Uh oh!
There was an error while loading. Please reload this page.
[ciq-6.18.y] Multiple patches tested (6 commits) - #1545
[ciq-6.18.y] Multiple patches tested (6 commits)#1545ciq-kernel-automation[bot] wants to merge 6 commits into
Conversation
bmastbergen
commented
Aug 21, 2026
Test results: |
PlaidCat
commented
Aug 24, 2026
Still need to review this BUT its been merged upstream as well. |
eb2f26d to
3985545Comparebmastbergen
commented
Aug 24, 2026
Commit headers updated with upstream shas. Thanks! |
PlaidCat
commented
Aug 24, 2026
I guess in Commit 2 and Commit 5 we're also missing the |
commit-author Nick Hudson <nhudson@akamai.com> commit 5e4bcad The existing anonymous enum for BPF_FUNC_skb_adjust_room flags is named to enum bpf_adj_room_flags to enable CO-RE (Compile Once - Run Everywhere) lookups in BPF programs. Co-developed-by: Max Tottenham <mtottenh@akamai.com> Co-developed-by: Anna Glasgall <aglasgal@akamai.com> Signed-off-by: Max Tottenham <mtottenh@akamai.com> Signed-off-by: Anna Glasgall <aglasgal@akamai.com> Signed-off-by: Nick Hudson <nhudson@akamai.com> Signed-off-by: Daniel Borkmann <daniel@iogearbox.net> Reviewed-by: Willem de Bruijn <willemb@google.com> Link: https://lore.kernel.org/bpf/20260812083115.73100-2-nhudson@akamai.com (cherry picked from commit 5e4bcad) Signed-off-by: Brett Mastbergen <bmastbergen@ciq.com>
commit-author Nick Hudson <nhudson@akamai.com> commit 7b2ea11 upstream-diff | applied with line offset fuzz due to absence of bool decap variable (present in bpf-next, not in this tree). Code changes are identical to upstream. Refactor the helper masks for bpf_skb_adjust_room() flags to simplify validation logic and introduce: - BPF_F_ADJ_ROOM_ENCAP_MASK - BPF_F_ADJ_ROOM_DECAP_MASK Refactor existing validation checks in bpf_skb_net_shrink() and bpf_skb_adjust_room() to use the new masks (no behavior change). This is in preparation for supporting the new decap flags. Co-developed-by: Max Tottenham <mtottenh@akamai.com> Co-developed-by: Anna Glasgall <aglasgal@akamai.com> Signed-off-by: Max Tottenham <mtottenh@akamai.com> Signed-off-by: Anna Glasgall <aglasgal@akamai.com> Signed-off-by: Nick Hudson <nhudson@akamai.com> Signed-off-by: Daniel Borkmann <daniel@iogearbox.net> Reviewed-by: Willem de Bruijn <willemb@google.com> Link: https://lore.kernel.org/bpf/20260812083115.73100-3-nhudson@akamai.com (cherry picked from commit 7b2ea11) Signed-off-by: Brett Mastbergen <bmastbergen@ciq.com>
commit-author Nick Hudson <nhudson@akamai.com> commit da19907 Add new bpf_skb_adjust_room() decapsulation flags: - BPF_F_ADJ_ROOM_DECAP_L4_GRE - BPF_F_ADJ_ROOM_DECAP_L4_UDP - BPF_F_ADJ_ROOM_DECAP_IPXIP4 - BPF_F_ADJ_ROOM_DECAP_IPXIP6 These flags let BPF programs describe which tunnel layer is being removed, so later changes can update tunnel-related GSO state accordingly during decapsulation. This patch only introduces the UAPI flag definitions and helper documentation. Co-developed-by: Max Tottenham <mtottenh@akamai.com> Co-developed-by: Anna Glasgall <aglasgal@akamai.com> Signed-off-by: Max Tottenham <mtottenh@akamai.com> Signed-off-by: Anna Glasgall <aglasgal@akamai.com> Signed-off-by: Nick Hudson <nhudson@akamai.com> Signed-off-by: Daniel Borkmann <daniel@iogearbox.net> Reviewed-by: Willem de Bruijn <willemb@google.com> Link: https://lore.kernel.org/bpf/20260812083115.73100-4-nhudson@akamai.com (cherry picked from commit da19907) Signed-off-by: Brett Mastbergen <bmastbergen@ciq.com>
commit-author Nick Hudson <nhudson@akamai.com> commit 3a39c21 Add checks to require shrink-only decap, reject conflicting decap flag combinations, and verify removed length is sufficient for claimed header decapsulation. Co-developed-by: Max Tottenham <mtottenh@akamai.com> Co-developed-by: Anna Glasgall <aglasgal@akamai.com> Signed-off-by: Max Tottenham <mtottenh@akamai.com> Signed-off-by: Anna Glasgall <aglasgal@akamai.com> Signed-off-by: Nick Hudson <nhudson@akamai.com> Signed-off-by: Daniel Borkmann <daniel@iogearbox.net> Reviewed-by: Willem de Bruijn <willemb@google.com> Link: https://lore.kernel.org/bpf/20260812083115.73100-5-nhudson@akamai.com (cherry picked from commit 3a39c21) Signed-off-by: Brett Mastbergen <bmastbergen@ciq.com>
commit-author Nick Hudson <nhudson@akamai.com> commit ec20dee On shrink in bpf_skb_adjust_room(), apply decapsulation state updates according to BPF_F_ADJ_ROOM_DECAP_* flags. For GSO skbs, clear only the tunnel gso_type bits that correspond to the requested decap layer: - DECAP_L4_UDP: SKB_GSO_UDP_TUNNEL{,_CSUM} - DECAP_L4_GRE: SKB_GSO_GRE{,_CSUM} - DECAP_IPXIP4: SKB_GSO_IPXIP4 - DECAP_IPXIP6: SKB_GSO_IPXIP6 Then clear skb->encapsulation only if no tunnel GSO bits remain, keeping encapsulation set for cases such as ESP-in-UDP where tunnel state remains. For non-GSO skbs, there are no tunnel GSO bits to consult, so clear skb->encapsulation directly when DECAP_L4_* or DECAP_IPXIP_* flags are set. This keeps decap state handling consistent between GSO and non-GSO packets. Co-developed-by: Max Tottenham <mtottenh@akamai.com> Co-developed-by: Anna Glasgall <aglasgal@akamai.com> Signed-off-by: Max Tottenham <mtottenh@akamai.com> Signed-off-by: Anna Glasgall <aglasgal@akamai.com> Signed-off-by: Nick Hudson <nhudson@akamai.com> Signed-off-by: Daniel Borkmann <daniel@iogearbox.net> Reviewed-by: Willem de Bruijn <willemb@google.com> Link: https://lore.kernel.org/bpf/20260812083115.73100-6-nhudson@akamai.com (cherry picked from commit ec20dee) Signed-off-by: Brett Mastbergen <bmastbergen@ciq.com>
commit-author Nick Hudson <nhudson@akamai.com> commit adb7719 upstream-diff | The upstream patch targets bpf-next where the BPF program has been converted to use vmlinux.h (commit 86433db) and the test runner has been migrated from a shell script to a C-based test_progs harness (commit 8517b1a). This tree has neither of those prerequisites, so the following upstream changes were dropped: - Post-decap GSO gso_type and skb->encapsulation validation via bpf_cast_to_kern_ctx/bpf_core_cast into skb_shared_info. These require vmlinux.h to access kernel-internal structs (sk_buff, skb_shared_info) and SKB_GSO_* constants. - TSO disable removal from prog_tests/test_tc_tunnel.c (file absent; this tree still uses test_tc_tunnel.sh). The CO-RE enum existence checks, functional flag-passing changes (DECAP_L4_GRE, DECAP_L4_UDP, DECAP_IPXIP4, DECAP_IPXIP6), and ipxip_flag parameter plumbing through decap_internal/decap_ipv4/ decap_ipv6 are applied as in upstream. The test exercises the new kernel flag acceptance path and will fail to load on kernels lacking the new enum values, but does not validate post-decap skb state. tc_tunnel only partially validated decap state and missed some tunnel cases. In particular, IPXIP decap checks were not exercised for IPIP/SIT paths, and non-GSO decap encapsulation state was not verified. Tighten the test by: - setting DECAP_IPXIP4/6 flags for IPIP/SIT/IP6 decap paths based on the outer tunnel header family; - requiring needed DECAP enum values via CO-RE enum existence checks so missing kernel support fails fast; - validating post-decap tunnel state for both GSO and non-GSO packets: expected gso_type bits must be cleared and skb->encapsulation must match remaining tunnel flags; - removing forced TSO disable in the test harness so GSO validation is exercised. This improves coverage for decap tunnel-state regressions and ensures sit_none/ipip-style paths are checked correctly. Signed-off-by: Nick Hudson <nhudson@akamai.com> Signed-off-by: Daniel Borkmann <daniel@iogearbox.net> Link: https://lore.kernel.org/bpf/20260812083115.73100-7-nhudson@akamai.com (cherry picked from commit adb7719) Signed-off-by: Brett Mastbergen <bmastbergen@ciq.com>
3985545 to
86dc0d0Comparebmastbergen
commented
Aug 24, 2026
Ah yea, I just updated the commit line, but didn't think about the fact that the upstream commits might be different in other ways. Updated all commits to be in sync with the upstream commits, plus our headers and trailers. |
kerneltoast
left a comment
There was a problem hiding this comment.
I iterated with Claude (Feeble 5) reviewing this. Nothing that's a blocker in this PR. Here's the feedback written by Claude:
The upstream-diff note on 192a27a ("bpf: Refactor masks for ADJ_ROOM flags and encap validation") attributes the missing bool decap context line to bpf-next, but that line actually comes from 699f47e ("net: Clear the dst when performing encap / decap"), which has been in mainline since v7.1. Preferably backport 699f47e as a prerequisite, since it's a small filter.c-only patch and with it the patched functions come out byte-identical to upstream; otherwise correct the note.
The four bpf_core_enum_value_exists() checks kept in test_tc_tunnel.c here were dropped on #1546, whose note cites iproute2's legacy tc loader. Both ciq-6.18.y and ciqlts9_6 carry byte-identical copies of test_tc_tunnel.sh and load the program the same way, so whichever rationale is right applies to both PRs; see the comment on #1546 for the suggested resolution.
The kprobe checker results above cover the DECAP_IPXIP4 paths (ipip and sit), but every GRE row is a SKIP and there are no UDP or IPXIP6 rows, so the new L4 decap handling never got exercised: the guard-rail length math for GRE/UDP headers and the SKB_GSO_GRE*/SKB_GSO_UDP_TUNNEL* clearing in the shrink path. Worth closing that gap before this ships, even if it takes extending the test-decap-gso-618.sh harness you attached.
Summary
This PR has been automatically created after successful completion of all CI stages.
Commit Message(s)
Test Results
✅ Build Stage
✅ Boot Verification
✅ Kernel Selftests
✅ LTP Results
🤖 This PR was automatically generated by GitHub Actions
Run ID: 32773041301