On Jul 26, Sun Jian wrote: > veth exposes non-linear skb fragments through an xdp_buff. If an XDP > program adjusts the fragment area, veth_xdp_rcv_skb() copies > xdp_frags_size back to skb->data_len but leaves skb->len containing the > old fragment contribution. > > After a fragment shrink, this makes skb_headlen() larger than the actual > linear area. In the reproduced UDP receive path, __skb_datagram_iter() > copied 1024 bytes past the actual linear tail to userspace, starting at > struct skb_shared_info. The copied bytes included the affected skb's > nr_frags, xdp_frags_size and a kernel pointer from > skb_shinfo(skb)->frags[0]. Real packet data was displaced by the same > amount and truncated at the end. > > Subtract the old data_len before replacing it and add the new data_len > afterwards, keeping skb->len and skb->data_len synchronized. > > A 60000-byte UDP datagram on a veth pair with MTU 64000 was shortened by > 1024 bytes from its fragment area. Before the fix, all 10 runs produced > corrupted payloads. After the fix, all 10 runs matched the expected > payload exactly. > > Fixes: 718a18a0c8a6 ("veth: Rework veth_xdp_rcv_skb in order to accept non-linear skb") > Cc: stable@vger.kernel.org > Link: https://lore.kernel.org/r/20260720141859.19FF41F000E9@smtp.kernel.org > Link: https://lore.kernel.org/bpf/al9T9Eto%2FhRIzP5W@boxer/ > Signed-off-by: Sun Jian > --- > drivers/net/veth.c | 4 +++- > 1 file changed, 3 insertions(+), 1 deletion(-) > > diff --git a/drivers/net/veth.c b/drivers/net/veth.c > index 00e34afd858e..a956498a073b 100644 > --- a/drivers/net/veth.c > +++ b/drivers/net/veth.c > @@ -871,12 +871,14 @@ static struct sk_buff *veth_xdp_rcv_skb(struct veth_rq *rq, > __skb_put(skb, off); /* positive on grow, negative on shrink */ > > /* XDP frag metadata (e.g. nr_frags) are updated in eBPF helpers > - * (e.g. bpf_xdp_adjust_tail), we need to update data_len here. > + * (e.g. bpf_xdp_adjust_tail), update skb length fields here. > */ > + skb->len -= skb->data_len; > if (xdp_buff_has_frags(xdp)) > skb->data_len = skb_shinfo(skb)->xdp_frags_size; > else > skb->data_len = 0; > + skb->len += skb->data_len; nit: I guess you can move this one just in the if () branch. Regards, Lorenzo > > skb->protocol = eth_type_trans(skb, rq->dev); > > -- > 2.43.0 >