From: Jacob Keller <jacob.e.keller@intel.com>
To: Yun Lu <luyun_611@163.com>, <justinlai0215@realtek.com>,
<larry.chiu@realtek.com>, <andrew+netdev@lunn.ch>,
<davem@davemloft.net>, <edumazet@google.com>, <kuba@kernel.org>,
<pabeni@redhat.com>
Cc: <netdev@vger.kernel.org>
Subject: Re: [PATCH] rtase: fix double free of multi-frag skb on DMA map failure
Date: Wed, 22 Jul 2026 12:55:02 -0700 [thread overview]
Message-ID: <0678a4a6-c3d8-4dca-a935-4ce5da10dae3@intel.com> (raw)
In-Reply-To: <20260721023836.6691-1-luyun_611@163.com>
On 7/20/2026 7:38 PM, Yun Lu wrote:
> From: Yun Lu <luyun@kylinos.cn>
>
> In rtase_start_xmit(), when the head buffer DMA mapping fails after
> rtase_xmit_frags() has mapped all fragments, the error path clears
> the fragment descriptors with rtase_tx_clear_range(), which frees
> the skb through the last-frag slot and accounts tx_dropped. Control
> then falls through to the common error label, which frees the same
> skb a second time and counts it again.
>
> Return right after clearing the fragments when the skb owns frags;
> the no-frag case still drops through and frees the head skb once.
>
> Fixes: d6e882b89fdf ("rtase: Implement .ndo_start_xmit function")
> Signed-off-by: Yun Lu <luyun@kylinos.cn>
> ---
> drivers/net/ethernet/realtek/rtase/rtase_main.c | 3 +++
> 1 file changed, 3 insertions(+)
>
> diff --git a/drivers/net/ethernet/realtek/rtase/rtase_main.c b/drivers/net/ethernet/realtek/rtase/rtase_main.c
> index 255667775f0e..67f7fdada119 100644
> --- a/drivers/net/ethernet/realtek/rtase/rtase_main.c
> +++ b/drivers/net/ethernet/realtek/rtase/rtase_main.c
> @@ -1426,6 +1426,9 @@ static netdev_tx_t rtase_start_xmit(struct sk_buff *skb,
> err_dma_1:
> ring->skbuff[entry] = NULL;
> rtase_tx_clear_range(ring, ring->cur_idx + 1, frags);
> + if (frags)
> + /* the frags were cleared above, along with the skb */
> + return NETDEV_TX_OK;
>
This feels a bit strange, but it matches the code in
rtase_tx_clear_range. I do find it a bit odd we're checking frags here
even though they got freed.. but it does seem to check out with how the
rtase_tx_clear_range() works.
Reviewed-by: Jacob Keller <jacob.e.keller@intel.com>
> err_dma_0:
> tp->stats.tx_dropped++;
next prev parent reply other threads:[~2026-07-22 19:55 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-21 2:38 [PATCH] rtase: fix double free of multi-frag skb on DMA map failure Yun Lu
2026-07-22 19:55 ` Jacob Keller [this message]
2026-07-23 17:25 ` Jakub Kicinski
2026-07-27 9:49 ` Justin Lai
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=0678a4a6-c3d8-4dca-a935-4ce5da10dae3@intel.com \
--to=jacob.e.keller@intel.com \
--cc=andrew+netdev@lunn.ch \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=justinlai0215@realtek.com \
--cc=kuba@kernel.org \
--cc=larry.chiu@realtek.com \
--cc=luyun_611@163.com \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.