The Linux Kernel Mailing List
 help / color / mirror / Atom feed
* [PATCH net v2 1/3] net: core: propagate unreadable flag in skb_zerocopy
@ 2026-08-03 17:14 Mina Almasry
  2026-08-03 17:14 ` [PATCH net v2 2/3] net: devmem: return EMSGSIZE on type mismatch Mina Almasry
                   ` (2 more replies)
  0 siblings, 3 replies; 9+ messages in thread
From: Mina Almasry @ 2026-08-03 17:14 UTC (permalink / raw)
  To: netdev, linux-kernel
  Cc: davem, edumazet, kuba, pabeni, horms, kerneljasonxing, kuniyu,
	bjorn, jiayuan.chen, kaiyuanz, willemb, asml.silence, sdf,
	bobbyeshleman, fw, Mina Almasry, Neal Cardwell, Ralf Lici,
	Will Deacon

When skb_zerocopy() copies devmem payload fragments, it fails to update
the target skb's unreadable flag. This causes the target to appear as
readable memory.

Propagate the unreadable flag if any devmem fragments were copied from
the source.

Additionally, to prevent memory corruption, explicitly return -EFAULT
if standard payload from the head is mixed into the same skb alongside
unreadable devmem fragments during a head-to-frag extraction.

Fixes: 65249feb6b3d ("net: add support for skbs with unreadable frags")
Cc: Pavel Begunkov <asml.silence@gmail.com>
Cc: Stanislav Fomichev <sdf@fomichev.me>
Cc: Bobby Eshleman <bobbyeshleman@gmail.com>
Cc: Florian Westphal <fw@strlen.de>
Signed-off-by: Mina Almasry <almasrymina@google.com>
Reviewed-by: Pavel Begunkov <asml.silence@gmail.com>

---
v2:
- Return -EFAULT when mixing head-to-frag unreadable/readable frags to prevent memory corruption (Pavel).
v1: https://lore.kernel.org/r/20260801125308.1342897-1-almasrymina@google.com
---
 net/core/skbuff.c | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/net/core/skbuff.c b/net/core/skbuff.c
index ba3dbac80fb49..8bacc6c4e16e1 100644
--- a/net/core/skbuff.c
+++ b/net/core/skbuff.c
@@ -3905,6 +3905,9 @@ skb_zerocopy(struct sk_buff *to, struct sk_buff *from, int len, int hlen)
 		}
 	}
 
+	if (!skb_frags_readable(from) && j > 0 && len)
+		return -EFAULT;
+
 	skb_len_add(to, len + plen);
 
 	if (unlikely(skb_orphan_frags(from, GFP_ATOMIC))) {
@@ -3928,6 +3931,9 @@ skb_zerocopy(struct sk_buff *to, struct sk_buff *from, int len, int hlen)
 	}
 	skb_shinfo(to)->nr_frags = j;
 
+	if (i > 0 && from->unreadable)
+		to->unreadable = 1;
+
 	return 0;
 }
 EXPORT_SYMBOL_GPL(skb_zerocopy);

base-commit: af39eb111ce6b5eba9c08513b62c4868eb7e7fd5
-- 
2.55.0.571.g244d577d93-goog


^ permalink raw reply related	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2026-08-04 21:38 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-03 17:14 [PATCH net v2 1/3] net: core: propagate unreadable flag in skb_zerocopy Mina Almasry
2026-08-03 17:14 ` [PATCH net v2 2/3] net: devmem: return EMSGSIZE on type mismatch Mina Almasry
2026-08-03 17:32   ` Bobby Eshleman
2026-08-03 19:54   ` Jakub Kicinski
2026-08-04 15:36     ` Mina Almasry
2026-08-04 21:38       ` Jakub Kicinski
2026-08-03 17:14 ` [PATCH net v2 3/3] net: tcp: block standard payload injection into devmem skbs Mina Almasry
2026-08-03 17:35   ` Bobby Eshleman
2026-08-03 17:31 ` [PATCH net v2 1/3] net: core: propagate unreadable flag in skb_zerocopy Bobby Eshleman

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox