diff options
| author | Pavel Begunkov <asml.silence@gmail.com> | 2026-09-04 14:43:07 +0100 |
|---|---|---|
| committer | Paolo Abeni <pabeni@redhat.com> | 2026-09-10 14:45:57 +0200 |
| commit | 125755776bc6d4dd53eaf551c87e3d460625d638 (patch) | |
| tree | 2849f24849762901d55b340b73e9f442211eeffb /scripts/basic/split-include.c | |
| parent | 7addb4e5ef1702704914b47bca3f706ef96c1589 (diff) | |
| download | linux-125755776bc6d4dd53eaf551c87e3d460625d638.tar.gz linux-125755776bc6d4dd53eaf551c87e3d460625d638.zip | |
tcp: reject non zerocopy devmem tx
Devmem tcp tx doesn't work without zero-copy, however it's not currently
enforced if NETIF_F_SG isn't present. In this case, tcp_sendmsg_locked()
will try the copy path and try to copy data from an iovec which consists
of offsets into the dma-buf and would normally fail. Moreover,
d9c56501c72fd ("net: tcp: block mixing readable and unreadable frags")
relies on that and assumes that the devmem binding is present IFF we're
using the zero-copy path, which can be used to mix net-iov and pages in
a single skb, and break invariants. Let's reject devmem tx without
zero-copy.
Note, the parameter check the patch is modifying is too loose, we can
create an io_uring request with dmabuf_id and all ZC flags, but which
won't have the binding. We replace it with stricter validation.
Fixes: bd61848900bff ("net: devmem: Implement TX path")
Fixes: d9c56501c72fd ("net: tcp: block mixing readable and unreadable frags")
Signed-off-by: Pavel Begunkov <asml.silence@gmail.com>
Reviewed-by: Mina Almasry <almasrymina@google.com>
Link: https://patch.msgid.link/fdc2478d8f21268d7078556409887d8e6ba0ad32.1788529053.git.asml.silence@gmail.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Diffstat (limited to 'scripts/basic/split-include.c')
0 files changed, 0 insertions, 0 deletions
