Netdev List
 help / color / mirror / Atom feed
From: Harshit Mogalapalli <harshit.m.mogalapalli@oracle.com>
To: maheshb@google.com, willemdebruijn.kernel@gmail.com,
	jasowangio@gmail.com, andrew+netdev@lunn.ch, davem@davemloft.net,
	edumazet@google.com, kuba@kernel.org, pabeni@redhat.com,
	peterpenkov96@gmail.com, netdev@vger.kernel.org,
	linux-kernel@vger.kernel.org
Cc: kernel-janitors@vger.kernel.org, error27@gmail.com,
	Harshit Mogalapalli <harshit.m.mogalapalli@oracle.com>,
	stable@vger.kernel.org
Subject: [PATCH] tun: fix skb length underflow in NAPI frags path
Date: Sun,  4 Oct 2026 22:42:24 -0700	[thread overview]
Message-ID: <20261005054224.4154727-1-harshit.m.mogalapalli@oracle.com> (raw)

When experimental vhost-net zero-copy TX is used with an IFF_NAPI_FRAGS
TAP backend, tun_get_user() receives msg_control, selects zerocopy, and
limits copylen to the linear prefix.

The NAPI frags path subsequently disables zerocopy after allocating the
skb and copies the complete frame instead. tun_napi_alloc_frags() derives
the linear length from the first iterator segment, so a segment larger
than copylen makes skb->data_len underflow. Pulling the Ethernet header
then triggers BUG() because skb->len is smaller than skb->data_len.

Disable zerocopy before calculating the allocation length so this path
allocates and copies the complete iterator.

Fixes: 90e33d459407 ("tun: enable napi_gro_frags() for TUN/TAP driver")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Harshit Mogalapalli <harshit.m.mogalapalli@oracle.com>
---
 drivers/net/tun.c | 9 ++++-----
 1 file changed, 4 insertions(+), 5 deletions(-)

diff --git a/drivers/net/tun.c b/drivers/net/tun.c
index 5a302709a68a..1124b8b33664 100644
--- a/drivers/net/tun.c
+++ b/drivers/net/tun.c
@@ -1848,6 +1848,10 @@ static ssize_t tun_get_user(struct tun_struct *tun, struct tun_file *tfile,
 			zerocopy = true;
 	}
 
+	/* The NAPI frags path copies the complete iterator. */
+	if (frags)
+		zerocopy = false;
+
 	if (!frags && tun_can_build_skb(tun, tfile, len, noblock, zerocopy)) {
 		/* For the packet that is not easy to be processed
 		 * (e.g gso or jumbo packet), we will do it at after
@@ -1868,11 +1872,6 @@ static ssize_t tun_get_user(struct tun_struct *tun, struct tun_file *tfile,
 		if (frags) {
 			mutex_lock(&tfile->napi_mutex);
 			skb = tun_napi_alloc_frags(tfile, copylen, from);
-			/* tun_napi_alloc_frags() enforces a layout for the skb.
-			 * If zerocopy is enabled, then this layout will be
-			 * overwritten by zerocopy_sg_from_iter().
-			 */
-			zerocopy = false;
 		} else {
 			if (!linear)
 				linear = min_t(size_t, good_linear, copylen);
-- 
2.52.0


             reply	other threads:[~2026-10-05  5:42 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-05  5:42 Harshit Mogalapalli [this message]
2026-10-05  5:48 ` [PATCH] tun: fix skb length underflow in NAPI frags path netdev-bot+sinfo
2026-10-09  5:58 ` netdev-bot+sashiko

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261005054224.4154727-1-harshit.m.mogalapalli@oracle.com \
    --to=harshit.m.mogalapalli@oracle.com \
    --cc=andrew+netdev@lunn.ch \
    --cc=davem@davemloft.net \
    --cc=edumazet@google.com \
    --cc=error27@gmail.com \
    --cc=jasowangio@gmail.com \
    --cc=kernel-janitors@vger.kernel.org \
    --cc=kuba@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=maheshb@google.com \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    --cc=peterpenkov96@gmail.com \
    --cc=stable@vger.kernel.org \
    --cc=willemdebruijn.kernel@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox