[PATCH net v3 3/3] net: stmmac: document oversized AF_XDP frame handling

From: Stanislav Fomichev

Date: Wed Aug 19 2026 - 12:13:45 EST


stmmac drops AF_XDP zero-copy frames that exceed taprio's queueMaxSDU
after xsk_tx_peek_desc() has reserved their completion entries.

Completing a rejected descriptor is unsafe because AF_XDP completions are
ordered: xsk_tx_completed(pool, 1) would complete the oldest outstanding
descriptor, which may still be owned by hardware. Instead, leave the
completion pending so the ring eventually wedges and increment the drop
counter to expose the application error without risking hardware
misbehavior.

Document this intentional ring imbalance at the check.

Signed-off-by: Stanislav Fomichev <sdf@xxxxxxxxxxx>
---
drivers/net/ethernet/stmicro/stmmac/stmmac_main.c | 4 ++++
1 file changed, 4 insertions(+)

diff --git a/drivers/net/ethernet/stmicro/stmmac/stmmac_main.c b/drivers/net/ethernet/stmicro/stmmac/stmmac_main.c
index 62de03e65a90..6a532747c039 100644
--- a/drivers/net/ethernet/stmicro/stmmac/stmmac_main.c
+++ b/drivers/net/ethernet/stmicro/stmmac/stmmac_main.c
@@ -2713,6 +2713,10 @@ static bool stmmac_xdp_xmit_zc(struct stmmac_priv *priv, u32 queue, u32 budget)
if (priv->est && priv->est->enable &&
priv->est->max_sdu[queue] &&
xdp_desc.len > priv->est->max_sdu[queue]) {
+ /* Completions are ordered, so this descriptor cannot
+ * be completed safely. Wedge the ring to expose the
+ * application error instead.
+ */
priv->xstats.max_sdu_txq_drop[queue]++;
continue;
}
--
2.53.0-Meta