All of lore.kernel.org
 help / color / mirror / Atom feed
From: Lorenzo Bianconi <lorenzo@kernel.org>
To: Matt Fleming <matt@readmodwrite.com>
Cc: "Alexei Starovoitov" <ast@kernel.org>,
	"Daniel Borkmann" <daniel@iogearbox.net>,
	"Andrew Lunn" <andrew+netdev@lunn.ch>,
	"David S . Miller" <davem@davemloft.net>,
	"Eric Dumazet" <edumazet@google.com>,
	"Jakub Kicinski" <kuba@kernel.org>,
	"Paolo Abeni" <pabeni@redhat.com>,
	"Simon Horman" <horms@kernel.org>,
	"Jesper Dangaard Brouer" <hawk@kernel.org>,
	"John Fastabend" <john.fastabend@gmail.com>,
	"Stanislav Fomichev" <sdf@fomichev.me>,
	"Toke Høiland-Jørgensen" <toke@toke.dk>,
	bpf@vger.kernel.org, netdev@vger.kernel.org,
	stable@vger.kernel.org, kernel-team@cloudflare.com,
	"Matt Fleming" <mfleming@cloudflare.com>
Subject: Re: [PATCH bpf v2] veth: convert frag_list skbs before running XDP
Date: Tue, 21 Jul 2026 12:05:45 +0200	[thread overview]
Message-ID: <al9EeXMW9Mi-YDZZ@lore-desk> (raw)
In-Reply-To: <20260720140545.461747-1-matt@readmodwrite.com>

[-- Attachment #1: Type: text/plain, Size: 3615 bytes --]

> From: Matt Fleming <mfleming@cloudflare.com>
> 
> A frag_list skb can reach veth with data_len set but nr_frags zero.
> veth_convert_skb_to_xdp_buff() only converts skbs that are shared,
> locked, have frags[], or do not have enough headroom. It later uses
> skb_is_nonlinear() to decide whether to set XDP_FLAGS_HAS_FRAGS and
> xdp_frags_size.
> 
> That exposes frag_list data to XDP as if it were stored in frags[], but
> frags[] is empty. AF_XDP copy mode can then trust the bogus XDP fragment
> metadata, walk an empty fragment entry, and crash in memcpy() from
> __xsk_rcv().
> 
> Route non-linear skbs through skb_pp_cow_data() before exposing them to
> XDP, and only advertise XDP frags when the resulting skb has frags[].
> skb_copy_bits() already handles frag_list input, and skb_pp_cow_data()
> builds frags[] output with skb_add_rx_frag(), which is the
> representation XDP multi-buffer expects.
> 
> Fixes: 718a18a0c8a6 ("veth: Rework veth_xdp_rcv_skb in order to accept non-linear skb")
> Cc: stable@vger.kernel.org
> Signed-off-by: Matt Fleming <mfleming@cloudflare.com>

Acked-by: Lorenzo Bianconi <lorenzo@kernel.org>

> ---
> Changes in v2:
> - Use skb_is_nonlinear() in veth_convert_skb_to_xdp_buff().
> - Move the skb_pp_cow_data() comment into kerneldoc.
> 
>  drivers/net/veth.c |  4 ++--
>  net/core/skbuff.c  | 16 ++++++++++------
>  2 files changed, 12 insertions(+), 8 deletions(-)
> 
> diff --git a/drivers/net/veth.c b/drivers/net/veth.c
> index 1c5142149175..00e34afd858e 100644
> --- a/drivers/net/veth.c
> +++ b/drivers/net/veth.c
> @@ -756,7 +756,7 @@ static int veth_convert_skb_to_xdp_buff(struct veth_rq *rq,
>  	u32 frame_sz;
>  
>  	if (skb_shared(skb) || skb_head_is_locked(skb) ||
> -	    skb_shinfo(skb)->nr_frags ||
> +	    skb_is_nonlinear(skb) ||
>  	    skb_headroom(skb) < XDP_PACKET_HEADROOM) {
>  		if (skb_pp_cow_data(rq->page_pool, pskb, XDP_PACKET_HEADROOM))
>  			goto drop;
> @@ -771,7 +771,7 @@ static int veth_convert_skb_to_xdp_buff(struct veth_rq *rq,
>  	xdp_prepare_buff(xdp, skb->head, skb_headroom(skb),
>  			 skb_headlen(skb), true);
>  
> -	if (skb_is_nonlinear(skb)) {
> +	if (skb_shinfo(skb)->nr_frags) {
>  		skb_shinfo(skb)->xdp_frags_size = skb->data_len;
>  		xdp_buff_set_frags_flag(xdp);
>  	} else {
> diff --git a/net/core/skbuff.c b/net/core/skbuff.c
> index 18dabb4e9cfa..66f57131633a 100644
> --- a/net/core/skbuff.c
> +++ b/net/core/skbuff.c
> @@ -927,6 +927,16 @@ static void skb_clone_fraglist(struct sk_buff *skb)
>  		skb_get(list);
>  }
>  
> +/**
> + * skb_pp_cow_data() - copy skb data into page-pool backed storage
> + * @pool: page pool to allocate from
> + * @pskb: pointer to skb pointer, replaced with the copied skb on success
> + * @headroom: headroom to reserve in the copied skb
> + *
> + * skb_copy_bits() handles both frags[] and frag_list input. If the copied
> + * skb remains non-linear, it uses frags[], which is the representation used
> + * by XDP multi-buffer.
> + */
>  int skb_pp_cow_data(struct page_pool *pool, struct sk_buff **pskb,
>  		    unsigned int headroom)
>  {
> @@ -936,12 +946,6 @@ int skb_pp_cow_data(struct page_pool *pool, struct sk_buff **pskb,
>  	int err, i, head_off;
>  	void *data;
>  
> -	/* XDP does not support fraglist so we need to linearize
> -	 * the skb.
> -	 */
> -	if (skb_has_frag_list(skb))
> -		return -EOPNOTSUPP;
> -
>  	max_head_size = SKB_WITH_OVERHEAD(PAGE_SIZE - headroom);
>  	if (skb->len > max_head_size + MAX_SKB_FRAGS * PAGE_SIZE)
>  		return -ENOMEM;
> -- 
> 2.43.0
> 

[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 228 bytes --]

  parent reply	other threads:[~2026-07-21 10:05 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-20 14:05 [PATCH bpf v2] veth: convert frag_list skbs before running XDP Matt Fleming
2026-07-20 14:18 ` sashiko-bot
2026-07-21 11:11   ` Maciej Fijalkowski
2026-07-20 20:28 ` Toke Høiland-Jørgensen
2026-07-21 10:05 ` Lorenzo Bianconi [this message]
2026-07-21 16:50 ` patchwork-bot+netdevbpf
2026-07-21 21:14   ` Jakub Kicinski
2026-07-21 21:28     ` Kumar Kartikeya Dwivedi

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=al9EeXMW9Mi-YDZZ@lore-desk \
    --to=lorenzo@kernel.org \
    --cc=andrew+netdev@lunn.ch \
    --cc=ast@kernel.org \
    --cc=bpf@vger.kernel.org \
    --cc=daniel@iogearbox.net \
    --cc=davem@davemloft.net \
    --cc=edumazet@google.com \
    --cc=hawk@kernel.org \
    --cc=horms@kernel.org \
    --cc=john.fastabend@gmail.com \
    --cc=kernel-team@cloudflare.com \
    --cc=kuba@kernel.org \
    --cc=matt@readmodwrite.com \
    --cc=mfleming@cloudflare.com \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    --cc=sdf@fomichev.me \
    --cc=stable@vger.kernel.org \
    --cc=toke@toke.dk \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.