Netdev List
 help / color / mirror / Atom feed
* [PATCH net] bng_en: pad short frames before sampling nr_frags
@ 2026-10-07  7:56 Eric Dumazet
  2026-10-07  8:00 ` netdev-bot+sinfo
                   ` (2 more replies)
  0 siblings, 3 replies; 4+ messages in thread
From: Eric Dumazet @ 2026-10-07  7:56 UTC (permalink / raw)
  To: David S . Miller, Jakub Kicinski, Paolo Abeni
  Cc: Simon Horman, netdev, Eric Dumazet, Vikas Gupta, Michael Chan,
	Pavan Chebbi

bnge_start_xmit() samples skb_shinfo(skb)->nr_frags into last_frag,
and stores it in tx_buf->nr_frags, before calling eth_skb_pad().

If a nonlinear skb is shorter than ETH_ZLEN, __skb_pad() calls
skb_linearize(), which pulls the frags into the linear part,
releases the frag pages and sets nr_frags to zero.

bnge_start_xmit() then uses the stale last_frag to fill TX_BD_CNT()
and to walk skb_shinfo(skb)->frags[], DMA-mapping pages the skb
no longer holds a reference on, and sending their content twice.

Fix this by calling eth_skb_pad() before nr_frags is sampled.

Found by Sashiko while reviewing the similar bnxt_en fix.

Fixes: bd5ad9c052c8 ("bng_en: Add TX support")
Link: https://lore.kernel.org/netdev/179134695789.434549.53526916334276884@kernel.org/
Signed-off-by: Eric Dumazet <edumazet@kernel.org>
---
Cc: Vikas Gupta <vikas.gupta@broadcom.com>
Cc: Michael Chan <michael.chan@broadcom.com>
Cc: Pavan Chebbi <pavan.chebbi@broadcom.com>
---
 drivers/net/ethernet/broadcom/bnge/bnge_txrx.c | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/drivers/net/ethernet/broadcom/bnge/bnge_txrx.c b/drivers/net/ethernet/broadcom/bnge/bnge_txrx.c
index 7d45e057f2e82069b3b54936a02e4c955b2787c8..472b02cc43b3c1174e061906b730c0edf9478846 100644
--- a/drivers/net/ethernet/broadcom/bnge/bnge_txrx.c
+++ b/drivers/net/ethernet/broadcom/bnge/bnge_txrx.c
@@ -1490,6 +1490,9 @@ netdev_tx_t bnge_start_xmit(struct sk_buff *skb, struct net_device *dev)
 			return NETDEV_TX_BUSY;
 	}
 
+	if (eth_skb_pad(skb))
+		goto tx_kick_pending;
+
 	last_frag = skb_shinfo(skb)->nr_frags;
 
 	txbd = &txr->tx_desc_ring[TX_RING(bn, prod)][TX_IDX(prod)];
@@ -1513,9 +1516,6 @@ netdev_tx_t bnge_start_xmit(struct sk_buff *skb, struct net_device *dev)
 	if (unlikely(skb->no_fcs))
 		lflags |= cpu_to_le32(TX_BD_FLAGS_NO_CRC);
 
-	if (eth_skb_pad(skb))
-		goto tx_kick_pending;
-
 	len = skb_headlen(skb);
 
 	mapping = dma_map_single(bd->dev, skb->data, len, DMA_TO_DEVICE);
-- 
2.53.0


^ permalink raw reply related	[flat|nested] 4+ messages in thread

* Re: [PATCH net] bng_en: pad short frames before sampling nr_frags
  2026-10-07  7:56 [PATCH net] bng_en: pad short frames before sampling nr_frags Eric Dumazet
@ 2026-10-07  8:00 ` netdev-bot+sinfo
  2026-10-07  8:43 ` Vikas Gupta
  2026-10-08 18:10 ` patchwork-bot+netdevbpf
  2 siblings, 0 replies; 4+ messages in thread
From: netdev-bot+sinfo @ 2026-10-07  8:00 UTC (permalink / raw)
  To: Eric Dumazet
  Cc: David S . Miller, Jakub Kicinski, Paolo Abeni, Simon Horman,
	netdev, Vikas Gupta, Michael Chan, Pavan Chebbi

Hi!

This is an automated message. This series looks like a fix, but its
commit messages seem to be missing some information:

 - Whether the issue was actually triggered, or is only theoretical
   (e.g. found by code inspection). If it was triggered please include
   the symptoms, like the stack trace or error messages.

 - What hardware the change was tested on. For driver fixes please
   mention the device (and if relevant firmware version) used for
   testing, or say that the change was not tested on real hardware.

Please do not repost the series just to address the above. Instead,
reply to this email with the missing information, so that reviewers
can take it into account. If the series needs another revision for
other reasons, please include the information in the commit messages
then.

The evaluation is done by an LLM so it may be wrong, if you think
that is the case please reply and explain.

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH net] bng_en: pad short frames before sampling nr_frags
  2026-10-07  7:56 [PATCH net] bng_en: pad short frames before sampling nr_frags Eric Dumazet
  2026-10-07  8:00 ` netdev-bot+sinfo
@ 2026-10-07  8:43 ` Vikas Gupta
  2026-10-08 18:10 ` patchwork-bot+netdevbpf
  2 siblings, 0 replies; 4+ messages in thread
From: Vikas Gupta @ 2026-10-07  8:43 UTC (permalink / raw)
  To: Eric Dumazet
  Cc: David S . Miller, Jakub Kicinski, Paolo Abeni, Simon Horman,
	netdev, Michael Chan, Pavan Chebbi

[-- Attachment #1: Type: text/plain, Size: 2376 bytes --]

On Wed, Oct 7, 2026 at 1:26 PM Eric Dumazet <edumazet@kernel.org> wrote:
>
> bnge_start_xmit() samples skb_shinfo(skb)->nr_frags into last_frag,
> and stores it in tx_buf->nr_frags, before calling eth_skb_pad().
>
> If a nonlinear skb is shorter than ETH_ZLEN, __skb_pad() calls
> skb_linearize(), which pulls the frags into the linear part,
> releases the frag pages and sets nr_frags to zero.
>
> bnge_start_xmit() then uses the stale last_frag to fill TX_BD_CNT()
> and to walk skb_shinfo(skb)->frags[], DMA-mapping pages the skb
> no longer holds a reference on, and sending their content twice.
>
> Fix this by calling eth_skb_pad() before nr_frags is sampled.
>
> Found by Sashiko while reviewing the similar bnxt_en fix.
>
> Fixes: bd5ad9c052c8 ("bng_en: Add TX support")
> Link: https://lore.kernel.org/netdev/179134695789.434549.53526916334276884@kernel.org/
> Signed-off-by: Eric Dumazet <edumazet@kernel.org>

Reviewed-by: Vikas Gupta <vikas.gupta@broadcom.com>

> ---
> Cc: Vikas Gupta <vikas.gupta@broadcom.com>
> Cc: Michael Chan <michael.chan@broadcom.com>
> Cc: Pavan Chebbi <pavan.chebbi@broadcom.com>
> ---
>  drivers/net/ethernet/broadcom/bnge/bnge_txrx.c | 6 +++---
>  1 file changed, 3 insertions(+), 3 deletions(-)
>
> diff --git a/drivers/net/ethernet/broadcom/bnge/bnge_txrx.c b/drivers/net/ethernet/broadcom/bnge/bnge_txrx.c
> index 7d45e057f2e82069b3b54936a02e4c955b2787c8..472b02cc43b3c1174e061906b730c0edf9478846 100644
> --- a/drivers/net/ethernet/broadcom/bnge/bnge_txrx.c
> +++ b/drivers/net/ethernet/broadcom/bnge/bnge_txrx.c
> @@ -1490,6 +1490,9 @@ netdev_tx_t bnge_start_xmit(struct sk_buff *skb, struct net_device *dev)
>                         return NETDEV_TX_BUSY;
>         }
>
> +       if (eth_skb_pad(skb))
> +               goto tx_kick_pending;
> +
>         last_frag = skb_shinfo(skb)->nr_frags;
>
>         txbd = &txr->tx_desc_ring[TX_RING(bn, prod)][TX_IDX(prod)];
> @@ -1513,9 +1516,6 @@ netdev_tx_t bnge_start_xmit(struct sk_buff *skb, struct net_device *dev)
>         if (unlikely(skb->no_fcs))
>                 lflags |= cpu_to_le32(TX_BD_FLAGS_NO_CRC);
>
> -       if (eth_skb_pad(skb))
> -               goto tx_kick_pending;
> -
>         len = skb_headlen(skb);
>
>         mapping = dma_map_single(bd->dev, skb->data, len, DMA_TO_DEVICE);
> --
> 2.53.0
>

[-- Attachment #2: S/MIME Cryptographic Signature --]
[-- Type: application/pkcs7-signature, Size: 5465 bytes --]

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH net] bng_en: pad short frames before sampling nr_frags
  2026-10-07  7:56 [PATCH net] bng_en: pad short frames before sampling nr_frags Eric Dumazet
  2026-10-07  8:00 ` netdev-bot+sinfo
  2026-10-07  8:43 ` Vikas Gupta
@ 2026-10-08 18:10 ` patchwork-bot+netdevbpf
  2 siblings, 0 replies; 4+ messages in thread
From: patchwork-bot+netdevbpf @ 2026-10-08 18:10 UTC (permalink / raw)
  To: Eric Dumazet
  Cc: davem, kuba, pabeni, horms, netdev, vikas.gupta, michael.chan,
	pavan.chebbi

Hello:

This patch was applied to netdev/net-next.git (main)
by Jakub Kicinski <kuba@kernel.org>:

On Wed,  7 Oct 2026 09:56:49 +0200 you wrote:
> bnge_start_xmit() samples skb_shinfo(skb)->nr_frags into last_frag,
> and stores it in tx_buf->nr_frags, before calling eth_skb_pad().
> 
> If a nonlinear skb is shorter than ETH_ZLEN, __skb_pad() calls
> skb_linearize(), which pulls the frags into the linear part,
> releases the frag pages and sets nr_frags to zero.
> 
> [...]

Here is the summary with links:
  - [net] bng_en: pad short frames before sampling nr_frags
    https://git.kernel.org/netdev/net-next/c/056d046bf530

You are awesome, thank you!
-- 
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html



^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-10-08 18:10 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-07  7:56 [PATCH net] bng_en: pad short frames before sampling nr_frags Eric Dumazet
2026-10-07  8:00 ` netdev-bot+sinfo
2026-10-07  8:43 ` Vikas Gupta
2026-10-08 18:10 ` patchwork-bot+netdevbpf

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox