]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets
authorHarshaka Narayana <harshaka.narayana@broadcom.com>
Mon, 13 Jul 2026 14:09:15 +0000 (07:09 -0700)
committerJakub Kicinski <kuba@kernel.org>
Wed, 22 Jul 2026 20:52:44 +0000 (13:52 -0700)
vmxnet3_get_hdr_len() assumes gdesc->rcd.v4/v6/tcp always describe the
outer header, but for a Geneve-encapsulated packet the device can set
them based on the inner header instead, signalled by the
VMXNET3_RCD_HDR_INNER_SHIFT bit in the completion descriptor. Since the
function never skips the outer encapsulation, this mismatch triggers:

- BUG_ON(hdr.ipv4->protocol != IPPROTO_TCP), because the outer
  protocol is UDP (Geneve), not TCP.
- BUG_ON(hdr.eth->h_proto != ...), when the tunnel's outer and inner
  IP versions differ (e.g. outer IPv6/inner IPv4 or vice versa).

Check VMXNET3_RCD_HDR_INNER_SHIFT up front and bail out, since the
function cannot locate the inner header it would need to parse. Also
convert the remaining BUG_ON()s in this function to return 0
defensively.

Fixes: 45dac1d6ea04 ("vmxnet3: Changes for vmxnet3 adapter version 2 (fwd)")
Signed-off-by: Harshaka Narayana <harshaka.narayana@broadcom.com>
Reviewed-by: Ronak Doshi <ronak.doshi@broadcom.com>
Reviewed-by: Sankararaman Jayaraman <sankararaman.jayaraman@broadcom.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260713140915.3381715-1-harshaka.narayana@broadcom.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
drivers/net/vmxnet3/vmxnet3_drv.c

index 40522afc053203da440ed86be4431b90d68443fe..f8df83f9965db507c00e980bc108c52e948624f3 100644 (file)
@@ -1530,7 +1530,11 @@ vmxnet3_get_hdr_len(struct vmxnet3_adapter *adapter, struct sk_buff *skb,
                struct ipv6hdr *ipv6;
                struct tcphdr *tcp;
        } hdr;
-       BUG_ON(gdesc->rcd.tcp == 0);
+
+       /* v4/v6/tcp then describe the inner header, which we can't locate. */
+       if ((le32_to_cpu(gdesc->dword[0]) & (1UL << VMXNET3_RCD_HDR_INNER_SHIFT)) ||
+           gdesc->rcd.tcp == 0)
+               return 0;
 
        maplen = skb_headlen(skb);
        if (unlikely(sizeof(struct iphdr) + sizeof(struct tcphdr) > maplen))
@@ -1544,15 +1548,21 @@ vmxnet3_get_hdr_len(struct vmxnet3_adapter *adapter, struct sk_buff *skb,
 
        hdr.eth = eth_hdr(skb);
        if (gdesc->rcd.v4) {
-               BUG_ON(hdr.eth->h_proto != htons(ETH_P_IP) &&
-                      hdr.veth->h_vlan_encapsulated_proto != htons(ETH_P_IP));
+               if (hdr.eth->h_proto != htons(ETH_P_IP) &&
+                   hdr.veth->h_vlan_encapsulated_proto != htons(ETH_P_IP))
+                       return 0;
+
                hdr.ptr += hlen;
-               BUG_ON(hdr.ipv4->protocol != IPPROTO_TCP);
+               if (hdr.ipv4->protocol != IPPROTO_TCP)
+                       return 0;
+
                hlen = hdr.ipv4->ihl << 2;
                hdr.ptr += hdr.ipv4->ihl << 2;
        } else if (gdesc->rcd.v6) {
-               BUG_ON(hdr.eth->h_proto != htons(ETH_P_IPV6) &&
-                      hdr.veth->h_vlan_encapsulated_proto != htons(ETH_P_IPV6));
+               if (hdr.eth->h_proto != htons(ETH_P_IPV6) &&
+                   hdr.veth->h_vlan_encapsulated_proto != htons(ETH_P_IPV6))
+                       return 0;
+
                hdr.ptr += hlen;
                /* Use an estimated value, since we also need to handle
                 * TSO case.