From: netdev-bot+sashiko@kernel.org
To: josef@toxicpanda.com
Cc: davem@davemloft.net, edumazet@kernel.org, kuba@kernel.org,
pabeni@redhat.com, horms@kernel.org, kaiyuanz@google.com,
almasrymina@google.com, willemb@google.com,
netdev@vger.kernel.org, linux-kernel@vger.kernel.org,
bpf@vger.kernel.org
Subject: Re: [PATCH net-next 5/9] net: skbuff: don't BUG() on leftover length in skb_checksum() and friends
Date: Fri, 09 Oct 2026 08:12:01 +0000 [thread overview]
Message-ID: <179153352121.434549.5341536281761448782@kernel.org> (raw)
In-Reply-To: <20261006-b4-skbuff-bug-on-v1-5-1b4434c5357c@toxicpanda.com>
Thank you for your contribution! Sashiko AI review found more severe
issue(s) in other patches of this series. This mail is only an FYI, in case
you want to address the nit picks below when you respin.
Low priority / nit picks for your consideration:
- [Low] The skb_to_sgvec() kernel-doc in net/core/skbuff.c still says it
"Returns either the number of scatterlist items used, or -EMSGSIZE if…
--
net: skbuff: don't BUG() on leftover length in skb_checksum() and friends
skb_checksum(), skb_crc32c() and __skb_to_sgvec() used to BUG() when
they ran out of skb data before @len was used up. This patch changes
each of them to warn once and return an error instead. __skb_to_sgvec()
now returns -EINVAL, and the two checksum helpers return 0.
> diff --git a/net/core/skbuff.c b/net/core/skbuff.c
> index 6cd7135e0dce2..4070e0c25f63e 100644
> --- a/net/core/skbuff.c
> +++ b/net/core/skbuff.c
[ ... ]
> @@ -5333,7 +5335,8 @@ __skb_to_sgvec(struct sk_buff *skb, struct scatterlist *sg, int offset, int len,
> }
> start = end;
> }
> - BUG_ON(len);
> + if (WARN_ON_ONCE(len))
> + return -EINVAL;
[Severity: Low]
Should the skb_to_sgvec() kernel-doc be updated to match this new return
value? It still lists -EMSGSIZE as the only error:
net/core/skbuff.c:
* Fill the specified scatter-gather list with mappings/pointers into a
* region of the buffer space attached to a socket buffer. Returns either
* the number of scatterlist items used, or -EMSGSIZE if the contents
* could not fit.
*/
int skb_to_sgvec(struct sk_buff *skb, struct scatterlist *sg, int offset, int len)
{
int nsg = __skb_to_sgvec(skb, sg, offset, len, 0);
if (nsg <= 0)
return nsg;
This -EINVAL is also passed up through the frag_list recursion by
"if (unlikely(ret < 0)) return ret;". skb_to_sgvec() and
skb_to_sgvec_nomark() then return it to their callers unchanged.
All in-tree callers check for any negative return, so nothing breaks
today. However, a caller written to the documented contract that only
checks for -EMSGSIZE would miss the new error.
The comment is still unchanged at the end of the series.
> return elt;
> }
>
--
Sashiko AI review · https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20261006-b4-skbuff-bug-on-v1-0-1b4434c5357c%40toxicpanda.com
next prev parent reply other threads:[~2026-10-09 8:12 UTC|newest]
Thread overview: 25+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-06 17:10 [PATCH net-next 0/9] net: skbuff: convert most BUG_ON()s to WARN_ON_ONCE() and an error Josef Bacik
2026-10-06 17:10 ` [PATCH net-next 1/9] net: skbuff: don't leave stale bytes in skb_copy_and_csum_bits() Josef Bacik
2026-10-07 14:50 ` Willem de Bruijn
2026-10-07 17:11 ` sashiko-bot
2026-10-09 8:11 ` netdev-bot+sashiko
2026-10-06 17:10 ` [PATCH net-next 2/9] net: skbuff: don't BUG() on bad arguments to pskb_expand_head() Josef Bacik
2026-10-07 14:51 ` Willem de Bruijn
2026-10-06 17:10 ` [PATCH net-next 3/9] net: skbuff: don't BUG() on a bad frag_list layout in skb_segment() Josef Bacik
2026-10-09 8:12 ` netdev-bot+sashiko
2026-10-09 16:10 ` Mina Almasry
2026-10-06 17:10 ` [PATCH net-next 4/9] net: skbuff: don't BUG() when skb_copy_bits() fails in copy helpers Josef Bacik
2026-10-06 17:10 ` [PATCH net-next 5/9] net: skbuff: don't BUG() on leftover length in skb_checksum() and friends Josef Bacik
2026-10-09 8:12 ` netdev-bot+sashiko [this message]
2026-10-09 16:27 ` Mina Almasry
2026-10-06 17:10 ` [PATCH net-next 6/9] net: skbuff: don't BUG() on a bad csum_start in skb_copy_and_csum_dev() Josef Bacik
2026-10-09 8:12 ` netdev-bot+sashiko
2026-10-06 17:10 ` [PATCH net-next 7/9] net: skbuff: don't BUG() on leftover length in skb_copy_and_csum_bits() Josef Bacik
2026-10-07 17:11 ` sashiko-bot
2026-10-09 8:12 ` netdev-bot+sashiko
2026-10-06 17:10 ` [PATCH net-next 8/9] net: skbuff: don't BUG() on a missing head_frag in skb_zerocopy() Josef Bacik
2026-10-09 8:12 ` netdev-bot+sashiko
2026-10-09 16:11 ` Mina Almasry
2026-10-06 17:10 ` [PATCH net-next 9/9] net: skbuff: remove the BUG_ON()s from skb_shift() Josef Bacik
2026-10-07 14:48 ` [PATCH net-next 0/9] net: skbuff: convert most BUG_ON()s to WARN_ON_ONCE() and an error Willem de Bruijn
2026-10-07 14:59 ` Fernando Fernandez Mancera
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=179153352121.434549.5341536281761448782@kernel.org \
--to=netdev-bot+sashiko@kernel.org \
--cc=almasrymina@google.com \
--cc=bpf@vger.kernel.org \
--cc=davem@davemloft.net \
--cc=edumazet@kernel.org \
--cc=horms@kernel.org \
--cc=josef@toxicpanda.com \
--cc=kaiyuanz@google.com \
--cc=kuba@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=willemb@google.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox