* [PATCH net] can: netlink: fix IFLA_CAN_BITRATE_MAX attribute sizing
@ 2026-09-04 16:20 Zhu Ling
2026-09-04 16:28 ` sashiko-bot
0 siblings, 1 reply; 3+ messages in thread
From: Zhu Ling @ 2026-09-04 16:20 UTC (permalink / raw)
To: linux-can
Cc: mkl, mailhol, nsekhar, faiz_abbas, s-anna, fcooper, linux-kernel,
Zhu Ling, stable
can_fill_info() emits IFLA_CAN_BITRATE_MAX with nla_put(), which consumes
space for both the attribute header and its aligned payload. However,
can_get_size() accounts for the payload only. The resulting underestimate
can make filling the netlink response fail with -EMSGSIZE when the skb has
no remaining slack.
Use nla_total_size() to account for the complete attribute.
Fixes: 2290aefa2e90 ("can: dev: Add support for limiting configured bitrate")
Cc: stable@vger.kernel.org
Signed-off-by: Zhu Ling <zhuling0805@qq.com>
---
drivers/net/can/dev/netlink.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/can/dev/netlink.c b/drivers/net/can/dev/netlink.c
index 766d455950f5..ba26c61a82c2 100644
--- a/drivers/net/can/dev/netlink.c
+++ b/drivers/net/can/dev/netlink.c
@@ -822,7 +822,7 @@ static size_t can_get_size(const struct net_device *dev)
if (priv->bitrate_const) /* IFLA_CAN_BITRATE_CONST */
size += nla_total_size(sizeof(*priv->bitrate_const) *
priv->bitrate_const_cnt);
- size += sizeof(priv->bitrate_max); /* IFLA_CAN_BITRATE_MAX */
+ size += nla_total_size(sizeof(priv->bitrate_max)); /* IFLA_CAN_BITRATE_MAX */
size += can_ctrlmode_ext_get_size(); /* IFLA_CAN_CTRLMODE_EXT */
size += can_data_bittiming_get_size(&priv->fd,
base-commit: 641d03105cc0d2437e32fdeec164f91a4ccef6c4
--
2.43.0
^ permalink raw reply related [flat|nested] 3+ messages in thread
* Re: [PATCH net] can: netlink: fix IFLA_CAN_BITRATE_MAX attribute sizing
2026-09-04 16:20 [PATCH net] can: netlink: fix IFLA_CAN_BITRATE_MAX attribute sizing Zhu Ling
@ 2026-09-04 16:28 ` sashiko-bot
2026-09-04 17:10 ` zhuling0805
0 siblings, 1 reply; 3+ messages in thread
From: sashiko-bot @ 2026-09-04 16:28 UTC (permalink / raw)
To: Zhu Ling
Cc: Oliver Hartkopp, Vincent Mailhol, Marc Kleine-Budde, linux-can,
Oleksij Rempel
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] Pre-existing netlink payload size underestimation in `can_pwm_get_size()` when PWM capabilities exist but `CAN_CTRLMODE_XL_TMS` is disabled, leading to `-EMSGSIZE` when filling the response.
--
commit 9a3cf7f66d6ea7a9d4aba48ff7c5376d72db7fe3
Author: Zhu Ling <zhuling0805@qq.com>
can: netlink: fix IFLA_CAN_BITRATE_MAX attribute sizing
This commit fixes an issue in can_get_size() where the size for
IFLA_CAN_BITRATE_MAX was missing the netlink attribute header overhead. By
using nla_total_size(), it prevents -EMSGSIZE errors when the skb has no slack
left.
> diff --git a/drivers/net/can/dev/netlink.c b/drivers/net/can/dev/netlink.c
> index 766d455950f55..ba26c61a82c2f 100644
> --- a/drivers/net/can/dev/netlink.c
> +++ b/drivers/net/can/dev/netlink.c
> @@ -822,7 +822,7 @@ static size_t can_get_size(const struct net_device *dev)
> if (priv->bitrate_const) /* IFLA_CAN_BITRATE_CONST */
> size += nla_total_size(sizeof(*priv->bitrate_const) *
> priv->bitrate_const_cnt);
> - size += sizeof(priv->bitrate_max); /* IFLA_CAN_BITRATE_MAX */
> + size += nla_total_size(sizeof(priv->bitrate_max)); /* IFLA_CAN_BITRATE_MAX */
> size += can_ctrlmode_ext_get_size(); /* IFLA_CAN_CTRLMODE_EXT */
>
> size += can_data_bittiming_get_size(&priv->fd,
[Severity: High]
This isn't a bug introduced by this patch, but while looking at
can_get_size(), I noticed another potential size underestimation just below
this diff in can_pwm_get_size():
drivers/net/can/dev/netlink.c:can_pwm_get_size() {
if (!pwm_const || !pwm_on)
return 0;
...
}
If a CAN interface has hardware PWM support (pwm_const is non-NULL) but PWM is
currently disabled (pwm_on is false), can_pwm_get_size() returns 0.
However, can_pwm_fill_info() only checks pwm_const:
drivers/net/can/dev/netlink.c:can_pwm_fill_info() {
if (!pwm_const)
return 0;
nest = nla_nest_start(skb, IFLA_CAN_XL_PWM);
...
}
Could this mismatch cause can_pwm_fill_info() to write 52 bytes that were not
accounted for by can_get_size() when CAN_CTRLMODE_XL_TMS is disabled?
If so, could this also overflow the skb and cause nla_put() to fail with
-EMSGSIZE, breaking interface notifications and queries like 'ip link show'
for such devices?
--
Sashiko AI review · https://sashiko.dev/#/patchset/tencent_D1C873B86B0E92011A264B0E196B911D5308@qq.com?part=1
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH net] can: netlink: fix IFLA_CAN_BITRATE_MAX attribute sizing
2026-09-04 16:28 ` sashiko-bot
@ 2026-09-04 17:10 ` zhuling0805
0 siblings, 0 replies; 3+ messages in thread
From: zhuling0805 @ 2026-09-04 17:10 UTC (permalink / raw)
To: sashiko-reviews
Cc: Oliver Hartkopp, Vincent Mailhol, Marc Kleine-Budde, linux-can,
Oleksij Rempel
Thanks for the review.
Yes, this is a pre-existing issue independent of the
IFLA_CAN_BITRATE_MAX sizing fix. It has already been addressed in the
separate patch:
[PATCH net] can: netlink: fix CAN XL PWM attribute sizing
https://lore.kernel.org/all/tencent_9A525E0656A4F7D4CA9CFA1AB1A4BFC6D706@qq.com/
No changes are needed for this patch.
Regards,
Zhu
原始邮件
发件人:sashiko-bot <sashiko-bot@kernel.org>
发件时间:2026年9月5日 00:28
收件人:Zhu Ling <zhuling0805@qq.com>
抄送:Oliver Hartkopp <socketcan@hartkopp.net>, Vincent Mailhol <mailhol@kernel.org>, Marc Kleine-Budde <mkl@pengutronix.de>, linux-can <linux-can@vger.kernel.org>, Oleksij Rempel <o.rempel@pengutronix.de>
主题:Re: [PATCH net] can: netlink: fix IFLA_CAN_BITRATE_MAX attribute sizing
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] Pre-existing netlink payload size underestimation in `can_pwm_get_size()` when PWM capabilities exist but `CAN_CTRLMODE_XL_TMS` is disabled, leading to `-EMSGSIZE` when filling the response.
--
commit 9a3cf7f66d6ea7a9d4aba48ff7c5376d72db7fe3
Author: Zhu Ling <zhuling0805@qq.com>
can: netlink: fix IFLA_CAN_BITRATE_MAX attribute sizing
This commit fixes an issue in can_get_size() where the size for
IFLA_CAN_BITRATE_MAX was missing the netlink attribute header overhead. By
using nla_total_size(), it prevents -EMSGSIZE errors when the skb has no slack
left.
> diff --git a/drivers/net/can/dev/netlink.c b/drivers/net/can/dev/netlink.c
> index 766d455950f55..ba26c61a82c2f 100644
> --- a/drivers/net/can/dev/netlink.c
> +++ b/drivers/net/can/dev/netlink.c
> @@ -822,7 +822,7 @@ static size_t can_get_size(const struct net_device *dev)
> if (priv->bitrate_const) /* IFLA_CAN_BITRATE_CONST */
> size += nla_total_size(sizeof(*priv->bitrate_const) *
> priv->bitrate_const_cnt);
> - size += sizeof(priv->bitrate_max); /* IFLA_CAN_BITRATE_MAX */
> + size += nla_total_size(sizeof(priv->bitrate_max)); /* IFLA_CAN_BITRATE_MAX */
> size += can_ctrlmode_ext_get_size(); /* IFLA_CAN_CTRLMODE_EXT */
>
> size += can_data_bittiming_get_size(&priv->fd,
[Severity: High]
This isn't a bug introduced by this patch, but while looking at
can_get_size(), I noticed another potential size underestimation just below
this diff in can_pwm_get_size():
drivers/net/can/dev/netlink.c:can_pwm_get_size() {
if (!pwm_const || !pwm_on)
return 0;
...
}
If a CAN interface has hardware PWM support (pwm_const is non-NULL) but PWM is
currently disabled (pwm_on is false), can_pwm_get_size() returns 0.
However, can_pwm_fill_info() only checks pwm_const:
drivers/net/can/dev/netlink.c:can_pwm_fill_info() {
if (!pwm_const)
return 0;
nest = nla_nest_start(skb, IFLA_CAN_XL_PWM);
...
}
Could this mismatch cause can_pwm_fill_info() to write 52 bytes that were not
accounted for by can_get_size() when CAN_CTRLMODE_XL_TMS is disabled?
If so, could this also overflow the skb and cause nla_put() to fail with
-EMSGSIZE, breaking interface notifications and queries like 'ip link show'
for such devices?
--
Sashiko AI review · https://sashiko.dev/#/patchset/tencent_D1C873B86B0E92011A264B0E196B911D5308@qq.com?part=1
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-09-04 17:10 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-04 16:20 [PATCH net] can: netlink: fix IFLA_CAN_BITRATE_MAX attribute sizing Zhu Ling
2026-09-04 16:28 ` sashiko-bot
2026-09-04 17:10 ` zhuling0805
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.