From: "Morten Brørup" <mb@smartsharesystems.com>
To: Stephen Hemminger <stephen@networkplumber.org>, dev@dpdk.org
Cc: stable@dpdk.org, "Morten Brørup" <mb@smartsharesystems.com>,
"Konstantin Ananyev" <konstantin.ananyev@huawei.com>
Subject: [PATCH v3] mbuf: fix packet copy
Date: Tue, 20 Jan 2026 07:24:14 +0000 [thread overview]
Message-ID: <20260120072414.465240-1-mb@smartsharesystems.com> (raw)
In-Reply-To: <20251119120403.907511-1-mb@smartsharesystems.com>
mbuf: fix packet copy
Requests for copying the at the end of a packet incorrectly returned NULL,
as if copying past the end of a packet.
When allocating the mbuf for the copy from a mempool using pinned external
buffers, the external flag in this mbuf was not preserved.
Fixes: c3a90c381daa ("mbuf: add a copy routine")
Signed-off-by: Morten Brørup <mb@smartsharesystems.com>
Acked-by: Konstantin Ananyev <konstantin.ananyev@huawei.com>
---
v3:
* Improved comment about flags being copied from newly allocated mbuf.
* Added test cases for copying at and past end of packet. (Stephen)
v2:
* Improved comment about preserving flags for newly allocated mbuf
potentially using pinned external buffer.
* Added missing spaces in expression. (Stephen)
---
app/test/test_mbuf.c | 20 ++++++++++++++++++++
lib/mbuf/rte_mbuf.c | 10 +++++++---
2 files changed, 27 insertions(+), 3 deletions(-)
diff --git a/app/test/test_mbuf.c b/app/test/test_mbuf.c
index 17be977f31..19b49cec12 100644
--- a/app/test/test_mbuf.c
+++ b/app/test/test_mbuf.c
@@ -541,6 +541,26 @@ test_pktmbuf_copy(struct rte_mempool *pktmbuf_pool,
rte_pktmbuf_free(copy2);
+ /* test offset copy at the end */
+ copy2 = rte_pktmbuf_copy(copy, pktmbuf_pool,
+ 2 * sizeof(uint32_t), UINT32_MAX);
+ if (copy2 == NULL)
+ GOTO_FAIL("cannot copy at the end of the copy\n");
+
+ if (rte_pktmbuf_pkt_len(copy2) != 0)
+ GOTO_FAIL("copy at the end, length incorrect\n");
+
+ if (rte_pktmbuf_data_len(copy2) != 0)
+ GOTO_FAIL("copy at the end, data length incorrect\n");
+
+ rte_pktmbuf_free(copy2);
+
+ /* test offset copy past the end */
+ copy2 = rte_pktmbuf_copy(copy, pktmbuf_pool,
+ 2 * sizeof(uint32_t) + 1, UINT32_MAX);
+ if (copy2 != NULL)
+ GOTO_FAIL("can copy past the end of the copy\n");
+
/* test truncation copy */
copy2 = rte_pktmbuf_copy(copy, pktmbuf_pool,
0, sizeof(uint32_t));
diff --git a/lib/mbuf/rte_mbuf.c b/lib/mbuf/rte_mbuf.c
index 0d931c7a15..a5d16e4c97 100644
--- a/lib/mbuf/rte_mbuf.c
+++ b/lib/mbuf/rte_mbuf.c
@@ -675,7 +675,7 @@ rte_pktmbuf_copy(const struct rte_mbuf *m, struct rte_mempool *mp,
__rte_mbuf_sanity_check(m, 1);
/* check for request to copy at offset past end of mbuf */
- if (unlikely(off >= m->pkt_len))
+ if (unlikely(off > m->pkt_len))
return NULL;
mc = rte_pktmbuf_alloc(mp);
@@ -688,8 +688,12 @@ rte_pktmbuf_copy(const struct rte_mbuf *m, struct rte_mempool *mp,
__rte_pktmbuf_copy_hdr(mc, m);
- /* copied mbuf is not indirect or external */
- mc->ol_flags = m->ol_flags & ~(RTE_MBUF_F_INDIRECT|RTE_MBUF_F_EXTERNAL);
+ /*
+ * copy flags except indirect and external,
+ * while preserving flags of newly allocated mbuf
+ * (specifically RTE_MBUF_F_EXTERNAL if using pinned external buffer)
+ */
+ mc->ol_flags |= m->ol_flags & ~(RTE_MBUF_F_INDIRECT | RTE_MBUF_F_EXTERNAL);
prev = &mc->next;
m_last = mc;
--
2.43.0
next prev parent reply other threads:[~2026-01-20 7:24 UTC|newest]
Thread overview: 18+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-11-19 12:04 [PATCH] mbuf: fix packet copy Morten Brørup
2025-11-24 13:35 ` Morten Brørup
2025-11-28 10:50 ` Morten Brørup
2025-12-18 16:12 ` Morten Brørup
2026-01-03 17:46 ` Morten Brørup
2026-01-11 15:19 ` Konstantin Ananyev
2026-01-11 17:43 ` Morten Brørup
2026-01-12 10:56 ` Konstantin Ananyev
2026-01-12 10:58 ` Konstantin Ananyev
2026-01-16 11:16 ` [PATCH v2] " Morten Brørup
2026-01-16 17:06 ` Stephen Hemminger
2026-01-16 17:16 ` Morten Brørup
2026-01-16 17:18 ` Stephen Hemminger
2026-01-20 7:24 ` Morten Brørup [this message]
2026-02-10 17:21 ` [PATCH v3] " Thomas Monjalon
2026-02-25 15:58 ` Kevin Traynor
2026-02-25 17:17 ` Morten Brørup
2026-02-26 10:01 ` Kevin Traynor
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260120072414.465240-1-mb@smartsharesystems.com \
--to=mb@smartsharesystems.com \
--cc=dev@dpdk.org \
--cc=konstantin.ananyev@huawei.com \
--cc=stable@dpdk.org \
--cc=stephen@networkplumber.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox