Re: [PATCH net v2] net: erspan: set lltx to avoid sch_direct_xmit deadlock
From: Ido Schimmel
Date: Mon Jul 20 2026 - 03:54:12 EST
On Mon, Jul 13, 2026 at 11:14:35PM +0800, Yun Zhou wrote:
> erspan_xmit() re-enters the network stack via ip_tunnel_xmit(), causing
> nested acquisition of _xmit_lock on the underlay device while already
> holding the ERSPAN device's _xmit_lock. Both are ARPHRD_ETHER and share
> the same lockdep class, creating an ABBA deadlock:
>
> sch_direct_xmit [lock erspan] -> erspan_xmit -> ip_tunnel_xmit ->
> ip_output -> __dev_queue_xmit -> sch_direct_xmit [lock underlay]
>
> Set dev->lltx = true so HARD_TX_LOCK() skips the spinlock for ERSPAN.
> This is safe as erspan_xmit() has no shared mutable state: o_seqno is
> atomic, stats use atomic_long_inc, and dst_cache is per-CPU. GRETAP,
> the sibling device with identical xmit structure, already sets lltx.
erspan_xmit() (unlike gre_tap_xmit()) is performing non-atomic
__clear_bit() on shared tunnel flags and KCSAN will probably flag it.
Eric had a patch [1] that changes erspan_xmit() to use a private copy of
these flags. I think it's better to wait for Eric's patch to be merged
before setting lltx.
Eric, can you please submit v2 of your patch to net?
Also, doesn't ip6erspan suffer from the same problem? Please try to
reproduce and fix.
[1] https://lore.kernel.org/netdev/20260615140333.3161072-1-edumazet@xxxxxxxxxx/
>
> Closes: https://syzkaller.appspot.com/bug?extid=9bda1b9fbb7fbdf9b62b
> Reported-by: syzbot+9bda1b9fbb7fbdf9b62b@xxxxxxxxxxxxxxxxxxxxxxxxx
> Fixes: 84e54fe0a5ea ("gre: introduce native tunnel support for ERSPAN")
> Signed-off-by: Yun Zhou <yun.zhou@xxxxxxxxxxxxx>
> ---
> v2:
> - change subject prefix to [PATCH net]
>
> net/ipv4/ip_gre.c | 2 ++
> 1 file changed, 2 insertions(+)
>
> diff --git a/net/ipv4/ip_gre.c b/net/ipv4/ip_gre.c
> index 3efdfb4ffa21..9fbff16cda1d 100644
> --- a/net/ipv4/ip_gre.c
> +++ b/net/ipv4/ip_gre.c
> @@ -1363,6 +1363,8 @@ static int erspan_tunnel_init(struct net_device *dev)
> dev->features |= GRE_FEATURES;
> dev->hw_features |= GRE_FEATURES;
> dev->priv_flags |= IFF_LIVE_ADDR_CHANGE;
> + /* Skip TX lock: xmit re-enters stack, risking ABBA with underlay */
> + dev->lltx = true;
> netif_keep_dst(dev);
>
> return ip_tunnel_init(dev);
> --
> 2.43.0
>