Re: [PATCH net-next 0/9] net: skbuff: convert most BUG_ON()s to WARN_ON_ONCE() and an error

From: Willem de Bruijn

Date: Wed Oct 07 2026 - 10:49:04 EST


Josef Bacik wrote:
> I'm going through and reducing BUG_ON() usage in areas that have created
> the most problems for us. 89 commits in the tree quote "kernel BUG at
> net/core/skbuff.c", 31 of them since 2024, and some of those could be
> triggered from inside a user namespace.
>
> The first patch is a fix: skb_copy_and_csum_bits() leaves stale bytes
> in a buffer headed for the wire when it hits unreadable frags. The
> BUG_ON() conversion of the same function needs the same handling, so
> it's here rather than sent separately.
>
> The rest of the series converts 17 of the 19 BUG_ON()s in skbuff.c.
> Each one becomes
>
> if (WARN_ON_ONCE(cond))
> <error path>;

Good idea. I was thinking of doing exactly this sweep after addressing
one case recently in commit ee1972def665 ("net: downgrade BUG_ON
EIOCBQUEUED in sock_sendmsg_nosec")

Instead of WARN_ON_ONCE, which still triggers a panic on systems with
panic_on_warn, DEBUG_NET_WARN_ON_ONCE?