Received: by 2002:a05:6a10:1d13:0:0:0:0 with SMTP id pp19csp542924pxb; Wed, 1 Sep 2021 04:57:45 -0700 (PDT) X-Google-Smtp-Source: ABdhPJxDzwuwnAqxG0Ls78aBswdMXoKsB4Vf/LR6eK9k5Gy+xOVRlhH2FAMdatvM+TC8mVcHVmYb X-Received: by 2002:a05:6402:1cb4:: with SMTP id cz20mr34171655edb.0.1630497465312; Wed, 01 Sep 2021 04:57:45 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1630497465; cv=none; d=google.com; s=arc-20160816; b=fDEAe7wzoQwtjJgNxSFHlclV//Jd6IlANZISlG7cwN7kgLm7BixWoDFuRsvttU2Biw 3W8XuRfQ0YYFFj5/StcojgtO/k+iO+ly5zQ8+xE0GKufbQb1AmuYN8gWE0l8cxTm9NmX EZpvxISDg2/mRElWkCWTME6ENjifuedpTBnDqpqvACFUViu0q0tlCVQ6xTjkL6KTpBk+ O76c22xVRvxaucalkj3BVd9fuimt1/kbMu4kkefilT81T80IhOyh0x0Ag68RI/eDiZZI sr3J/OsOmvIimL8AtqYOIQhp0XO/aWe2nxjfvilu04KuCTEVVNOTf5OWwLdk8hHGZsyj /OKQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:in-reply-to:content-disposition:mime-version :references:message-id:subject:cc:to:from:date:dkim-signature; bh=z4qIXyLcujV2U5CyH1bzUJqLI8i07tbLSNrRKX1gOog=; b=IfI1V0X78vtYKuMdk1UQ3il6fPsC/7lD/5AnCSNfJmzK62SBe97SeQ497rus0hG8px q1WBxkKvGLe27LIGmiuwApAzMi/UhzwAYbQ7fE7MWyjuz1vOcJ1jMCus6lCzDMSQwWyr DsbsUX7PnsUCJC5DLprOkLbO5/2lxm5jazja5KNXzHeRckC8UjdW0HoiCkoE6j1NRoou bJgdbE9L8B8PrYfzJM9x6+/7XljcHHyn5sols+65yMF/o5WClvN46Q/GNib07fFgxVqn dTmaAyHwd2xbJJdP2zwXo+FA9KzOwoI0kaheP7JUbMeFATdcdYCzKE60bbtsKemEFFbX 0m3Q== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@messagingengine.com header.s=fm3 header.b=v9wQbBaW; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id y19si5704137edd.539.2021.09.01.04.57.01; Wed, 01 Sep 2021 04:57:45 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; dkim=pass header.i=@messagingengine.com header.s=fm3 header.b=v9wQbBaW; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S243887AbhIALyd (ORCPT + 99 others); Wed, 1 Sep 2021 07:54:33 -0400 Received: from out1-smtp.messagingengine.com ([66.111.4.25]:48385 "EHLO out1-smtp.messagingengine.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S243737AbhIALyb (ORCPT ); Wed, 1 Sep 2021 07:54:31 -0400 Received: from compute3.internal (compute3.nyi.internal [10.202.2.43]) by mailout.nyi.internal (Postfix) with ESMTP id 60EF15C0136; Wed, 1 Sep 2021 07:53:34 -0400 (EDT) Received: from mailfrontend1 ([10.202.2.162]) by compute3.internal (MEProxy); Wed, 01 Sep 2021 07:53:34 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to:x-me-proxy :x-me-proxy:x-me-sender:x-me-sender:x-sasl-enc; s=fm3; bh=z4qIXy LcujV2U5CyH1bzUJqLI8i07tbLSNrRKX1gOog=; b=v9wQbBaWV9uoucX3bZfEk1 pOezAv9s2miXludOgBWk0nsHf2ktrBq9HRX7vWbjeOYkQav2eY56TzxbdkH7eqiy 8UFH2kmVuCJgpKKkiMf2CK1G2V1sZWQIWU2Z3xp7ZbN8Het4xftTJIkPb9o4nlWO jSkhhvtC2UTsloa/qf6o+fL4qd1b7Ftq72xHrUHCMPYtcWwvqnbLaRZHoFqup5oD 3JG+5v/HCgnUAqSu56L9EJX0AuDyYNE/Sf+F/qIPQh9ishOb1jJlZtMn8NTPfnlT dpc8N+swoYUTW1WUqvevSoZpoMXEgOe1p8lEDgUrQkN3XYcoEU0W13dh9dS/OUEg == X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgedvtddruddvfedggeehucetufdoteggodetrfdotf fvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfqfgfvpdfurfetoffkrfgpnffqhgen uceurghilhhouhhtmecufedttdenucesvcftvggtihhpihgvnhhtshculddquddttddmne cujfgurhepfffhvffukfhfgggtuggjsehttdertddttddvnecuhfhrohhmpefkughoucfu tghhihhmmhgvlhcuoehiughoshgthhesihguohhstghhrdhorhhgqeenucggtffrrghtth gvrhhnpedtffekkeefudffveegueejffejhfetgfeuuefgvedtieehudeuueekhfduheel teenucevlhhushhtvghrufhiiigvpedtnecurfgrrhgrmhepmhgrihhlfhhrohhmpehiug hoshgthhesihguohhstghhrdhorhhg X-ME-Proxy: Received: by mail.messagingengine.com (Postfix) with ESMTPA; Wed, 1 Sep 2021 07:53:32 -0400 (EDT) Date: Wed, 1 Sep 2021 14:53:29 +0300 From: Ido Schimmel To: Willem de Bruijn Cc: Shreyansh Chouhan , davem@davemloft.net, yoshfuji@linux-ipv6.org, dsahern@kernel.org, kuba@kernel.org, pshelar@nicira.com, netdev@vger.kernel.org, linux-kernel@vger.kernel.org, syzbot+ff8e1b9f2f36481e2efc@syzkaller.appspotmail.com Subject: Re: [PATCH 1/2 net] ip_gre: add validation for csum_start Message-ID: References: <20210819100447.00201b26@kicinski-fedora-pc1c0hjn.dhcp.thefacebook.com> <20210821071425.512834-1-chouhan.shreyansh630@gmail.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Sat, Aug 21, 2021 at 09:41:14AM -0400, Willem de Bruijn wrote: > On Sat, Aug 21, 2021 at 3:14 AM Shreyansh Chouhan > wrote: > > > > Validate csum_start in gre_handle_offloads before we call _gre_xmit so > > that we do not crash later when the csum_start value is used in the > > lco_csum function call. > > > > This patch deals with ipv4 code. > > > > Fixes: c54419321455 ("GRE: Refactor GRE tunneling code.") > > Reported-by: syzbot+ff8e1b9f2f36481e2efc@syzkaller.appspotmail.com > > Signed-off-by: Shreyansh Chouhan > > Reviewed-by: Willem de Bruijn Hi Shreyansh, Willem, I bisected packet drops with a GRE tunnel to this patch. With the following debug patch [1], I'm getting this output [2]. Tested with IPv4 underlay only, but I assume problem exists with ip6gre as well. Thanks [1] diff --git a/net/ipv4/ip_gre.c b/net/ipv4/ip_gre.c index 177d26d8fb9c..cf4e13db030b 100644 --- a/net/ipv4/ip_gre.c +++ b/net/ipv4/ip_gre.c @@ -473,8 +473,11 @@ static void __gre_xmit(struct sk_buff *skb, struct net_device *dev, static int gre_handle_offloads(struct sk_buff *skb, bool csum) { - if (csum && skb_checksum_start(skb) < skb->data) + if (csum && skb_checksum_start(skb) < skb->data) { + if (net_ratelimit()) + skb_dump(KERN_WARNING, skb, false); return -EINVAL; + } return iptunnel_handle_offloads(skb, csum ? SKB_GSO_GRE_CSUM : SKB_GSO_GRE); } [2] skb len=84 headroom=78 headlen=84 tailroom=15902 mac=(78,0) net=(78,20) trans=98 shinfo(txflags=0 nr_frags=0 gso(size=0 type=0 segs=0)) csum(0x0 ip_summed=0 complete_sw=0 valid=0 level=0) hash(0x0 sw=0 l4=0) proto=0x0800 pkttype=0 iif=32 dev name=g1a feat=0x0x00000006401d5869 skb linear: 00000000: 45 00 00 54 be 12 40 00 3f 01 f9 82 c0 00 02 01 skb linear: 00000010: c0 00 02 12 08 00 fe ad 8c 39 00 01 7c 65 2f 61 skb linear: 00000020: 00 00 00 00 f8 7d 0a 00 00 00 00 00 10 11 12 13 skb linear: 00000030: 14 15 16 17 18 19 1a 1b 1c 1d 1e 1f 20 21 22 23 skb linear: 00000040: 24 25 26 27 28 29 2a 2b 2c 2d 2e 2f 30 31 32 33 skb linear: 00000050: 34 35 36 37