Re: [PATCH net v2 1/3] net: core: propagate unreadable flag in skb_zerocopy
Bobby Eshleman <[email protected]> Mon, 3 Aug 2026 10:31:25 -0700
| Newsgroups | org.kernel.vger.netdev,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <[email protected]> |
On Mon, Aug 03, 2026 at 05:14:39PM +0000, Mina Almasry wrote:
> When skb_zerocopy() copies devmem payload fragments, it fails to update
> the target skb's unreadable flag. This causes the target to appear as
> readable memory.
>
> Propagate the unreadable flag if any devmem fragments were copied from
> the source.
>
> Additionally, to prevent memory corruption, explicitly return -EFAULT
> if standard payload from the head is mixed into the same skb alongside
> unreadable devmem fragments during a head-to-frag extraction.
>
> Fixes: 65249feb6b3d ("net: add support for skbs with unreadable frags")
> Cc: Pavel Begunkov <[email protected]>
> Cc: Stanislav Fomichev <[email protected]>
> Cc: Bobby Eshleman <[email protected]>
> Cc: Florian Westphal <[email protected]>
> Signed-off-by: Mina Almasry <[email protected]>
> Reviewed-by: Pavel Begunkov <[email protected]>
>
> ---
> v2:
> - Return -EFAULT when mixing head-to-frag unreadable/readable frags to prevent memory corruption (Pavel).
> v1: https://lore.kernel.org/r/[email protected]
> ---
> net/core/skbuff.c | 6 ++++++
> 1 file changed, 6 insertions(+)
>
> diff --git a/net/core/skbuff.c b/net/core/skbuff.c
> index ba3dbac80fb49..8bacc6c4e16e1 100644
> --- a/net/core/skbuff.c
> +++ b/net/core/skbuff.c
> @@ -3905,6 +3905,9 @@ skb_zerocopy(struct sk_buff *to, struct sk_buff *from, int len, int hlen)
> }
> }
>
> + if (!skb_frags_readable(from) && j > 0 && len)
> + return -EFAULT;
> +
> skb_len_add(to, len + plen);
>
> if (unlikely(skb_orphan_frags(from, GFP_ATOMIC))) {
> @@ -3928,6 +3931,9 @@ skb_zerocopy(struct sk_buff *to, struct sk_buff *from, int len, int hlen)
> }
> skb_shinfo(to)->nr_frags = j;
>
> + if (i > 0 && from->unreadable)
> + to->unreadable = 1;
> +
> return 0;
> }
> EXPORT_SYMBOL_GPL(skb_zerocopy);
>
> base-commit: af39eb111ce6b5eba9c08513b62c4868eb7e7fd5
> --
> 2.55.0.571.g244d577d93-goog
>
Reviewed-by: Bobby Eshleman <[email protected]>