From mboxrd@z Thu Jan 1 00:00:00 1970 Authentication-Results: passt.top; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: passt.top; dkim=pass (1024-bit key; unprotected) header.d=redhat.com header.i=@redhat.com header.a=rsa-sha256 header.s=mimecast20190719 header.b=H6d69DpL; dkim-atps=neutral Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) by passt.top (Postfix) with ESMTPS id 084845A0265 for ; Tue, 26 May 2026 14:58:24 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1779800303; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:autocrypt:autocrypt; bh=jrGZyuPwxVVFxoCWt9QhZ+smAAPhVJDvSfc5iSotkew=; b=H6d69DpLfB494ovU3QiCI+I6L6xGv7k2/NjAa7ER7tyOEzWiC+Tqtl1FqvunfH+LIAPCrT 4XhzATxk8DCm47eZKTuFUpkwvXijbYgqCeh55BxleEKLFie3D6GsmUl0kTRaMsv8TtjneJ EBrbTvRjRVxzdgJrL1SUYYhYhyPYQkg= Received: from mail-wr1-f70.google.com (mail-wr1-f70.google.com [209.85.221.70]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-153-VNpSk2wEOreiKwkFgjIJpw-1; Tue, 26 May 2026 08:58:21 -0400 X-MC-Unique: VNpSk2wEOreiKwkFgjIJpw-1 X-Mimecast-MFC-AGG-ID: VNpSk2wEOreiKwkFgjIJpw_1779800299 Received: by mail-wr1-f70.google.com with SMTP id ffacd0b85a97d-44d83e45febso7517632f8f.0 for ; Tue, 26 May 2026 05:58:19 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779800299; x=1780405099; h=content-transfer-encoding:in-reply-to:autocrypt:from :content-language:references:cc:to:subject:user-agent:mime-version :date:message-id:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=jrGZyuPwxVVFxoCWt9QhZ+smAAPhVJDvSfc5iSotkew=; b=rgsrDDqAR26zL9TjRDaF1RVEgDFZbw4plOKNK5wF+nXMIJk+mZPuTgyNWGCCIJAH3v W3FMOzANKPFo6wqInNBAzrQyfv8FgSzz7vHYpQYJFwCmRLO51vxrjEC7hxbSNoxPcz4o iKcV+cgRhiSc0SY2wHWwhSnHqA46Xr57Pa8SlE87HEHrzdM75uaT45mGm+OUoMcebaxQ gSIYWrR9kJDwyKzW/lto7BUy4ApG+ZRTwMt1rAQmKWSSVQ49SUgDp8O8dBY3XckPV2Sf 6QmRuribyD+TVOHD1k3G1svHJvlrHXQeDj7vciM6JNVhToeK2s6T4Hok63uVFQ0Co0Tb XRcg== X-Forwarded-Encrypted: i=1; AFNElJ/TRrfvOk69bUkREE7rczxQ/8ywtXwGaFL045VR3ZP4nIqt7T8YU1xbvZla3MCku5m/8BNUHHzxqCg=@passt.top X-Gm-Message-State: AOJu0YyWIrw+4li9pCL/hMtHrb6VhXCMh3PysR6nBD9a8yTZNKNvZnfc /XO18mZrqYlJZCDFQZfvABVaw8ZFlY3lEW/Go/S3YHg6+cAK6wYI+dR1YnMJGsyLNCqe4bvA0MZ zCLaZUMZqfzgmj11cfqkOGDg+l+pfCS4vZHR/FXGA4fIMk5GDD8imrg== X-Gm-Gg: Acq92OH1c2T6kUjVKo0FHxHcVGIGMHa960tHX6BuY61kbBsFXR1Rq/gIEGhwq3Z5Drq 4rGshZIcq33o1oDqlX/jm/mstDgZrqPCMRrUpHaVPJkPuAgsLCRKHboX9fAVWlDhQtdX2XDdLqG qDAwIxeWa0NfpVVUeicsckQ0Y/jdBJLwC1gu3dfVC4OoldXbTtvo0NGczyd3QNn4Ce7m2iuqZjo yeAAEvOa1MHkAaMHLGSWPJ3Uz7K3kC7HOWh+CeFFqUx/43CbYr9KEOFQF3mg7bkIXDZP8S5p5P6 rvb44+EHyN6WVXdEqXMeejoNicyNWGgYxiB1fW9VPgJ9FtcoqQx/vpH/1wtzWa5/S4ZQWJA+s6g lGJ1qMP8190Co2ZLW4BIJE7Zfmb404Eh2b6HA56T1MxeVYabBvzybo9O4kMTb+LV8EA== X-Received: by 2002:a05:600c:1992:b0:48a:79d8:a8d6 with SMTP id 5b1f17b1804b1-4904245f54cmr249603825e9.7.1779800298808; Tue, 26 May 2026 05:58:18 -0700 (PDT) X-Received: by 2002:a05:600c:1992:b0:48a:79d8:a8d6 with SMTP id 5b1f17b1804b1-4904245f54cmr249603495e9.7.1779800298302; Tue, 26 May 2026 05:58:18 -0700 (PDT) Received: from [192.168.100.100] (82-64-211-94.subs.proxad.net. [82.64.211.94]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-490428d4cefsm112241815e9.14.2026.05.26.05.58.17 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Tue, 26 May 2026 05:58:17 -0700 (PDT) Message-ID: Date: Tue, 26 May 2026 14:58:16 +0200 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH v2 1/2] vhost_user: Offer VIRTIO_NET_F_GUEST_CSUM To: Stefano Brivio References: <20260416162140.3830027-1-lvivier@redhat.com> <20260416162140.3830027-2-lvivier@redhat.com> From: Laurent Vivier Autocrypt: addr=lvivier@redhat.com; keydata= xsFNBFYFJhkBEAC2me7w2+RizYOKZM+vZCx69GTewOwqzHrrHSG07MUAxJ6AY29/+HYf6EY2 WoeuLWDmXE7A3oJoIsRecD6BXHTb0OYS20lS608anr3B0xn5g0BX7es9Mw+hV/pL+63EOCVm SUVTEQwbGQN62guOKnJJJfphbbv82glIC/Ei4Ky8BwZkUuXd7d5NFJKC9/GDrbWdj75cDNQx UZ9XXbXEKY9MHX83Uy7JFoiFDMOVHn55HnncflUncO0zDzY7CxFeQFwYRbsCXOUL9yBtqLer Ky8/yjBskIlNrp0uQSt9LMoMsdSjYLYhvk1StsNPg74+s4u0Q6z45+l8RAsgLw5OLtTa+ePM JyS7OIGNYxAX6eZk1+91a6tnqfyPcMbduxyBaYXn94HUG162BeuyBkbNoIDkB7pCByed1A7q q9/FbuTDwgVGVLYthYSfTtN0Y60OgNkWCMtFwKxRaXt1WFA5ceqinN/XkgA+vf2Ch72zBkJL RBIhfOPFv5f2Hkkj0MvsUXpOWaOjatiu0fpPo6Hw14UEpywke1zN4NKubApQOlNKZZC4hu6/ 8pv2t4HRi7s0K88jQYBRPObjrN5+owtI51xMaYzvPitHQ2053LmgsOdN9EKOqZeHAYG2SmRW LOxYWKX14YkZI5j/TXfKlTpwSMvXho+efN4kgFvFmP6WT+tPnwARAQABzSNMYXVyZW50IFZp dmllciA8bHZpdmllckByZWRoYXQuY29tPsLBeAQTAQIAIgUCVgVQgAIbAwYLCQgHAwIGFQgC CQoLBBYCAwECHgECF4AACgkQ8ww4vT8vvjwpgg//fSGy0Rs/t8cPFuzoY1cex4limJQfReLr SJXCANg9NOWy/bFK5wunj+h/RCFxIFhZcyXveurkBwYikDPUrBoBRoOJY/BHK0iZo7/WQkur 6H5losVZtrotmKOGnP/lJYZ3H6OWvXzdz8LL5hb3TvGOP68K8Bn8UsIaZJoeiKhaNR0sOJyI YYbgFQPWMHfVwHD/U+/gqRhD7apVysxv5by/pKDln1I5v0cRRH6hd8M8oXgKhF2+rAOL7gvh jEHSSWKUlMjC7YwwjSZmUkL+TQyE18e2XBk85X8Da3FznrLiHZFHQ/NzETYxRjnOzD7/kOVy gKD/o7asyWQVU65mh/ECrtjfhtCBSYmIIVkopoLaVJ/kEbVJQegT2P6NgERC/31kmTF69vn8 uQyW11Hk8tyubicByL3/XVBrq4jZdJW3cePNJbTNaT0d/bjMg5zCWHbMErUib2Nellnbg6bc 2HLDe0NLVPuRZhHUHM9hO/JNnHfvgiRQDh6loNOUnm9Iw2YiVgZNnT4soUehMZ7au8PwSl4I KYE4ulJ8RRiydN7fES3IZWmOPlyskp1QMQBD/w16o+lEtY6HSFEzsK3o0vuBRBVp2WKnssVH qeeV01ZHw0bvWKjxVNOksP98eJfWLfV9l9e7s6TaAeySKRRubtJ+21PRuYAxKsaueBfUE7ZT 7zfOwU0EVgUmGQEQALxSQRbl/QOnmssVDxWhHM5TGxl7oLNJms2zmBpcmlrIsn8nNz0rRyxT 460k2niaTwowSRK8KWVDeAW6ZAaWiYjLlTunoKwvF8vP3JyWpBz0diTxL5o+xpvy/Q6YU3BN efdq8Vy3rFsxgW7mMSrI/CxJ667y8ot5DVugeS2NyHfmZlPGE0Nsy7hlebS4liisXOrN3jFz asKyUws3VXek4V65lHwB23BVzsnFMn/bw/rPliqXGcwl8CoJu8dSyrCcd1Ibs0/Inq9S9+t0 VmWiQWfQkz4rvEeTQkp/VfgZ6z98JRW7S6l6eophoWs0/ZyRfOm+QVSqRfFZdxdP2PlGeIFM C3fXJgygXJkFPyWkVElr76JTbtSHsGWbt6xUlYHKXWo+xf9WgtLeby3cfSkEchACrxDrQpj+ Jt/JFP+q997dybkyZ5IoHWuPkn7uZGBrKIHmBunTco1+cKSuRiSCYpBIXZMHCzPgVDjk4viP brV9NwRkmaOxVvye0vctJeWvJ6KA7NoAURplIGCqkCRwg0MmLrfoZnK/gRqVJ/f6adhU1oo6 z4p2/z3PemA0C0ANatgHgBb90cd16AUxpdEQmOCmdNnNJF/3Zt3inzF+NFzHoM5Vwq6rc1JP jfC3oqRLJzqAEHBDjQFlqNR3IFCIAo4SYQRBdAHBCzkM4rWyRhuVABEBAAHCwV8EGAECAAkF AlYFJhkCGwwACgkQ8ww4vT8vvjwg9w//VQrcnVg3TsjEybxDEUBm8dBmnKqcnTBFmxN5FFtI WlEuY8+YMiWRykd8Ln9RJ/98/ghABHz9TN8TRo2b6WimV64FmlVn17Ri6FgFU3xNt9TTEChq AcNg88eYryKsYpFwegGpwUlaUaaGh1m9OrTzcQy+klVfZWaVJ9Nw0keoGRGb8j4XjVpL8+2x OhXKrM1fzzb8JtAuSbuzZSQPDwQEI5CKKxp7zf76J21YeRrEW4WDznPyVcDTa+tz++q2S/Bp P4W98bXCBIuQgs2m+OflERv5c3Ojldp04/S4NEjXEYRWdiCxN7ca5iPml5gLtuvhJMSy36gl U6IW9kn30IWuSoBpTkgV7rLUEhh9Ms82VWW/h2TxL8enfx40PrfbDtWwqRID3WY8jLrjKfTd R3LW8BnUDNkG+c4FzvvGUs8AvuqxxyHbXAfDx9o/jXfPHVRmJVhSmd+hC3mcQ+4iX5bBPBPM oDqSoLt5w9GoQQ6gDVP2ZjTWqwSRMLzNr37rJjZ1pt0DCMMTbiYIUcrhX8eveCJtY7NGWNyx FCRkhxRuGcpwPmRVDwOl39MB3iTsRighiMnijkbLXiKoJ5CDVvX5yicNqYJPKh5MFXN1bvsB kmYiStMRbrD0HoY1kx5/VozBtc70OU0EB8Wrv9hZD+Ofp0T3KOr1RUHvCZoLURfFhSQ= In-Reply-To: <20260416162140.3830027-2-lvivier@redhat.com> X-Mimecast-Spam-Score: 0 X-Mimecast-MFC-PROC-ID: Qw3-yBHSytjH1PQY7GG4e2eyVtcKNVmYDXdO_28uciE_1779800299 X-Mimecast-Originator: redhat.com Content-Language: en-US Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit Message-ID-Hash: 4YTCN5Y3KAPFEZ4X6DJFRDREPG2OT2FJ X-Message-ID-Hash: 4YTCN5Y3KAPFEZ4X6DJFRDREPG2OT2FJ X-MailFrom: lvivier@redhat.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header CC: David Gibson , passt-dev@passt.top X-Mailman-Version: 3.3.8 Precedence: list List-Id: Development discussion and patches for passt Archived-At: Archived-At: List-Archive: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: Hi Stefano, could you apply this one too? Thanks, Laurent On 4/16/26 18:21, Laurent Vivier wrote: > According to the virtio-net specification, when the VIRTIO_NET_F_GUEST_CSUM > is negotiated, the device can set VIRTIO_NET_HDR_F_DATA_VALID in the > virtio-net header to indicate that packet checksums have been validated, > allowing the guest to skip verification. Without this feature, the device > must provide fully checksummed packets. > > The vhost-user TCP and UDP paths were unconditionally skipping checksum > computation, regardless of whether GUEST_CSUM was negotiated. This > went undetected with Linux guests because Linux's virtio-net driver > honours VIRTIO_NET_HDR_F_DATA_VALID regardless of whether > VIRTIO_NET_F_GUEST_CSUM was negotiated, marking such packets as > CHECKSUM_UNNECESSARY and skipping verification. > > iPXE, however, does not negotiate GUEST_CSUM, ignores the DATA_VALID > flag entirely, and always verifies checksums. This caused TCP > connections to fail: the SYN-ACK had a zero TCP checksum, iPXE rejected > it, and the connection timed out in SYN_RCVD. > > Adding --pcap happened to mask the bug, because the pcap code path > forces checksum computation to ensure correct captures. > > Offer VIRTIO_NET_F_GUEST_CSUM in the device features, and only skip > checksum computation when the guest has actually negotiated it. When > GUEST_CSUM is not negotiated, always compute valid checksums as required > by the specification. > > We keep setting VIRTIO_NET_HDR_F_DATA_VALID unconditionally in > VU_HEADER: when GUEST_CSUM is negotiated, the flag lets the guest skip > checksum verification; when it is not, the spec says the guest should > ignore the flags field, so setting it is harmless. > > Signed-off-by: Laurent Vivier > Reviewed-by: David Gibson > --- > tcp_vu.c | 8 ++++++-- > udp_vu.c | 7 ++++--- > vhost_user.c | 1 + > 3 files changed, 11 insertions(+), 5 deletions(-) > > diff --git a/tcp_vu.c b/tcp_vu.c > index 7f7e43860b10..3da14a4942d6 100644 > --- a/tcp_vu.c > +++ b/tcp_vu.c > @@ -124,6 +124,7 @@ int tcp_vu_send_flag(const struct ctx *c, struct tcp_tap_conn *conn, int flags) > struct vu_virtq *vq = &vdev->vq[VHOST_USER_RX_QUEUE]; > size_t optlen, hdrlen, iov_cnt, iov_used; > struct vu_virtq_element flags_elem[2]; > + uint32_t csum_flags = IP4_CSUM; > struct iovec flags_iov[64]; > int elem_cnt, dup_elem_cnt = 0; > struct tcp_syn_opts opts; > @@ -135,6 +136,9 @@ int tcp_vu_send_flag(const struct ctx *c, struct tcp_tap_conn *conn, int flags) > uint32_t seq; > int ret; > > + if (*c->pcap || !vu_has_feature(vdev, VIRTIO_NET_F_GUEST_CSUM)) > + csum_flags |= TCP_CSUM; > + > hdrlen = tcp_vu_hdrlen(CONN_V6(conn)); > > elem_cnt = vu_collect(vdev, vq, &flags_elem[0], 1, > @@ -173,7 +177,7 @@ int tcp_vu_send_flag(const struct ctx *c, struct tcp_tap_conn *conn, int flags) > iov_from_buf(payload.iov, payload.cnt, payload.off, &opts, optlen); > tcp_fill_headers(c, conn, &eh, CONN_V4(conn) ? &ip4h : NULL, > CONN_V6(conn) ? &ip6h : NULL, &th, &payload, > - optlen, IP4_CSUM | (*c->pcap ? TCP_CSUM : 0), seq); > + optlen, csum_flags, seq); > > vu_pad(flags_elem[0].in_sg, iov_cnt, hdrlen + optlen); > > @@ -519,7 +523,7 @@ int tcp_vu_data_from_sock(const struct ctx *c, struct tcp_tap_conn *conn) > > hdrlen = tcp_vu_hdrlen(v6); > check = IP4_CSUM; > - if (*c->pcap) > + if (*c->pcap || !vu_has_feature(vdev, VIRTIO_NET_F_GUEST_CSUM)) > check |= TCP_CSUM; > for (i = 0, previous_dlen = -1; i < frame_cnt; i++) { > struct iovec *iov = &iov_vu[frame[i].idx_iovec]; > diff --git a/udp_vu.c b/udp_vu.c > index 8cf50ca1c38f..54d824b5530c 100644 > --- a/udp_vu.c > +++ b/udp_vu.c > @@ -233,12 +233,13 @@ void udp_vu_sock_to_tap(const struct ctx *c, int s, int n, flow_sidx_t tosidx) > if (iov_cnt > 0) { > struct iov_tail data = IOV_TAIL(iov_vu, iov_cnt, VNET_HLEN); > udp_vu_prepare(c, &data, toside, dlen); > - if (*c->pcap) { > + if (!vu_has_feature(vdev, VIRTIO_NET_F_GUEST_CSUM) || > + *c->pcap) > udp_vu_csum(toside, &data, dlen); > + vu_pad(iov_vu, iov_cnt, hdrlen + dlen); > + if (*c->pcap) > pcap_iov(iov_vu, iov_cnt, VNET_HLEN, > hdrlen + dlen - VNET_HLEN); > - } > - vu_pad(iov_vu, iov_cnt, hdrlen + dlen); > vu_flush(vdev, vq, elem, elem_used, hdrlen + dlen); > vu_queue_notify(vdev, vq); > } > diff --git a/vhost_user.c b/vhost_user.c > index f062badd3311..a1259c2624c0 100644 > --- a/vhost_user.c > +++ b/vhost_user.c > @@ -322,6 +322,7 @@ static bool vu_get_features_exec(struct vu_dev *vdev, > { > uint64_t features = > 1ULL << VIRTIO_F_VERSION_1 | > + 1ULL << VIRTIO_NET_F_GUEST_CSUM | > 1ULL << VIRTIO_NET_F_MRG_RXBUF | > 1ULL << VHOST_F_LOG_ALL | > 1ULL << VHOST_USER_F_PROTOCOL_FEATURES;