Skip to content

[RLC-10] Rebase Custom Changes to rlc-10/6.12.0-211.37.1.el10_2#1472

Merged
PlaidCat merged 16 commits into
rlc-10/6.12.0-211.37.1.el10_2from
jmaple_rlc-10/6.12.0-211.37.1.el10_2
Jul 25, 2026
Merged

[RLC-10] Rebase Custom Changes to rlc-10/6.12.0-211.37.1.el10_2#1472
PlaidCat merged 16 commits into
rlc-10/6.12.0-211.37.1.el10_2from
jmaple_rlc-10/6.12.0-211.37.1.el10_2

Conversation

@PlaidCat

Copy link
Copy Markdown
Collaborator

https://ciqinc.atlassian.net/browse/KERNEL-1356

Update process (This kernel CentOS base for 6.12.0-211.37.1.el10_2)

  • Rolling Release Rebase Process
  • Create rlc-10/6.12.0-211.37.1.el10_2 branch from rocky10_2
  • Cherry-pick all code from previous branch rlc-10/6.12.0-211.34.1.el10_2 into new branch (skipping unneeded code)
    • Fix conflicts as they arise
  • Build and Test

Rebase Log

Already on 'rlc-10/6.12.0-211.34.1.el10_2'
Already on 'jmaple_rlc-10/6.12.0-211.37.1.el10_2'
[rolling release update] Rolling Product:  rlc-10
[rolling release update] Checking out branch:  rlc-10/6.12.0-211.34.1.el10_2
[rolling release update] Gathering all the RESF kernel Tags
[rolling release update] Found 13 RESF kernel tags
[rolling release update] Checking out branch:  rocky10_2
[rolling release update] Gathering all the RESF kernel Tags
[rolling release update] Found 14 RESF kernel tags
[rolling release update] Common tag sha:  b'10587f08856b'
"10587f08856b97f0368f781c4cb2814c87c599bc Rebuild rocky10_2 with kernel-6.12.0-211.34.1.el10_2"
[rolling release update] Checking for FIPS protected changes between the common tag and HEAD
[rolling release update] Checking for FIPS protected changes
[rolling release update] Getting SHAS 10587f08856b..HEAD
[rolling release update] Number of commits to check:  62
[rolling release update] Checking modifications of shas
[rolling release update] Checked 6 of 62 commits
[rolling release update] Checked 12 of 62 commits
[rolling release update] Checked 18 of 62 commits
[rolling release update] Checked 24 of 62 commits
[rolling release update] Checked 30 of 62 commits
[rolling release update] Checked 36 of 62 commits
[rolling release update] Checked 42 of 62 commits
[rolling release update] Checked commit b'f7492a19848c07b331814e6e2fa8292d91d7ff9f' touched 1 FIPS protected files
  - b'crypto/'
[rolling release update] Checked 48 of 62 commits
[rolling release update] Checked 54 of 62 commits
[rolling release update] Checked 60 of 62 commits
[rolling release update] 1 of 62 commits have FIPS protected changes
[rolling release update] Checking out old rolling branch:  rlc-10/6.12.0-211.34.1.el10_2
[rolling release update] Finding the CIQ Kernel and Associated Upstream commits between the last resf tag and HEAD
[rolling release update] Getting SHAS 10587f08856b..HEAD
[rolling release update] Last RESF tag sha:  b'10587f08856b'
[rolling release update] Total commits in old branch: 21
[rolling release update] Checking out new base branch:  rocky10_2
[rolling release update] Finding the kernel version for the new rolling release
[rolling release update] New Branch to create: rlc-10/6.12.0-211.37.1.el10_2
[rolling release update] Creating new branch: rlc-10/6.12.0-211.37.1.el10_2
[rolling release update] Creating new branch for PR:  jmaple_rlc-10/6.12.0-211.37.1.el10_2
[rolling release update] Creating Map of all new commits from last rolling release fork
[rolling release update] Total commits in new branch: 61
[rolling release update] Checking if any of the commits from the old rolling release are already present in the new base branch
- Old commit b0f188e8f48a backported upstream 1a4f03d22fb6
  Already in new base as a2dec2b15b8f: drm/gem: Try to fix change_handle ioctl, attempt 4
- Old commit 94f5b8af6989 backported upstream 7164d78559b0
  Already in new base as ee6fb1bdc9d1: drm/gem: fix race between change_handle and handle_delete
- Old commit a256bdf71102 backported upstream dc366607c41c
  Already in new base as 963b5d3fd805: drm: Replace old pointer to new idr
- Old commit 0b932ac681cc backported upstream 5e28b7b94408
  Already in new base as b369c0190270: drm: Set old handle to NULL before prime swap in change_handle
- Old commit 07928f1fcd76 backported upstream 12f15d52d38a
  Already in new base as f7fd828967e9: drm: Do not allow userspace to trigger kernel warnings in drm_gem_change_handle_ioctl()
[rolling release update] Found 5 duplicate commits to remove
[rolling release update] Removing duplicate commits:
  - b0f188e8f48ab511e99741efc2c90f1b614c45a8 drm/gem: Try to fix change_handle ioctl, attempt 4
  - 94f5b8af6989aec1acbfb2a9527dbfecb4aed37d drm/gem: fix race between change_handle and handle_delete
  - a256bdf71102b71ae801f8a20f416e7cf5c21f18 drm: Replace old pointer to new idr
  - 0b932ac681cceb8881a58ebd7de1ffeb15c041a9 drm: Set old handle to NULL before prime swap in change_handle
  - 07928f1fcd7634381998d77e9305e1ff891395cf drm: Do not allow userspace to trigger kernel warnings in drm_gem_change_handle_ioctl()
[rolling release update] Applying 16 remaining commits to the new branch
  [1/16] 74b72ea32783 github actions: Add kernelCI for rlc-10
  [2/16] dffc6b49f121 github actions: Use trigger for kernelCI
  [3/16] 829600d53b10 github actions: Pin Checkout action to v6.0.2
  [4/16] d9b7a06c8b1a github actions: set make to `nproc` rather than hardcoded
  [5/16] 8c1c5b44b3dc tools: hv: Enable debug logs for hv_kvp_daemon
  [6/16] 0c059486cc05 dcache: export shrink_dentry_list() and add new helper d_dispose_if_unused()
  [7/16] 49f5e2fd63cc fuse: don't truncate cached, mutated symlink
  [8/16] ea33b88133b4 fuse: add more control over cache invalidation behaviour
  [9/16] 3aab8b6f1eb7 fuse: fix possibly missing fuse_copy_finish() call in fuse_notify()
  [10/16] 9a7782e5e6af fs: fuse: add dev id to /dev/fuse fdinfo
  [11/16] 1565cde106be fuse: respect FOPEN_KEEP_CACHE on opendir
  [12/16] f2c427c06d8c rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
  [13/16] f1337f40e048 net: gro: don't merge zcopy skbs
  [14/16] 91cbee727047 KVM: arm64: Reassign nested_mmus array behind mmu_lock
  [15/16] b3573964aa4c KVM: arm64: Take the SRCU lock for page table walks in fault injection and AT emulation
  [16/16] 2548660c9174 net: openvswitch: reject oversized nested action attrs
[rolling release update] Successfully applied all 16 commits

BUILD

$ egrep -B 5 -A 5 "\[TIMER\]|^Starting Build" $(ls -t kbuild* | head -n1)
/mnt/code/kernel-src-tree-build
Running make mrproper...
  CLEAN   scripts/basic
  CLEAN   scripts/kconfig
  CLEAN   include/config include/generated
[TIMER]{MRPROPER}: 6s
x86_64 architecture detected, copying config
'configs/kernel-x86_64-rhel.config' -> '.config'
Setting Local Version for build
CONFIG_LOCALVERSION="-rocky10_2_rebuild-784c133082f3"
Making olddefconfig
--
  HOSTCC  scripts/kconfig/util.o
  HOSTLD  scripts/kconfig/conf
#
# configuration written to .config
#
Starting Build
  GEN     arch/x86/include/generated/asm/orc_hash.h
  WRAP    arch/x86/include/generated/uapi/asm/bpf_perf_event.h
  WRAP    arch/x86/include/generated/uapi/asm/errno.h
  WRAP    arch/x86/include/generated/uapi/asm/fcntl.h
  WRAP    arch/x86/include/generated/uapi/asm/ioctl.h
--
  LD [M]  net/qrtr/qrtr-mhi.ko
  BTF [M] net/qrtr/qrtr.ko
  BTF [M] net/qrtr/qrtr-mhi.ko
  LD [M]  virt/lib/irqbypass.ko
  BTF [M] virt/lib/irqbypass.ko
[TIMER]{BUILD}: 2255s
Making Modules
  SYMLINK /lib/modules/6.12.0-rocky10_2_rebuild-784c133082f3+/build
  INSTALL /lib/modules/6.12.0-rocky10_2_rebuild-784c133082f3+/modules.order
  INSTALL /lib/modules/6.12.0-rocky10_2_rebuild-784c133082f3+/modules.builtin
  INSTALL /lib/modules/6.12.0-rocky10_2_rebuild-784c133082f3+/modules.builtin.modinfo
--
  SIGN    /lib/modules/6.12.0-rocky10_2_rebuild-784c133082f3+/kernel/net/qrtr/qrtr-mhi.ko
  INSTALL /lib/modules/6.12.0-rocky10_2_rebuild-784c133082f3+/kernel/virt/lib/irqbypass.ko
  STRIP   /lib/modules/6.12.0-rocky10_2_rebuild-784c133082f3+/kernel/virt/lib/irqbypass.ko
  SIGN    /lib/modules/6.12.0-rocky10_2_rebuild-784c133082f3+/kernel/virt/lib/irqbypass.ko
  DEPMOD  /lib/modules/6.12.0-rocky10_2_rebuild-784c133082f3+
[TIMER]{MODULES}: 16s
Making Install
  INSTALL /boot
[TIMER]{INSTALL}: 18s
Checking kABI
kABI check passed
Setting Default Kernel to /boot/vmlinuz-6.12.0-rocky10_2_rebuild-784c133082f3+ and Index to 2
Hopefully Grub2.0 took everything ... rebooting after time metrices
[TIMER]{MRPROPER}: 6s
[TIMER]{BUILD}: 2255s
[TIMER]{MODULES}: 16s
[TIMER]{INSTALL}: 18s
[TIMER]{TOTAL} 2300s
Rebooting in 10 seconds

KSelfTest

$ ./kernel-tools/kernel_auto_rebuild/get_kselftest_diff.sh
selftest-6.12.0-jmaple_rlc-10_6.12.0-211.30.1.el10_2-ddb3d41be8db+-1.log: 491 passed
selftest-6.12.0-jmaple_rlc-10_6.12.0-211.32.1.el10_2-ef4138557427+-1.log: 491 passed
selftest-6.12.0-jmaple_rlc-10_6.12.0-211.34.1.el10_2-798c4b2f087b+-1.log: 490 passed
selftest-6.12.0-jmaple_rlc-10_6.12.0-211.37.1.el10_2-7a8f6e146430+-1.log: 490 passed

Before: selftest-6.12.0-jmaple_rlc-10_6.12.0-211.34.1.el10_2-798c4b2f087b+-1.log
After: selftest-6.12.0-jmaple_rlc-10_6.12.0-211.37.1.el10_2-7a8f6e146430+-1.log
Diff:
No differences found.

roxanan1996 and others added 16 commits July 24, 2026 16:42
Signed-off-by: Roxana Nicolescu <rnicolescu@ciq.com>
Signed-off-by: Roxana Nicolescu <rnicolescu@ciq.com>
jira LE-3207
feature tools_hv
commit-author Shradha Gupta <shradhagupta@linux.microsoft.com>
commit a9c0b33

Allow the KVP daemon to log the KVP updates triggered in the VM
with a new debug flag(-d).
When the daemon is started with this flag, it logs updates and debug
information in syslog with loglevel LOG_DEBUG. This information comes
in handy for debugging issues where the key-value pairs for certain
pools show mismatch/incorrect values.
The distro-vendors can further consume these changes and modify the
respective service files to redirect the logs to specific files as
needed.

	Signed-off-by: Shradha Gupta <shradhagupta@linux.microsoft.com>
	Reviewed-by: Naman Jain <namjain@linux.microsoft.com>
	Reviewed-by: Dexuan Cui <decui@microsoft.com>
Link: https://lore.kernel.org/r/1744715978-8185-1-git-send-email-shradhagupta@linux.microsoft.com
	Signed-off-by: Wei Liu <wei.liu@kernel.org>
Message-ID: <1744715978-8185-1-git-send-email-shradhagupta@linux.microsoft.com>
(cherry picked from commit a9c0b33)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
…nused()

jira SECO-468
commit-author Luis Henriques <luis@igalia.com>
commit 395b955

Add and export a new helper d_dispose_if_unused() which is simply a wrapper
around to_shrink_list(), to add an entry to a dispose list if it's not used
anymore.

Also export shrink_dentry_list() to kill all dentries in a dispose list.

	Suggested-by: Miklos Szeredi <miklos@szeredi.hu>
	Signed-off-by: Luis Henriques <luis@igalia.com>
	Signed-off-by: Miklos Szeredi <mszeredi@redhat.com>
(cherry picked from commit 395b955)
	Signed-off-by: Roxana Nicolescu <rnicolescu@ciq.com>
jira SECO-478
RFBugFix: FUSE
commit-author Miklos Szeredi <mszeredi@redhat.com>
commit b4c173d

Fuse allows the value of a symlink to change and this property is exploited
by some filesystems (e.g. CVMFS).

It has been observed, that sometimes after changing the symlink contents,
the value is truncated to the old size.

This is caused by fuse_getattr() racing with fuse_reverse_inval_inode().
fuse_reverse_inval_inode() updates the fuse_inode's attr_version, which
results in fuse_change_attributes() exiting before updating the cached
attributes

This is okay, as the cached attributes remain invalid and the next call to
fuse_change_attributes() will likely update the inode with the correct
values.

The reason this causes problems is that cached symlinks will be
returned through page_get_link(), which truncates the symlink to
inode->i_size.  This is correct for filesystems that don't mutate
symlinks, but in this case it causes bad behavior.

The solution is to just remove this truncation.  This can cause a
regression in a filesystem that relies on supplying a symlink larger than
the file size, but this is unlikely.  If that happens we'd need to make
this behavior conditional.

	Reported-by: Laura Promberger <laura.promberger@cern.ch>
	Tested-by: Sam Lewis <samclewis@google.com>
	Signed-off-by: Miklos Szeredi <mszeredi@redhat.com>
Link: https://lore.kernel.org/r/20250220100258.793363-1-mszeredi@redhat.com
	Reviewed-by: Bernd Schubert <bschubert@ddn.com>
	Signed-off-by: Christian Brauner <brauner@kernel.org>
(cherry picked from commit b4c173d)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira SECO-478
RFBugFix: FUSE
commit-author Luis Henriques <luis@igalia.com>
commit 2396356
upstream-diff | conflict in fs/fuse/dir.c due to missing this piece:
       d701902 - fuse: return correct dentry for ->mkdir
       Which is a part of a larger changeset here that we're not going to
       take: https://lore.kernel.org/all/20250227013949.536172-1-neilb@suse.de/
       | Additionally this bumps the Kernel FUSE API minor version from 41
       to 44.  The interface into via fuse3 currently in Rocky 10.1 is
       limited to API 38 anyways at 3.16.2.
       | There is a build conflict due to a major rewrite of the d_revalidate
       calls which now includes the parent directory being passed.
       5be1fa8 Pass parent directory inode and expected name to ->d_revalidate()
       In this case we can use the dentry->i_sb because we only need the
       superblock for get_fuse_conn_super().

Currently userspace is able to notify the kernel to invalidate the cache
for an inode.  This means that, if all the inodes in a filesystem need to
be invalidated, then userspace needs to iterate through all of them and do
this kernel notification separately.

This patch adds the concept of 'epoch': each fuse connection will have the
current epoch initialized and every new dentry will have it's d_time set to
the current epoch value.  A new operation will then allow userspace to
increment the epoch value.  Every time a dentry is d_revalidate()'ed, it's
epoch is compared with the current connection epoch and invalidated if it's
value is different.

	Signed-off-by: Luis Henriques <luis@igalia.com>
	Tested-by: Laura Promberger <laura.promberger@cern.ch>
	Signed-off-by: Miklos Szeredi <mszeredi@redhat.com>
(cherry picked from commit 2396356)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>

build fix: fuse: add more control over cache invalidation behaviour
jira SECO-478
BUGFIX: FUSE
commit-author Miklos Szeredi <mszeredi@redhat.com>
commit 0b563aa

In case of FUSE_NOTIFY_RESEND and FUSE_NOTIFY_INC_EPOCH fuse_copy_finish()
isn't called.

Fix by always calling fuse_copy_finish() after fuse_notify().  It's a no-op
if called a second time.

Fixes: 760eac7 ("fuse: Introduce a new notification type for resend pending requests")
Fixes: 2396356 ("fuse: add more control over cache invalidation behaviour")
	Cc: <stable@vger.kernel.org> # v6.9
	Reviewed-by: Joanne Koong <joannelkoong@gmail.com>
	Signed-off-by: Miklos Szeredi <mszeredi@redhat.com>
(cherry picked from commit 0b563aa)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira SECO-511
commit-author Chen Linxuan <chenlinxuan@uniontech.com>
commit f092229
upstream-diff | There were conflicts seen while applying
this patch due to the following missing commit :-
786412a ("fuse: enable fuse-over-io-uring")

This commit add fuse connection device id to
fdinfo of opened /dev/fuse files.

Related discussions can be found at links below.

Link: https://lore.kernel.org/all/CAJfpegvEYUgEbpATpQx8NqVR33Mv-VK96C+gbTag1CEUeBqvnA@mail.gmail.com/
	Signed-off-by: Chen Linxuan <chenlinxuan@uniontech.com>
	Signed-off-by: Miklos Szeredi <mszeredi@redhat.com>
(cherry picked from commit f092229)
	Signed-off-by: Shreeya Patel <spatel@ciq.com>
jira SECO-518
commit-author Amir Goldstein <amir73il@gmail.com>
commit 03f275a

The re-factoring of fuse_dir_open() missed the need to invalidate
directory inode page cache with open flag FOPEN_KEEP_CACHE.

Fixes: 7de64d5 ("fuse: break up fuse_open_common()")
	Reported-by: Prince Kumar <princer@google.com>
Closes: https://lore.kernel.org/linux-fsdevel/CAEW=TRr7CYb4LtsvQPLj-zx5Y+EYBmGfM24SuzwyDoGVNoKm7w@mail.gmail.com/
	Signed-off-by: Amir Goldstein <amir73il@gmail.com>
Link: https://lore.kernel.org/r/20250101130037.96680-1-amir73il@gmail.com
	Reviewed-by: Bernd Schubert <bernd.schubert@fastmail.fm>
	Signed-off-by: Christian Brauner <brauner@kernel.org>
(cherry picked from commit 03f275a)
	Signed-off-by: Shreeya Patel <spatel@ciq.com>
cve CVE-2026-43500
commit-author Hyunwoo Kim <imv4bel@gmail.com>
commit -
commit-source https://lore.kernel.org/all/af2kdW2F1gJ9U-Gg@v4bel
upstream-diff |
        The conn_event.c hunk is dropped entirely. Upstream wraps the
        conn->security->verify_response() call inside a new
        rxrpc_verify_response() function that copies non-linear skbs before
        in-place decryption. This kernel doesn't have that wrapper; the
        security op is called directly from rxrpc_process_event(), so there
        is no call site to patch. Additionally, the rxkad_verify_response()
        implementation in this tree already pulls the response and ticket
        out via skb_copy_bits() into kmalloc'd local buffers and decrypts
        those buffers (not the skb backing pages), so the RESPONSE-packet
        vector that v3 closes upstream is not reachable here. The
        call_event.c hunk applies as-is.

The DATA-packet handler in rxrpc_input_call_event() and the RESPONSE
handler in rxrpc_verify_response() copy the skb to a linear one before
calling into the security ops only when skb_cloned() is true.  An skb
that is not cloned but still carries externally-owned paged fragments
(e.g. SKBFL_SHARED_FRAG set by splice() into a UDP socket via
__ip_append_data, or a chained skb_has_frag_list()) falls through to
the in-place decryption path, which binds the frag pages directly into
the AEAD/skcipher SGL via skb_to_sgvec().

Extend the gate to also unshare when skb_has_frag_list() or
skb_has_shared_frag() is true.  This catches the splice-loopback vector
and other externally-shared frag sources while preserving the
zero-copy fast path for skbs whose frags are kernel-private (e.g. NIC
page_pool RX, GRO).  The OOM/trace handling already in place is reused.

Fixes: d0d5c0c ("rxrpc: Use skb_unshare() rather than skb_cow_data()")
	Cc: stable@vger.kernel.org
	Signed-off-by: Hyunwoo Kim <imv4bel@gmail.com>
(cherry picked from commit 544687651fe57721c5e4e76380ed8ef8fdfdc98b)
	Signed-off-by: Shreeya Patel <spatel@ciq.com>
cve CVE-Pending
commit-author Sabrina Dubroca <sd@queasysnail.net>
commit 4db79a3

skb_gro_receive() can currently copy frags between the source and GRO
skb, without checking the zerocopy status, and in particular the
SKBFL_MANAGED_FRAG_REFS flag.

When SKBFL_MANAGED_FRAG_REFS is set, the skb doesn't hold a reference
on the pages in shinfo->frags. Appending those frags to another skb's
frags without fixing up the page refcount can lead to UAF.

When either the last skb in the GRO chain (the one we would append
frags to) or the source skb is zerocopy, don't merge the skbs.

Fixes: 753f1ca ("net: introduce managed frags infrastructure")
Reported-by: Huzaifa Sidhpurwala <huzaifas@redhat.com>
Signed-off-by: Sabrina Dubroca <sd@queasysnail.net>
Reviewed-by: Willem de Bruijn <willemb@google.com>
Link: https://patch.msgid.link/c3b7f906bbfcbdfd7b4fa9d6c18a438870df85be.1779307748.git.sd@queasysnail.net
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Shreeya Patel <spatel@ciq.com>
cve CVE-2026-46317
commit-author Hyunwoo Kim <imv4bel@gmail.com>
commit 7054335

kvm->arch.nested_mmus[] is walked under kvm->mmu_lock, including from the
MMU notifier path (kvm_unmap_gfn_range() -> kvm_nested_s2_unmap()), which
can run at any time. kvm_vcpu_init_nested() reallocates the array and frees
the old buffer while holding only kvm->arch.config_lock, so such a walker
can reference the freed array.

Allocate the new array outside of mmu_lock, as the allocation can sleep.
Under the lock, copy the existing entries, fix up the back pointers and
reassign the array. Free the old buffer after dropping the lock, as
kvfree() can sleep as well.

Fixes: 4f128f8 ("KVM: arm64: nv: Support multiple nested Stage-2 mmu structures")
	Signed-off-by: Hyunwoo Kim <imv4bel@gmail.com>
	Reviewed-by: Oliver Upton <oupton@kernel.org>
Link: https://patch.msgid.link/aiKIVVeIr1aAB1yp@v4bel
	Signed-off-by: Marc Zyngier <maz@kernel.org>
	Cc: stable@vger,kernel.org
(cherry picked from commit 7054335)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
…n and AT emulation

bugfix aarch64 kvm
commit-author Hyunwoo Kim <imv4bel@gmail.com>
commit f2ca45b

walk_s1() and kvm_walk_nested_s2() expect to be called while holding
kvm->srcu to guard against memslot changes. While this is generally
the case, __kvm_at_s12() and __kvm_find_s1_desc_level() call into the
respective walkers without taking kvm->srcu.

Fix by acquiring kvm->srcu prior to the table walk in both instances.

	Cc: stable@vger.kernel.org
Fixes: 50f77dc ("KVM: arm64: Populate level on S1PTW SEA injection")
Fixes: be04ceb ("KVM: arm64: nv: Add emulation of AT S12E{0,1}{R,W}")
	Suggested-by: Oliver Upton <oupton@kernel.org>
	Signed-off-by: Hyunwoo Kim <imv4bel@gmail.com>
	Reviewed-by: Oliver Upton <oupton@kernel.org>
Link: https://patch.msgid.link/aiAZfdeyanIvP8SD@v4bel
	Signed-off-by: Marc Zyngier <maz@kernel.org>
(cherry picked from commit f2ca45b)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
commit-author Asim Viladi Oglu Manizada <manizada@pm.me>
commit 3f1f755

Open vSwitch stores generated flow actions as nlattrs, whose nla_len
field is u16. Commit a1e64ad ("net: openvswitch: remove
misbehaving actions length check") allowed the total sw_flow_actions
stream to grow beyond 64 KiB, which is valid, but also removed the last
guard preventing a generated nested action attribute from exceeding
U16_MAX.

An oversized generated container can thus be closed with a truncated
nla_len. A later dump or teardown then walks a structurally different
stream than the one that was validated. In particular, an oversized
nested CLONE/CT action may cause subsequent bytes in the generated
stream to be interpreted as independent actions.

Keep the larger total-action-stream behavior, but make nested action
close reject generated containers that do not fit in nla_len, and return
the error through all callers. For recursive SAMPLE, CLONE, DEC_TTL, and
CHECK_PKT_LEN builders, trim resource-owning action-list tails in reverse
construction order before discarding failed wrappers, so resources copied
into the rejected tails are released before the wrappers are removed.

Most failed outer wrappers are discarded by truncating actions_len after
child resources have been released. CHECK_PKT_LEN also trims its parent
after branch resources are gone. SET/TUNNEL close failures unwind their
known tun_dst ownership directly, and SET_TO_MASKED has no external
ownership and truncates on close failure.

Fixes: a1e64ad ("net: openvswitch: remove misbehaving actions length check")
	Cc: stable@vger.kernel.org
Assisted-by: avom-custom-harness:gpt-5.5-qwen3.6-mod-mix
	Signed-off-by: Asim Viladi Oglu Manizada <manizada@pm.me>
	Reviewed-by: Eelco Chaudron <echaudro@redhat.com>
	Reviewed-by: Aaron Conole <aconole@redhat.com>
	Reviewed-by: Ilya Maximets <i.maximets@ovn.org>
Link: https://patch.msgid.link/20260706094336.38639-1-manizada@pm.me
	Signed-off-by: Paolo Abeni <pabeni@redhat.com>
(cherry picked from commit 3f1f755)
	Signed-off-by: Sultan Alsawaf <sultan@ciq.com>

@kerneltoast kerneltoast left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

:shipit:

@bmastbergen bmastbergen left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🥌

@PlaidCat
PlaidCat merged commit 1b59c51 into rlc-10/6.12.0-211.37.1.el10_2 Jul 25, 2026
5 of 7 checks passed
@PlaidCat
PlaidCat deleted the jmaple_rlc-10/6.12.0-211.37.1.el10_2 branch July 25, 2026 01:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

7 participants