• Shmulik Ladkani's avatar
    net: ip_finish_output_gso: Allow fragmenting segments of tunneled skbs if their DF is unset · c0451fe1
    Shmulik Ladkani authored
    In b8247f09,
    
       "net: ip_finish_output_gso: If skb_gso_network_seglen exceeds MTU, allow segmentation for local udp tunneled skbs"
    
    gso skbs arriving from an ingress interface that go through UDP
    tunneling, are allowed to be fragmented if the resulting encapulated
    segments exceed the dst mtu of the egress interface.
    
    This aligned the behavior of gso skbs to non-gso skbs going through udp
    encapsulation path.
    
    However the non-gso vs gso anomaly is present also in the following
    cases of a GRE tunnel:
     - ip_gre in collect_md mode, where TUNNEL_DONT_FRAGMENT is not set
       (e.g. OvS vport-gre with df_default=false)
     - ip_gre in nopmtudisc mode, where IFLA_GRE_IGNORE_DF is set
    
    In both of the above cases, the non-gso skbs get fragmented, whereas the
    gso skbs (having skb_gso_network_seglen that exceeds dst mtu) get dropped,
    as they don't go through the segment+fragment code path.
    
    Fix: Setting IPSKB_FRAG_SEGS if the tunnel specified IP_DF bit is NOT set.
    
    Tunnels that do set IP_DF, will not go to fragmentation of segments.
    This preserves behavior of ip_gre in (the default) pmtudisc mode.
    
    Fixes: b8247f09 ("net: ip_finish_output_gso: If skb_gso_network_seglen exceeds MTU, allow segmentation for local udp tunneled skbs")
    Reported-by: default avatarwenxu <wenxu@ucloud.cn>
    Cc: Hannes Frederic Sowa <hannes@stressinduktion.org>
    Signed-off-by: default avatarShmulik Ladkani <shmulik.ladkani@gmail.com>
    Tested-by: default avatarwenxu <wenxu@ucloud.cn>
    Acked-by: default avatarHannes Frederic Sowa <hannes@stressinduktion.org>
    Signed-off-by: default avatarDavid S. Miller <davem@davemloft.net>
    c0451fe1
ip_tunnel_core.c 12.2 KB