On 14/08/2026 03:27, Jakub Kicinski wrote:
> [Severity: High]
> This isn't a bug introduced by this patch, but should the sibling
> get_untagged_frame() callbacks be privatized the same way?
> ... 
> One more consumer of the same bytes: an AF_PACKET listener on the slave
> device gets its clone in packet_rcv() before hsr_handle_frame() runs, so
> does it also observe the rewritten h_source?
Yes. Master delivery can rewrite frame->skb_std through its clone before
the later slave copies it. When the learned A and B addresses differ,
that copy preserves the substituted address rather than the original
source. An earlier packet-socket clone can also be affected.

I'll compare private untagged returns with COW at the writers before
settling the v4 ownership changes.

-- 
Xin

Reply via email to