* [PATCH v3 net] bnxt_en: fix DMA mapping length for padded small packets
@ 2026-10-07 5:17 Eric Dumazet
2026-10-07 22:58 ` Michael Chan
2026-10-08 1:00 ` patchwork-bot+netdevbpf
0 siblings, 2 replies; 4+ messages in thread
From: Eric Dumazet @ 2026-10-07 5:17 UTC (permalink / raw)
To: David S . Miller, Jakub Kicinski, Paolo Abeni
Cc: Simon Horman, netdev, Eric Dumazet, stable, Stefan Fleischmann,
Eric Dumazet, Michael Chan, Pavan Chebbi, Andrew Lunn,
Bernhard Schmidt, Joe Damato
Stefan Fleischmann reported Intel IOMMU DMA Read faults on BCM57412
NetXtreme-E NICs when transmitting packets on VLAN/macvlan interfaces:
DMAR: [DMA Read NO_PASID] Request device [18:00.0] fault addr 0xfc499000
[fault reason 0x06] PTE Read access is not set
bnxt_en 0000:18:00.0 eno1np0: Abandoning msg {0xb4 0x41a} len: 0 due to firmware status: 0x2000001
...
NETDEV WATCHDOG: eno1np0 (bnxt_en): transmit queue 0 timed out
The fault address (0xfc499000) is on an exact 4KB page boundary,
pointing to a DMA read buffer overrun.
In bnxt_start_xmit(), packets smaller than BNXT_MIN_PKT_SIZE (52 bytes),
such as 42-byte untagged ARP frames, are padded:
if (length < BNXT_MIN_PKT_SIZE) {
pad = BNXT_MIN_PKT_SIZE - length;
if (skb_pad(skb, pad))
goto tx_kick_pending;
length = BNXT_MIN_PKT_SIZE;
}
mapping = dma_map_single(&pdev->dev, skb->data, len, DMA_TO_DEVICE);
...
dma_unmap_len_set(tx_buf, len, len);
However, 'len' was initialized earlier to skb_headlen(skb) (e.g. 42 bytes)
and is left unadjusted after padding. Consequently, dma_map_single() and
dma_unmap_len_set() map and track only 42 bytes.
Later, the hardware TX buffer descriptor is programmed with the padded length:
txbd->tx_bd_len_flags_type =
cpu_to_le32(((len + pad) << TX_BD_LEN_SHIFT) | flags |
TX_BD_FLAGS_PACKET_END);
The NIC DMA engine is thus instructed to read 52 bytes from a region where
only 42 bytes were DMA-mapped. If skb->data ends near the boundary of a 4KB
page (within 'pad' bytes of the next page), the hardware DMA read overruns
into the unmapped adjacent page, triggering an IOMMU fault.
This issue was exposed after commit 447cbe95ebb9 ("vlan: fix skb_under_panic
and races when toggling HW VLAN offload") because reserving extra VLAN
headroom rounded LL_RESERVED_SPACE from 48 up to 64 bytes, shifting skb->data
offsets and potentially causing small frames to land right against page
boundaries.
Fix this by using skb_put_padto(skb, BNXT_MIN_PKT_SIZE) in
bnxt_start_xmit(), before skb_shinfo(skb)->nr_frags is sampled,
because padding might linearize the skb.
This ensures skb->len and skb_headlen(skb) reflect the padded size so
that dma_map_single() maps the full buffer and the descriptor length is
consistent. This also removes the temporary 'pad' variable and masking logic.
The padding is done after the SW USO branch, otherwise
bnxt_sw_udp_gso_xmit() would account the padding as UDP payload
and send it in extra segments.
Note that SW USO segments are still not padded: with IPv4, a segment
carrying less than 10 bytes of UDP payload (small gso_size, or a short
last segment) is sent as a frame shorter than BNXT_MIN_PKT_SIZE.
This is a separate issue, left for a followup patch.
Fixes: c0c050c58d84 ("bnxt_en: New Broadcom ethernet driver.")
Cc: stable@vger.kernel.org
Reported-by: Stefan Fleischmann <sfle@kth.se>
Closes: https://lore.kernel.org/netdev/20261004122616.56714cbd@nargothrond/
Assisted-by: LLM
Signed-off-by: Eric Dumazet <edumazet@google.com>
---
Cc: Michael Chan <michael.chan@broadcom.com>
Cc: Pavan Chebbi <pavan.chebbi@broadcom.com>
Cc: Andrew Lunn <andrew+netdev@lunn.ch>
Cc: Bernhard Schmidt <berni@debian.org>
Cc: Joe Damato <joe@dama.to>
---
v3: Pad after the SW USO branch (Sashiko)
v2: Move skb_put_padto() earlier (Sashiko)
https://lore.kernel.org/netdev/20261006042153.199444-1-edumazet@kernel.org/
v1: https://lore.kernel.org/netdev/20261005023812.130639-1-edumazet@kernel.org/
---
drivers/net/ethernet/broadcom/bnxt/bnxt.c | 25 +++++++++++------------
1 file changed, 12 insertions(+), 13 deletions(-)
diff --git a/drivers/net/ethernet/broadcom/bnxt/bnxt.c b/drivers/net/ethernet/broadcom/bnxt/bnxt.c
index d7728d0c5b6e63ee72de9dea54426bb4c8b7a9fc..631c759b3752b29c1a649eedb08f8bbc9f37a607 100644
--- a/drivers/net/ethernet/broadcom/bnxt/bnxt.c
+++ b/drivers/net/ethernet/broadcom/bnxt/bnxt.c
@@ -486,7 +486,7 @@ static netdev_tx_t bnxt_start_xmit(struct sk_buff *skb, struct net_device *dev)
struct netdev_queue *txq;
int i;
dma_addr_t mapping;
- unsigned int length, pad = 0;
+ unsigned int length;
u32 len, free_size, vlan_tag_flags, cfa_action, flags;
struct bnxt_ptp_cfg *ptp = bp->ptp_cfg;
struct pci_dev *pdev = bp->pdev;
@@ -536,6 +536,16 @@ static netdev_tx_t bnxt_start_xmit(struct sk_buff *skb, struct net_device *dev)
return rc < 0 ? NETDEV_TX_BUSY : NETDEV_TX_OK;
}
+ /* Pad after the SW USO branch: bnxt_sw_udp_gso_xmit() would
+ * otherwise account the padding as UDP payload.
+ * Must be done before skb_shinfo(skb)->nr_frags is sampled,
+ * because skb_put_padto() might linearize the skb.
+ */
+ if (skb_put_padto(skb, BNXT_MIN_PKT_SIZE)) {
+ /* SKB already freed. */
+ goto tx_kick_pending;
+ }
+
free_size = bnxt_tx_avail(bp, txr);
if (unlikely(free_size < skb_shinfo(skb)->nr_frags + 2)) {
/* We must have raced with NAPI cleanup */
@@ -672,14 +682,6 @@ static netdev_tx_t bnxt_start_xmit(struct sk_buff *skb, struct net_device *dev)
}
normal_tx:
- if (length < BNXT_MIN_PKT_SIZE) {
- pad = BNXT_MIN_PKT_SIZE - length;
- if (skb_pad(skb, pad))
- /* SKB already freed. */
- goto tx_kick_pending;
- length = BNXT_MIN_PKT_SIZE;
- }
-
mapping = dma_map_single(&pdev->dev, skb->data, len, DMA_TO_DEVICE);
if (unlikely(dma_mapping_error(&pdev->dev, mapping)))
@@ -759,10 +761,7 @@ static netdev_tx_t bnxt_start_xmit(struct sk_buff *skb, struct net_device *dev)
txbd->tx_bd_len_flags_type = cpu_to_le32(flags);
}
- flags &= ~TX_BD_LEN;
- txbd->tx_bd_len_flags_type =
- cpu_to_le32(((len + pad) << TX_BD_LEN_SHIFT) | flags |
- TX_BD_FLAGS_PACKET_END);
+ txbd->tx_bd_len_flags_type |= cpu_to_le32(TX_BD_FLAGS_PACKET_END);
netdev_tx_sent_queue(txq, skb->len);
--
2.53.0
^ permalink raw reply related [flat|nested] 4+ messages in thread* Re: [PATCH v3 net] bnxt_en: fix DMA mapping length for padded small packets
2026-10-07 5:17 [PATCH v3 net] bnxt_en: fix DMA mapping length for padded small packets Eric Dumazet
@ 2026-10-07 22:58 ` Michael Chan
2026-10-07 23:14 ` Joe Damato
2026-10-08 1:00 ` patchwork-bot+netdevbpf
1 sibling, 1 reply; 4+ messages in thread
From: Michael Chan @ 2026-10-07 22:58 UTC (permalink / raw)
To: Eric Dumazet
Cc: David S . Miller, Jakub Kicinski, Paolo Abeni, Simon Horman,
netdev, stable, Stefan Fleischmann, Eric Dumazet, Pavan Chebbi,
Andrew Lunn, Bernhard Schmidt, Joe Damato
[-- Attachment #1: Type: text/plain, Size: 1330 bytes --]
On Tue, Oct 6, 2026 at 10:17 PM Eric Dumazet <edumazet@kernel.org> wrote:
> Fix this by using skb_put_padto(skb, BNXT_MIN_PKT_SIZE) in
> bnxt_start_xmit(), before skb_shinfo(skb)->nr_frags is sampled,
> because padding might linearize the skb.
> This ensures skb->len and skb_headlen(skb) reflect the padded size so
> that dma_map_single() maps the full buffer and the descriptor length is
> consistent. This also removes the temporary 'pad' variable and masking logic.
>
> The padding is done after the SW USO branch, otherwise
> bnxt_sw_udp_gso_xmit() would account the padding as UDP payload
> and send it in extra segments.
>
> Note that SW USO segments are still not padded: with IPv4, a segment
> carrying less than 10 bytes of UDP payload (small gso_size, or a short
> last segment) is sent as a frame shorter than BNXT_MIN_PKT_SIZE.
> This is a separate issue, left for a followup patch.
>
> Fixes: c0c050c58d84 ("bnxt_en: New Broadcom ethernet driver.")
> Cc: stable@vger.kernel.org
> Reported-by: Stefan Fleischmann <sfle@kth.se>
> Closes: https://lore.kernel.org/netdev/20261004122616.56714cbd@nargothrond/
> Assisted-by: LLM
> Signed-off-by: Eric Dumazet <edumazet@google.com>
v3 looks perfect to me for non SW USO packets. Thanks.
Reviewed-by: Michael Chan <michael.chan@broadcom.com>
[-- Attachment #2: S/MIME Cryptographic Signature --]
[-- Type: application/pkcs7-signature, Size: 5469 bytes --]
^ permalink raw reply [flat|nested] 4+ messages in thread* Re: [PATCH v3 net] bnxt_en: fix DMA mapping length for padded small packets
2026-10-07 22:58 ` Michael Chan
@ 2026-10-07 23:14 ` Joe Damato
0 siblings, 0 replies; 4+ messages in thread
From: Joe Damato @ 2026-10-07 23:14 UTC (permalink / raw)
To: Michael Chan
Cc: Eric Dumazet, David S . Miller, Jakub Kicinski, Paolo Abeni,
Simon Horman, netdev, stable, Stefan Fleischmann, Eric Dumazet,
Pavan Chebbi, Andrew Lunn, Bernhard Schmidt
On Wed, Oct 07, 2026 at 03:58:31PM -0700, Michael Chan wrote:
> On Tue, Oct 6, 2026 at 10:17 PM Eric Dumazet <edumazet@kernel.org> wrote:
>
> > Fix this by using skb_put_padto(skb, BNXT_MIN_PKT_SIZE) in
> > bnxt_start_xmit(), before skb_shinfo(skb)->nr_frags is sampled,
> > because padding might linearize the skb.
> > This ensures skb->len and skb_headlen(skb) reflect the padded size so
> > that dma_map_single() maps the full buffer and the descriptor length is
> > consistent. This also removes the temporary 'pad' variable and masking logic.
> >
> > The padding is done after the SW USO branch, otherwise
> > bnxt_sw_udp_gso_xmit() would account the padding as UDP payload
> > and send it in extra segments.
> >
> > Note that SW USO segments are still not padded: with IPv4, a segment
> > carrying less than 10 bytes of UDP payload (small gso_size, or a short
> > last segment) is sent as a frame shorter than BNXT_MIN_PKT_SIZE.
> > This is a separate issue, left for a followup patch.
> >
> > Fixes: c0c050c58d84 ("bnxt_en: New Broadcom ethernet driver.")
> > Cc: stable@vger.kernel.org
> > Reported-by: Stefan Fleischmann <sfle@kth.se>
> > Closes: https://lore.kernel.org/netdev/20261004122616.56714cbd@nargothrond/
> > Assisted-by: LLM
> > Signed-off-by: Eric Dumazet <edumazet@google.com>
>
> v3 looks perfect to me for non SW USO packets. Thanks.
FWIW: Once Eric's patch is in, I'll try to come up with a SW USO fix.
Thanks Eric for facing off with sashiko.
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH v3 net] bnxt_en: fix DMA mapping length for padded small packets
2026-10-07 5:17 [PATCH v3 net] bnxt_en: fix DMA mapping length for padded small packets Eric Dumazet
2026-10-07 22:58 ` Michael Chan
@ 2026-10-08 1:00 ` patchwork-bot+netdevbpf
1 sibling, 0 replies; 4+ messages in thread
From: patchwork-bot+netdevbpf @ 2026-10-08 1:00 UTC (permalink / raw)
To: Eric Dumazet
Cc: davem, kuba, pabeni, horms, netdev, stable, sfle, edumazet,
michael.chan, pavan.chebbi, andrew+netdev, berni, joe
Hello:
This patch was applied to netdev/net.git (main)
by Jakub Kicinski <kuba@kernel.org>:
On Wed, 7 Oct 2026 07:17:47 +0200 you wrote:
> Stefan Fleischmann reported Intel IOMMU DMA Read faults on BCM57412
> NetXtreme-E NICs when transmitting packets on VLAN/macvlan interfaces:
>
> DMAR: [DMA Read NO_PASID] Request device [18:00.0] fault addr 0xfc499000
> [fault reason 0x06] PTE Read access is not set
> bnxt_en 0000:18:00.0 eno1np0: Abandoning msg {0xb4 0x41a} len: 0 due to firmware status: 0x2000001
> ...
> NETDEV WATCHDOG: eno1np0 (bnxt_en): transmit queue 0 timed out
>
> [...]
Here is the summary with links:
- [v3,net] bnxt_en: fix DMA mapping length for padded small packets
https://git.kernel.org/netdev/net/c/a51d233ccd48
You are awesome, thank you!
--
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-10-08 1:00 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-07 5:17 [PATCH v3 net] bnxt_en: fix DMA mapping length for padded small packets Eric Dumazet
2026-10-07 22:58 ` Michael Chan
2026-10-07 23:14 ` Joe Damato
2026-10-08 1:00 ` patchwork-bot+netdevbpf
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox