[PATCH net v2] net: gro: avoid nesting TCP GSO skbs in skb_gro_receive_list()

From: zhaoping.shu

Date: Thu Jul 23 2026 - 05:22:40 EST


From: HW He <hw.he@xxxxxxxxxxxx>

On devices that support both NETIF_F_GRO_HW and NETIF_F_GRO_FRAGLIST,
the hardware or driver may deliver packets that have already been
aggregated into a TCP GSO skb with frags[]. GRO may then
aggregate the skb again in skb_gro_receive_list().

This can create a nested GSO skb, which is not handled correctly by the
later GSO segmentation paths. When the skb is segmented by
skb_segment_list(), it not be fully restored to the original packets.

Avoid this by setting NAPI_GRO_CB(skb)->flush for GSO skbs before
aggregation.

Signed-off-by: HW He <hw.he@xxxxxxxxxxxx>
Signed-off-by: Zhaoping Shu <zhaoping.shu@xxxxxxxxxxxx>
---
v2: Take Antoine Tenart's suggestion
v1: https://lore.kernel.org/netdev/amB7wb1A2Oo2dv5d@kwain/
---
net/ipv4/tcp_offload.c | 1 +
1 file changed, 1 insertion(+)

diff --git a/net/ipv4/tcp_offload.c b/net/ipv4/tcp_offload.c
index 3b1fdcd3cb29..c363434a5646 100644
--- a/net/ipv4/tcp_offload.c
+++ b/net/ipv4/tcp_offload.c
@@ -332,6 +332,7 @@ struct sk_buff *tcp_gro_receive(struct list_head *head, struct sk_buff *skb,
flush |= skb->ip_summed != p->ip_summed;
flush |= skb->csum_level != p->csum_level;
flush |= NAPI_GRO_CB(p)->count >= 64;
+ NAPI_GRO_CB(skb)->flush |= skb_is_gso(skb);
skb_set_network_header(skb, skb_gro_receive_network_offset(skb));

if (flush || skb_gro_receive_list(p, skb))
--
2.17.0