Re: [PATCH net] net: skbuff: don't leave stale bytes in skb_copy_and_csum_bits()

From: Josef Bacik

Date: Wed Oct 07 2026 - 14:30:59 EST


On Wed, Oct 07, 2026 at 05:34:41PM +0000, netdev-bot+sinfo@xxxxxxxxxx wrote:
> This is an automated message. This series looks like a fix, but its
> commit messages seem to be missing some information:
>
> - How the issue was discovered, e.g. hit in production, hit during
> development, syzbot report, manual code inspection, LLM or static
> analysis tool scan.

Found during development. I was converting the BUG_ON()s in skbuff.c
[1], and the conversion of the leftover-length BUG_ON() in
skb_copy_and_csum_bits() zeroes the part of the caller's buffer it
couldn't fill. An LLM review of that change pointed out that the
existing unreadable-frags early return in the same function leaves the
buffer unfilled. I confirmed it by reading the code and with a test
module that marks a nonlinear skb unreadable. It hasn't been hit in
production that I know of.

[1] https://lore.kernel.org/all/20261007-b4-skbuff-bug-on-v2-0-b9a5f732895b@xxxxxxxxxxxxxx/

Thanks,
Josef