Re: [PATCH net v1] net: devmem: prevent mixing fragments from different bindings
From: Pavel Begunkov
Date: Thu Oct 08 2026 - 09:09:42 EST
On 10/8/26 04:39, Mina Almasry wrote:
validate_xmit_unreadable_skb() only inspects shinfo->frags[0] and
assumes all fragments in an unreadable skb belong to that same devmem
binding. However, tcp_sendmsg_locked() only checks that readability
matches the presence of a binding (skb_frags_readable(skb) != !binding),
allowing consecutive sendmsg() calls with different dmabuf bindings to
collapse into the same skb and bypass per-device and unbind checks in
validate_xmit_unreadable_skb().
Add net_devmem_skb_binding() to query the binding associated with an
skb, reuse it in validate_xmit_unreadable_skb(), and check in
zerocopy_fill_skb_from_devmem() that existing fragments match the target
binding.
Looks good
Pavel Begunkov <asml.silence@xxxxxxxxx>
--
Pavel Begunkov