From nobody Sat Jul 25 16:18:39 2026 Received: from mail-pf1-f182.google.com (mail-pf1-f182.google.com [209.85.210.182]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4E0BB34574B for ; Thu, 16 Jul 2026 06:34:43 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.182 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784183685; cv=none; b=fR0idLqBZVoTyMDQ7TiKZEIwEK12/5aaa/x/HWatUwK4XEXfrBFABB8IEdZsfnSBwNVx7Mrx2PngkYXSFUVYdW5Xf2KA0aN8XtEtoXaX9Pw8JQomRcvdmrCInFEiX3xBtsm6vw3BBEGynV2iy+KJa2RoiincTVn4qeuiwxtNDbo= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784183685; c=relaxed/simple; bh=qcxtIhicU4yjTcuHKm9/uZfexpxtxK7NRRzA5uQ3Zio=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=GEV7v55bv2qAy0U/7tsAO5su28MGdRp/GhlsS26yHnayrq1gtxWedS2DbyW27s+Dc1djX3e8G8m4kDyS7eyNaDnAd59k4Xu1WVjn8AeXHORKrjaMxndU6YW9NoZ2clQdIFJpHaGQbskggMtrfcdRihlzXdfDGDeN4GjCA2wEh1c= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=Igyuf2fI; arc=none smtp.client-ip=209.85.210.182 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="Igyuf2fI" Received: by mail-pf1-f182.google.com with SMTP id d2e1a72fcca58-8486ac3f347so215184b3a.1 for ; Wed, 15 Jul 2026 23:34:43 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784183683; x=1784788483; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=7Wh24uH+pJSF3cGDjRO13znY6HNZJNEVNTxW5E0WYJA=; b=Igyuf2fIB1lH4cABZCFKKi2PdNaReBGRSGfAfjSohbAtGJoRH5PDuiZiF5zhrSQA2r 8RxYfVoExTWvX1p18MVo47oDzTGMHNlTPXfVGwY8MjV9V8K7rQbuStG/fjCwhy/uL7HL NTYwgK5Gk0KCBfpShMbnRrsyB3b1Z2Lv1ZZhACxttwiz/MhaZD3ATkH5Qa9eS89IMKTe CLhcp7MSksFJeWP0dk1spSM4KwgVODE9n5n5kd2+OHTbHmclFwhdidvDn+UVNqiWxuHA uWiB+7heHp8Ev8z+w+QEFtxeuGHOU+nNaOchI39vENsPjL5d3xPG3Bpd5Mk2/AcKM53g 6FAg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784183683; x=1784788483; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=7Wh24uH+pJSF3cGDjRO13znY6HNZJNEVNTxW5E0WYJA=; b=Lbj0zwZBksIX4tI4w0gMs4YYUp3kKwe26HZHmAf4o5N01VJGf8i6h/CUOW5OeLnUlN Ie4koCtqMXSocZ6s2qtC1qQvB7UsiwBeYysnleK8514ZMpPS5OFHvJdRzaV7NuCM9G5M V8W6mdQlaE4kLRJK9H9JPfHB25BY86dTq5ucPgGEx32EbWfDQiR2UNbbMFR2lcBHT7WU nkgO+2M7omWQUu/osOvlnrhwJkCcXgDOJ47KbvisAMXJ7r1NrrngJKsQnWGXAHXyOQHg IDJPEwGEyoQIXYhk4+Yy9nuYpmpBhkVbuSueoMX9wXgBCJmNCcoy74esIepEcrSBVdrW cc2w== X-Forwarded-Encrypted: i=1; AHgh+RqmSOz1RbMDK+DUm+67gN8AyBX6J+eXNFiOAGEKN0AwhOz8VuqEnHg5l5RGDkZKCj3WCmGMncsOCnCLVbE=@vger.kernel.org X-Gm-Message-State: AOJu0YzrP3e2fakWpx+OQujl0GQOToE5mViMJqeanZYtNhPyYp9yZLwA 92KqLSCO+iwqwLqadbShZ5z/lqDIzepavFH/E75wM0HJ3PKgrjX+R6/d X-Gm-Gg: AfdE7cmX2ybw/VNNcrCbMjpQcfcn/Z2Oqjfr/VlXzE2vfbaYRvPQ+Yh+EV5kbc8EDah 9sdT+SPKB80C7BKYz/WJOkLnnHLC6SgUY7F3tUZ2Mv467RH18HXb1MGV2IFd0rjDd4kHwJuCshh Sm/i+BAn+CaUOYVZftQR1c8gxzg69FAxUVgfhK5ELt9t7FC1zo1IE2uMJx0bFttZDuPy6O7FYl1 ROUEj8Z+s6ozz0G+urClpQgepHEbCE1SXD0UxVgwcKoxw1lSdgAkCO0R8jdp+YP196PIUZz4eyK bSmjaVxHNeWnkNZpGa+hSuvLA1gnPkTkWD2/+W16JhEzTkY64jk73jyVhEUUmIY7bDZVAyivUD5 UVaHTumdwrWspXkXDS8QeGMgNgUnI848lx1IaWNowDyCYwZU9GiIU/vjnaAUuL3dOtAD/Hp5msH NO3tOWEh8aL5II9/JXsyxH3J7bEtk= X-Received: by 2002:a05:6a00:440b:b0:847:9aa8:d3c1 with SMTP id d2e1a72fcca58-84beb53e204mr1322880b3a.34.1784183682572; Wed, 15 Jul 2026 23:34:42 -0700 (PDT) Received: from csl-conti-dell7858.ntu.edu.sg ([155.69.195.57]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-84a4f7dadcfsm4242172b3a.48.2026.07.15.23.34.38 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 15 Jul 2026 23:34:42 -0700 (PDT) From: Maoyi Xie To: Veerasenareddy Burru , Sathesh Edara , Satananda Burla , Shinas Rasheed Cc: Andrew Lunn , "David S . Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Maciej Fijalkowski , Guangshuo Li , David Carlier , Simon Horman , netdev@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH net v5 1/3] octeon_ep: fix skb frags overflow in the RX path Date: Thu, 16 Jul 2026 14:34:30 +0800 Message-Id: <20260716063432.2908100-2-maoyixie.tju@gmail.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260716063432.2908100-1-maoyixie.tju@gmail.com> References: <20260716063432.2908100-1-maoyixie.tju@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" __octep_oq_process_rx() builds an skb for a multi-buffer packet by adding one fragment per buffer_size chunk: data_len =3D buff_info->len - oq->max_single_buffer_size; while (data_len) { ... skb_add_rx_frag(skb, shinfo->nr_frags, buff_info->page, 0, buff_info->len, buff_info->len); ... } buff_info->len comes from the device response header (be64_to_cpu(resp_hw->length)). Nothing bounds the fragment count against MAX_SKB_FRAGS. data_len can be close to 65535. buffer_size defaults to about 3776 on 4K pages, so a full packet yields about 18 fragments. That is one more than the default MAX_SKB_FRAGS of 17, so skb_add_rx_frag() writes past shinfo->frags[]. The fragment count is now checked before build_skb(). A packet that needs more fragments than the skb can hold is dropped. octep_oq_drop_rx() consumes its descriptors like the build_skb failure path. The same class was fixed in other RX paths, including commit 5ffcb7b890f6 ("net: atlantic: fix fragment overflow handling in RX path") and commit f0813bcd2d9d ("net: wwan: t7xx: fix potential skb->frags overflow in RX path"). Fixes: 37d79d059606 ("octeon_ep: add Tx/Rx processing and interrupt support= ") Co-developed-by: Kaixuan Li Signed-off-by: Kaixuan Li Signed-off-by: Maoyi Xie Reviewed-by: Maciej Fijalkowski --- drivers/net/ethernet/marvell/octeon_ep/octep_rx.c | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/drivers/net/ethernet/marvell/octeon_ep/octep_rx.c b/drivers/ne= t/ethernet/marvell/octeon_ep/octep_rx.c index e6ebc7e44a..1e5494c652 100644 --- a/drivers/net/ethernet/marvell/octeon_ep/octep_rx.c +++ b/drivers/net/ethernet/marvell/octeon_ep/octep_rx.c @@ -453,6 +453,15 @@ static int __octep_oq_process_rx(struct octep_device *= oct, =20 octep_oq_next_pkt(oq, buff_info, &read_idx, &desc_used); =20 + if (buff_info->len > oq->max_single_buffer_size) { + u32 data_len =3D buff_info->len - oq->max_single_buffer_size; + + if (DIV_ROUND_UP(data_len, oq->buffer_size) > MAX_SKB_FRAGS) { + octep_oq_drop_rx(oq, buff_info, &read_idx, &desc_used); + continue; + } + } + skb =3D build_skb((void *)resp_hw, PAGE_SIZE); if (!skb) { octep_oq_drop_rx(oq, buff_info, --=20 2.34.1 From nobody Sat Jul 25 16:18:39 2026 Received: from mail-pf1-f171.google.com (mail-pf1-f171.google.com [209.85.210.171]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 563B3345751 for ; Thu, 16 Jul 2026 06:34:47 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.171 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784183688; cv=none; b=ZxZs+VT1P42YIkM7GSwqa1iywu1DCTOZ5TCeZXqZkRtAV2MBfudUtyBnq0LvcCmwr23U0pjAefgE0GG3SrBv4lzyAWndv+CgPSk6X5O7uoWHhQLO1DTkwUzqOW4mQoGi29931XRnsAvuaf2FMoZk5zUFKL2o+Eal48GfB09v3Jc= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784183688; c=relaxed/simple; bh=cTQoP0lWlAxfFS21VMcXcV5AqjPUsdSmGaP2HtEb0nM=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=a9JunnIR6WwYvScOXK6YCMvXH2AeS+CG/psOw9Rd8MLquZO5IFUJB8cRr8Z981p4gdb6SsGwdlorqarggsuIVd7aEFuAJT1rVzhocxJpUQh9P6/xdgTzrWe2Oyb0iDCvXQNzeX6t91VatDdYk7l++93kQ8VWYijE+8x6jZZs8fU= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=ec972UkW; arc=none smtp.client-ip=209.85.210.171 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="ec972UkW" Received: by mail-pf1-f171.google.com with SMTP id d2e1a72fcca58-8486ac3f347so215232b3a.1 for ; Wed, 15 Jul 2026 23:34:47 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784183687; x=1784788487; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=SAC+WsEZ64mnrQj0pnVENutWORk+53oxQVLeMc2X3SA=; b=ec972UkWOzctDho/p8NFJV00QvG+UYuw+HgQOFyD3+kG6ywBNDM7Uk0jN1aMZ3LgiQ dFd6kRMaudmlFAfHIte7TJB6y4aEyO+vVN2IbxeRQBOolYOykKGoneAjxCOV+1211fLf QX1Th/5teYVviEsLycxIa4gDQgXEv2BppPDf7GW8jcqFxnsLiWkm4+tDyg9bhEGpiVFQ 24jEEmlxVFkQfWQW5OCqPraC4Q1MVIyI69Xf+tBamonxTk3+3CYsmZtLkndACrcrktV4 FhJgKLjFkgfowbJ78+e2NrqOwrK15AYgjca1nN1mVvEufM625wlsYt2+Vg0g3DbnxQ9n D5jg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784183687; x=1784788487; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=SAC+WsEZ64mnrQj0pnVENutWORk+53oxQVLeMc2X3SA=; b=aKpO1nWvl98fmOkDUuZgw2dUsFhjhsp5rJYxCD7ONrkqvwp1DTg8UTfMU01XFMrano E+sCRIOk5p5Rm4e6HewnpG86CFCiMn8V2SqtG1rFI5ZLuKuuet8YITVyM/xH0NxZrgDx 8wKok6Szl1KDMGPd8KbNhEOMeE3xXwfDw+zzkzNsYwoXKVy54dK6L2SJeICBkfNomzLP 2TkISyZinDNvYbb4sxhe06IsGRpauSwzzCnWhdj/HzpM7dGO+aUUgghmwWTdcEzCRDAX QlywLUfJis5HDFNGzG6y7QM62/bufq0e5PbC8wMqta29V+3sLbpnPhMvh1YjtLRE0aOK TwkQ== X-Forwarded-Encrypted: i=1; AHgh+RqhPzVLpduA9vshyRhUJ+eVCUPVj52UaOkUZTRMRsg3HLYG9UYHxFbhb8Y1mYmFDdv7HVtZE3SIqX3Eb0s=@vger.kernel.org X-Gm-Message-State: AOJu0YwDxjtVL49Gej+UnYTcv3S/6WvfNIpZIcX943cfpd7suUlcBZSK ZbcuIy/AbZyi1sF5vlxBY8rPz6mnTfFCDEkbl3O1WkSfaoqPfxjB99JR X-Gm-Gg: AfdE7cnLbJbbHHgOHKnI3fOideeyl/37MNnGKXNz+s6R9H/Fe4SEhpJ+i0Cq775hUM5 8cnhlKmlqOgN2ZPf8Fid0IawrD6h/h76EjUwPp+3J3DMWzIRzHxWKIyvaqAKM8dtmFQCXSUzFFn FA9N0hcsy9+wuS3eNWWwSazoQCocwSLqH8f14boFS3mkEg2RieAPJhLZ5O9rXuWSvWS67jItyVv u30D7wqacQJVR/DbLS8fts67JtDHWbVg2kaIeSpvXfY73a+1K2gvpm26SVC/htwUVVrAGzl6TWJ 9wx59oGakEASEoHyhdzIYT3rqLKwU4T3Z2B5qmrmb12WX/s88NhLZ+/AaZmZSgIh6I8T2RdaWN4 aLNi/fWMxSx2l5dAQLYaeSvyWR0U3um6ZCmwK5wkeM9ApTcJHzHuivFbS/K2ZytOCpOi7rI5M0g FKGFtlc8+4VOuLN4nK58q5p25FwFM= X-Received: by 2002:a05:6a00:1250:b0:84a:32ba:a262 with SMTP id d2e1a72fcca58-84beb05714cmr1199736b3a.7.1784183686611; Wed, 15 Jul 2026 23:34:46 -0700 (PDT) Received: from csl-conti-dell7858.ntu.edu.sg ([155.69.195.57]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-84a4f7dadcfsm4242172b3a.48.2026.07.15.23.34.42 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 15 Jul 2026 23:34:46 -0700 (PDT) From: Maoyi Xie To: Veerasenareddy Burru , Sathesh Edara , Satananda Burla , Shinas Rasheed Cc: Andrew Lunn , "David S . Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Maciej Fijalkowski , Guangshuo Li , David Carlier , Simon Horman , netdev@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH net v5 2/3] octeon_ep_vf: Fix RX page leak on napi_build_skb() failure Date: Thu, 16 Jul 2026 14:34:31 +0800 Message-Id: <20260716063432.2908100-3-maoyixie.tju@gmail.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260716063432.2908100-1-maoyixie.tju@gmail.com> References: <20260716063432.2908100-1-maoyixie.tju@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Guangshuo Li __octep_vf_oq_process_rx() clears buff_info->page before building an skb from the RX page. On the success path the page is consumed by the skb, either as the skb head or as an RX fragment. If napi_build_skb() fails, however, the page is not consumed by an skb. The error path advances the descriptor and leaves the ring slot cleared, so the page is no longer tracked and is leaked. In the multi-fragment case, the remaining fragment pages are also unmapped and removed from their ring slots without being released. Release the head page when napi_build_skb() fails, and release each remaining fragment page before clearing its ring slot. Fixes: dd66b4285470 ("octeon_ep_vf: add NULL check for napi_build_skb()") Signed-off-by: Guangshuo Li Reviewed-by: Maciej Fijalkowski --- drivers/net/ethernet/marvell/octeon_ep_vf/octep_vf_rx.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/drivers/net/ethernet/marvell/octeon_ep_vf/octep_vf_rx.c b/driv= ers/net/ethernet/marvell/octeon_ep_vf/octep_vf_rx.c index d982474082..302559b16b 100644 --- a/drivers/net/ethernet/marvell/octeon_ep_vf/octep_vf_rx.c +++ b/drivers/net/ethernet/marvell/octeon_ep_vf/octep_vf_rx.c @@ -418,6 +418,7 @@ static int __octep_vf_oq_process_rx(struct octep_vf_dev= ice *oct, skb =3D napi_build_skb((void *)resp_hw, PAGE_SIZE); if (!skb) { oq->stats->alloc_failures++; + put_page(virt_to_page(resp_hw)); desc_used++; read_idx =3D octep_vf_oq_next_idx(oq, read_idx); continue; @@ -434,6 +435,7 @@ static int __octep_vf_oq_process_rx(struct octep_vf_dev= ice *oct, skb =3D napi_build_skb((void *)resp_hw, PAGE_SIZE); if (!skb) { oq->stats->alloc_failures++; + put_page(virt_to_page(resp_hw)); desc_used++; read_idx =3D octep_vf_oq_next_idx(oq, read_idx); data_len =3D buff_info->len - oq->max_single_buffer_size; @@ -442,6 +444,7 @@ static int __octep_vf_oq_process_rx(struct octep_vf_dev= ice *oct, PAGE_SIZE, DMA_FROM_DEVICE); buff_info =3D (struct octep_vf_rx_buffer *) &oq->buff_info[read_idx]; + put_page(buff_info->page); buff_info->page =3D NULL; if (data_len < oq->buffer_size) data_len =3D 0; --=20 2.34.1 From nobody Sat Jul 25 16:18:39 2026 Received: from mail-pf1-f170.google.com (mail-pf1-f170.google.com [209.85.210.170]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 30DDD2E7391 for ; Thu, 16 Jul 2026 06:34:51 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.170 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784183692; cv=none; b=q/5W1tOP0FSkxKKPPtOSL8qWYVolKNq+v6vKwiSpOayyXct0s/FViZCiUTue9azkYHFsrJNVydCH890x7EeIUpseicv02AjTuEm2lBxlD9Y13bK0QedAgaz4K2ptl5qTewqGgtNjawR6u/4w28UGIgPkXndLlnKWumDgUN/3fsc= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784183692; c=relaxed/simple; bh=vwtzLaUn7wHgUAalpp5RyegEj5VMiUcE2KwC9OxQpoA=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=hn6ffTNMERwgO0zJo9c5F6bRdY7QhueeFNCpF2sSPefIVpcH+rTGmhflfm1fZG/GNoM58nV4mfLwJzrnLzp/QM2iOawoDSGhEr3OpqbywgHyExxaYPXSpjflNFg5Njote9ns5ekgtIohA4vU08XQSo6PX+xTJYHrtH3mpcsEHVw= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=nbdkXmL4; arc=none smtp.client-ip=209.85.210.170 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="nbdkXmL4" Received: by mail-pf1-f170.google.com with SMTP id d2e1a72fcca58-848761b5897so3275443b3a.3 for ; Wed, 15 Jul 2026 23:34:51 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784183690; x=1784788490; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=GwXxw7O4TWZvXWtuVAmXlGrveb0Tk1fsMJGJIBcnjmk=; b=nbdkXmL46zpBls7LPE4Ql/QjaIyicnvx7h+gpaWtq3xr+D49YtGTfMvoF0Wj4uGAgx IeNBy539JJ7tVL8y4404MTz1EPGHVfjErPqJV5/djiMTKfnxGx2Be5popFww8VFrqMkL PimpZsiM1XkvuJIdmMWklR8LWbihstK2pAGz0Tqvk+ziy8QB3yp4vqea5LwU5IuL9CmN lSx6lnDruyqGMUvXrabbmVBw0qBye0h0YYwWxKDmSCx/HB0cIhTyFvVLRSAuN3PWBJDY 6RWKnsJqbCRbqacMqpkyWpxflE+DrrRyZANgeYFR2arCRk2wbyn5/h4oLdjJ57yz3Znr UbsQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784183690; x=1784788490; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=GwXxw7O4TWZvXWtuVAmXlGrveb0Tk1fsMJGJIBcnjmk=; b=RxVCEjSLHAhzoZfK1TWSRhBOkRDB6fPKZl/YFSL59LqqO397PQHF0MVoNJGOrCFLVb ckv2aTAMSWkR/F4xOmfpfbEo9jrAHS4W7rn0S7/pjalb3hpjlusTZdTN8fuk/Aio7P+l Pem1JkQmywAgIhsbN66nXTkcziExhPqmHkUHWfbOxF/OtYntzARDglPETTRyQ8T3Xy8y +gvjNk0rToQN2Vj+LTj96gDPaoYJAfAPCno1uErMsqrILBeCaB7WTz2x6uURdC49UOnR 3JmmvKXGqRrLu4ltAnC7oNmigSOG3N7S40jFPj5jth2cEZ6/kcJK+hd00nwmoIC9MRNH TZyQ== X-Forwarded-Encrypted: i=1; AHgh+Rps4FEqjFyGtnlOxG+Op5Bc8JXxK6p6FSPlctTUzqJIOccVnNSnTJ1TYsepSMXXw7sqMDe79DE37P4mViI=@vger.kernel.org X-Gm-Message-State: AOJu0YxsEoL/KprkT99Lm151ikA1D/lfgRYURq32AZdyst4SSQ4fgefw 8GxhnriuZFW9BuSJUc2EearHfp/IDQ57hLbUpKlKtZAM2PDA8XfL37NL X-Gm-Gg: AfdE7cnJdmVwzWZnYTuqjanxGknHt5J87aPgMxarwvsvOcsVHyglqjh6L/9yz2dMzSr W4PQ6a0rFcuXACyqUim9ktPj06/mOGFGt5dXwLVUikrgbyIdsgCjjF9Yy6iob+m4cIY0PZMFOMq M0QRdte4JMEUJneUxd6LLZV50cx/C85NXac758Mpn5ck004pkSz7Z6nLE8KEy2KZpdFppy1IFVN 7KI1RGYrr7r0cPfz4qw6JXz/V4FsqkMy+lXakzVkHVD0hjbiZMmerFLBEBz1aUBPFQNfQ/J+9xu qIDZyO9dZe2YwNbbkt0jyLBsW9fBj9cEs8s1w6ML0O3+1EAGCdpXZXyjsm5VQR2VV7XNEfaseSm U3zEz63FLQCKgDCRTlOh+S1p/ALns4KMKqa2/oZ/830kuKdoVFv9wEvUjvwlonrw4QtBdCqmsL8 AR0iKQvPXZHOPiHU8NeFZsFIWAzVcGVUEluNV99Q== X-Received: by 2002:a05:6a00:2da4:b0:845:e41f:9696 with SMTP id d2e1a72fcca58-84a5574252bmr8683937b3a.25.1784183690556; Wed, 15 Jul 2026 23:34:50 -0700 (PDT) Received: from csl-conti-dell7858.ntu.edu.sg ([155.69.195.57]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-84a4f7dadcfsm4242172b3a.48.2026.07.15.23.34.46 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 15 Jul 2026 23:34:50 -0700 (PDT) From: Maoyi Xie To: Veerasenareddy Burru , Sathesh Edara , Satananda Burla , Shinas Rasheed Cc: Andrew Lunn , "David S . Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Maciej Fijalkowski , Guangshuo Li , David Carlier , Simon Horman , netdev@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH net v5 3/3] octeon_ep_vf: fix skb frags overflow in the RX path Date: Thu, 16 Jul 2026 14:34:32 +0800 Message-Id: <20260716063432.2908100-4-maoyixie.tju@gmail.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260716063432.2908100-1-maoyixie.tju@gmail.com> References: <20260716063432.2908100-1-maoyixie.tju@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" __octep_vf_oq_process_rx() has the same unbounded fragment loop as the PF driver. buff_info->len comes from the device response header. The loop adds one fragment per buffer_size chunk with no check against MAX_SKB_FRAGS. A long packet yields about 18 fragments. That is one past the default MAX_SKB_FRAGS of 17. skb_add_rx_frag() then writes past shinfo->frags[]. The fragment count is now checked before napi_build_skb(). A packet that needs more fragments than the skb can hold is dropped. octep_vf_oq_drop_rx() drains those descriptors. It also frees the head page and every fragment page. The previous patch added those frees to the inline drop path. The napi_build_skb() failure path now uses the same helper. Fixes: 1cd3b407977c ("octeon_ep_vf: add Tx/Rx processing and interrupt supp= ort") Co-developed-by: Kaixuan Li Signed-off-by: Kaixuan Li Signed-off-by: Maoyi Xie Reviewed-by: Maciej Fijalkowski --- .../marvell/octeon_ep_vf/octep_vf_rx.c | 52 ++++++++++++------- 1 file changed, 33 insertions(+), 19 deletions(-) diff --git a/drivers/net/ethernet/marvell/octeon_ep_vf/octep_vf_rx.c b/driv= ers/net/ethernet/marvell/octeon_ep_vf/octep_vf_rx.c index 302559b16b..138e779f7e 100644 --- a/drivers/net/ethernet/marvell/octeon_ep_vf/octep_vf_rx.c +++ b/drivers/net/ethernet/marvell/octeon_ep_vf/octep_vf_rx.c @@ -357,6 +357,31 @@ static inline u32 octep_vf_oq_next_idx(struct octep_vf= _oq *oq, u32 idx) return (idx + 1 =3D=3D oq->max_count) ? 0 : idx + 1; } =20 +static void octep_vf_oq_drop_rx(struct octep_vf_oq *oq, + struct octep_vf_rx_buffer *buff_info, + void *resp_hw, u32 *read_idx, u32 *desc_used) +{ + u32 data_len =3D buff_info->len - oq->max_single_buffer_size; + + put_page(virt_to_page(resp_hw)); + (*desc_used)++; + *read_idx =3D octep_vf_oq_next_idx(oq, *read_idx); + while (data_len) { + dma_unmap_page(oq->dev, oq->desc_ring[*read_idx].buffer_ptr, + PAGE_SIZE, DMA_FROM_DEVICE); + buff_info =3D (struct octep_vf_rx_buffer *) + &oq->buff_info[*read_idx]; + put_page(buff_info->page); + buff_info->page =3D NULL; + if (data_len < oq->buffer_size) + data_len =3D 0; + else + data_len -=3D oq->buffer_size; + (*desc_used)++; + *read_idx =3D octep_vf_oq_next_idx(oq, *read_idx); + } +} + /** * __octep_vf_oq_process_rx() - Process hardware Rx queue and push to stac= k. * @@ -430,29 +455,18 @@ static int __octep_vf_oq_process_rx(struct octep_vf_d= evice *oct, read_idx =3D octep_vf_oq_next_idx(oq, read_idx); } else { struct skb_shared_info *shinfo; - u16 data_len; + u32 data_len; + + data_len =3D buff_info->len - oq->max_single_buffer_size; + if (DIV_ROUND_UP(data_len, oq->buffer_size) > MAX_SKB_FRAGS) { + octep_vf_oq_drop_rx(oq, buff_info, resp_hw, &read_idx, &desc_used); + continue; + } =20 skb =3D napi_build_skb((void *)resp_hw, PAGE_SIZE); if (!skb) { oq->stats->alloc_failures++; - put_page(virt_to_page(resp_hw)); - desc_used++; - read_idx =3D octep_vf_oq_next_idx(oq, read_idx); - data_len =3D buff_info->len - oq->max_single_buffer_size; - while (data_len) { - dma_unmap_page(oq->dev, oq->desc_ring[read_idx].buffer_ptr, - PAGE_SIZE, DMA_FROM_DEVICE); - buff_info =3D (struct octep_vf_rx_buffer *) - &oq->buff_info[read_idx]; - put_page(buff_info->page); - buff_info->page =3D NULL; - if (data_len < oq->buffer_size) - data_len =3D 0; - else - data_len -=3D oq->buffer_size; - desc_used++; - read_idx =3D octep_vf_oq_next_idx(oq, read_idx); - } + octep_vf_oq_drop_rx(oq, buff_info, resp_hw, &read_idx, &desc_used); continue; } rx_bytes +=3D buff_info->len; --=20 2.34.1