On 14/08/2026 03:27, Jakub Kicinski wrote: > [Severity: High] > This isn't a bug introduced by this patch, but should the sibling > get_untagged_frame() callbacks be privatized the same way? > ... > One more consumer of the same bytes: an AF_PACKET listener on the slave > device gets its clone in packet_rcv() before hsr_handle_frame() runs, so > does it also observe the rewritten h_source? Yes. Master delivery can rewrite frame->skb_std through its clone before the later slave copies it. When the learned A and B addresses differ, that copy preserves the substituted address rather than the original source. An earlier packet-socket clone can also be affected.
I'll compare private untagged returns with COW at the writers before settling the v4 ownership changes. -- Xin
