From: DENG Qingfang <dqfext@gmail.com> Date: 2021-02-28 17:09:33
Commit 86dd9868b878 has several issues, but was accepted too soon
before anyone could take a look.
- Double free. dsa_slave_xmit() will free the skb if the xmit function
returns NULL, but the skb is already freed by eth_skb_pad(). Use
__skb_put_padto() to avoid that.
- Unnecessary allocation. It has been done by DSA core since commit
a3b0b6479700.
- A u16 pointer points to skb data. It should be __be16 for network
byte order.
- Typo in comments. "numer" -> "number".
Fixes: 86dd9868b878 ("net: dsa: tag_rtl4_a: Support also egress tags")
Signed-off-by: DENG Qingfang <dqfext@gmail.com>
---
net/dsa/tag_rtl4_a.c | 12 +++++-------
1 file changed, 5 insertions(+), 7 deletions(-)
@@ -35,14 +35,12 @@ static struct sk_buff *rtl4a_tag_xmit(struct sk_buff *skb,structnet_device*dev){structdsa_port*dp=dsa_slave_to_port(dev);+__be16*p;u8*tag;-u16*p;u16out;/* Pad out to at least 60 bytes */-if(unlikely(eth_skb_pad(skb)))-returnNULL;-if(skb_cow_head(skb,RTL4_A_HDR_LEN)<0)+if(unlikely(__skb_put_padto(skb,ETH_ZLEN,false)))returnNULL;netdev_dbg(dev,"add realtek tag to package to port %d\n",
@@ -53,13 +51,13 @@ static struct sk_buff *rtl4a_tag_xmit(struct sk_buff *skb,tag=skb->data+2*ETH_ALEN;/* Set Ethertype */-p=(u16*)tag;+p=(__be16*)tag;*p=htons(RTL4_A_ETHERTYPE);out=(RTL4_A_PROTOCOL_RTL8366RB<<12)|(2<<8);-/* The lower bits is the port numer */+/* The lower bits is the port number */out|=(u8)dp->index;-p=(u16*)(tag+2);+p=(__be16*)(tag+2);*p=htons(out);returnskb;
Commit 86dd9868b878 has several issues, but was accepted too soon
before anyone could take a look.
- Double free. dsa_slave_xmit() will free the skb if the xmit function
returns NULL, but the skb is already freed by eth_skb_pad(). Use
__skb_put_padto() to avoid that.
- Unnecessary allocation. It has been done by DSA core since commit
a3b0b6479700.
- A u16 pointer points to skb data. It should be __be16 for network
byte order.
- Typo in comments. "numer" -> "number".
Fixes: 86dd9868b878 ("net: dsa: tag_rtl4_a: Support also egress tags")
Signed-off-by: DENG Qingfang <dqfext@gmail.com>
On Sun, Feb 28, 2021 at 6:08 PM DENG Qingfang [off-list ref] wrote:
Commit 86dd9868b878 has several issues, but was accepted too soon
before anyone could take a look.
- Double free. dsa_slave_xmit() will free the skb if the xmit function
returns NULL, but the skb is already freed by eth_skb_pad(). Use
__skb_put_padto() to avoid that.
- Unnecessary allocation. It has been done by DSA core since commit
a3b0b6479700.
- A u16 pointer points to skb data. It should be __be16 for network
byte order.
- Typo in comments. "numer" -> "number".
Fixes: 86dd9868b878 ("net: dsa: tag_rtl4_a: Support also egress tags")
Signed-off-by: DENG Qingfang <dqfext@gmail.com>
Ooops I send patches before properly going through the mailbox.
Oh well things like that happen.
David: ignore my patches to the same tagger and apply this instead!
Reviewed-by: Linus Walleij <redacted>
Yours,
Linus Walleij
From: Vladimir Oltean <olteanv@gmail.com> Date: 2021-03-01 14:02:32
On Mon, Mar 01, 2021 at 02:58:59PM +0100, Linus Walleij wrote:
On Sun, Feb 28, 2021 at 6:08 PM DENG Qingfang [off-list ref] wrote:
quoted
Commit 86dd9868b878 has several issues, but was accepted too soon
before anyone could take a look.
- Double free. dsa_slave_xmit() will free the skb if the xmit function
returns NULL, but the skb is already freed by eth_skb_pad(). Use
__skb_put_padto() to avoid that.
- Unnecessary allocation. It has been done by DSA core since commit
a3b0b6479700.
- A u16 pointer points to skb data. It should be __be16 for network
byte order.
- Typo in comments. "numer" -> "number".
Fixes: 86dd9868b878 ("net: dsa: tag_rtl4_a: Support also egress tags")
Signed-off-by: DENG Qingfang <dqfext@gmail.com>
Ooops I send patches before properly going through the mailbox.
Oh well things like that happen.
David: ignore my patches to the same tagger and apply this instead!
Reviewed-by: Linus Walleij <redacted>
Yours,
Linus Walleij
Last time I checked, performance/timing sensitive code is impacted by
netdev_dbg calls even if dynamic debugging isn't turned on. However,
neither your patches nor Qingfang's have removed that netdev_dbg line.
Is there any good reason to keep it?