* [PATCH] tun: fix skb length underflow in NAPI frags path
@ 2026-10-05 5:42 Harshit Mogalapalli
2026-10-05 5:48 ` netdev-bot+sinfo
0 siblings, 1 reply; 2+ messages in thread
From: Harshit Mogalapalli @ 2026-10-05 5:42 UTC (permalink / raw)
To: maheshb, willemdebruijn.kernel, jasowangio, andrew+netdev, davem,
edumazet, kuba, pabeni, peterpenkov96, netdev, linux-kernel
Cc: kernel-janitors, error27, Harshit Mogalapalli, stable
When experimental vhost-net zero-copy TX is used with an IFF_NAPI_FRAGS
TAP backend, tun_get_user() receives msg_control, selects zerocopy, and
limits copylen to the linear prefix.
The NAPI frags path subsequently disables zerocopy after allocating the
skb and copies the complete frame instead. tun_napi_alloc_frags() derives
the linear length from the first iterator segment, so a segment larger
than copylen makes skb->data_len underflow. Pulling the Ethernet header
then triggers BUG() because skb->len is smaller than skb->data_len.
Disable zerocopy before calculating the allocation length so this path
allocates and copies the complete iterator.
Fixes: 90e33d459407 ("tun: enable napi_gro_frags() for TUN/TAP driver")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Harshit Mogalapalli <harshit.m.mogalapalli@oracle.com>
---
drivers/net/tun.c | 9 ++++-----
1 file changed, 4 insertions(+), 5 deletions(-)
diff --git a/drivers/net/tun.c b/drivers/net/tun.c
index 5a302709a68a..1124b8b33664 100644
--- a/drivers/net/tun.c
+++ b/drivers/net/tun.c
@@ -1848,6 +1848,10 @@ static ssize_t tun_get_user(struct tun_struct *tun, struct tun_file *tfile,
zerocopy = true;
}
+ /* The NAPI frags path copies the complete iterator. */
+ if (frags)
+ zerocopy = false;
+
if (!frags && tun_can_build_skb(tun, tfile, len, noblock, zerocopy)) {
/* For the packet that is not easy to be processed
* (e.g gso or jumbo packet), we will do it at after
@@ -1868,11 +1872,6 @@ static ssize_t tun_get_user(struct tun_struct *tun, struct tun_file *tfile,
if (frags) {
mutex_lock(&tfile->napi_mutex);
skb = tun_napi_alloc_frags(tfile, copylen, from);
- /* tun_napi_alloc_frags() enforces a layout for the skb.
- * If zerocopy is enabled, then this layout will be
- * overwritten by zerocopy_sg_from_iter().
- */
- zerocopy = false;
} else {
if (!linear)
linear = min_t(size_t, good_linear, copylen);
--
2.52.0
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: [PATCH] tun: fix skb length underflow in NAPI frags path
2026-10-05 5:42 [PATCH] tun: fix skb length underflow in NAPI frags path Harshit Mogalapalli
@ 2026-10-05 5:48 ` netdev-bot+sinfo
0 siblings, 0 replies; 2+ messages in thread
From: netdev-bot+sinfo @ 2026-10-05 5:48 UTC (permalink / raw)
To: Harshit Mogalapalli
Cc: maheshb, willemdebruijn.kernel, jasowangio, andrew+netdev, davem,
edumazet, kuba, pabeni, peterpenkov96, netdev, linux-kernel,
kernel-janitors, error27, stable
Hi!
This is an automated message. This series looks like a fix, but its
commit messages seem to be missing some information:
- Whether the issue was actually triggered, or is only theoretical
(e.g. found by code inspection). If it was triggered please include
the symptoms, like the stack trace or error messages.
Please do not repost the series just to address the above. Instead,
reply to this email with the missing information, so that reviewers
can take it into account. If the series needs another revision for
other reasons, please include the information in the commit messages
then.
The evaluation is done by an LLM so it may be wrong, if you think
that is the case please reply and explain.
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-10-05 5:49 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-05 5:42 [PATCH] tun: fix skb length underflow in NAPI frags path Harshit Mogalapalli
2026-10-05 5:48 ` netdev-bot+sinfo
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®