Netdev List
 help / color / mirror / Atom feed
From: Nicolai Buchwitz <nb@tipi-net.de>
To: netdev-bot+sashiko@kernel.org
Cc: davem@davemloft.net, edumazet@kernel.org, kuba@kernel.org,
	pabeni@redhat.com, horms@kernel.org, o.rempel@pengutronix.de,
	maxime.chevallier@bootlin.com, andrew+netdev@lunn.ch,
	mcoquelin.stm32@gmail.com, alexandre.torgue@foss.st.com,
	Jose.Abreu@synopsys.com, saeedm@nvidia.com, tariqt@nvidia.com,
	mbloch@nvidia.com, leon@kernel.org, dtatulea@nvidia.com,
	alazar@nvidia.com, netdev@vger.kernel.org,
	linux-kernel@vger.kernel.org,
	linux-stm32@st-md-mailman.stormreply.com,
	linux-arm-kernel@lists.infradead.org, linux-rdma@vger.kernel.org
Subject: Re: [PATCH net-next 3/3] net/mlx5e: use skb_share_check() in the loopback selftest hook
Date: Fri, 09 Oct 2026 10:37:26 +0200	[thread overview]
Message-ID: <b90df783d996dbad672656dc81c8f5de@tipi-net.de> (raw)
In-Reply-To: <179149509264.434549.15492783775949444420@kernel.org>

On 8.10.2026 23:31, netdev-bot+sashiko@kernel.org wrote:

> [...]

> [Severity: Low]
> This isn't a bug, but the comment just below this hunk in
> mlx5e_test_loopback_validate() now contradicts the new code:
> 
> 	if (skb_linearize(skb))
> 		goto out;
> 
> 	/* We are only going to peek, no need to clone the SKB */
> 	if (MLX5E_TEST_PKT_SIZE - ETH_HLEN > skb_headlen(skb))
> 		goto out;
> 
> skb_share_check() calls skb_clone() whenever the skb is shared. After
> that, skb_linearize() can modify or reallocate the skb head.
> 
> Should this comment be dropped or reworded? A later reader could take
> "no need to clone" at face value and remove the skb_share_check().
> stmmac_test_loopback_validate() uses the same skb_share_check() +
> skb_linearize() sequence and has no such comment.

Yes, it is stale. I'll drop it if a v2 is needed.

> [...]

> [Severity: Low]
> This is a pre-existing issue and was not introduced by this patch.
> Further down in mlx5e_test_loopback_validate(), the UDP header is
> located using iph->ihl, which comes from the packet and is never
> checked:
> 
> 	/* Don't assume skb_transport_header() was set */
> 	udph = (struct udphdr *)((u8 *)iph + 4 * iph->ihl);
> 	if (udph->dest != htons(9))
> 		goto out;
> 
> 	mlxh = (struct mlx5ehdr *)((char *)udph + sizeof(*udph));
> 	if (mlxh->magic != cpu_to_be64(MLX5E_TEST_MAGIC))
> 
> The only length check is this one:
> 
> 	if (MLX5E_TEST_PKT_SIZE - ETH_HLEN > skb_headlen(skb))
> 		goto out;
> 
> That guarantees 44 bytes: 20 for IP, 8 for UDP, and 16 for struct
> mlx5ehdr, which includes the padding before magic.
> 
> The hook is registered with dev_add_pack() for every ETH_P_IP frame on
> priv->netdev. While the loopback test is running, could an external UDP
> frame sent to the port MAC with ihl up to 15 make this code read
> udph->dest and mlxh->magic up to 40 bytes past skb_headlen()?
> 
> Those bytes stay inside the skb head allocation, in the tailroom or
> skb_shared_info, and they are only compared against constants. The
> result could be a spurious selftest outcome or a KMSAN uninit-value
> report. Would it make sense to check 4 * iph->ihl against skb_headlen()
> before using it?

Yes, pre-existing. I can send a separate patch for this.

      reply	other threads:[~2026-10-09  8:37 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-07 18:29 [PATCH net-next 0/3] net: use skb_share_check() in loopback selftest hooks Nicolai Buchwitz
2026-10-07 18:29 ` [PATCH net-next 1/3] net: selftests: use skb_share_check() in the loopback receive hook Nicolai Buchwitz
2026-10-08 21:31   ` netdev-bot+sashiko
2026-10-09  6:49     ` Nicolai Buchwitz
2026-10-07 18:29 ` [PATCH net-next 2/3] net: stmmac: " Nicolai Buchwitz
2026-10-07 18:29 ` [PATCH net-next 3/3] net/mlx5e: use skb_share_check() in the loopback selftest hook Nicolai Buchwitz
2026-10-08 21:31   ` netdev-bot+sashiko
2026-10-09  8:37     ` Nicolai Buchwitz [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=b90df783d996dbad672656dc81c8f5de@tipi-net.de \
    --to=nb@tipi-net.de \
    --cc=Jose.Abreu@synopsys.com \
    --cc=alazar@nvidia.com \
    --cc=alexandre.torgue@foss.st.com \
    --cc=andrew+netdev@lunn.ch \
    --cc=davem@davemloft.net \
    --cc=dtatulea@nvidia.com \
    --cc=edumazet@kernel.org \
    --cc=horms@kernel.org \
    --cc=kuba@kernel.org \
    --cc=leon@kernel.org \
    --cc=linux-arm-kernel@lists.infradead.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-rdma@vger.kernel.org \
    --cc=linux-stm32@st-md-mailman.stormreply.com \
    --cc=maxime.chevallier@bootlin.com \
    --cc=mbloch@nvidia.com \
    --cc=mcoquelin.stm32@gmail.com \
    --cc=netdev-bot+sashiko@kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=o.rempel@pengutronix.de \
    --cc=pabeni@redhat.com \
    --cc=saeedm@nvidia.com \
    --cc=tariqt@nvidia.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox