Re: [PATCH v2 net] net/packet: guard the ll header push in packet_rcv_spkt()

From: Quchaosheng

Date: Mon Sep 28 2026 - 04:22:50 EST


Manual code inspection, and nothing reported it before this.

I was working out what else the CAN skb header regression (9f10374bb024)
reaches, and the packet socket turned out not to be covered by the CAN
patch: packet_rcv_spkt() is the one call site of the ll header restore
that d549699048b4 left without dev_has_header(), and SOCK_PACKET reaches
it. It came out of reading the receive paths, not from a scan, a tool
or a report.

Because nothing had reported it, I built the reproduction before posting
rather than sending a theoretical path:

v7.3-rc5 under QEMU, slcan on a pty (the driver RX path; vcan resets
the headers in can_send() and does not reproduce it), defconfig plus
CONFIG_CAN_SLCAN=y, two images from one tree differing only in the
hunk. Unpatched: skb_under_panic len:-65455 out of
packet_rcv_spkt+0xe1 and a panic in interrupt. Patched: no panic.

The v1 had an extra skb_mac_header_was_set() conjunct; v2 drops it after
Oliver asked whether af_packet.c was the right place for this, and both
kernels were re-run with the version posted here.