Re: [PATCH] firewire: net: Fix fragmented datagram reassembly
From: Takashi Sakamoto
Date: Mon Jul 13 2026 - 07:21:33 EST
Hi,
On Tue, Jul 07, 2026 at 11:04:54PM +0800, Ruoyu Wang wrote:
> fwnet_frag_new() keeps a sorted list of received fragments for a partial
> datagram. When a new fragment is adjacent to an existing fragment, the
> code checks whether the new fragment also closes the gap to the next or
> previous list entry.
>
> Those neighbor lookups currently assume that the current fragment always
> has a real next or previous fragment. At a list edge, the next or
> previous entry is the list head, not a struct fwnet_fragment_info.
>
> The gap checks also compare against the old edge of the current fragment
> instead of the edge after adding the new fragment. As a result, a
> fragment that bridges two existing ranges may leave two adjacent ranges
> unmerged, so fwnet_pd_is_complete() can miss a complete datagram.
>
> Check for the list head before looking up the neighboring fragment, and
> compare the neighbor against the new fragment's far edge when deciding
> whether to merge all three ranges.
>
> This issue was found by a static analysis checker and confirmed by
> manual source review.
>
> Fixes: c76acec6d551 ("firewire: add IPv4 support")
> Signed-off-by: Ruoyu Wang <ruoyuw560@xxxxxxxxx>
> ---
> drivers/firewire/net.c | 39 +++++++++++++++++++++------------------
> 1 file changed, 21 insertions(+), 18 deletions(-)
Applied to for-linus branch.
Thanks
Takashi Sakamoto