From: sashiko-bot@kernel.org
To: "Zhu Ling" <zhuling0805@qq.com>
Cc: "Oliver Hartkopp" <socketcan@hartkopp.net>,
"Vincent Mailhol" <mailhol@kernel.org>,
"Marc Kleine-Budde" <mkl@pengutronix.de>,
linux-can@vger.kernel.org,
"Oleksij Rempel" <o.rempel@pengutronix.de>
Subject: Re: [PATCH net] can: netlink: fix IFLA_CAN_BITRATE_MAX attribute sizing
Date: Fri, 04 Sep 2026 16:28:47 +0000 [thread overview]
Message-ID: <20260904162848.5831E1F00A3D@smtp.kernel.org> (raw)
In-Reply-To: <tencent_D1C873B86B0E92011A264B0E196B911D5308@qq.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] Pre-existing netlink payload size underestimation in `can_pwm_get_size()` when PWM capabilities exist but `CAN_CTRLMODE_XL_TMS` is disabled, leading to `-EMSGSIZE` when filling the response.
--
commit 9a3cf7f66d6ea7a9d4aba48ff7c5376d72db7fe3
Author: Zhu Ling <zhuling0805@qq.com>
can: netlink: fix IFLA_CAN_BITRATE_MAX attribute sizing
This commit fixes an issue in can_get_size() where the size for
IFLA_CAN_BITRATE_MAX was missing the netlink attribute header overhead. By
using nla_total_size(), it prevents -EMSGSIZE errors when the skb has no slack
left.
> diff --git a/drivers/net/can/dev/netlink.c b/drivers/net/can/dev/netlink.c
> index 766d455950f55..ba26c61a82c2f 100644
> --- a/drivers/net/can/dev/netlink.c
> +++ b/drivers/net/can/dev/netlink.c
> @@ -822,7 +822,7 @@ static size_t can_get_size(const struct net_device *dev)
> if (priv->bitrate_const) /* IFLA_CAN_BITRATE_CONST */
> size += nla_total_size(sizeof(*priv->bitrate_const) *
> priv->bitrate_const_cnt);
> - size += sizeof(priv->bitrate_max); /* IFLA_CAN_BITRATE_MAX */
> + size += nla_total_size(sizeof(priv->bitrate_max)); /* IFLA_CAN_BITRATE_MAX */
> size += can_ctrlmode_ext_get_size(); /* IFLA_CAN_CTRLMODE_EXT */
>
> size += can_data_bittiming_get_size(&priv->fd,
[Severity: High]
This isn't a bug introduced by this patch, but while looking at
can_get_size(), I noticed another potential size underestimation just below
this diff in can_pwm_get_size():
drivers/net/can/dev/netlink.c:can_pwm_get_size() {
if (!pwm_const || !pwm_on)
return 0;
...
}
If a CAN interface has hardware PWM support (pwm_const is non-NULL) but PWM is
currently disabled (pwm_on is false), can_pwm_get_size() returns 0.
However, can_pwm_fill_info() only checks pwm_const:
drivers/net/can/dev/netlink.c:can_pwm_fill_info() {
if (!pwm_const)
return 0;
nest = nla_nest_start(skb, IFLA_CAN_XL_PWM);
...
}
Could this mismatch cause can_pwm_fill_info() to write 52 bytes that were not
accounted for by can_get_size() when CAN_CTRLMODE_XL_TMS is disabled?
If so, could this also overflow the skb and cause nla_put() to fail with
-EMSGSIZE, breaking interface notifications and queries like 'ip link show'
for such devices?
--
Sashiko AI review · https://sashiko.dev/#/patchset/tencent_D1C873B86B0E92011A264B0E196B911D5308@qq.com?part=1
next prev parent reply other threads:[~2026-09-04 16:28 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-04 16:20 [PATCH net] can: netlink: fix IFLA_CAN_BITRATE_MAX attribute sizing Zhu Ling
2026-09-04 16:28 ` sashiko-bot [this message]
2026-09-04 17:10 ` zhuling0805
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260904162848.5831E1F00A3D@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=linux-can@vger.kernel.org \
--cc=mailhol@kernel.org \
--cc=mkl@pengutronix.de \
--cc=o.rempel@pengutronix.de \
--cc=sashiko-reviews@lists.linux.dev \
--cc=socketcan@hartkopp.net \
--cc=zhuling0805@qq.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.