Netdev List
 help / color / mirror / Atom feed
* [PATCH net v3] net: mvneta: clear XDP pfmemalloc flag between frames
@ 2026-09-28  7:23 Lorenzo Bianconi
  2026-09-28  7:25 ` netdev-bot+sinfo
  2026-09-28 12:27 ` Toke Høiland-Jørgensen
  0 siblings, 2 replies; 4+ messages in thread
From: Lorenzo Bianconi @ 2026-09-28  7:23 UTC (permalink / raw)
  To: Marcin Wojtas, Andrew Lunn, David S. Miller, Eric Dumazet,
	Jakub Kicinski, Paolo Abeni, Alexei Starovoitov, Daniel Borkmann,
	Jesper Dangaard Brouer, John Fastabend, Stanislav Fomichev,
	Toke Hoiland-Jorgensen, Lorenzo Bianconi, Simon Horman
  Cc: netdev, bpf, Lorenzo Bianconi

mvneta_swbm_add_rx_fragment() sets XDP_FLAGS_FRAGS_PF_MEMALLOC on the
xdp_buff when a fragment page is a pfmemalloc one (page under memory
pressure). The xdp_buff is reused for the next frame, but only the
XDP_FLAGS_HAS_FRAGS bit was cleared at frame start, so the pfmemalloc
bit leaked from one frame into the following ones. mvneta_swbm_build_skb()
propagates the flag to skb->pfmemalloc through xdp_update_skb_frags_info(),
so the skb of a subsequent fragmented frame could be wrongly marked as
pfmemalloc even if none of its pages are under pressure.

Clear all the xdp_buff flags in mvneta_swbm_rx_frame(), which is invoked
for each new frame, instead of just the XDP_FLAGS_HAS_FRAGS bit.

Fixes: ed7a58cb40bd ("net: marvell: rely on xdp_update_skb_shared_info utility routine")
Reviewed-by: Simon Horman <horms@kernel.org>
Signed-off-by: Lorenzo Bianconi <lorenzo.bianconi@oss.qualcomm.com>
---
Changes in v3:
- Rename xdp_buff_clear_flags() in xdp_reinit_buf().
- Link to v2: https://lore.kernel.org/r/20260923-mvneta-xdp-clear-frag-fix-v2-1-298693a7ea6b@oss.qualcomm.com

Changes in v2:
- Introduce xdp_buff_clear_flags() utility routine.
- Link to v1: https://lore.kernel.org/r/20260920-mvneta-xdp-clear-frag-fix-v1-1-d7efadecf959@oss.qualcomm.com
---
 drivers/net/ethernet/marvell/mvneta.c | 2 +-
 include/net/xdp.h                     | 5 +++++
 2 files changed, 6 insertions(+), 1 deletion(-)

diff --git a/drivers/net/ethernet/marvell/mvneta.c b/drivers/net/ethernet/marvell/mvneta.c
index c2b1098d8d1d..485af7e395ae 100644
--- a/drivers/net/ethernet/marvell/mvneta.c
+++ b/drivers/net/ethernet/marvell/mvneta.c
@@ -2340,7 +2340,7 @@ mvneta_swbm_rx_frame(struct mvneta_port *pp,
 
 	/* Prefetch header */
 	prefetch(data);
-	xdp_buff_clear_frags_flag(xdp);
+	xdp_reinit_buf(xdp);
 	xdp_prepare_buff(xdp, data, pp->rx_offset_correction + MVNETA_MH_SIZE,
 			 data_len, true);
 }
diff --git a/include/net/xdp.h b/include/net/xdp.h
index aa742f413c35..8d928eb73dc1 100644
--- a/include/net/xdp.h
+++ b/include/net/xdp.h
@@ -106,6 +106,11 @@ struct xdp_buff {
 	};
 };
 
+static __always_inline void xdp_reinit_buf(struct xdp_buff *xdp)
+{
+	xdp->flags = 0;
+}
+
 static __always_inline bool xdp_buff_has_frags(const struct xdp_buff *xdp)
 {
 	return !!(xdp->flags & XDP_FLAGS_HAS_FRAGS);

---
base-commit: 014d795c73837ea2339a4ea8e8f82c6e959b845d
change-id: 20260919-mvneta-xdp-clear-frag-fix-7ac691e1659b

Best regards,
-- 
Lorenzo Bianconi <lorenzo.bianconi@oss.qualcomm.com>


^ permalink raw reply related	[flat|nested] 4+ messages in thread

* Re: [PATCH net v3] net: mvneta: clear XDP pfmemalloc flag between frames
  2026-09-28  7:23 [PATCH net v3] net: mvneta: clear XDP pfmemalloc flag between frames Lorenzo Bianconi
@ 2026-09-28  7:25 ` netdev-bot+sinfo
  2026-09-28 12:27 ` Toke Høiland-Jørgensen
  1 sibling, 0 replies; 4+ messages in thread
From: netdev-bot+sinfo @ 2026-09-28  7:25 UTC (permalink / raw)
  To: Lorenzo Bianconi
  Cc: Marcin Wojtas, Andrew Lunn, David S. Miller, Eric Dumazet,
	Jakub Kicinski, Paolo Abeni, Alexei Starovoitov, Daniel Borkmann,
	Jesper Dangaard Brouer, John Fastabend, Stanislav Fomichev,
	Toke Hoiland-Jorgensen, Lorenzo Bianconi, Simon Horman, netdev,
	bpf

Hi!

This is an automated message. This series looks like a fix, but its
commit messages seem to be missing some information:

 - How the issue was discovered, e.g. hit in production, hit during
   development, syzbot report, manual code inspection, LLM or static
   analysis tool scan.

 - Whether the issue was actually triggered, or is only theoretical
   (e.g. found by code inspection). If it was triggered please include
   the symptoms, like the stack trace or error messages.

 - What hardware the change was tested on. For driver fixes please
   mention the device (and if relevant firmware version) used for
   testing, or say that the change was not tested on real hardware.

Please do not repost the series just to address the above. Instead,
reply to this email with the missing information, so that reviewers
can take it into account. If the series needs another revision for
other reasons, please include the information in the commit messages
then.

The evaluation is done by an LLM so it may be wrong, if you think
that is the case please reply and explain.

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH net v3] net: mvneta: clear XDP pfmemalloc flag between frames
  2026-09-28  7:23 [PATCH net v3] net: mvneta: clear XDP pfmemalloc flag between frames Lorenzo Bianconi
  2026-09-28  7:25 ` netdev-bot+sinfo
@ 2026-09-28 12:27 ` Toke Høiland-Jørgensen
  2026-09-28 16:50   ` Lorenzo Bianconi
  1 sibling, 1 reply; 4+ messages in thread
From: Toke Høiland-Jørgensen @ 2026-09-28 12:27 UTC (permalink / raw)
  To: Lorenzo Bianconi, Marcin Wojtas, Andrew Lunn, David S. Miller,
	Eric Dumazet, Jakub Kicinski, Paolo Abeni, Alexei Starovoitov,
	Daniel Borkmann, Jesper Dangaard Brouer, John Fastabend,
	Stanislav Fomichev, Lorenzo Bianconi, Simon Horman
  Cc: netdev, bpf, Lorenzo Bianconi

Lorenzo Bianconi <lorenzo.bianconi@oss.qualcomm.com> writes:

> mvneta_swbm_add_rx_fragment() sets XDP_FLAGS_FRAGS_PF_MEMALLOC on the
> xdp_buff when a fragment page is a pfmemalloc one (page under memory
> pressure). The xdp_buff is reused for the next frame, but only the
> XDP_FLAGS_HAS_FRAGS bit was cleared at frame start, so the pfmemalloc
> bit leaked from one frame into the following ones. mvneta_swbm_build_skb()
> propagates the flag to skb->pfmemalloc through xdp_update_skb_frags_info(),
> so the skb of a subsequent fragmented frame could be wrongly marked as
> pfmemalloc even if none of its pages are under pressure.
>
> Clear all the xdp_buff flags in mvneta_swbm_rx_frame(), which is invoked
> for each new frame, instead of just the XDP_FLAGS_HAS_FRAGS bit.
>
> Fixes: ed7a58cb40bd ("net: marvell: rely on xdp_update_skb_shared_info utility routine")
> Reviewed-by: Simon Horman <horms@kernel.org>
> Signed-off-by: Lorenzo Bianconi <lorenzo.bianconi@oss.qualcomm.com>
> ---
> Changes in v3:
> - Rename xdp_buff_clear_flags() in xdp_reinit_buf().
> - Link to v2: https://lore.kernel.org/r/20260923-mvneta-xdp-clear-frag-fix-v2-1-298693a7ea6b@oss.qualcomm.com
>
> Changes in v2:
> - Introduce xdp_buff_clear_flags() utility routine.
> - Link to v1: https://lore.kernel.org/r/20260920-mvneta-xdp-clear-frag-fix-v1-1-d7efadecf959@oss.qualcomm.com
> ---
>  drivers/net/ethernet/marvell/mvneta.c | 2 +-
>  include/net/xdp.h                     | 5 +++++
>  2 files changed, 6 insertions(+), 1 deletion(-)
>
> diff --git a/drivers/net/ethernet/marvell/mvneta.c b/drivers/net/ethernet/marvell/mvneta.c
> index c2b1098d8d1d..485af7e395ae 100644
> --- a/drivers/net/ethernet/marvell/mvneta.c
> +++ b/drivers/net/ethernet/marvell/mvneta.c
> @@ -2340,7 +2340,7 @@ mvneta_swbm_rx_frame(struct mvneta_port *pp,
>  
>  	/* Prefetch header */
>  	prefetch(data);
> -	xdp_buff_clear_frags_flag(xdp);
> +	xdp_reinit_buf(xdp);

nit: we spell buff with two f's everywhere else, so seems a bit odd to
have only one here...

-Toke


^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH net v3] net: mvneta: clear XDP pfmemalloc flag between frames
  2026-09-28 12:27 ` Toke Høiland-Jørgensen
@ 2026-09-28 16:50   ` Lorenzo Bianconi
  0 siblings, 0 replies; 4+ messages in thread
From: Lorenzo Bianconi @ 2026-09-28 16:50 UTC (permalink / raw)
  To: Toke Høiland-Jørgensen
  Cc: Marcin Wojtas, Andrew Lunn, David S. Miller, Eric Dumazet,
	Jakub Kicinski, Paolo Abeni, Alexei Starovoitov, Daniel Borkmann,
	Jesper Dangaard Brouer, John Fastabend, Stanislav Fomichev,
	Lorenzo Bianconi, Simon Horman, netdev, bpf

[-- Attachment #1: Type: text/plain, Size: 2243 bytes --]

On Sep 28, Toke wrote:
> Lorenzo Bianconi <lorenzo.bianconi@oss.qualcomm.com> writes:
> 
> > mvneta_swbm_add_rx_fragment() sets XDP_FLAGS_FRAGS_PF_MEMALLOC on the
> > xdp_buff when a fragment page is a pfmemalloc one (page under memory
> > pressure). The xdp_buff is reused for the next frame, but only the
> > XDP_FLAGS_HAS_FRAGS bit was cleared at frame start, so the pfmemalloc
> > bit leaked from one frame into the following ones. mvneta_swbm_build_skb()
> > propagates the flag to skb->pfmemalloc through xdp_update_skb_frags_info(),
> > so the skb of a subsequent fragmented frame could be wrongly marked as
> > pfmemalloc even if none of its pages are under pressure.
> >
> > Clear all the xdp_buff flags in mvneta_swbm_rx_frame(), which is invoked
> > for each new frame, instead of just the XDP_FLAGS_HAS_FRAGS bit.
> >
> > Fixes: ed7a58cb40bd ("net: marvell: rely on xdp_update_skb_shared_info utility routine")
> > Reviewed-by: Simon Horman <horms@kernel.org>
> > Signed-off-by: Lorenzo Bianconi <lorenzo.bianconi@oss.qualcomm.com>
> > ---
> > Changes in v3:
> > - Rename xdp_buff_clear_flags() in xdp_reinit_buf().
> > - Link to v2: https://lore.kernel.org/r/20260923-mvneta-xdp-clear-frag-fix-v2-1-298693a7ea6b@oss.qualcomm.com
> >
> > Changes in v2:
> > - Introduce xdp_buff_clear_flags() utility routine.
> > - Link to v1: https://lore.kernel.org/r/20260920-mvneta-xdp-clear-frag-fix-v1-1-d7efadecf959@oss.qualcomm.com
> > ---
> >  drivers/net/ethernet/marvell/mvneta.c | 2 +-
> >  include/net/xdp.h                     | 5 +++++
> >  2 files changed, 6 insertions(+), 1 deletion(-)
> >
> > diff --git a/drivers/net/ethernet/marvell/mvneta.c b/drivers/net/ethernet/marvell/mvneta.c
> > index c2b1098d8d1d..485af7e395ae 100644
> > --- a/drivers/net/ethernet/marvell/mvneta.c
> > +++ b/drivers/net/ethernet/marvell/mvneta.c
> > @@ -2340,7 +2340,7 @@ mvneta_swbm_rx_frame(struct mvneta_port *pp,
> >  
> >  	/* Prefetch header */
> >  	prefetch(data);
> > -	xdp_buff_clear_frags_flag(xdp);
> > +	xdp_reinit_buf(xdp);
> 
> nit: we spell buff with two f's everywhere else, so seems a bit odd to
> have only one here...

ack, I will fix it in v4.

Regards,
Lorenzo

> 
> -Toke
> 

[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 228 bytes --]

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-09-28 16:50 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-28  7:23 [PATCH net v3] net: mvneta: clear XDP pfmemalloc flag between frames Lorenzo Bianconi
2026-09-28  7:25 ` netdev-bot+sinfo
2026-09-28 12:27 ` Toke Høiland-Jørgensen
2026-09-28 16:50   ` Lorenzo Bianconi

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox