From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail.openvz.org (unknown [69.168.225.77]) by lore.virtuozzo.com (Postfix) with ESMTPS id 3484480275 for ; Tue, 1 Sep 2026 00:43:43 +0000 (UTC) Received: from mail.openvz.org (localhost [127.0.0.1]) by mail.openvz.org (8.14.4/8.14.4) with ESMTP id 6810gSlF001401; Tue, 1 Sep 2026 03:42:29 +0300 DKIM-Filter: OpenDKIM Filter v2.11.0 mail.openvz.org 6810gSlF001401 Authentication-Results: mail.openvz.org; dkim=fail reason="signature verification failed" (2048-bit key) header.d=virtuozzo.com header.i=@virtuozzo.com header.b="oH8u36eE" Received: from mail-wm1-f71.google.com (mail-wm1-f71.google.com [209.85.128.71]) by mail.openvz.org (8.14.4/8.14.4) with ESMTP id 6810gP1O001397 (version=TLSv1/SSLv3 cipher=AES128-GCM-SHA256 bits=128 verify=FAIL) for ; Tue, 1 Sep 2026 03:42:25 +0300 DKIM-Filter: OpenDKIM Filter v2.11.0 mail.openvz.org 6810gP1O001397 Received: by mail-wm1-f71.google.com with SMTP id 5b1f17b1804b1-49554715277so37770995e9.1 for ; Mon, 31 Aug 2026 17:42:25 -0700 (PDT) X-Gm-Message-State: AFuF++n0FPqtrtfa3SnpIDjrMhXyA9I8UdmwoKdakMmK/lYsdMzvYbax pqTYUUDu6vES/9oRUvNhM7lz0aq3v5UDgCisavuNcf8jDA10tetGLlgT1iPWk5RXs/vEhZ74qz+ OSwXZcPP/o83wqPLhdtGqqruZJc6ZxDwyEOaIpYv6tph70LRwndHFQg== X-Gm-Gg: AR+sD10v8W2BHYgjtxqv5nLW62GYfx4BZJfb2MehPdO5x5bsvMvIg1Mxcpgmpss7VCo hmDNlsmWvkMLoHko6jcHsFy9azutBSN9rHwUPmLul05rFkafSds9F4mdmTm+88ocdsyi+nBUb4Z o+zqjlVqhcDjc6xz3gf00COU21RHUnnJKnSYtTZTjRdqdlQVLTSElNA/Iwf1yk4J3s/VbG1NPnS b1gQSZm62aGU8s3NiL8Srj8j5rBCfy2qYNZ098OaQi2RdnPTZQwIrO86rp6l2KJNoKE5iFJWVvq FOxahTnQ3PdQnwdHvDgwUsyXQwMc+gFpT9Je7dPgTYkdXw6mTVkKL/NlaCbO9E/lIRzCI1ABUH8 Oj+uDyK8/sq3lg2pLj8Lis1DDWg== X-Received: by 2002:a05:600c:524b:b0:49c:c9ac:a4f3 with SMTP id 5b1f17b1804b1-49cdc42f43dmr70611995e9.1.1788223345493; Mon, 31 Aug 2026 17:42:25 -0700 (PDT) X-Received: by 2002:a05:600c:524b:b0:49c:c9ac:a4f3 with SMTP id 5b1f17b1804b1-49cdc42f43dmr70611615e9.1.1788223345028; Mon, 31 Aug 2026 17:42:25 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1788223345; cv=none; d=google.com; s=arc-20260327; b=FGhaCNCu5SOIBduMdu7vknjjxZkvMV9hh0wMWpnC4mb7zv/hKJYpM9t7ACyAicx61G JeqFX9vxFx+HQ8DK40EZZMHHGVUQ69hsl1ZmkMCEvlpqaIiR2E9sYs8SvC/RGKaL8RuB aRkKPV0ThcC1+dFViEG6RQ7E+3NCVEdioHnUBTOVsIM2t8CROG9vlyPZ2dA/p58lefWw FUc3S0/MdFCU9SnVOeYbtspf+eKKIXrT9gV7Rb5PVfge0ydyWfrV4W/kYa/gD3wIIOl3 xb9rl0imot41d29XStaFsp094gmsKDmQpctY26LZbnqE/y7gaT4vS8Uh0gNNM0fyWbTT DooQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:dkim-signature; bh=QkbJsBzj4pN6JLFpi3HpecCk3O8Y9CoYuTWwzoBskf8=; fh=WpT6aB7RBAGHZeWZzqAr71yzRFbPTYkPWKsRagLn48Q=; b=g8YYK+vYPJCdSPDwOsyYR76ONNjkeHIpdmygtCwd3uG/ldOO/lcnjLHpn6kMfZg99b tkAQJ6VYs1eGmq5s+j9DGcUzAtAsQ4I6dZSzOPp52AoOBkFR11RS1JpUSOXWiYeMWZ1v cmJxyHTSq6wFER5rDk+3DNsxPf+fi1RaW+V3lqZPevRnpYx6QlQFR67CsDdAXq8R+xur FlmEB2DnYnjmWQ4A2m21BkXaDXVwj7ZHXJnfgSEQTon6JkjEZgtxIZJ+dzrhEnbgvub5 Neu2aJwTy+k6oH8I/Np7/cSyYEI4SkJ512Er1oa2S5RQ3fExn6aRwX3hFfSX/BYSgVQd OvKg==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@virtuozzo.com header.s=relay header.b=oH8u36eE; spf=pass (google.com: domain of eva.kurchatova@virtuozzo.com designates 130.117.225.111 as permitted sender) smtp.mailfrom=eva.kurchatova@virtuozzo.com; dmarc=pass (p=QUARANTINE sp=QUARANTINE dis=NONE) header.from=virtuozzo.com Received: from relay.virtuozzo.com (relay.virtuozzo.com. [130.117.225.111]) by mx.google.com with ESMTPS id ffacd0b85a97d-48442d3b84dsi1159191f8f.120.2026.08.31.17.42.24 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 31 Aug 2026 17:42:25 -0700 (PDT) Received-SPF: pass (google.com: domain of eva.kurchatova@virtuozzo.com designates 130.117.225.111 as permitted sender) client-ip=130.117.225.111; Authentication-Results: mx.google.com; dkim=pass header.i=@virtuozzo.com header.s=relay header.b=oH8u36eE; spf=pass (google.com: domain of eva.kurchatova@virtuozzo.com designates 130.117.225.111 as permitted sender) smtp.mailfrom=eva.kurchatova@virtuozzo.com; dmarc=pass (p=QUARANTINE sp=QUARANTINE dis=NONE) header.from=virtuozzo.com DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=virtuozzo.com; s=relay; h=MIME-Version:Message-ID:Date:Subject:From: Content-Type; bh=QkbJsBzj4pN6JLFpi3HpecCk3O8Y9CoYuTWwzoBskf8=; b=oH8u36eEOqKk BF6Ywmeag6lUu0Ij6nyEsX1KtVCFp1JOKvhcvaLRhs0v5qinY35c+/Td1Lbf43/Rul6Nbdthl8wog 8HgZ8DB1arsSH0+fjg8l4LCLzsFCofXoNdL1rUQWqC4xq1ff5DjSnfK92TIfMxhTy8xo5XVb4Ykqi UkKp/BkEL+2/iyeMhTxFjILOmsBJebQgrCXVSY24riaAK2OWI59Ywzxb2oM7bNyaqeP+3+1hZqYuz we+2zXcjy5ZD3QXEb/ECxSSIXFNTZdIs0u9kt4/49M6lVFEHJKic24j3ealjzlMHyLTGoacyREEgx mOE1I8g6T01K21LzO3ZQ+Q==; Received: from ch-vpn.virtuozzo.com ([130.117.225.6] helo=LekKit-T14) by relay.virtuozzo.com with esmtp (Exim 4.96) (envelope-from ) id 1x1CXd-00BvWj-2s; Tue, 01 Sep 2026 02:42:15 +0200 From: Eva Kurchatova To: khorenko@virtuozzo.com Date: Tue, 1 Sep 2026 03:42:22 +0300 Message-ID: <20260901004222.1655126-1-eva.kurchatova@virtuozzo.com> X-Mailer: git-send-email 2.55.0 MIME-Version: 1.0 X-OZ-Fwd: true Cc: devel@openvz.org Subject: [Devel] [PATCH vz10] ms/net: dst_metadata: fix IP_DF bit not extracted from tunnel headers X-BeenThere: devel@openvz.org X-Mailman-Version: 2.1.12 Precedence: list List-Id: OpenVZ development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Sender: devel-bounces@openvz.org Errors-To: devel-bounces@openvz.org From: Ilya Maximets Both OVS and TC flower allow extracting and matching on the DF bit of the outer IP header via OVS_TUNNEL_KEY_ATTR_DONT_FRAGMENT in the OVS_KEY_ATTR_TUNNEL and TCA_FLOWER_KEY_FLAGS_TUNNEL_DONT_FRAGMENT in the TCA_FLOWER_KEY_ENC_FLAGS respectively. Flow dissector extracts this information as FLOW_DIS_F_TUNNEL_DONT_FRAGMENT from the tunnel info key. However, the IP_TUNNEL_DONT_FRAGMENT_BIT in the tunnel key is never actually set, because the tunneling code doesn't actually extract it from the IP header. OAM and CRIT_OPT are extracted by the tunnel implementation code, same code also sets the KEY flag, if present. UDP tunnel core takes care of setting the CSUM flag if the checksum is present in the UDP header, but the DONT_FRAGMENT is not handled at any layer. Fix that by checking the bit and setting the corresponding flag while populating the tunnel info in the IP layer where it belongs. Not using __assign_bit as we don't really need to clear the bit in a just initialized field. It also doesn't seem like using __assign_bit will make the code look better. Clearly, users didn't rely on this functionality for anything very important until now. The reason why this doesn't break OVS logic is that it only matches on what kernel previously parsed out and if kernel consistently reports this bit as zero, OVS will only match on it to be zero, which sort of works. But it is still a bug that the uAPI reports and allows matching on the field that is not actually checked in the packet. And this is causing misleading -df reporting in OVS datapath flows, while the tunnel traffic actually has the bit set in most cases. This may also cause issues if a hardware properly implements support for tunnel flag matching as it will disagree with the implementation in a software path of TC flower. Fixes: 7d5437c709de ("openvswitch: Add tunneling interface.") Fixes: 1d17568e74de ("net/sched: cls_flower: add support for matching tunnel control flags") Signed-off-by: Ilya Maximets Reviewed-by: Ido Schimmel Link: https://patch.msgid.link/20250909165440.229890-2-i.maximets@ovn.org Signed-off-by: Jakub Kicinski (cherry picked from commit a9888628cb2c768202a4530e2816da1889cc3165) https://virtuozzo.atlassian.net/browse/VSTOR-139651 Feature: fix ms/net Signed-off-by: Eva Kurchatova --- include/net/dst_metadata.h | 11 +++++++++-- 1 file changed, 9 insertions(+), 2 deletions(-) diff --git a/include/net/dst_metadata.h b/include/net/dst_metadata.h index 4160731dcb6e..1fc2fb03ce3f 100644 --- a/include/net/dst_metadata.h +++ b/include/net/dst_metadata.h @@ -3,6 +3,7 @@ #define __NET_DST_METADATA_H 1 #include +#include #include #include #include @@ -220,9 +221,15 @@ static inline struct metadata_dst *ip_tun_rx_dst(struct sk_buff *skb, int md_size) { const struct iphdr *iph = ip_hdr(skb); + struct metadata_dst *tun_dst; + + tun_dst = __ip_tun_set_dst(iph->saddr, iph->daddr, iph->tos, iph->ttl, + 0, flags, tunnel_id, md_size); - return __ip_tun_set_dst(iph->saddr, iph->daddr, iph->tos, iph->ttl, - 0, flags, tunnel_id, md_size); + if (tun_dst && (iph->frag_off & htons(IP_DF))) + __set_bit(IP_TUNNEL_DONT_FRAGMENT_BIT, + tun_dst->u.tun_info.key.tun_flags); + return tun_dst; } static inline struct metadata_dst *__ipv6_tun_set_dst(const struct in6_addr *saddr, -- 2.55.0 _______________________________________________ Devel mailing list Devel@openvz.org https://lists.openvz.org/mailman/listinfo/devel