/T/#u
> Reported-by: Tangxin Xie <[email protected]>
> Closes: https://lore.kernel.org/netdev/CANn89i+1EW-sFNK8xoq98gMbPCeLS7e=+rs9gHfLg5Wj+4x0sw@mail.gmail.com/T/#mcc6307f115e500df23ea2980d5669fe95f20b6b4
> Signed-off-by: Eric Dumazet <[email protected]>
> ---
>  drivers/net/ipvlan/ipvlan_main.c | 2 ++
>  1 file changed, 2 insertions(+)
>
> diff --git a/drivers/net/ipvlan/ipvlan_main.c b/drivers/net/ipvlan/ipvlan_main.c
> index ed46439a9f4eb1dd8bfaf6c83476ba4f2aff31bc..7513c005a5121676d3f8edb0898492ad434a9fab 100644
> --- a/drivers/net/ipvlan/ipvlan_main.c
> +++ b/drivers/net/ipvlan/ipvlan_main.c
> @@ -146,6 +146,7 @@ static int ipvlan_init(struct net_device *dev)
>         dev->lltx = true;
>         netif_inherit_tso_max(dev, phy_dev);
>         dev->hard_header_len = phy_dev->hard_header_len;
> +       dev->needed_headroom = phy_dev->needed_headroom;
>
>         netdev_lockdep_set_classes(dev);
>
> @@ -773,6 +774,7 @@ static int ipvlan_device_event(struct notifier_block *unused,
>         case NETDEV_FEAT_CHANGE:
>                 list_for_each_entry(ipvlan, &port->ipvlans, pnode) {
>                         netif_inherit_tso_max(ipvlan->dev, dev);
> +                       ipvlan->dev->needed_headroom = dev->needed_headroom;
>                         netdev_update_features(ipvlan->dev);
>                 }
>                 break;

Sashiko suggests to also inherit  needed_tailroom.

I will add this in V2, although I think devices having a non zero
needed_tailroom handle the case just fine,
since TCP never cared.

This is a pre-existing issue, but since we are inheriting needed_headroom to
avoid reallocation failures, should we also inherit needed_tailroom here?
If the underlying device requires tailroom for trailers or ICVs (like MACsec
or IPsec), failing to set needed_tailroom will cause packets to be reallocated
and copied on the fast path. It could also potentially trigger skb_over_panic
if the driver appends data without checking.

pw-bot: cr
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.