linux/net/ipv6
HW He 66817a9794 net: gro: Fix nesting of TCP GSO SKBs in skb_gro_receive_list()
Fraglist GRO and hardware GRO can create an fraglist of
HW-GRO packets. This cannot be segmented back into
the original form on TCP tethering scenario.

Avoid constructing such a GSO packet, by flushing an already
built fraglist GRO packet if a hardware GRO packet arrives.

Scenario (Tethering/Forwarding):
1.Driver submits a single TCP packet, P1. P1 is kept in the
gro_list as the first packet.

2. The driver submits a TCP GSO skb, P2. P2 has already aggregated
multiple TCP packets by HW_GRO, and its non-linear data is stored in
frags[].

3. P1 and P2 match the GRO rules, and since there is no local socket,
they are aggregated by skb_gro_receive_list(). The resulting skb,
P3, has a frag_list entry that still contains frags[]:
P3: [ Linear Data ] -> frag_list -> [ Linear Data ]
                                    [ frag[1] ]
                                    [ frag[2] ]
                                    ...
4. Later, tcp4_gso_segment() or tcp6_gso_segment() calls
skb_segment_list() to segment P3. However, skb_segment_list() only
segments the entries in frag_list. It does not segment the frags[]
inside P2, so P3 is not restored to the original packets, which leads
to IP fragmentation or packet drop in the following path.

Check skb_is_gso(skb) and current GRO method, make sure fraglist GRO
applies to consecutive non-GSO skb, others adopt regular GRO path.

Fixes: 8d95dc474f ("net: add code for TCP fraglist GRO")
Signed-off-by: Zhaoping Shu <zhaoping.shu@mediatek.com>
Signed-off-by: HW He <hw.he@mediatek.com>
Reviewed-by: Willem de Bruijn <willemb@google.com>
Link: https://patch.msgid.link/20260901082312.14596-1-zhaoping.shu@mediatek.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
2026-09-03 12:20:38 +02:00
..
ila ila: reload IPv6 header after pskb_may_pull in checksum adjust 2026-07-22 14:00:41 -07:00
netfilter netfilter: x_tables: remove pr_debug 2026-08-27 16:10:57 +02:00
addrconf_core.c ipv6: remove obsolete EXPORT_SYMBOL() and EXPORT_SYMBOL_GPL() 2026-06-05 17:47:42 -07:00
addrconf.c ipv6: record the reason for kernel-initiated route deletions 2026-08-13 12:30:27 +02:00
addrlabel.c Convert 'alloc_obj' family to use the new default GFP_KERNEL argument 2026-02-21 17:09:51 -08:00
af_inet6.c tcp: rehash onto different local ECMP path on retransmit timeout 2026-06-15 15:57:31 -07:00
ah6.c xfrm: ah6: validate routing header segments_left 2026-07-27 09:40:23 +02:00
anycast.c ipv6: anycast: insert aca into global hash under idev->lock 2026-06-02 19:30:39 -07:00
calipso.c Convert remaining multi-line kmalloc_obj/flex GFP_KERNEL uses 2026-02-22 08:26:33 -08:00
datagram.c ipv6: validate extension header length before copying to cmsg 2026-05-26 18:53:10 -07:00
esp6_offload.c xfrm: Fix inner mode lookup in tunnel mode GSO segmentation 2025-12-04 09:54:53 +01:00
esp6.c Revert "esp: do not unref managed frag pages in esp_ssg_unref()" 2026-08-17 07:17:58 +02:00
exthdrs_core.c ipv6: Implement limits on extension header parsing 2026-04-30 17:21:45 -07:00
exthdrs_offload.c net: gso: add HBH extension header offload support 2024-01-05 08:11:49 -08:00
exthdrs.c ipv6: sr: restore network header before routing and forwarding 2026-08-31 20:04:37 -07:00
fib6_notifier.c net: Add SPDX ids to some source files 2026-03-09 18:32:45 -07:00
fib6_rules.c Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net 2026-07-30 12:53:19 -07:00
fou6.c udp: Support BIG TCP GSO packets where they can occur 2026-07-22 13:47:02 +02:00
icmp.c net: Const qualify ctl_tables that kmemdup unconditionally 2026-08-13 13:12:24 +02:00
inet6_connection_sock.c tcp: rehash onto different local ECMP path on retransmit timeout 2026-06-15 15:57:31 -07:00
inet6_hashtables.c tcp: use __jhash_final() in inet6_ehashfn() 2026-03-29 11:45:48 -07:00
ioam6_iptunnel.c ipv6: ioam: fix type confusion of dst_entry 2026-06-21 15:26:40 -07:00
ioam6.c net: ioam6: no longer acquire qdisc spinlock while calling qdisc_qstats_qlen_backlog() 2026-05-14 17:05:20 -07:00
ip6_checksum.c udp: Remove UDPLITE_SEND_CSCOV and UDPLITE_RECV_CSCOV. 2026-03-13 18:57:45 -07:00
ip6_fib.c ipv6: add inet6_rt_del_notify() 2026-08-13 12:30:27 +02:00
ip6_flowlabel.c ipv6: use READ_ONCE() in ipv6_flowlabel_get() 2026-06-04 18:31:18 -07:00
ip6_gre.c ip6_gre: check tunnel info before xmit in ip6gre_tunnel_xmit 2026-08-31 17:56:52 -07:00
ip6_icmp.c ipv6: remove dynamic ICMPv6 sender registration infrastructure 2026-03-29 11:21:23 -07:00
ip6_input.c ip: orphan prefetched skbs before multicast forwarding 2026-08-18 13:05:14 +02:00
ip6_offload.c net: pppoe: implement GRO/GSO support 2026-05-19 09:47:53 +02:00
ip6_offload.h
ip6_output.c ipv6: fix use-after-free in ip6_finish_output2() 2026-08-17 13:15:09 -07:00
ip6_tunnel.c Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net 2026-08-18 10:42:41 -07:00
ip6_udp_tunnel.c udp: Set length in UDP header to 0 for big GSO packets 2026-07-22 13:47:02 +02:00
ip6_vti.c net: ip6_vti: require CAP_NET_ADMIN in the device netns for changelink 2026-06-17 16:01:52 -07:00
ip6mr.c ip6mr: do not clone dst in ip6mr_cache_report() 2026-08-20 12:54:29 -07:00
ipcomp6.c xfrm: add extack to xfrm_init_state 2026-06-04 12:22:35 +02:00
ipv6_sockglue.c ipv6: Remove UDP-Lite support for IPV6_ADDRFORM. 2026-03-13 18:57:44 -07:00
Kconfig ipv6: default IPV6_SIT to m 2026-05-05 17:31:51 -07:00
Makefile ipv6: ndisc: Add ndisc_check_ns_na() validation helper 2026-08-07 16:32:46 -07:00
mcast_snoop.c
mcast.c ipv6: mcast: use jiffies_delta_to_clock_t() in igmp6_mc_seq_show() 2026-08-31 17:54:46 -07:00
mip6.c net: fill in MODULE_DESCRIPTION()s for ipv6 modules 2024-02-09 14:12:01 -08:00
ndisc_snoop.c ipv6: ndisc: Add ndisc_check_ns_na() validation helper 2026-08-07 16:32:46 -07:00
ndisc.c ipv6: record the reason for kernel-initiated route deletions 2026-08-13 12:30:27 +02:00
netfilter.c netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment() 2026-07-10 16:28:47 +02:00
output_core.c ipv6: remove obsolete EXPORT_SYMBOL() and EXPORT_SYMBOL_GPL() 2026-06-05 17:47:42 -07:00
ping.c net: remove addr_len argument of recvmsg() handlers 2026-03-02 18:17:17 -08:00
proc.c udp: Remove UDP-Lite SNMP stats. 2026-03-13 18:57:44 -07:00
protocol.c
raw.c ipv6: raw: convert do_rawv6_getsockopt to sockopt_t 2026-08-03 16:55:22 -07:00
reassembly.c ipv6: frags: cleanup __IP6_INC_STATS() confusion 2026-05-27 17:27:26 -07:00
route.c ipv6: Fix redirect exception creation for UDP/RAW sockets 2026-08-31 19:56:30 -07:00
rpl_iptunnel.c net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels 2026-04-28 11:16:14 +02:00
rpl.c
seg6_hmac.c ipv6: add NULL checks for idev in SRv6 paths 2026-03-18 17:23:43 -07:00
seg6_iptunnel.c seg6: add FIB table attribute for post-encap SID route lookup 2026-07-22 08:01:02 -07:00
seg6_local.c seg6: reset IP6CB after IPv6 decapsulation 2026-08-26 09:31:09 +01:00
seg6.c seg6: validate SRH length before reading fixed fields 2026-06-26 18:49:37 -07:00
sit.c net: cap advertised IP tunnel headroom 2026-08-18 12:42:30 +02:00
syncookies.c tcp: rehash onto different local ECMP path on retransmit timeout 2026-06-15 15:57:31 -07:00
sysctl_net_ipv6.c net: Const qualify ctl_tables that kmemdup unconditionally 2026-08-13 13:12:24 +02:00
tcp_ao.c net/tcp-ao: Return void from functions that can no longer fail 2026-04-30 09:38:56 +02:00
tcp_ipv6.c tcp: clamp route advmss to TCP_MIN_MSS 2026-08-22 13:05:19 -07:00
tcpv6_offload.c net: gro: Fix nesting of TCP GSO SKBs in skb_gro_receive_list() 2026-09-03 12:20:38 +02:00
tunnel6.c net: fill in MODULE_DESCRIPTION()s for ipv6 modules 2024-02-09 14:12:01 -08:00
udp_offload.c udp: Support gro_ipv4_max_size > 65536 2026-07-22 13:47:02 +02:00
udp.c ipv6: udp: Create exceptions before socket matching 2026-08-31 19:56:30 -07:00
xfrm6_input.c xfrm6: fix out-of-bounds write in xfrm6_input_addr() when secpath is full 2026-07-13 09:30:18 +02:00
xfrm6_output.c ipv6: adopt skb_dst_dev() and skb_dst_dev_net[_rcu]() helpers 2025-07-02 14:32:30 -07:00
xfrm6_policy.c net: Const qualify network templated ctl_tables Arrays 2026-08-13 13:12:24 +02:00
xfrm6_protocol.c ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() 2026-04-17 10:40:29 +02:00
xfrm6_state.c
xfrm6_tunnel.c xfrm: flush all states in xfrm_state_fini 2025-08-06 09:23:38 +02:00