[PATCH net v4 0/3] octeon_ep, octeon_ep_vf: fix RX skb frags overflow and page leak
From: Maoyi Xie
Date: Mon Jul 06 2026 - 11:22:57 EST
The octeon_ep and octeon_ep_vf RX paths add one skb fragment per buffer
with no bound against MAX_SKB_FRAGS. buff_info->len comes from the device
response header. A long packet needs about 18 fragments. That is one past
the default MAX_SKB_FRAGS of 17, so skb_add_rx_frag() writes past
shinfo->frags[]. Patch 1 bounds octeon_ep. Patch 3 bounds octeon_ep_vf.
Patch 2 is Guangshuo Li's fix for an octeon_ep_vf RX page leak on the
napi_build_skb() failure path. It touches the same drop code as patch 3.
I carry it here so the series applies without conflict, per Maciej. Patch 3
moves that drain loop into a helper. The helper carries the page frees from
patch 2, so the overflow drop path frees its pages too.
octeon_ep has the same leak on its drop path. A separate patch will fix it
once this series lands.
v4:
- add Guangshuo Li's octeon_ep_vf page leak fix as patch 2, per Maciej.
- octeon_ep_vf: the fragment count fix now sits on top of patch 2. The drop
helper octep_vf_oq_drop_rx() frees the head and fragment pages.
- octeon_ep: no change, keeps Maciej's Reviewed-by.
v1: https://lore.kernel.org/r/20260701112825.1653044-1-maoyixie.tju@xxxxxxxxx
v2: https://lore.kernel.org/r/20260702180518.2013324-1-maoyixie.tju@xxxxxxxxx
v3: https://lore.kernel.org/r/20260704061511.2350737-1-maoyixie.tju@xxxxxxxxx
Guangshuo Li (1):
octeon_ep_vf: Fix RX page leak on napi_build_skb() failure
Maoyi Xie (2):
octeon_ep: fix skb frags overflow in the RX path
octeon_ep_vf: fix skb frags overflow in the RX path
.../net/ethernet/marvell/octeon_ep/octep_rx.c | 9 ++++
.../marvell/octeon_ep_vf/octep_vf_rx.c | 49 +++++++++++++------
2 files changed, 42 insertions(+), 16 deletions(-)
--
2.34.1