android_kernel_motorola_sm6375/include/net
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Yafang Shao b08669127e net/cls_cgroup: Fix task_get_classid() during qdisc run
[ Upstream commit 66048f8b3cc7e462953c04285183cdee43a1cb89 ]

During recent testing with the netem qdisc to inject delays into TCP
traffic, we observed that our CLS BPF program failed to function correctly
due to incorrect classid retrieval from task_get_classid(). The issue
manifests in the following call stack:

        bpf_get_cgroup_classid+5
        cls_bpf_classify+507
        __tcf_classify+90
        tcf_classify+217
        __dev_queue_xmit+798
        bond_dev_queue_xmit+43
        __bond_start_xmit+211
        bond_start_xmit+70
        dev_hard_start_xmit+142
        sch_direct_xmit+161
        __qdisc_run+102             <<<<< Issue location
        __dev_xmit_skb+1015
        __dev_queue_xmit+637
        neigh_hh_output+159
        ip_finish_output2+461
        __ip_finish_output+183
        ip_finish_output+41
        ip_output+120
        ip_local_out+94
        __ip_queue_xmit+394
        ip_queue_xmit+21
        __tcp_transmit_skb+2169
        tcp_write_xmit+959
        __tcp_push_pending_frames+55
        tcp_push+264
        tcp_sendmsg_locked+661
        tcp_sendmsg+45
        inet_sendmsg+67
        sock_sendmsg+98
        sock_write_iter+147
        vfs_write+786
        ksys_write+181
        __x64_sys_write+25
        do_syscall_64+56
        entry_SYSCALL_64_after_hwframe+100

The problem occurs when multiple tasks share a single qdisc. In such cases,
__qdisc_run() may transmit skbs created by different tasks. Consequently,
task_get_classid() retrieves an incorrect classid since it references the
current task's context rather than the skb's originating task.

Given that dev_queue_xmit() always executes with bh disabled, we can use
softirq_count() instead to obtain the correct classid.

The simple steps to reproduce this issue:
1. Add network delay to the network interface:
  such as: tc qdisc add dev bond0 root netem delay 1.5ms
2. Build two distinct net_cls cgroups, each with a network-intensive task
3. Initiate parallel TCP streams from both tasks to external servers.

Under this specific condition, the issue reliably occurs. The kernel
eventually dequeues an SKB that originated from Task-A while executing in
the context of Task-B.

It is worth noting that it will change the established behavior for a
slightly different scenario:

  <sock S is created by task A>
  <class ID for task A is changed>
  <skb is created by sock S xmit and classified>

prior to this patch the skb will be classified with the 'new' task A
classid, now with the old/original one. The bpf_get_cgroup_classid_curr()
function is a more appropriate choice for this case.

Signed-off-by: Yafang Shao <laoar.shao@gmail.com>
Cc: Daniel Borkmann <daniel@iogearbox.net>
Cc: Thomas Graf <tgraf@suug.ch>
Cc: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
Cc: Nikolay Aleksandrov <razor@blackwall.org>
Link: https://patch.msgid.link/20250902062933.30087-1-laoar.shao@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-12-03 12:45:12 +01:00
..
9p
bluetooth Bluetooth: L2CAP: Fix rejecting L2CAP_CONN_PARAM_UPDATE_REQ 2024-07-05 09:08:17 +02:00
caif
iucv
netfilter netfilter: nf_tables: do not defer rule destruction via call_rcu 2025-06-04 14:32:36 +02:00
netns ipv6: make ip6_rt_gc_expire an atomic_t 2024-01-15 18:25:29 +01:00
nfc net: nfc: nci: Increase NCI_DATA_TIMEOUT to 3000 ms 2025-12-03 12:45:11 +01:00
phonet
sctp sctp: detect and prevent references to a freed transport in sendmsg 2025-05-02 07:39:16 +02:00
tc_act
6lowpan.h
act_api.h net: sched: extract qstats update code into functions 2025-08-28 16:21:36 +02:00
addrconf.h ipv6: fix race condition between ipv6_get_ifaddr and ipv6_del_addr 2024-05-02 16:18:28 +02:00
af_ieee802154.h
af_rxrpc.h
af_unix.h af_unix: Suppress false-positive lockdep splat for spin_lock() in __unix_gc(). 2024-05-02 16:18:35 +02:00
af_vsock.h
ah.h
arp.h
atmclip.h
ax25.h
ax88796.h
bond_3ad.h
bond_alb.h
bond_options.h
bonding.h bonding: fix macvlan over alb bond support 2023-08-30 16:27:24 +02:00
bpf_sk_storage.h
busy_poll.h net: busy-poll: use ktime_get_ns() instead of local_clock() 2024-09-04 13:15:03 +02:00
calipso.h
cfg80211-wext.h
cfg80211.h wifi: cfg80211: Fix interface type validation 2025-08-28 16:21:26 +02:00
cfg802154.h
checksum.h
cipso_ipv4.h
cls_cgroup.h net/cls_cgroup: Fix task_get_classid() during qdisc run 2025-12-03 12:45:12 +01:00
codel.h
codel_impl.h
codel_qdisc.h
compat.h
datalink.h
dcbevent.h
dcbnl.h
devlink.h
drop_monitor.h
dsa.h
dsfield.h
dst.h
dst_cache.h
dst_metadata.h
dst_ops.h net: fix __dst_negative_advice() race 2024-06-16 13:28:52 +02:00
erspan.h erspan: Add type I version 0 support. 2024-04-13 12:51:36 +02:00
esp.h
ethoc.h
failover.h
fib_notifier.h
fib_rules.h
firewire.h
flow.h inet: shrink struct flowi_common 2023-11-20 10:30:15 +01:00
flow_dissector.h net: extract port range fields from fl_flow_key 2025-03-13 12:43:23 +01:00
flow_offload.h net: extract port range fields from fl_flow_key 2025-03-13 12:43:23 +01:00
fou.h
fq.h
fq_impl.h
garp.h
gen_stats.h
genetlink.h genetlink: hold RCU in genlmsg_mcast() 2024-11-08 16:20:50 +01:00
geneve.h
gre.h
gro_cells.h
gtp.h
gue.h
hwbm.h
icmp.h
ieee80211_radiotap.h
ieee802154_netdev.h
if_inet6.h net: ipv6: support reporting otherwise unknown prefix flags in RTM_NEWPREFIX 2023-12-20 15:41:13 +01:00
ife.h
ila.h
inet6_connection_sock.h
inet6_hashtables.h
inet_common.h
inet_connection_sock.h tcp/dccp: allow a connection when sk_max_ack_backlog is zero 2025-02-01 18:18:45 +01:00
inet_ecn.h
inet_frag.h
inet_hashtables.h
inet_sock.h
inet_timewait_sock.h
inetpeer.h
ip.h
ip6_checksum.h
ip6_fib.h
ip6_route.h
ip6_tunnel.h
ip_fib.h
ip_tunnels.h net/ip6_tunnel: Prevent perpetual tunnel growth 2025-10-29 13:59:56 +01:00
ip_vs.h
ipcomp.h
ipconfig.h
ipv6.h tcp: Reduce chance of collisions in inet6_hashfn(). 2023-08-11 11:53:47 +02:00
ipv6_frag.h
ipv6_stubs.h
ipx.h
iw_handler.h
kcm.h kcm: Serialise kcm_sendmsg() for the same socket. 2024-09-04 13:14:59 +02:00
l3mdev.h vrf: use RCU protection in l3mdev_l3_out() 2025-03-13 12:43:12 +01:00
lag.h
lapb.h net: lapb: increase LAPB_HEADER_LEN 2024-12-19 18:05:03 +01:00
lib80211.h
llc.h
llc_c_ac.h
llc_c_ev.h
llc_c_st.h
llc_conn.h
llc_if.h
llc_pdu.h llc: Drop support for ETH_P_TR_802_2. 2024-02-23 08:24:50 +01:00
llc_s_ac.h
llc_s_ev.h
llc_s_st.h
llc_sap.h
lwtunnel.h lwt: Check LWTUNNEL_XMIT_CONTINUE strictly 2023-09-23 10:59:42 +02:00
mac80211.h mac80211: Add support to trigger sta disconnect on hardware restart 2024-11-08 16:20:52 +01:00
mac802154.h
mip6.h
mld.h
mpls.h
mpls_iptunnel.h
mrp.h
ncsi.h
ndisc.h
neighbour.h
net_failover.h
net_namespace.h net: add dev_net_rcu() helper 2025-03-13 12:43:17 +01:00
net_ratelimit.h
netevent.h
netlabel.h
netlink.h
netprio_cgroup.h
netrom.h
nexthop.h
nl802154.h
nsh.h
p8022.h
page_pool.h
ping.h
pkt_cls.h
pkt_sched.h net/sched: sch_qfq: Fix null-deref in agg_dequeue 2025-12-03 12:45:04 +01:00
pptp.h
protocol.h
psample.h
psnap.h
raw.h
rawv6.h
red.h
regulatory.h
request_sock.h
rose.h
route.h
rsi_91x.h
rtnetlink.h net: rtnetlink: add bulk delete support flag 2025-10-29 13:59:59 +01:00
rtnh.h
sch_generic.h net/sched: act_mirred: refactor the handle of xmit 2025-08-28 16:21:36 +02:00
scm.h
secure_seq.h
seg6.h
seg6_hmac.h
seg6_local.h
slhc_vj.h
smc.h
snmp.h
sock.h net: Fix null-ptr-deref by sock_lock_init_class_and_name() and rmmod. 2025-10-02 13:34:27 +02:00
sock_reuseport.h
Space.h
stp.h
strparser.h
switchdev.h
tcp.h tcp: check skb is non-NULL in tcp_rto_delta_us() 2024-11-08 16:20:33 +01:00
tcp_states.h
timewait_sock.h
tipc.h
tls.h
transp_v6.h
tso.h
tun_proto.h
udp.h net: drop UFO packets in udp_rcv_segment() 2025-08-28 16:21:22 +02:00
udp_tunnel.h
udplite.h
vsock_addr.h
vxlan.h vxlan: calculate correct header length for GPE 2023-08-11 11:53:47 +02:00
wext.h
wimax.h
x25.h
x25device.h
xdp.h
xdp_priv.h
xdp_sock.h
xfrm.h xfrm: Preserve vlan tags for transport mode software GRO 2024-05-17 11:43:53 +02:00