All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH net] can: netlink: fix IFLA_CAN_BITRATE_MAX attribute sizing
@ 2026-09-04 16:20 Zhu Ling
  2026-09-04 16:28 ` sashiko-bot
  0 siblings, 1 reply; 3+ messages in thread
From: Zhu Ling @ 2026-09-04 16:20 UTC (permalink / raw)
  To: linux-can
  Cc: mkl, mailhol, nsekhar, faiz_abbas, s-anna, fcooper, linux-kernel,
	Zhu Ling, stable

can_fill_info() emits IFLA_CAN_BITRATE_MAX with nla_put(), which consumes
space for both the attribute header and its aligned payload. However,
can_get_size() accounts for the payload only. The resulting underestimate
can make filling the netlink response fail with -EMSGSIZE when the skb has
no remaining slack.

Use nla_total_size() to account for the complete attribute.

Fixes: 2290aefa2e90 ("can: dev: Add support for limiting configured bitrate")
Cc: stable@vger.kernel.org
Signed-off-by: Zhu Ling <zhuling0805@qq.com>
---
 drivers/net/can/dev/netlink.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/net/can/dev/netlink.c b/drivers/net/can/dev/netlink.c
index 766d455950f5..ba26c61a82c2 100644
--- a/drivers/net/can/dev/netlink.c
+++ b/drivers/net/can/dev/netlink.c
@@ -822,7 +822,7 @@ static size_t can_get_size(const struct net_device *dev)
 	if (priv->bitrate_const)				/* IFLA_CAN_BITRATE_CONST */
 		size += nla_total_size(sizeof(*priv->bitrate_const) *
 				       priv->bitrate_const_cnt);
-	size += sizeof(priv->bitrate_max);			/* IFLA_CAN_BITRATE_MAX */
+	size += nla_total_size(sizeof(priv->bitrate_max));	/* IFLA_CAN_BITRATE_MAX */
 	size += can_ctrlmode_ext_get_size();			/* IFLA_CAN_CTRLMODE_EXT */
 
 	size += can_data_bittiming_get_size(&priv->fd,

base-commit: 641d03105cc0d2437e32fdeec164f91a4ccef6c4
-- 
2.43.0


^ permalink raw reply related	[flat|nested] 3+ messages in thread

* Re: [PATCH net] can: netlink: fix IFLA_CAN_BITRATE_MAX attribute sizing
  2026-09-04 16:20 [PATCH net] can: netlink: fix IFLA_CAN_BITRATE_MAX attribute sizing Zhu Ling
@ 2026-09-04 16:28 ` sashiko-bot
  2026-09-04 17:10   ` zhuling0805
  0 siblings, 1 reply; 3+ messages in thread
From: sashiko-bot @ 2026-09-04 16:28 UTC (permalink / raw)
  To: Zhu Ling
  Cc: Oliver Hartkopp, Vincent Mailhol, Marc Kleine-Budde, linux-can,
	Oleksij Rempel

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [High] Pre-existing netlink payload size underestimation in `can_pwm_get_size()` when PWM capabilities exist but `CAN_CTRLMODE_XL_TMS` is disabled, leading to `-EMSGSIZE` when filling the response.
--

commit 9a3cf7f66d6ea7a9d4aba48ff7c5376d72db7fe3
Author: Zhu Ling <zhuling0805@qq.com>

can: netlink: fix IFLA_CAN_BITRATE_MAX attribute sizing

This commit fixes an issue in can_get_size() where the size for
IFLA_CAN_BITRATE_MAX was missing the netlink attribute header overhead. By
using nla_total_size(), it prevents -EMSGSIZE errors when the skb has no slack
left.

> diff --git a/drivers/net/can/dev/netlink.c b/drivers/net/can/dev/netlink.c
> index 766d455950f55..ba26c61a82c2f 100644
> --- a/drivers/net/can/dev/netlink.c
> +++ b/drivers/net/can/dev/netlink.c
> @@ -822,7 +822,7 @@ static size_t can_get_size(const struct net_device *dev)
>  	if (priv->bitrate_const)				/* IFLA_CAN_BITRATE_CONST */
>  		size += nla_total_size(sizeof(*priv->bitrate_const) *
>  				       priv->bitrate_const_cnt);
> -	size += sizeof(priv->bitrate_max);			/* IFLA_CAN_BITRATE_MAX */
> +	size += nla_total_size(sizeof(priv->bitrate_max));	/* IFLA_CAN_BITRATE_MAX */
>  	size += can_ctrlmode_ext_get_size();			/* IFLA_CAN_CTRLMODE_EXT */
>  
>  	size += can_data_bittiming_get_size(&priv->fd,

[Severity: High]
This isn't a bug introduced by this patch, but while looking at
can_get_size(), I noticed another potential size underestimation just below
this diff in can_pwm_get_size():

drivers/net/can/dev/netlink.c:can_pwm_get_size() {
	if (!pwm_const || !pwm_on)
		return 0;
	...
}

If a CAN interface has hardware PWM support (pwm_const is non-NULL) but PWM is
currently disabled (pwm_on is false), can_pwm_get_size() returns 0.

However, can_pwm_fill_info() only checks pwm_const:

drivers/net/can/dev/netlink.c:can_pwm_fill_info() {
	if (!pwm_const)
		return 0;

	nest = nla_nest_start(skb, IFLA_CAN_XL_PWM);
	...
}

Could this mismatch cause can_pwm_fill_info() to write 52 bytes that were not
accounted for by can_get_size() when CAN_CTRLMODE_XL_TMS is disabled?

If so, could this also overflow the skb and cause nla_put() to fail with
-EMSGSIZE, breaking interface notifications and queries like 'ip link show'
for such devices?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/tencent_D1C873B86B0E92011A264B0E196B911D5308@qq.com?part=1

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH net] can: netlink: fix IFLA_CAN_BITRATE_MAX attribute sizing
  2026-09-04 16:28 ` sashiko-bot
@ 2026-09-04 17:10   ` zhuling0805
  0 siblings, 0 replies; 3+ messages in thread
From: zhuling0805 @ 2026-09-04 17:10 UTC (permalink / raw)
  To: sashiko-reviews
  Cc: Oliver Hartkopp, Vincent Mailhol, Marc Kleine-Budde, linux-can,
	Oleksij Rempel

Thanks for the review.

Yes, this is a pre-existing issue independent of the
IFLA_CAN_BITRATE_MAX sizing fix. It has already been addressed in the
separate patch:

[PATCH net] can: netlink: fix CAN XL PWM attribute sizing

https://lore.kernel.org/all/tencent_9A525E0656A4F7D4CA9CFA1AB1A4BFC6D706@qq.com/

No changes are needed for this patch.

Regards,
Zhu



原始邮件
发件人:sashiko-bot <sashiko-bot@kernel.org>
发件时间:2026年9月5日 00:28
收件人:Zhu Ling <zhuling0805@qq.com>
抄送:Oliver Hartkopp <socketcan@hartkopp.net>, Vincent Mailhol <mailhol@kernel.org>, Marc Kleine-Budde <mkl@pengutronix.de>, linux-can <linux-can@vger.kernel.org>, Oleksij Rempel <o.rempel@pengutronix.de>
主题:Re: [PATCH net] can: netlink: fix IFLA_CAN_BITRATE_MAX attribute sizing


Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [High] Pre-existing netlink payload size underestimation in `can_pwm_get_size()` when PWM capabilities exist but `CAN_CTRLMODE_XL_TMS` is disabled, leading to `-EMSGSIZE` when filling the response.
--

commit 9a3cf7f66d6ea7a9d4aba48ff7c5376d72db7fe3
Author: Zhu Ling <zhuling0805@qq.com>

can: netlink: fix IFLA_CAN_BITRATE_MAX attribute sizing

This commit fixes an issue in can_get_size() where the size for
IFLA_CAN_BITRATE_MAX was missing the netlink attribute header overhead. By
using nla_total_size(), it prevents -EMSGSIZE errors when the skb has no slack
left.

> diff --git a/drivers/net/can/dev/netlink.c b/drivers/net/can/dev/netlink.c
> index 766d455950f55..ba26c61a82c2f 100644
> --- a/drivers/net/can/dev/netlink.c
> +++ b/drivers/net/can/dev/netlink.c
> @@ -822,7 +822,7 @@ static size_t can_get_size(const struct net_device *dev)
>   if (priv->bitrate_const) /* IFLA_CAN_BITRATE_CONST */
>   size += nla_total_size(sizeof(*priv->bitrate_const) *
>          priv->bitrate_const_cnt);
> - size += sizeof(priv->bitrate_max); /* IFLA_CAN_BITRATE_MAX */
> + size += nla_total_size(sizeof(priv->bitrate_max)); /* IFLA_CAN_BITRATE_MAX */
>   size += can_ctrlmode_ext_get_size(); /* IFLA_CAN_CTRLMODE_EXT */
>  
>   size += can_data_bittiming_get_size(&priv->fd,

[Severity: High]
This isn't a bug introduced by this patch, but while looking at
can_get_size(), I noticed another potential size underestimation just below
this diff in can_pwm_get_size():

drivers/net/can/dev/netlink.c:can_pwm_get_size() {
if (!pwm_const || !pwm_on)
return 0;
...
}

If a CAN interface has hardware PWM support (pwm_const is non-NULL) but PWM is
currently disabled (pwm_on is false), can_pwm_get_size() returns 0.

However, can_pwm_fill_info() only checks pwm_const:

drivers/net/can/dev/netlink.c:can_pwm_fill_info() {
if (!pwm_const)
return 0;

nest = nla_nest_start(skb, IFLA_CAN_XL_PWM);
...
}

Could this mismatch cause can_pwm_fill_info() to write 52 bytes that were not
accounted for by can_get_size() when CAN_CTRLMODE_XL_TMS is disabled?

If so, could this also overflow the skb and cause nla_put() to fail with
-EMSGSIZE, breaking interface notifications and queries like 'ip link show'
for such devices?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/tencent_D1C873B86B0E92011A264B0E196B911D5308@qq.com?part=1


^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-09-04 17:10 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-04 16:20 [PATCH net] can: netlink: fix IFLA_CAN_BITRATE_MAX attribute sizing Zhu Ling
2026-09-04 16:28 ` sashiko-bot
2026-09-04 17:10   ` zhuling0805

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.