From: Josef Bacik <josef@toxicpanda.com>
To: Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
Eric Dumazet <edumazet@kernel.org>,
"David S. Miller" <davem@davemloft.net>,
Andrew Lunn <andrew+netdev@lunn.ch>
Cc: Saeed Mahameed <saeedm@nvidia.com>,
Tariq Toukan <tariqt@nvidia.com>, Mark Bloch <mbloch@nvidia.com>,
Leon Romanovsky <leon@kernel.org>,
Juergen Gross <jgross@suse.com>,
Stefano Stabellini <sstabellini@kernel.org>,
Oleksandr Tyshchenko <oleksandr_tyshchenko@epam.com>,
Tony Nguyen <anthony.l.nguyen@intel.com>,
Przemek Kitszel <przemyslaw.kitszel@intel.com>,
Manish Chopra <manishc@marvell.com>,
Rahul Verma <rahulv@marvell.com>,
GR-Linux-NIC-Dev@marvell.com,
Shahed Shaikh <shshaikh@marvell.com>,
Simon Horman <horms@kernel.org>,
netdev@vger.kernel.org, linux-kernel@vger.kernel.org,
linux-rdma@vger.kernel.org, xen-devel@lists.xenproject.org,
intel-wired-lan@lists.osuosl.org,
Josef Bacik <josef@toxicpanda.com>
Subject: [PATCH net-next v2 10/10] net: skbuff: don't reset truesize in skb_condense() if the pull fails
Date: Thu, 08 Oct 2026 21:02:57 +0000 [thread overview]
Message-ID: <20261008-b4-pskb-pull-tail-drivers-v2-10-8f2bd9bee138@toxicpanda.com> (raw)
In-Reply-To: <20261008-b4-pskb-pull-tail-drivers-v2-0-8f2bd9bee138@toxicpanda.com>
skb_condense() pulls all of the frag data into the head and then sets
truesize to cover just the head, but it ignores the return value of
__pskb_pull_tail(). If the pull failed, the frags would still be
attached and truesize would undercount them.
It can't fail today. The caller has checked that the head has room,
that the skb isn't cloned and that the frags are readable, and pulling
all of data_len eats every frag_list skb whole, so nothing is
allocated. Check the result anyway and leave the skb alone on
failure, so this stays correct if any of that changes. Use
__skb_linearize(), which is what this pull is.
Assisted-by: LLM
Signed-off-by: Josef Bacik <josef@toxicpanda.com>
---
net/core/skbuff.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/net/core/skbuff.c b/net/core/skbuff.c
index f798118df112..556d37981f0f 100644
--- a/net/core/skbuff.c
+++ b/net/core/skbuff.c
@@ -7158,7 +7158,8 @@ void skb_condense(struct sk_buff *skb)
return;
/* Nice, we can free page frag(s) right now */
- __pskb_pull_tail(skb, skb->data_len);
+ if (__skb_linearize(skb))
+ return;
}
/* At this point, skb->truesize might be over estimated,
* because skb had a fragment, and fragments do not tell
--
2.55.0
next prev parent reply other threads:[~2026-10-08 21:03 UTC|newest]
Thread overview: 12+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-08 21:02 [PATCH net-next v2 00/10] net: stop calling __pskb_pull_tail() from drivers Josef Bacik
2026-10-08 21:02 ` [PATCH net-next v2 01/10] net: skbuff: add skb_drop_empty_frags() Josef Bacik
2026-10-08 21:02 ` [PATCH net-next v2 02/10] net: ftmac100: check for failure when pulling in the RX header Josef Bacik
2026-10-08 21:02 ` [PATCH net-next v2 03/10] net/mlx5e: check for failure when pulling the Ethernet header after XDP Josef Bacik
2026-10-08 21:02 ` [PATCH net-next v2 04/10] net: niu: check for failure when pulling in the RX header Josef Bacik
2026-10-08 21:02 ` [PATCH net-next v2 05/10] xen/netfront: check for failure when pulling in xennet_fill_frags() Josef Bacik
2026-10-08 21:02 ` [PATCH net-next v2 06/10] e1000: use pskb_may_pull() in the 82544 TSO workaround Josef Bacik
2026-10-08 21:02 ` [PATCH net-next v2 07/10] e1000e: use pskb_may_pull() in the 82571/2/3 " Josef Bacik
2026-10-08 21:02 ` [PATCH net-next v2 08/10] netxen: use pskb_may_pull() to pull excess TX frags into the head Josef Bacik
2026-10-08 21:02 ` [PATCH net-next v2 09/10] qlcnic: " Josef Bacik
2026-10-08 21:02 ` Josef Bacik [this message]
2026-10-08 21:11 ` [PATCH net-next v2 00/10] net: stop calling __pskb_pull_tail() from drivers Jakub Kicinski
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261008-b4-pskb-pull-tail-drivers-v2-10-8f2bd9bee138@toxicpanda.com \
--to=josef@toxicpanda.com \
--cc=GR-Linux-NIC-Dev@marvell.com \
--cc=andrew+netdev@lunn.ch \
--cc=anthony.l.nguyen@intel.com \
--cc=davem@davemloft.net \
--cc=edumazet@kernel.org \
--cc=horms@kernel.org \
--cc=intel-wired-lan@lists.osuosl.org \
--cc=jgross@suse.com \
--cc=kuba@kernel.org \
--cc=leon@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-rdma@vger.kernel.org \
--cc=manishc@marvell.com \
--cc=mbloch@nvidia.com \
--cc=netdev@vger.kernel.org \
--cc=oleksandr_tyshchenko@epam.com \
--cc=pabeni@redhat.com \
--cc=przemyslaw.kitszel@intel.com \
--cc=rahulv@marvell.com \
--cc=saeedm@nvidia.com \
--cc=shshaikh@marvell.com \
--cc=sstabellini@kernel.org \
--cc=tariqt@nvidia.com \
--cc=xen-devel@lists.xenproject.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).