Hi Andrea,
On Wed, Sep 23, 2026 at 06:05:06PM +0200, Andrea Mayer wrote:
> > diff --git a/net/ipv6/seg6_local.c b/net/ipv6/seg6_local.c
> > index 584e6aca3893..7462da1da362 100644
> > --- a/net/ipv6/seg6_local.c
> > +++ b/net/ipv6/seg6_local.c
> > @@ -121,7 +121,8 @@ struct bpf_lwt_prog {
> >  
> >  #define SEG6_LOCAL_END_FLV_SUPP_OPS        (SEG6_F_LOCAL_FLV_NEXT_CSID | \
> >                                      SEG6_LOCAL_FLV8986_SUPP_OPS)
> > -#define SEG6_LOCAL_END_X_FLV_SUPP_OPS      SEG6_F_LOCAL_FLV_NEXT_CSID
> > +#define SEG6_LOCAL_END_X_FLV_SUPP_OPS      (SEG6_F_LOCAL_FLV_NEXT_CSID | \
> > +                                    SEG6_LOCAL_FLV8986_SUPP_OPS)
> > 
> 
> This adds PSP to a mask that already had NEXT-C-SID. PSP alone then
> works through end_flv8986_core().
>  
> >  struct seg6_flavors_info {
> >     /* Flavor operations */
> > @@ -841,12 +842,19 @@ static int input_action_end_x(struct sk_buff *skb, 
> > struct seg6_local_lwt *slwt)
> >  {
> >     const struct seg6_flavors_info *finfo = &slwt->flv_info;
> >     __u32 fops = finfo->flv_ops;
> > +   int ret;
> > +
> > +   if (!fops)
> > +           return input_action_end_x_core(skb, slwt);
> >  
> >     /* check for the presence of NEXT-C-SID since it applies first */
> >     if (seg6_next_csid_enabled(fops))
> >             return end_x_next_csid_core(skb, slwt);
> >  
> > -   return input_action_end_x_core(skb, slwt);
> > +   ret = end_flv8986_core(skb, slwt);
> > +   if (ret)
> > +           return ret;
> > +   return input_action_end_x_finish(skb, slwt);
> >  }
> >
>   
> The problem is the combination with NEXT-C-SID: the NEXT-C-SID early
> return above is still taken, and neither branch of
> end_x_next_csid_core() applies PSP. So "End.X flavors next-csid,psp"
> becomes configurable and PSP is never applied.

Ah, right. The NEXT-C-SID could combine with other flavors.

> 
> The same mask and the same early return are already in End, where the
> combination is accepted and PSP is not applied either. I will send a
> fix for that to net.

OK
> 
> For this patch I would handle the combination.

Thanks
> 
> On the selftest side, the combination of next-csid and psp is not
> covered yet. I am going to add coverage for it in any case with the
> End fix, and I would be glad to do it with you if you are interested:
> the same coverage would serve End.X too, if you decide to handle the
> combination there.

Yes, I will add support for the End.X combination (and End.T in follow-up
patch) once you add the next-csid/psp selftest.

Thanks
Hangbin

Reply via email to