All of lore.kernel.org
 help / color / mirror / Atom feed
From: Vadim Fedorenko <vadim.fedorenko@linux.dev>
To: "Anton Protopopov" <a.s.protopopov@gmail.com>,
	"Michael S. Tsirkin" <mst@redhat.com>,
	"Jason Wang" <jasowangio@gmail.com>,
	"Xuan Zhuo" <xuanzhuo@linux.alibaba.com>,
	"Eugenio Pérez" <eperezma@redhat.com>,
	"Andrew Lunn" <andrew+netdev@lunn.ch>,
	"David S. Miller" <davem@davemloft.net>,
	"Eric Dumazet" <edumazet@google.com>,
	"Jakub Kicinski" <kuba@kernel.org>,
	"Paolo Abeni" <pabeni@redhat.com>,
	netdev@vger.kernel.org, virtualization@lists.linux.dev,
	linux-kernel@vger.kernel.org
Subject: Re: [PATCH net] virtio_net: Fix resize of the RX ring
Date: Mon, 10 Aug 2026 14:07:08 +0100	[thread overview]
Message-ID: <2aef652e-d98d-4ca5-8270-5f108e5593a2@linux.dev> (raw)
In-Reply-To: <20260810120728.47445-1-a.s.protopopov@gmail.com>

On 10/08/2026 13:07, Anton Protopopov wrote:
> When a AF_XDP socket is attached, the virtnet_rx_resize
> should resize the rq->xsk_buffs XSK buffer array. Otherwise,
> when the size grows, the virtnet_rx_resume() causes a write
> past the end of the array. This is easily reproducable with
> 
>      ethtool -G ens3 rx 32
>      ./xdpsock -i eth0 -q 0 -r -z &
>      ethtool -G eth0 rx 256
> 
> Fixes: e9f3962441c0 ("virtio_net: xsk: rx: support fill with xsk buffer")
> Signed-off-by: Anton Protopopov <a.s.protopopov@gmail.com>
> ---
>   drivers/net/virtio_net.c | 14 ++++++++++++++
>   1 file changed, 14 insertions(+)
> 
> diff --git a/drivers/net/virtio_net.c b/drivers/net/virtio_net.c
> index 3e2a5876c6c8..e34c52d059d3 100644
> --- a/drivers/net/virtio_net.c
> +++ b/drivers/net/virtio_net.c
> @@ -3444,17 +3444,31 @@ static void virtnet_rx_resume_all(struct virtnet_info *vi)
>   static int virtnet_rx_resize(struct virtnet_info *vi,
>   			     struct receive_queue *rq, u32 ring_num)
>   {
> +	unsigned int old_ring_num = virtqueue_get_vring_size(rq->vq);
> +	struct xdp_buff **tmp_xsk_buffs = NULL;
>   	int err, qindex;
>   
>   	qindex = rq - vi->rq;
>   
> +	if (rq->xsk_pool && ring_num > old_ring_num) {

why do you cover only the case for growing buffer? Don't we expect to
free some memory in case of shrinking? Should be fine given you are
swapping buffers completely...

> +		tmp_xsk_buffs = kvzalloc_objs(*tmp_xsk_buffs, ring_num);
> +		if (!tmp_xsk_buffs)
> +			return -ENOMEM;
> +	}
> +
>   	virtnet_rx_pause(vi, rq);
>   
>   	err = virtqueue_resize(rq->vq, ring_num, virtnet_rq_unmap_free_buf, NULL);
> +
> +	/* virtqueue_resize may have changed the size even if err != 0 */
> +	if (tmp_xsk_buffs && virtqueue_get_vring_size(rq->vq) > old_ring_num)
> +		swap(rq->xsk_buffs, tmp_xsk_buffs);
> +
>   	if (err)
>   		netdev_err(vi->dev, "resize rx fail: rx queue index: %d err: %d\n", qindex, err);
>   
>   	virtnet_rx_resume(vi, rq, true);
> +	kvfree(tmp_xsk_buffs);
>   	return err;
>   }
>   


  reply	other threads:[~2026-08-10 13:07 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-10 12:07 [PATCH net] virtio_net: Fix resize of the RX ring Anton Protopopov
2026-08-10 13:07 ` Vadim Fedorenko [this message]
2026-08-10 13:35   ` Anton Protopopov

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=2aef652e-d98d-4ca5-8270-5f108e5593a2@linux.dev \
    --to=vadim.fedorenko@linux.dev \
    --cc=a.s.protopopov@gmail.com \
    --cc=andrew+netdev@lunn.ch \
    --cc=davem@davemloft.net \
    --cc=edumazet@google.com \
    --cc=eperezma@redhat.com \
    --cc=jasowangio@gmail.com \
    --cc=kuba@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=mst@redhat.com \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    --cc=virtualization@lists.linux.dev \
    --cc=xuanzhuo@linux.alibaba.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.