Since nf_bridge_maybe_copy_header() may change the length of skb,
we should check the length of skb after it to handle the ppoe skbs.
Signed-off-by: Changli Gao <xiaosuo@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
 
 int br_dev_queue_push_xmit(struct sk_buff *skb)
 {
-       /* drop mtu oversized packets except gso */
-       if (packet_length(skb) > skb->dev->mtu && !skb_is_gso(skb))
+       /* ip_fragment doesn't copy the MAC header */
+       if (nf_bridge_maybe_copy_header(skb) ||
+           (packet_length(skb) > skb->dev->mtu && !skb_is_gso(skb))) {
                kfree_skb(skb);
-       else {
-               /* ip_fragment doesn't copy the MAC header */
-               if (nf_bridge_maybe_copy_header(skb))
-                       kfree_skb(skb);
-               else {
-                       skb_push(skb, ETH_HLEN);
-                       dev_queue_xmit(skb);
-               }
+       } else {
+               skb_push(skb, ETH_HLEN);
+               dev_queue_xmit(skb);
        }
 
        return 0;