DPDK patches and discussions
 help / color / mirror / Atom feed
* [DPDK/ethdev Bug 1416] net/af_packet: tx_burst() can modify packets
@ 2024-04-16 10:29 bugzilla
  2024-04-16 15:38 ` Stephen Hemminger
  2024-04-16 15:58 ` bugzilla
  0 siblings, 2 replies; 9+ messages in thread
From: bugzilla @ 2024-04-16 10:29 UTC (permalink / raw)
  To: dev

[-- Attachment #1: Type: text/plain, Size: 1725 bytes --]

https://bugs.dpdk.org/show_bug.cgi?id=1416

            Bug ID: 1416
           Summary: net/af_packet: tx_burst() can modify packets
           Product: DPDK
           Version: 24.03
          Hardware: All
                OS: All
            Status: UNCONFIRMED
          Severity: normal
          Priority: Normal
         Component: ethdev
          Assignee: dev@dpdk.org
          Reporter: konstantin.v.ananyev@yandex.ru
  Target Milestone: ---

According to the ethdev doc, in general, PMD tx_burst() should not modify mbuf
contents. To be more specific:

ethdev/rte_ethdev.h:6396
...
 * @note This function must not modify mbufs (including packets data)
 * unless the refcnt is 1.
 * An exception is the bonding PMD, which does not have "Tx prepare" support,
 * in this case, mbufs may be modified.
...

Though why looking at eth_af_packet_tx(), it looks to me like it does modify
the packet contents without any checks for refcnt, etc.:

static uint16_t
eth_af_packet_tx(void *queue, struct rte_mbuf **bufs, uint16_t nb_pkts)
{
        ...
        for (i = 0; i < nb_pkts; i++) {
                mbuf = *bufs++;

                ...

                /* insert vlan info if necessary */
                if (mbuf->ol_flags & RTE_MBUF_F_TX_VLAN) {
                        if (rte_vlan_insert(&mbuf)) {
                                rte_pktmbuf_free(mbuf);
                                continue; 

AFAIU, it does copy of mbuf contents into pbuf anyway (just few line below).
So the fix might be - simply insert VLAN tag at copying stage.
Feel free to correct me, if I missed something.

-- 
You are receiving this mail because:
You are the assignee for the bug.

[-- Attachment #2: Type: text/html, Size: 3625 bytes --]

^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: [DPDK/ethdev Bug 1416] net/af_packet: tx_burst() can modify packets
  2024-04-16 10:29 [DPDK/ethdev Bug 1416] net/af_packet: tx_burst() can modify packets bugzilla
@ 2024-04-16 15:38 ` Stephen Hemminger
  2024-04-16 15:56   ` Konstantin Ananyev
  2024-04-16 15:58 ` bugzilla
  1 sibling, 1 reply; 9+ messages in thread
From: Stephen Hemminger @ 2024-04-16 15:38 UTC (permalink / raw)
  To: bugzilla; +Cc: dev

On Tue, 16 Apr 2024 10:29:53 +0000
bugzilla@dpdk.org wrote:

> static uint16_t
> eth_af_packet_tx(void *queue, struct rte_mbuf **bufs, uint16_t nb_pkts)
> {
>         ...
>         for (i = 0; i < nb_pkts; i++) {
>                 mbuf = *bufs++;
> 
>                 ...
> 
>                 /* insert vlan info if necessary */
>                 if (mbuf->ol_flags & RTE_MBUF_F_TX_VLAN) {
>                         if (rte_vlan_insert(&mbuf)) {
>                                 rte_pktmbuf_free(mbuf);
>                                 continue; 
> 
> AFAIU, it does copy of mbuf contents into pbuf anyway (just few line below).
> So the fix might be - simply insert VLAN tag at copying stage.
> Feel free to correct me, if I missed something.

vlan_insert will fail if the mbuf is has refcnt > 1.

static inline int rte_vlan_insert(struct rte_mbuf **m)
{
	struct rte_ether_hdr *oh, *nh;
	struct rte_vlan_hdr *vh;

	/* Can't insert header if mbuf is shared */
	if (!RTE_MBUF_DIRECT(*m) || rte_mbuf_refcnt_read(*m) > 1)
		return -EINVAL;

^ permalink raw reply	[flat|nested] 9+ messages in thread

* RE: [DPDK/ethdev Bug 1416] net/af_packet: tx_burst() can modify packets
  2024-04-16 15:38 ` Stephen Hemminger
@ 2024-04-16 15:56   ` Konstantin Ananyev
  2024-04-16 16:14     ` Morten Brørup
  0 siblings, 1 reply; 9+ messages in thread
From: Konstantin Ananyev @ 2024-04-16 15:56 UTC (permalink / raw)
  To: Stephen Hemminger; +Cc: dev



> 
> > static uint16_t
> > eth_af_packet_tx(void *queue, struct rte_mbuf **bufs, uint16_t nb_pkts)
> > {
> >         ...
> >         for (i = 0; i < nb_pkts; i++) {
> >                 mbuf = *bufs++;
> >
> >                 ...
> >
> >                 /* insert vlan info if necessary */
> >                 if (mbuf->ol_flags & RTE_MBUF_F_TX_VLAN) {
> >                         if (rte_vlan_insert(&mbuf)) {
> >                                 rte_pktmbuf_free(mbuf);
> >                                 continue;
> >
> > AFAIU, it does copy of mbuf contents into pbuf anyway (just few line below).
> > So the fix might be - simply insert VLAN tag at copying stage.
> > Feel free to correct me, if I missed something.
> 
> vlan_insert will fail if the mbuf is has refcnt > 1.
> 
> static inline int rte_vlan_insert(struct rte_mbuf **m)
> {
> 	struct rte_ether_hdr *oh, *nh;
> 	struct rte_vlan_hdr *vh;
> 
> 	/* Can't insert header if mbuf is shared */
> 	if (!RTE_MBUF_DIRECT(*m) || rte_mbuf_refcnt_read(*m) > 1)
> 		return -EINVAL;

You are right, I missed that.
Will close it then.
Thanks
Konstantin


^ permalink raw reply	[flat|nested] 9+ messages in thread

* [DPDK/ethdev Bug 1416] net/af_packet: tx_burst() can modify packets
  2024-04-16 10:29 [DPDK/ethdev Bug 1416] net/af_packet: tx_burst() can modify packets bugzilla
  2024-04-16 15:38 ` Stephen Hemminger
@ 2024-04-16 15:58 ` bugzilla
  1 sibling, 0 replies; 9+ messages in thread
From: bugzilla @ 2024-04-16 15:58 UTC (permalink / raw)
  To: dev

[-- Attachment #1: Type: text/plain, Size: 956 bytes --]

https://bugs.dpdk.org/show_bug.cgi?id=1416

Konstantin Ananyev (konstantin.v.ananyev@yandex.ru) changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
             Status|UNCONFIRMED                 |RESOLVED
         Resolution|---                         |INVALID

--- Comment #1 from Konstantin Ananyev (konstantin.v.ananyev@yandex.ru) ---
As Stephen Hemminger <stephen@networkplumber.org> pointed out:

vlan_insert will fail if the mbuf is has refcnt > 1.

static inline int rte_vlan_insert(struct rte_mbuf **m)
{
        struct rte_ether_hdr *oh, *nh;
        struct rte_vlan_hdr *vh;

        /* Can't insert header if mbuf is shared */
        if (!RTE_MBUF_DIRECT(*m) || rte_mbuf_refcnt_read(*m) > 1)
                return -EINVAL;

So closing as not a bug.

-- 
You are receiving this mail because:
You are the assignee for the bug.

[-- Attachment #2: Type: text/html, Size: 3050 bytes --]

^ permalink raw reply	[flat|nested] 9+ messages in thread

* RE: [DPDK/ethdev Bug 1416] net/af_packet: tx_burst() can modify packets
  2024-04-16 15:56   ` Konstantin Ananyev
@ 2024-04-16 16:14     ` Morten Brørup
  2024-04-16 16:42       ` Konstantin Ananyev
  0 siblings, 1 reply; 9+ messages in thread
From: Morten Brørup @ 2024-04-16 16:14 UTC (permalink / raw)
  To: Konstantin Ananyev, Stephen Hemminger; +Cc: dev

> > > static uint16_t
> > > eth_af_packet_tx(void *queue, struct rte_mbuf **bufs, uint16_t
> nb_pkts)
> > > {
> > >         ...
> > >         for (i = 0; i < nb_pkts; i++) {
> > >                 mbuf = *bufs++;
> > >
> > >                 ...
> > >
> > >                 /* insert vlan info if necessary */
> > >                 if (mbuf->ol_flags & RTE_MBUF_F_TX_VLAN) {
> > >                         if (rte_vlan_insert(&mbuf)) {
> > >                                 rte_pktmbuf_free(mbuf);
> > >                                 continue;
> > >
> > > AFAIU, it does copy of mbuf contents into pbuf anyway (just few line
> below).
> > > So the fix might be - simply insert VLAN tag at copying stage.
> > > Feel free to correct me, if I missed something.
> >
> > vlan_insert will fail if the mbuf is has refcnt > 1.
> >
> > static inline int rte_vlan_insert(struct rte_mbuf **m)
> > {
> > 	struct rte_ether_hdr *oh, *nh;
> > 	struct rte_vlan_hdr *vh;
> >
> > 	/* Can't insert header if mbuf is shared */
> > 	if (!RTE_MBUF_DIRECT(*m) || rte_mbuf_refcnt_read(*m) > 1)
> > 		return -EINVAL;
> 
> You are right, I missed that.
> Will close it then.

Don't close, silent drop is also a bug.

The VLAN tag could be insert when copying, as originally suggested.

Alternatively, set tpacket2_hdr's tp_vlan_tci and tp_vlan_tpid fields and set TP_STATUS_VLAN_VALID and TP_STATUS_VLAN_TPID_VALID flags in tp_status. If the kernel reads those?


^ permalink raw reply	[flat|nested] 9+ messages in thread

* RE: [DPDK/ethdev Bug 1416] net/af_packet: tx_burst() can modify packets
  2024-04-16 16:14     ` Morten Brørup
@ 2024-04-16 16:42       ` Konstantin Ananyev
  2024-04-16 18:11         ` Morten Brørup
  0 siblings, 1 reply; 9+ messages in thread
From: Konstantin Ananyev @ 2024-04-16 16:42 UTC (permalink / raw)
  To: Morten Brørup, Stephen Hemminger; +Cc: dev



> > > > static uint16_t
> > > > eth_af_packet_tx(void *queue, struct rte_mbuf **bufs, uint16_t
> > nb_pkts)
> > > > {
> > > >         ...
> > > >         for (i = 0; i < nb_pkts; i++) {
> > > >                 mbuf = *bufs++;
> > > >
> > > >                 ...
> > > >
> > > >                 /* insert vlan info if necessary */
> > > >                 if (mbuf->ol_flags & RTE_MBUF_F_TX_VLAN) {
> > > >                         if (rte_vlan_insert(&mbuf)) {
> > > >                                 rte_pktmbuf_free(mbuf);
> > > >                                 continue;
> > > >
> > > > AFAIU, it does copy of mbuf contents into pbuf anyway (just few line
> > below).
> > > > So the fix might be - simply insert VLAN tag at copying stage.
> > > > Feel free to correct me, if I missed something.
> > >
> > > vlan_insert will fail if the mbuf is has refcnt > 1.
> > >
> > > static inline int rte_vlan_insert(struct rte_mbuf **m)
> > > {
> > > 	struct rte_ether_hdr *oh, *nh;
> > > 	struct rte_vlan_hdr *vh;
> > >
> > > 	/* Can't insert header if mbuf is shared */
> > > 	if (!RTE_MBUF_DIRECT(*m) || rte_mbuf_refcnt_read(*m) > 1)
> > > 		return -EINVAL;
> >
> > You are right, I missed that.
> > Will close it then.
> 
> Don't close, silent drop is also a bug.
> 
> The VLAN tag could be insert when copying, as originally suggested.

Agree, but to me that would be enhancement request, not a bug report.

> 
> Alternatively, set tpacket2_hdr's tp_vlan_tci and tp_vlan_tpid fields and set TP_STATUS_VLAN_VALID and
> TP_STATUS_VLAN_TPID_VALID flags in tp_status. If the kernel reads those?


^ permalink raw reply	[flat|nested] 9+ messages in thread

* RE: [DPDK/ethdev Bug 1416] net/af_packet: tx_burst() can modify packets
  2024-04-16 16:42       ` Konstantin Ananyev
@ 2024-04-16 18:11         ` Morten Brørup
  2024-04-16 20:09           ` Stephen Hemminger
  0 siblings, 1 reply; 9+ messages in thread
From: Morten Brørup @ 2024-04-16 18:11 UTC (permalink / raw)
  To: Konstantin Ananyev, Stephen Hemminger; +Cc: dev

> > > > > static uint16_t
> > > > > eth_af_packet_tx(void *queue, struct rte_mbuf **bufs, uint16_t
> > > nb_pkts)
> > > > > {
> > > > >         ...
> > > > >         for (i = 0; i < nb_pkts; i++) {
> > > > >                 mbuf = *bufs++;
> > > > >
> > > > >                 ...
> > > > >
> > > > >                 /* insert vlan info if necessary */
> > > > >                 if (mbuf->ol_flags & RTE_MBUF_F_TX_VLAN) {
> > > > >                         if (rte_vlan_insert(&mbuf)) {
> > > > >                                 rte_pktmbuf_free(mbuf);
> > > > >                                 continue;
> > > > >
> > > > > AFAIU, it does copy of mbuf contents into pbuf anyway (just few
> line
> > > below).
> > > > > So the fix might be - simply insert VLAN tag at copying stage.
> > > > > Feel free to correct me, if I missed something.
> > > >
> > > > vlan_insert will fail if the mbuf is has refcnt > 1.
> > > >
> > > > static inline int rte_vlan_insert(struct rte_mbuf **m)
> > > > {
> > > > 	struct rte_ether_hdr *oh, *nh;
> > > > 	struct rte_vlan_hdr *vh;
> > > >
> > > > 	/* Can't insert header if mbuf is shared */
> > > > 	if (!RTE_MBUF_DIRECT(*m) || rte_mbuf_refcnt_read(*m) > 1)
> > > > 		return -EINVAL;
> > >
> > > You are right, I missed that.
> > > Will close it then.
> >
> > Don't close, silent drop is also a bug.
> >
> > The VLAN tag could be insert when copying, as originally suggested.
> 
> Agree, but to me that would be enhancement request, not a bug report.

Hmm... there is still a bug, although slightly different:

net/af_packet: tx_burst() silently drops packets with RTE_MBUF_F_TX_VLAN if mbuf is shared

And the suggested fixes would fix this (other) bug.

> 
> >
> > Alternatively, set tpacket2_hdr's tp_vlan_tci and tp_vlan_tpid fields
> and set TP_STATUS_VLAN_VALID and
> > TP_STATUS_VLAN_TPID_VALID flags in tp_status. If the kernel reads
> those?


^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: [DPDK/ethdev Bug 1416] net/af_packet: tx_burst() can modify packets
  2024-04-16 18:11         ` Morten Brørup
@ 2024-04-16 20:09           ` Stephen Hemminger
  2024-04-16 22:21             ` Morten Brørup
  0 siblings, 1 reply; 9+ messages in thread
From: Stephen Hemminger @ 2024-04-16 20:09 UTC (permalink / raw)
  To: Morten Brørup; +Cc: Konstantin Ananyev, dev

On Tue, 16 Apr 2024 20:11:05 +0200
Morten Brørup <mb@smartsharesystems.com> wrote:

> > > > > > static uint16_t
> > > > > > eth_af_packet_tx(void *queue, struct rte_mbuf **bufs, uint16_t  
> > > > nb_pkts)  
> > > > > > {
> > > > > >         ...
> > > > > >         for (i = 0; i < nb_pkts; i++) {
> > > > > >                 mbuf = *bufs++;
> > > > > >
> > > > > >                 ...
> > > > > >
> > > > > >                 /* insert vlan info if necessary */
> > > > > >                 if (mbuf->ol_flags & RTE_MBUF_F_TX_VLAN) {
> > > > > >                         if (rte_vlan_insert(&mbuf)) {
> > > > > >                                 rte_pktmbuf_free(mbuf);
> > > > > >                                 continue;
> > > > > >
> > > > > > AFAIU, it does copy of mbuf contents into pbuf anyway (just few  
> > line  
> > > > below).  
> > > > > > So the fix might be - simply insert VLAN tag at copying stage.
> > > > > > Feel free to correct me, if I missed something.  
> > > > >
> > > > > vlan_insert will fail if the mbuf is has refcnt > 1.
> > > > >
> > > > > static inline int rte_vlan_insert(struct rte_mbuf **m)
> > > > > {
> > > > > 	struct rte_ether_hdr *oh, *nh;
> > > > > 	struct rte_vlan_hdr *vh;
> > > > >
> > > > > 	/* Can't insert header if mbuf is shared */
> > > > > 	if (!RTE_MBUF_DIRECT(*m) || rte_mbuf_refcnt_read(*m) > 1)
> > > > > 		return -EINVAL;  
> > > >
> > > > You are right, I missed that.
> > > > Will close it then.  
> > >
> > > Don't close, silent drop is also a bug.
> > >
> > > The VLAN tag could be insert when copying, as originally suggested.  
> > 
> > Agree, but to me that would be enhancement request, not a bug report.  
> 
> Hmm... there is still a bug, although slightly different:
> 
> net/af_packet: tx_burst() silently drops packets with RTE_MBUF_F_TX_VLAN if mbuf is shared
> 
> And the suggested fixes would fix this (other) bug.


In older DPDK, vlan_insert would try and clone the mbuf, but doing a rte_pktmbuf_clone().
But that was buggy and removed by:

commit 15a74163b12ed9b8b980b1576bdd8de16d60612b
Author: Ferruh Yigit <ferruh.yigit@intel.com>
Date:   Tue Apr 16 16:51:26 2019 +0100

    net: forbid VLAN insert in shared mbuf
    
    The vlan_insert() is buggy when it tries to handle the shared mbufs,
    instead don't support inserting VLAN tag into shared mbufs and return
    an error for that case.
    
    Signed-off-by: Ferruh Yigit <ferruh.yigit@intel.com>
    Acked-by: Olivier Matz <olivier.matz@6wind.com>




^ permalink raw reply	[flat|nested] 9+ messages in thread

* RE: [DPDK/ethdev Bug 1416] net/af_packet: tx_burst() can modify packets
  2024-04-16 20:09           ` Stephen Hemminger
@ 2024-04-16 22:21             ` Morten Brørup
  0 siblings, 0 replies; 9+ messages in thread
From: Morten Brørup @ 2024-04-16 22:21 UTC (permalink / raw)
  To: Stephen Hemminger, Konstantin Ananyev, John W. Linville; +Cc: dev

+TO: John W. Linville, AF_PACKET maintainer

> > > > > > > static uint16_t
> > > > > > > eth_af_packet_tx(void *queue, struct rte_mbuf **bufs,
> uint16_t
> > > > > nb_pkts)
> > > > > > > {
> > > > > > >         ...
> > > > > > >         for (i = 0; i < nb_pkts; i++) {
> > > > > > >                 mbuf = *bufs++;
> > > > > > >
> > > > > > >                 ...
> > > > > > >
> > > > > > >                 /* insert vlan info if necessary */
> > > > > > >                 if (mbuf->ol_flags & RTE_MBUF_F_TX_VLAN) {
> > > > > > >                         if (rte_vlan_insert(&mbuf)) {
> > > > > > >                                 rte_pktmbuf_free(mbuf);
> > > > > > >                                 continue;
> > > > > > >
> > > > > > > AFAIU, it does copy of mbuf contents into pbuf anyway (just
> few
> > > line
> > > > > below).
> > > > > > > So the fix might be - simply insert VLAN tag at copying
> stage.
> > > > > > > Feel free to correct me, if I missed something.
> > > > > >
> > > > > > vlan_insert will fail if the mbuf is has refcnt > 1.
> > > > > >
> > > > > > static inline int rte_vlan_insert(struct rte_mbuf **m)
> > > > > > {
> > > > > > 	struct rte_ether_hdr *oh, *nh;
> > > > > > 	struct rte_vlan_hdr *vh;
> > > > > >
> > > > > > 	/* Can't insert header if mbuf is shared */
> > > > > > 	if (!RTE_MBUF_DIRECT(*m) || rte_mbuf_refcnt_read(*m) > 1)
> > > > > > 		return -EINVAL;
> > > > >
> > > > > You are right, I missed that.
> > > > > Will close it then.
> > > >
> > > > Don't close, silent drop is also a bug.
> > > >
> > > > The VLAN tag could be insert when copying, as originally
> suggested.
> > >
> > > Agree, but to me that would be enhancement request, not a bug
> report.
> >
> > Hmm... there is still a bug, although slightly different:
> >
> > net/af_packet: tx_burst() silently drops packets with
> RTE_MBUF_F_TX_VLAN if mbuf is shared

I took a more thorough look at the code.
I was wrong: The drop is not silent, the err_pkts counter is incremented.
But still a bug (non-conformance) to claim VLAN Insert capability, and not fully support it.

> >
> > And the suggested fixes would fix this (other) bug.

The kernel doesn't look at TP_STATUS_VLAN_VALID in TX direction, so setting the VLAN tag in the tpacket2_hdr doesn't work; inserting it in the data when copying would be the fix.

Before the copy loop, the first segment should be copied, possibly with VLAN insertion.
And the copy loop should copy the following segments (if any), i.e. starting at *tmp_mbuf = mbuf->next.

As a separate bug, the check for oversize packets doesn't consider the length of an inserted VLAN tag, and could cause a buffer overrun if the packet is large enough.
However, with a default buffer size of 2048, this is very unlikely in reality.

> 
> 
> In older DPDK, vlan_insert would try and clone the mbuf, but doing a
> rte_pktmbuf_clone().
> But that was buggy and removed by:
> 
> commit 15a74163b12ed9b8b980b1576bdd8de16d60612b
> Author: Ferruh Yigit <ferruh.yigit@intel.com>
> Date:   Tue Apr 16 16:51:26 2019 +0100
> 
>     net: forbid VLAN insert in shared mbuf
> 
>     The vlan_insert() is buggy when it tries to handle the shared mbufs,
>     instead don't support inserting VLAN tag into shared mbufs and
> return
>     an error for that case.
> 
>     Signed-off-by: Ferruh Yigit <ferruh.yigit@intel.com>
>     Acked-by: Olivier Matz <olivier.matz@6wind.com>
> 
> 


^ permalink raw reply	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2024-04-16 22:21 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2024-04-16 10:29 [DPDK/ethdev Bug 1416] net/af_packet: tx_burst() can modify packets bugzilla
2024-04-16 15:38 ` Stephen Hemminger
2024-04-16 15:56   ` Konstantin Ananyev
2024-04-16 16:14     ` Morten Brørup
2024-04-16 16:42       ` Konstantin Ananyev
2024-04-16 18:11         ` Morten Brørup
2024-04-16 20:09           ` Stephen Hemminger
2024-04-16 22:21             ` Morten Brørup
2024-04-16 15:58 ` bugzilla

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).