Re: [PATCH net-next 0/9] net: skbuff: convert most BUG_ON()s to WARN_ON_ONCE() and an error

From: Fernando Fernandez Mancera

Date: Wed Oct 07 2026 - 11:04:44 EST


On 10/7/26 4:48 PM, Willem de Bruijn wrote:
Josef Bacik wrote:
I'm going through and reducing BUG_ON() usage in areas that have created
the most problems for us. 89 commits in the tree quote "kernel BUG at
net/core/skbuff.c", 31 of them since 2024, and some of those could be
triggered from inside a user namespace.

The first patch is a fix: skb_copy_and_csum_bits() leaves stale bytes
in a buffer headed for the wire when it hits unreadable frags. The
BUG_ON() conversion of the same function needs the same handling, so
it's here rather than sent separately.

The rest of the series converts 17 of the 19 BUG_ON()s in skbuff.c.
Each one becomes

if (WARN_ON_ONCE(cond))
<error path>;

Good idea. I was thinking of doing exactly this sweep after addressing
one case recently in commit ee1972def665 ("net: downgrade BUG_ON
EIOCBQUEUED in sock_sendmsg_nosec")

Instead of WARN_ON_ONCE, which still triggers a panic on systems with
panic_on_warn, DEBUG_NET_WARN_ON_ONCE?

I agree with using DEBUG_NET_WARN_ON_ONCE at least for paths that can be triggered from userspace. I did something similar in Netfilter subsystem not so long ago.