Re: [PATCH v4 net-next] gre: fix ERSPAN o_flags race/corruption in xmit and fill_info
| Newsgroups | org.kernel.vger.netdev |
|---|---|
| Message-ID | <178673820545.3942175.10731267597939666545.git-patchwork-notify@kernel.org> |
Hello: This patch was applied to netdev/net-next.git (main) by Jakub Kicinski <[email protected]>: On Wed, 12 Aug 2026 14:22:57 +0000 you wrote: > For IPv4 ERSPAN: > In erspan_xmit(), the driver clears IP_TUNNEL_SEQ_BIT (for version 0) > and IP_TUNNEL_KEY_BIT directly in the shared tunnel->parms.o_flags > structure. Since transmit paths can run locklessly and concurrently, > this leads to a data race. > > Furthermore, modifying tunnel->parms.o_flags permanently alters the > tunnel configuration. To work around this, erspan_fill_info() (which > reports config to userspace) was setting IP_TUNNEL_KEY_BIT back. If > erspan_fill_info (running under RTNL) and erspan_xmit (running locklessly) > race, erspan_xmit might see IP_TUNNEL_KEY_BIT set when it shouldn't, > leading to GRE header corruption (injecting a key field into the ERSPAN > GRE header). > > [...] Here is the summary with links: - [v4,net-next] gre: fix ERSPAN o_flags race/corruption in xmit and fill_info https://git.kernel.org/netdev/net-next/c/9958e69b9893 You are awesome, thank you! -- Deet-doot-dot, I am a bot. https://korg.docs.kernel.org/patchwork/pwbot.html