Re: [PATCH net] ipv6: rpl: unclone the skb before modifying the packet
From: Andrea Mayer
Date: Fri Oct 02 2026 - 18:53:18 EST
On Thu, 01 Oct 2026 18:29:07 +0000
netdev-bot+sinfo@xxxxxxxxxx wrote:
> Hi!
>
> This is an automated message. This series looks like a fix, but its
> commit messages seem to be missing some information:
>
> - Whether the issue was actually triggered, or is only theoretical
> (e.g. found by code inspection). If it was triggered please include
> the symptoms, like the stack trace or error messages.
>
> [snip]
Hi,
Yes, I triggered it. I reproduced it in a VM.
One namespace sends pings to fc00:2::1 through the RPL segment
fc00::2, which belongs to a second namespace with rpl_seg_enabled=1.
Each ping arrives with destination address fc00::2 and a routing header
with Segments Left 1 that carries fc00:2::1. In the second namespace, a
Python program opens an AF_PACKET socket and reads the queued frames
only after the pings were processed. For each frame with a routing
header, it prints the destination address and Segments Left.
Without the fix, all these frames showed:
daddr fc00:2::1 segments_left 0
These are the values written by ipv6_rpl_srh_rcv(), not the received
ones. With the fix, all the frames with a routing header showed the
received values:
daddr fc00::2 segments_left 1
To reproduce it, I did not modify the kernel or use error injection.
This is how the packet reaches ipv6_rpl_srh_rcv(), with some calls
left out:
__netif_receive_skb_one_core
__netif_receive_skb_core
deliver_skb [orig: users=2]
packet_rcv
skb_clone clone queued to the AF_PACKET socket
consume_skb(orig) [orig: users=1, cloned=1]
ipv6_rcv
ip6_rcv_core skb_share_check: no-op [orig: users=1]
[...]
ip6_protocol_deliver_rcu
ipv6_rthdr_rcv
ipv6_rpl_srh_rcv writes into the data shared with the clone
The reproducer is a shell script and a Python program.
I can post it if it helps.
Thanks,
Andrea