Re: [PATCH net] net/packet: preserve TX_RING progress on a later frame error
From: Willem de Bruijn
Date: Sun Sep 13 2026 - 18:29:32 EST
Mark Amirkan via B4 Relay wrote:
> From: Mark Amirkan <markdamirkan@xxxxxxxxx>
>
> tpacket_snd() can transmit one or more frames before a later frame fails
> validation. The failing frame is marked TP_STATUS_WRONG_FORMAT, but its
> error replaces len_sum, so send() reports failure despite the earlier
> transmission.
>
> Return the completed byte count when it is nonzero, as the allocation
> failure path already does. Keep TP_STATUS_WRONG_FORMAT on the bad frame
> so userspace can identify it.
>
> In a two-frame TPACKET_V2 test, a valid 60-byte frame followed by an
> oversized frame sends the first frame but returns -EMSGSIZE. With this
> change, send() returns 60 and the second frame remains marked
> TP_STATUS_WRONG_FORMAT.
>
> Fixes: 69e3c75f4d54 ("net: TX_RING and packet mmap")
> Cc: stable@xxxxxxxxxxxxxxx
> Assisted-by: Symbolic
> Signed-off-by: Mark Amirkan <markdamirkan@xxxxxxxxx>
> ---
> net/packet/af_packet.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/net/packet/af_packet.c b/net/packet/af_packet.c
> index 76bde7906d..b7e1848b61 100644
> --- a/net/packet/af_packet.c
> +++ b/net/packet/af_packet.c
> @@ -2893,7 +2893,7 @@ static int tpacket_snd(struct packet_sock *po, struct msghdr *msg)
> continue;
> } else {
> status = TP_STATUS_WRONG_FORMAT;
> - err = tp_len;
> + err = len_sum ? : tp_len;
> goto out_status;
> }
This makes sense in principle, but changes longtime established and
expected behavior.
In particular, applications may not know to recover from a
TP_STATUS_WRONG_FORMAT unless an error is returned.
If this sendmsg returns tp_len here, i.e., (partial) success,
subsequent calls will return 0 / -ETIMEDOUT, as if no space is
available.