[PATCH net-next v2 09/10] qlcnic: use pskb_may_pull() to pull excess TX frags into the head

From: Josef Bacik

Date: Thu Oct 08 2026 - 17:06:55 EST


qlcnic_xmit_frame() pulls the frags that don't fit in a TX descriptor
into the head with __pskb_pull_tail(). It already checks the result.
Switch to pskb_may_pull(), which takes the length the head should end up
with and checks it against the skb, so this driver no longer calls
__pskb_pull_tail() directly.

__pskb_pull_tail() also releases empty frags, even when there's nothing
to pull, so if the frags being pulled are all empty it still gets the
frag count under the limit. pskb_may_pull() returns early in that case,
so follow it with skb_drop_empty_frags().

Assisted-by: LLM
Signed-off-by: Josef Bacik <josef@xxxxxxxxxxxxxx>
---
drivers/net/ethernet/qlogic/qlcnic/qlcnic_io.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/drivers/net/ethernet/qlogic/qlcnic/qlcnic_io.c b/drivers/net/ethernet/qlogic/qlcnic/qlcnic_io.c
index 761ef3bc8193..e7ab5586798b 100644
--- a/drivers/net/ethernet/qlogic/qlcnic/qlcnic_io.c
+++ b/drivers/net/ethernet/qlogic/qlcnic/qlcnic_io.c
@@ -682,7 +682,8 @@ netdev_tx_t qlcnic_xmit_frame(struct sk_buff *skb, struct net_device *netdev)
for (i = 0; i < (frag_count - QLCNIC_MAX_FRAGS_PER_TX); i++)
delta += skb_frag_size(&skb_shinfo(skb)->frags[i]);

- if (!__pskb_pull_tail(skb, delta))
+ if (!pskb_may_pull(skb, skb_headlen(skb) + delta) ||
+ skb_drop_empty_frags(skb, GFP_ATOMIC))
goto drop_packet;

frag_count = 1 + skb_shinfo(skb)->nr_frags;

--
2.55.0