From: Chenguang Zhao <[email protected]>

When AF_XDP ZC receives a multi-buffer frame and XDP returns XDP_PASS,
i40e_construct_skb_zc() copied frags incorrectly: memcpy used
skb_frag_page() (page metadata) and __skb_fill_page_desc_noacc() was
given a virtual address instead of a struct page *.

Drop the custom helper and use xdp_build_skb_from_zc() instead. On
failure, free the xdp buff in the caller. Push the Ethernet header
back before eth_skb_pad()/i40e_process_skb_fields() because
xdp_build_skb_from_zc() already called eth_type_trans().

Fixes: 1c9ba9c14658 ("i40e: xsk: add RX multi-buffer support")
Signed-off-by: Chenguang Zhao <[email protected]>
---
Revised as suggested by Maciej:
 - Replace i40e_construct_skb_zc() with xdp_build_skb_from_zc()

v1:
 https://lore.kernel.org/all/[email protected]/

 drivers/net/ethernet/intel/i40e/i40e_xsk.c | 73 +++-------------------
 1 file changed, 8 insertions(+), 65 deletions(-)

diff --git a/drivers/net/ethernet/intel/i40e/i40e_xsk.c 
b/drivers/net/ethernet/intel/i40e/i40e_xsk.c
index 9f47388eaba5..1319a5c22625 100644
--- a/drivers/net/ethernet/intel/i40e/i40e_xsk.c
+++ b/drivers/net/ethernet/intel/i40e/i40e_xsk.c
@@ -3,6 +3,7 @@
 
 #include <linux/bpf_trace.h>
 #include <linux/unroll.h>
+#include <net/xdp.h>
 #include <net/xdp_sock_drv.h>
 #include "i40e_txrx_common.h"
 #include "i40e_xsk.h"
@@ -277,70 +278,6 @@ bool i40e_alloc_rx_buffers_zc(struct i40e_ring *rx_ring, 
u16 count)
        return count == nb_buffs;
 }
 
-/**
- * i40e_construct_skb_zc - Create skbuff from zero-copy Rx buffer
- * @rx_ring: Rx ring
- * @xdp: xdp_buff
- *
- * This functions allocates a new skb from a zero-copy Rx buffer.
- *
- * Returns the skb, or NULL on failure.
- **/
-static struct sk_buff *i40e_construct_skb_zc(struct i40e_ring *rx_ring,
-                                            struct xdp_buff *xdp)
-{
-       unsigned int totalsize = xdp->data_end - xdp->data_meta;
-       unsigned int metasize = xdp->data - xdp->data_meta;
-       struct skb_shared_info *sinfo = NULL;
-       struct sk_buff *skb;
-       u32 nr_frags = 0;
-
-       if (unlikely(xdp_buff_has_frags(xdp))) {
-               sinfo = xdp_get_shared_info_from_buff(xdp);
-               nr_frags = sinfo->nr_frags;
-       }
-       net_prefetch(xdp->data_meta);
-
-       /* allocate a skb to store the frags */
-       skb = napi_alloc_skb(&rx_ring->q_vector->napi, totalsize);
-       if (unlikely(!skb))
-               goto out;
-
-       memcpy(__skb_put(skb, totalsize), xdp->data_meta,
-              ALIGN(totalsize, sizeof(long)));
-
-       if (metasize) {
-               skb_metadata_set(skb, metasize);
-               __skb_pull(skb, metasize);
-       }
-
-       if (likely(!xdp_buff_has_frags(xdp)))
-               goto out;
-
-       for (int i = 0; i < nr_frags; i++) {
-               struct skb_shared_info *skinfo = skb_shinfo(skb);
-               skb_frag_t *frag = &sinfo->frags[i];
-               struct page *page;
-               void *addr;
-
-               page = dev_alloc_page();
-               if (!page) {
-                       dev_kfree_skb(skb);
-                       return NULL;
-               }
-               addr = page_to_virt(page);
-
-               memcpy(addr, skb_frag_page(frag), skb_frag_size(frag));
-
-               __skb_fill_page_desc_noacc(skinfo, skinfo->nr_frags++,
-                                          addr, 0, skb_frag_size(frag));
-       }
-
-out:
-       xsk_buff_free(xdp);
-       return skb;
-}
-
 static void i40e_handle_xdp_result_zc(struct i40e_ring *rx_ring,
                                      struct xdp_buff *xdp_buff,
                                      union i40e_rx_desc *rx_desc,
@@ -372,14 +309,20 @@ static void i40e_handle_xdp_result_zc(struct i40e_ring 
*rx_ring,
                 * BIT(I40E_RXD_QW1_ERROR_SHIFT). This is due to that
                 * SBP is *not* set in PRT_SBPVSI (default not set).
                 */
-               skb = i40e_construct_skb_zc(rx_ring, xdp_buff);
+               skb = xdp_build_skb_from_zc(xdp_buff);
                if (!skb) {
+                       xsk_buff_free(xdp_buff);
                        rx_ring->rx_stats.alloc_buff_failed++;
                        *rx_packets = 0;
                        *rx_bytes = 0;
                        return;
                }
 
+               /* xdp_build_skb_from_zc() already ran eth_type_trans();
+                * restore the header for eth_skb_pad()/process_skb_fields().
+                */
+               __skb_push(skb, skb->data - skb_mac_header(skb));
+
                if (eth_skb_pad(skb)) {
                        *rx_packets = 0;
                        *rx_bytes = 0;
-- 
2.25.1

Reply via email to