[PATCH net 2/2] net: macb: copy shared skbs before appending the FCS

From: Nicolai Buchwitz

Date: Tue Oct 06 2026 - 01:43:23 EST


macb_pad_and_fcs() appends the FCS in place when the skb has tailroom.
A shared skb, as pktgen sends in clone_skb mode, grows by one FCS per
transmit. BQL then completes more bytes than were queued and
dql_completed() hits its BUG_ON.

On a Raspberry Pi CM5 (RP1 GEM) pktgen with clone_skb 1000 burst 32 at
60 bytes kills the box within seconds.

Copy shared skbs before appending the FCS. Clearing IFF_TX_SKB_SHARING
would also fix it but makes pktgen refuse clone_skb on macb.

Fixes: 653e92a9175e ("net: macb: add support for padding and fcs computation")
Signed-off-by: Nicolai Buchwitz <nb@xxxxxxxxxxx>
---
drivers/net/ethernet/cadence/macb_main.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)

diff --git a/drivers/net/ethernet/cadence/macb_main.c b/drivers/net/ethernet/cadence/macb_main.c
index 6082e63009a5..261a7e87520a 100644
--- a/drivers/net/ethernet/cadence/macb_main.c
+++ b/drivers/net/ethernet/cadence/macb_main.c
@@ -2435,6 +2435,7 @@ static int macb_pad_and_fcs(struct sk_buff **skb, bool add_fcs)
skb_is_nonlinear(*skb);
int padlen = ETH_ZLEN - (*skb)->len;
int tailroom = skb_tailroom(*skb);
+ bool shared = skb_shared(*skb);
struct sk_buff *nskb;
u32 fcs;

@@ -2443,7 +2444,8 @@ static int macb_pad_and_fcs(struct sk_buff **skb, bool add_fcs)

if (padlen <= 0) {
/* FCS could be appended to tailroom. */
- if (!skb_is_nonlinear(*skb) && tailroom >= ETH_FCS_LEN)
+ if (!shared && !skb_is_nonlinear(*skb) &&
+ tailroom >= ETH_FCS_LEN)
goto add_fcs;
/* Reallocate with room for the FCS. */
padlen = ETH_FCS_LEN;
@@ -2452,7 +2454,7 @@ static int macb_pad_and_fcs(struct sk_buff **skb, bool add_fcs)
padlen += ETH_FCS_LEN;
}

- if (cloned || tailroom < padlen) {
+ if (shared || cloned || tailroom < padlen) {
nskb = skb_copy_expand(*skb, 0, padlen, GFP_ATOMIC);
if (!nskb)
return -ENOMEM;

--
2.53.0