Re: [PATCH net v4] ip6_gre: use skb_vlan_inet_prepare() instead of pskb_inet_may_pull()

From: Anton Danilov

Date: Mon Oct 05 2026 - 19:07:32 EST


On Mon, Oct 05, 2026 at 02:55:11PM +0000, netdev-bot+sashiko@xxxxxxxxxx wrote:

> - [High] The check/parse mismatch the commit says it fixes is still
> reachable in ip6gre_tunnel_xmit() on ip6gre devices that have ...
> - [High] One of the parses this patch is meant to protect is the one
> added by Fixes: b09ab9c92e50, i.e. payload_protocol = ...

Thanks for the review. I measured v4 against net on the cases it
points at - there is no regression. For a VLAN-tagged frame the outer
header stays the same where it was already wrong, and either starts to
inherit correctly or is now dropped where net let it through:

tagged frame net v4
ip6gretap with key, ttl inherit hlim 64 hlim 64 (unchanged)
ip6erspan, ttl inherit hlim 64 hlim 64 (unchanged)
ip6gretap without key, forwarded hlim 64 hlim 32 (now inherits)
20B gretap / 10B erspan short frame sent dropped

High #1 (header_ops branch): that branch keeps pskb_inet_may_pull()
exactly as net has it, so the mismatch there is not introduced by this
patch. It is reachable only on an ip6gre device created without a
remote that is later given one with changelink. That belongs with the
rest of the ip6gre changelink/header_ops handling; v5 only narrows the
commit message so it no longer claims to cover that branch.

High #2 (the parse added by b09ab9c92e50): yes, ip6_tnl_xmit() walks
the tags again after gre_build_header() has pushed the GRE header, and
clearing mac_len does not help that walk -- the first two rows above
are unchanged from net for exactly that reason. That inheritance is a
separate fix that depends on this one, so it will come after. v5 fixes
the comment, which was meant to describe skb_vlan_inet_prepare()'s own
length check, not the ip6_tnl_xmit() parse.

The two Medium notes are pre-existing as well: the IPv4 paths
(gre_tap_xmit/erspan_xmit/ip_tunnel_rcv) and the erspan_build_header()
reads on short frames. Fixes for those are queued separately.

v5 changes only the commit message and two comments; the code is
identical to v4.

pw-bot: cr

---

Anton Danilov