[PATCH net-next 3/7] net: qualcomm: rmnet: Restrict supported MAP checksum configurations

From: Subash Abhinov Kasiviswanathan

Date: Wed Sep 30 2026 - 01:15:08 EST


RmNet only supports three MAP data format configurations: MAPv1
(no checksum offload), MAPv4 (v4 checksum offload) and MAPv5 (v5
checksum offload). QMAP command support is orthogonal and may be
combined with any of the three. Mixing the v4 and v5 checksum
offload flags together is not a valid configuration.

Validate the requested data format in both rmnet_newlink() and
rmnet_changelink() and reject any combination that sets both the
v4 and v5 checksum offload flags at the same time. This is in
preparation for the next patch where coalescing support needs to be
allowed with MAPv5 format only.

Co-developed-by: Sean Tranchetti <sean.tranchetti@xxxxxxxxxxxxxxxx>
Signed-off-by: Sean Tranchetti <sean.tranchetti@xxxxxxxxxxxxxxxx>
Signed-off-by: Subash Abhinov Kasiviswanathan <subash.a.kasiviswanathan@xxxxxxxxxxxxxxxx>
---
.../ethernet/qualcomm/rmnet/rmnet_config.c | 62 ++++++++++++++-----
1 file changed, 46 insertions(+), 16 deletions(-)

diff --git a/drivers/net/ethernet/qualcomm/rmnet/rmnet_config.c b/drivers/net/ethernet/qualcomm/rmnet/rmnet_config.c
index 61b04c6c0390..8051aef01ae3 100644
--- a/drivers/net/ethernet/qualcomm/rmnet/rmnet_config.c
+++ b/drivers/net/ethernet/qualcomm/rmnet/rmnet_config.c
@@ -26,6 +26,22 @@ static int rmnet_is_real_dev_registered(const struct net_device *real_dev)
return rcu_access_pointer(real_dev->rx_handler) == rmnet_rx_handler;
}

+/* Only three MAP configurations are supported: MAPv1 (no checksum
+ * offload), MAPv4 (v4 checksum offload) and MAPv5 (v5 checksum
+ * offload). QMAP command support is orthogonal and permitted with
+ * any of the three. Mixing v4 and v5 checksum offload flags together
+ * is not a supported configuration.
+ */
+static bool rmnet_config_data_format_valid(u32 data_format)
+{
+ u32 v4_mask = RMNET_FLAGS_INGRESS_MAP_CKSUMV4 |
+ RMNET_FLAGS_EGRESS_MAP_CKSUMV4;
+ u32 v5_mask = RMNET_FLAGS_INGRESS_MAP_CKSUMV5 |
+ RMNET_FLAGS_EGRESS_MAP_CKSUMV5;
+
+ return !(data_format & v4_mask) || !(data_format & v5_mask);
+}
+
/* Needs rtnl lock */
struct rmnet_port*
rmnet_get_port_rtnl(const struct net_device *real_dev)
@@ -143,6 +159,20 @@ static int rmnet_newlink(struct net_device *dev,
return -ENODEV;
}

+ if (data[IFLA_RMNET_FLAGS]) {
+ struct ifla_rmnet_flags *flags;
+
+ flags = nla_data(data[IFLA_RMNET_FLAGS]);
+ data_format &= ~flags->mask;
+ data_format |= flags->flags & flags->mask;
+ }
+
+ if (!rmnet_config_data_format_valid(data_format)) {
+ NL_SET_ERR_MSG_MOD(extack,
+ "unsupported MAP checksum flag combination");
+ return -EINVAL;
+ }
+
ep = kzalloc_obj(*ep);
if (!ep)
return -ENOMEM;
@@ -167,14 +197,6 @@ static int rmnet_newlink(struct net_device *dev,

hlist_add_head_rcu(&ep->hlnode, &port->muxed_ep[mux_id]);

- if (data[IFLA_RMNET_FLAGS]) {
- struct ifla_rmnet_flags *flags;
-
- flags = nla_data(data[IFLA_RMNET_FLAGS]);
- data_format &= ~flags->mask;
- data_format |= flags->flags & flags->mask;
- }
-
netdev_dbg(dev, "data format [0x%08X]\n", data_format);
WRITE_ONCE(port->data_format, data_format);

@@ -301,8 +323,11 @@ static int rmnet_changelink(struct net_device *dev, struct nlattr *tb[],
struct netlink_ext_ack *extack)
{
struct rmnet_priv *priv = netdev_priv(dev);
+ struct ifla_rmnet_flags *flags;
struct net_device *real_dev;
struct rmnet_port *port;
+ u32 old_data_format;
+ u32 data_format;
u16 mux_id;

if (!dev)
@@ -320,6 +345,19 @@ static int rmnet_changelink(struct net_device *dev, struct nlattr *tb[],

port = rmnet_get_port_rtnl(real_dev);

+ if (data[IFLA_RMNET_FLAGS]) {
+ old_data_format = READ_ONCE(port->data_format);
+ flags = nla_data(data[IFLA_RMNET_FLAGS]);
+ data_format = old_data_format & ~flags->mask;
+ data_format |= flags->flags & flags->mask;
+
+ if (!rmnet_config_data_format_valid(data_format)) {
+ NL_SET_ERR_MSG_MOD(extack,
+ "unsupported MAP checksum flag combination");
+ return -EINVAL;
+ }
+ }
+
if (data[IFLA_RMNET_MUX_ID]) {
mux_id = nla_get_u16(data[IFLA_RMNET_MUX_ID]);

@@ -346,14 +384,6 @@ static int rmnet_changelink(struct net_device *dev, struct nlattr *tb[],
}

if (data[IFLA_RMNET_FLAGS]) {
- struct ifla_rmnet_flags *flags;
- u32 old_data_format;
- u32 data_format;
-
- old_data_format = port->data_format;
- flags = nla_data(data[IFLA_RMNET_FLAGS]);
- data_format = old_data_format & ~flags->mask;
- data_format |= flags->flags & flags->mask;
WRITE_ONCE(port->data_format, data_format);

if (rmnet_vnd_update_dev_mtu(port, real_dev)) {
--
2.34.1