Netdev List
 help / color / mirror / Atom feed
From: Nicolai Buchwitz <nb@tipi-net.de>
To: netdev-bot+sashiko@kernel.org
Cc: davem@davemloft.net, edumazet@kernel.org, kuba@kernel.org,
	pabeni@redhat.com, horms@kernel.org, o.rempel@pengutronix.de,
	maxime.chevallier@bootlin.com, andrew+netdev@lunn.ch,
	mcoquelin.stm32@gmail.com, alexandre.torgue@foss.st.com,
	Jose.Abreu@synopsys.com, saeedm@nvidia.com, tariqt@nvidia.com,
	mbloch@nvidia.com, leon@kernel.org, dtatulea@nvidia.com,
	alazar@nvidia.com, netdev@vger.kernel.org,
	linux-kernel@vger.kernel.org,
	linux-stm32@st-md-mailman.stormreply.com,
	linux-arm-kernel@lists.infradead.org, linux-rdma@vger.kernel.org
Subject: Re: [PATCH net-next 1/3] net: selftests: use skb_share_check() in the loopback receive hook
Date: Fri, 09 Oct 2026 08:49:02 +0200	[thread overview]
Message-ID: <533b88ce917b59f4f59f52145d2f035f@tipi-net.de> (raw)
In-Reply-To: <179149509090.434549.9918598206439291164@kernel.org>

Hi Clashiko

On 8.10.2026 23:31, netdev-bot+sashiko@kernel.org wrote:

> [...]

> [Severity: High]
> This change looks correct for net_test_loopback_validate(). The same
> pattern still seems to be present in stmmac_test_vlan_validate() in
> drivers/net/ethernet/stmicro/stmmac/stmmac_selftests.c, though.
> 
> A later commit in this series, "net: stmmac: selftests: use
> skb_share_check() in the loopback receive hook", converts
> stmmac_test_loopback_validate(). The second copy of this handler in the
> same file is left as:
> 
> stmmac_test_vlan_validate() {
>     ...
> 	skb = skb_unshare(skb, GFP_ATOMIC);
> 	if (!skb)
> 		goto out;
> 
> 	if (skb_linearize(skb))
> 		goto out;
>     ...
> }
> 
> __stmmac_test_vlanfilt() and the other VLAN tests register this handler 
> as
> a device-bound packet_type. The type is ETH_P_IP, ETH_P_8021Q, or 
> either
> one depending on svlan:
> 
> 	tpriv->pt.type = htons(ETH_P_IP);
> 	tpriv->pt.func = stmmac_test_vlan_validate;
> 	tpriv->pt.dev = priv->dev;
> 
> Suppose another handler for the same type sits later in the device's
> ptype list, for example an AF_PACKET socket bound to ETH_P_IP on that
> interface. deliver_skb() then increments skb->users, so the hook gets 
> an
> skb that is shared but not cloned. skb_unshare() only checks
> skb_cloned(), so it returns that skb unchanged.
> 
> For a non-linear frame with less tailroom than data_len, this path
> follows:
> 
> skb_linearize()
>   __pskb_pull_tail()
>     pskb_expand_head()
>       BUG_ON(skb_shared(skb));
> 
> Should stmmac_test_vlan_validate() get the same skb_share_check()
> conversion, so the series covers every copy of this hook?

No, AFAIU the VLAN tests can't get a shared skb here. They set
capture_all, so stmmac_sft_add_pack() registers stmmac_sft_filter()
instead, which passes stmmac_test_vlan_validate() its own clone.

> 
> The xgbe sibling, xgbe_test_loopback_validate(), does not seem to be
> affected. It already calls skb_share_check() before it expands a shared
> skb.
> 
> [Severity: Low]
> This is a pre-existing issue that this patch did not introduce. The
> length check further down in net_test_loopback_validate() looks too
> short for what the function parses afterwards:
> 
> 	if (skb_headlen(skb) < (NET_TEST_PKT_SIZE - ETH_HLEN))
> 		goto out;
> 
> NET_TEST_PKT_SIZE in include/net/selftests.h covers only ethhdr, iphdr
> and netsfhdr. That guarantees 33 bytes past the network header and does
> not include the TCP/UDP header.
> 
> The function then reads:
> 
> 	thdr = (struct tcphdr *)((u8 *)ihdr + 4 * ihdr->ihl);
> 	...
> 	if (shdr->magic != cpu_to_be64(NET_TEST_PKT_MAGIC))
> 
> It never checks ihl >= 5, the IP version, tot_len or the L4 header
> length, and double_vlan adds another 4 bytes.
> 
> Could an IPv4 frame that arrives during ethtool -t make the hook read 
> up
> to about 64 bytes past skb->tail? Examples would be a minimum-size TCP
> segment or a frame with ihl=15.
> 
> The over-read seems to stay inside the skb head allocation, because
> skb_shared_info follows skb->end. If so, the only effect is a possibly
> wrong selftest result.

The length check is pre-existing, will address that in a follow-up 
patch.

  reply	other threads:[~2026-10-09  6:49 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-07 18:29 [PATCH net-next 0/3] net: use skb_share_check() in loopback selftest hooks Nicolai Buchwitz
2026-10-07 18:29 ` [PATCH net-next 1/3] net: selftests: use skb_share_check() in the loopback receive hook Nicolai Buchwitz
2026-10-08 21:31   ` netdev-bot+sashiko
2026-10-09  6:49     ` Nicolai Buchwitz [this message]
2026-10-07 18:29 ` [PATCH net-next 2/3] net: stmmac: " Nicolai Buchwitz
2026-10-07 18:29 ` [PATCH net-next 3/3] net/mlx5e: use skb_share_check() in the loopback selftest hook Nicolai Buchwitz
2026-10-08 21:31   ` netdev-bot+sashiko
2026-10-09  8:37     ` Nicolai Buchwitz

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=533b88ce917b59f4f59f52145d2f035f@tipi-net.de \
    --to=nb@tipi-net.de \
    --cc=Jose.Abreu@synopsys.com \
    --cc=alazar@nvidia.com \
    --cc=alexandre.torgue@foss.st.com \
    --cc=andrew+netdev@lunn.ch \
    --cc=davem@davemloft.net \
    --cc=dtatulea@nvidia.com \
    --cc=edumazet@kernel.org \
    --cc=horms@kernel.org \
    --cc=kuba@kernel.org \
    --cc=leon@kernel.org \
    --cc=linux-arm-kernel@lists.infradead.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-rdma@vger.kernel.org \
    --cc=linux-stm32@st-md-mailman.stormreply.com \
    --cc=maxime.chevallier@bootlin.com \
    --cc=mbloch@nvidia.com \
    --cc=mcoquelin.stm32@gmail.com \
    --cc=netdev-bot+sashiko@kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=o.rempel@pengutronix.de \
    --cc=pabeni@redhat.com \
    --cc=saeedm@nvidia.com \
    --cc=tariqt@nvidia.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox