]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
tunnels: Accept PACKET_HOST in skb_tunnel_check_pmtu().
authorGuillaume Nault <gnault@redhat.com>
Sat, 29 Mar 2025 00:33:44 +0000 (01:33 +0100)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Thu, 10 Apr 2025 12:31:00 +0000 (14:31 +0200)
[ Upstream commit 8930424777e43257f5bf6f0f0f53defd0d30415c ]

Because skb_tunnel_check_pmtu() doesn't handle PACKET_HOST packets,
commit 30a92c9e3d6b ("openvswitch: Set the skbuff pkt_type for proper
pmtud support.") forced skb->pkt_type to PACKET_OUTGOING for
openvswitch packets that are sent using the OVS_ACTION_ATTR_OUTPUT
action. This allowed such packets to invoke the
iptunnel_pmtud_check_icmp() or iptunnel_pmtud_check_icmpv6() helpers
and thus trigger PMTU update on the input device.

However, this also broke other parts of PMTU discovery. Since these
packets don't have the PACKET_HOST type anymore, they won't trigger the
sending of ICMP Fragmentation Needed or Packet Too Big messages to
remote hosts when oversized (see the skb_in->pkt_type condition in
__icmp_send() for example).

These two skb->pkt_type checks are therefore incompatible as one
requires skb->pkt_type to be PACKET_HOST, while the other requires it
to be anything but PACKET_HOST.

It makes sense to not trigger ICMP messages for non-PACKET_HOST packets
as these messages should be generated only for incoming l2-unicast
packets. However there doesn't seem to be any reason for
skb_tunnel_check_pmtu() to ignore PACKET_HOST packets.

Allow both cases to work by allowing skb_tunnel_check_pmtu() to work on
PACKET_HOST packets and not overriding skb->pkt_type in openvswitch
anymore.

Fixes: 30a92c9e3d6b ("openvswitch: Set the skbuff pkt_type for proper pmtud support.")
Fixes: 4cb47a8644cc ("tunnels: PMTU discovery support for directly bridged IP packets")
Signed-off-by: Guillaume Nault <gnault@redhat.com>
Reviewed-by: Stefano Brivio <sbrivio@redhat.com>
Reviewed-by: Aaron Conole <aconole@redhat.com>
Tested-by: Aaron Conole <aconole@redhat.com>
Link: https://patch.msgid.link/eac941652b86fddf8909df9b3bf0d97bc9444793.1743208264.git.gnault@redhat.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
net/ipv4/ip_tunnel_core.c
net/openvswitch/actions.c

index ba1388ba6c6e5fcc79e7a24a689e52328f04d992..dad9d7db5bf6cf7f02a16ea01367d77bfd44ec78 100644 (file)
@@ -415,7 +415,7 @@ int skb_tunnel_check_pmtu(struct sk_buff *skb, struct dst_entry *encap_dst,
 
        skb_dst_update_pmtu_no_confirm(skb, mtu);
 
-       if (!reply || skb->pkt_type == PACKET_HOST)
+       if (!reply)
                return 0;
 
        if (skb->protocol == htons(ETH_P_IP))
index 4095456f413dfc4bae39140479f53933ebab9dae..80fee9d118eecdb13e0d125592dd3cdfc771a1da 100644 (file)
@@ -923,12 +923,6 @@ static void do_output(struct datapath *dp, struct sk_buff *skb, int out_port,
                                pskb_trim(skb, ovs_mac_header_len(key));
                }
 
-               /* Need to set the pkt_type to involve the routing layer.  The
-                * packet movement through the OVS datapath doesn't generally
-                * use routing, but this is needed for tunnel cases.
-                */
-               skb->pkt_type = PACKET_OUTGOING;
-
                if (likely(!mru ||
                           (skb->len <= mru + vport->dev->hard_header_len))) {
                        ovs_vport_send(vport, skb, ovs_key_mac_proto(key));