[PATCH net v2 1/3] net: core: propagate unreadable flag in skb_zerocopy
Mina Almasry <[email protected]> Mon, 3 Aug 2026 17:14:39 +0000
| Newsgroups | org.kernel.vger.netdev,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <[email protected]> |
When skb_zerocopy() copies devmem payload fragments, it fails to update
the target skb's unreadable flag. This causes the target to appear as
readable memory.
Propagate the unreadable flag if any devmem fragments were copied from
the source.
Additionally, to prevent memory corruption, explicitly return -EFAULT
if standard payload from the head is mixed into the same skb alongside
unreadable devmem fragments during a head-to-frag extraction.
Fixes: 65249feb6b3d ("net: add support for skbs with unreadable frags")
Cc: Pavel Begunkov <[email protected]>
Cc: Stanislav Fomichev <[email protected]>
Cc: Bobby Eshleman <[email protected]>
Cc: Florian Westphal <[email protected]>
Signed-off-by: Mina Almasry <[email protected]>
Reviewed-by: Pavel Begunkov <[email protected]>
---
v2:
- Return -EFAULT when mixing head-to-frag unreadable/readable frags to prevent memory corruption (Pavel).
v1: https://lore.kernel.org/r/[email protected]
---
net/core/skbuff.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/net/core/skbuff.c b/net/core/skbuff.c
index ba3dbac80fb49..8bacc6c4e16e1 100644
--- a/net/core/skbuff.c
+++ b/net/core/skbuff.c
@@ -3905,6 +3905,9 @@ skb_zerocopy(struct sk_buff *to, struct sk_buff *from, int len, int hlen)
}
}
+ if (!skb_frags_readable(from) && j > 0 && len)
+ return -EFAULT;
+
skb_len_add(to, len + plen);
if (unlikely(skb_orphan_frags(from, GFP_ATOMIC))) {
@@ -3928,6 +3931,9 @@ skb_zerocopy(struct sk_buff *to, struct sk_buff *from, int len, int hlen)
}
skb_shinfo(to)->nr_frags = j;
+ if (i > 0 && from->unreadable)
+ to->unreadable = 1;
+
return 0;
}
EXPORT_SYMBOL_GPL(skb_zerocopy);
base-commit: af39eb111ce6b5eba9c08513b62c4868eb7e7fd5
--
2.55.0.571.g244d577d93-goog