From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qt1-f180.google.com (mail-qt1-f180.google.com [209.85.160.180]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1DC4A3BB685 for ; Wed, 7 Oct 2026 17:36:19 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.160.180 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1791394582; cv=none; b=Gr3YnktQzZyjPhOa0B5m2KIjnXGVtvEi/dg2x26hAooInLgAi+qjxW5EvlaVwdQLkLBxnHKsHM6AAnHo9q4yBQ38OaddFM7fhDeesYcWdbk9NgOKqkssA3ukbDn8qVCRQMYBzZ9RcOts/hX0nSS8EJOFYtXunbsq/NN4s4GCEQs= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1791394582; c=relaxed/simple; bh=7/5tfJIy6W8TIdl9hZooAFhzBT+2SjfY6Wr1A0j34NI=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=uO27jjLFokuLhdV3Jv/Qt5Sx3ehmmsVaelP8mfsQZuHnKsdPrZbxLOoOyMaGj2OUoujZPyCiB18UZB/JA0Z4eFAekbhboAAt/IWIdObBI40f6MYJTiTGHEygPTVCT+pzgUS4hHqVzhGksuUGz6LSDMgsPl8I6j4IpD6bXld//pc= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=toxicpanda.com; spf=pass smtp.mailfrom=toxicpanda.com; dkim=pass (2048-bit key) header.d=toxicpanda.com header.i=@toxicpanda.com header.b=Ob00tajF; arc=none smtp.client-ip=209.85.160.180 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=toxicpanda.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=toxicpanda.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=toxicpanda.com header.i=@toxicpanda.com header.b="Ob00tajF" Received: by mail-qt1-f180.google.com with SMTP id d75a77b69052e-5351748222cso34184161cf.1 for ; Wed, 07 Oct 2026 10:36:19 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=toxicpanda.com; s=google; t=1791394578; x=1791999378; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=zrdwjfjy+S8tMtuXsIClvdWbR7PzRWTgUMrLZvnePDM=; b=Ob00tajFE580Nl/3pAL8HWGKONucJT/gc9PBUPGBgXk8LoBoHSZMDZQY33SgxzVzgB ElNtz4FyH48sfQKFUWfilxrbuo0QvhtQVXGFdbDmuHUOMjW5BC42aFW+Hv8b5aCtj5Bf 1YTz1mrlar5hcUrzmJvx6eEYoaP193rvzncOurKpmW4sg/MYZIsKJzTnG3ows13le49o e5NWOzw8a3qs+lJ8Qdrjzms0sc1gapMUOLfBONMaVZCJz35UggsKt17TJ8gjDTyIw408 Euk/lJLOf8UW9m79Uh/7/5N9ff2ODUmLa9nQ/kllnF/AOaJ//bOniTs4SeSFnGWXyCJ+ xLOw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791394578; x=1791999378; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=zrdwjfjy+S8tMtuXsIClvdWbR7PzRWTgUMrLZvnePDM=; b=TCcNqkEOIv2IZ3msa/TTvRkIQ7J8ym393cW4mWIaoFF55BPl7MDGhFL4mXPQ7KKKHP a+k9n07NnUqyocHjhNBiHmtQ50OuRCOCU81ucqpGFGmtS/L55pUgELO5jA0QkDZ9QjLj jWmKUfL9hWtbJoa/T9H6V15L2MjLHQXg8IwiSluNRjUGJmzDJMDii5GoGpwvT9MvGScT 91RwiiFCuAx17Ts0r5MNFVxzUrxml75y3UChJewh4KnjfhnKvS8+/QH02H3whnfUNHcT jZ7izIhLaKEGJYfpfN9V1bgvBRxbpa62F8pVektXwj6xTgqmLlOgeCpcKWO60Qa0JRSg 5aHA== X-Gm-Message-State: AFuF++kpXA1Mxtcx9CV6VQOIMB+ik/Tln3As92m0dyAoUsu88Lxyz7sk znSAyMdwpHNUmlukJ0mkW4Pf9yr7eTnnhyiGgYIJ37EDM2O6T/dLZd4T0coTK8c3HBUdMQ70XkB fFzlWGEg= X-Gm-Gg: AYBFou3iXNqlQy3epqonXzj969RMopAFZUsTZiFRZ5piKmYDxW65PGzasDWEuNIDfxS pI1w8XIBJuXhrH1j5XOm2PUZxFfbOZDM0VCYsyX4cvfZ8Jxp4qM4yDscS7TmU6V1e/JWQKXa6wu tFHC+r7ldVkpSN+WxMg5tVxJlUW6iUcDTNrneCKVUMFZgYQlv6fRK97XH3pjv6I0zebrGWrcKRF JDEXoLoS+tr5dQV1G//e6LDslLH8pKjhKzM+8EO+KB5uF8GcMB4HfIFZ0mqh5ysxCnLS1Pa8Vly 4H+ITTZyrmBmF/rOPOn8RJUGDZ4RMJaW934iuv1w6v7g7e2n9PMn4lTrYMelwekAv9ZQsh8371O lqTmMC3jOwnue+txibcEB4GFiiWWtDw28I7LknW19x5eI70xgfqEK/64lvRdKAIOIpYKo5sc5Fq ZbnB5IpFb+kaaSMi0Xh5B3/3MDQFFJKK6fZoBPR4pDSRLhgeGJdNVfqnsJoVM2PY4K6yhQqfkTF PgeH7eGPRTLAJc= X-Received: by 2002:a05:622a:418f:b0:533:2bf3:3301 with SMTP id d75a77b69052e-53575501674mr46954561cf.36.1791394577888; Wed, 07 Oct 2026 10:36:17 -0700 (PDT) Received: from toxicpanda.com ([153.61.196.250]) by smtp.gmail.com with ESMTPSA id d75a77b69052e-5357213f3dcsm24583961cf.17.2026.10.07.10.36.17 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 07 Oct 2026 10:36:17 -0700 (PDT) From: Josef Bacik Date: Wed, 07 Oct 2026 17:36:02 +0000 Subject: [PATCH net-next v2 3/8] net: skbuff: don't BUG() when skb_copy_bits() fails in copy helpers Precedence: bulk X-Mailing-List: netdev@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 7bit Message-Id: <20261007-b4-skbuff-bug-on-v2-3-b9a5f732895b@toxicpanda.com> References: <20261007-b4-skbuff-bug-on-v2-0-b9a5f732895b@toxicpanda.com> In-Reply-To: <20261007-b4-skbuff-bug-on-v2-0-b9a5f732895b@toxicpanda.com> To: "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman Cc: netdev@vger.kernel.org, linux-kernel@vger.kernel.org, bpf@vger.kernel.org, Josef Bacik X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=openssh-sha256; t=1791394570; l=2620; i=josef@toxicpanda.com; h=from:subject:message-id; bh=7/5tfJIy6W8TIdl9hZooAFhzBT+2SjfY6Wr1A0j34NI=; b=U1NIU0lHAAAAAQAAADMAAAALc3NoLWVkMjU1MTkAAAAgUBr36M/n0nWN0DNbnxwzIiCZez6MG JiruuNaSCI/zXsAAAAGcGF0YXR0AAAAAAAAAAZzaGE1MTIAAABTAAAAC3NzaC1lZDI1NTE5AAAA QG8qkTVUA4W+CHYi4hSjchPweqAtKNSPPJ2+IFTy68VmnoeA4rzJ6nve29AghKY4OXbgedSHcU1 ZI3SHq1Y+CQI= X-Developer-Key: i=josef@toxicpanda.com; a=openssh; fpr=SHA256:C8kOX2QUJCMqnCX+KEeoqRAjLo9L+ELOSH2NSAJHqGA skb_copy(), skb_copy_expand() and skb_try_coalesce() all BUG() if skb_copy_bits() fails. skb_copy_bits() only fails when the skb's lengths don't add up, which is a bug somewhere else, usually in a driver building the skb. Each of these functions already has a failure return its callers handle: - skb_copy() and skb_copy_expand() free the new skb and return NULL, as they do when the allocation fails. - skb_try_coalesce() returns false and the caller keeps the skbs separate. Copy into the tailroom before skb_put() so that @to is untouched on failure. Take those returns, with a DEBUG_NET_WARN_ON_ONCE() for debug kernels. __pskb_pull_tail() has the same BUG_ON(), but several of its callers can't otherwise fail and don't check its return, so it's left for a separate change that fixes them first. Assisted-by: LLM Signed-off-by: Josef Bacik --- net/core/skbuff.c | 27 ++++++++++++++++++++++----- 1 file changed, 22 insertions(+), 5 deletions(-) diff --git a/net/core/skbuff.c b/net/core/skbuff.c index a6821ab13969..ffc78b1a8ab8 100644 --- a/net/core/skbuff.c +++ b/net/core/skbuff.c @@ -2201,7 +2201,12 @@ struct sk_buff *skb_copy(const struct sk_buff *skb, gfp_t gfp_mask) /* Set the tail pointer and length */ skb_put(n, skb->len); - BUG_ON(skb_copy_bits(skb, -headerlen, n->head, headerlen + skb->len)); + if (unlikely(skb_copy_bits(skb, -headerlen, n->head, + headerlen + skb->len))) { + DEBUG_NET_WARN_ON_ONCE(1); + kfree_skb(n); + return NULL; + } skb_copy_header(n, skb); return n; @@ -2545,8 +2550,13 @@ struct sk_buff *skb_copy_expand(const struct sk_buff *skb, head_copy_off = newheadroom - head_copy_len; /* Copy the linear header and data. */ - BUG_ON(skb_copy_bits(skb, -head_copy_len, n->head + head_copy_off, - skb->len + head_copy_len)); + if (unlikely(skb_copy_bits(skb, -head_copy_len, + n->head + head_copy_off, + skb->len + head_copy_len))) { + DEBUG_NET_WARN_ON_ONCE(1); + kfree_skb(n); + return NULL; + } skb_copy_header(n, skb); @@ -6233,8 +6243,15 @@ bool skb_try_coalesce(struct sk_buff *to, struct sk_buff *from, return false; if (len <= skb_tailroom(to) && skb_frags_readable(from)) { - if (len) - BUG_ON(skb_copy_bits(from, 0, skb_put(to, len), len)); + if (len) { + if (unlikely(skb_copy_bits(from, 0, + skb_tail_pointer(to), + len))) { + DEBUG_NET_WARN_ON_ONCE(1); + return false; + } + skb_put(to, len); + } *delta_truesize = 0; return true; } -- 2.55.0