Skip to content

Packet bridge captures packets with incorrect checksums - #774

Open
kraney wants to merge 3 commits into
openconfig:mainfrom
kraney:hw-offload
Open

kraney wants to merge 3 commits into
openconfig:mainfrom
kraney:hw-offload

Conversation

@kraney

@kraney kraney commented Sep 25, 2026

Copy link
Copy Markdown
Contributor

This is due to hardware offloads - packets do not have correct checksums with the expectation the hardware will fill it in.

(Note this problem is already solved within meshnet; following that example.)

  1. Disable Hardware Offloads via ethtool: When NewSocketHandler opens an interface, it uses github.com/safchain/ethtool (matching meshnet's approach) to disable active TX checksum and segmentation offloads as well as RX GRO/LRO/checksum offloads so the Linux kernel veth driver does not coalesce incoming segments or leave local frames with partial checksums.

  2. Finalize Partial Checksums via PACKET_AUXDATA: Enabled PACKET_AUXDATA on the raw AF_PACKET socket and updated ReadPacket to inspect TP_STATUS_CSUMNOTREADY (skb->ip_summed == CHECKSUM_PARTIAL). If a frame arrives from a peer veth in another container namespace where TX checksum offload was still enabled, finalizePartialChecksum computes the missing L4 (TCP/UDP/ICMPv6) checksum in software before forwarding.

  3. Unit Tests: Added unit tests covering offload disabling, PACKET_AUXDATA parsing, and IPv4/IPv6/VLAN partial checksum finalization.

This is due to hardware offloads - packets do not have correct checksums
with the expectation the hardware will fill it in.

(Note this problem is already solved within meshnet; following that
example.)

1. Disable Hardware Offloads via ethtool:
   When NewSocketHandler opens an interface, it uses github.com/safchain/ethtool
   (matching meshnet's approach) to disable active TX checksum and segmentation
   offloads as well as RX GRO/LRO/checksum offloads so the Linux kernel veth
   driver does not coalesce incoming segments or leave local frames with
   partial checksums.

2. Finalize Partial Checksums via PACKET_AUXDATA:
   Enabled PACKET_AUXDATA on the raw AF_PACKET socket and updated ReadPacket to
   inspect TP_STATUS_CSUMNOTREADY (skb->ip_summed == CHECKSUM_PARTIAL). If a
   frame arrives from a peer veth in another container namespace where TX
   checksum offload was still enabled, finalizePartialChecksum computes the
   missing L4 (TCP/UDP/ICMPv6) checksum in software before forwarding.

3. Unit Tests:
   Added unit tests covering offload disabling, PACKET_AUXDATA parsing, and
   IPv4/IPv6/VLAN partial checksum finalization.
- don't try to calculate sums if something turns hw accel back on
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant