On Fri, Jul 17, 2026 at 9:24 AM Chenguang Zhao <[email protected]> wrote: > > From: Chenguang Zhao <[email protected]> > > When AF_XDP ZC receives a multi-buffer frame and XDP returns XDP_PASS, > i40e_construct_skb_zc() copied frags incorrectly: memcpy used > skb_frag_page() (page metadata) and __skb_fill_page_desc_noacc() was > given a virtual address instead of a struct page *. > > Drop the custom helper and use xdp_build_skb_from_zc() instead. On > failure, free the xdp buff in the caller. Push the Ethernet header > back before eth_skb_pad()/i40e_process_skb_fields() because > xdp_build_skb_from_zc() already called eth_type_trans(). > > Fixes: 1c9ba9c14658 ("i40e: xsk: add RX multi-buffer support") > Signed-off-by: Chenguang Zhao <[email protected]> > --- > Revised as suggested by Maciej: > - Replace i40e_construct_skb_zc() with xdp_build_skb_from_zc()
I might have a different opinion on this patch: yes, it actually belongs to -next material. The process should be like: 1) fix the issues by v1, 2) refactor it by v2. The reason behind that is the helper was introduced in 2024 while the home-grown part was in 2023, which means it doesn't help for stable steam to cherry-pick the patch in older kernels like 6.6[1]. [1]: https://www.kernel.org/ Thanks, Jason > > v1: > https://lore.kernel.org/all/[email protected]/ > > drivers/net/ethernet/intel/i40e/i40e_xsk.c | 73 +++------------------- > 1 file changed, 8 insertions(+), 65 deletions(-) > > diff --git a/drivers/net/ethernet/intel/i40e/i40e_xsk.c > b/drivers/net/ethernet/intel/i40e/i40e_xsk.c > index 9f47388eaba5..1319a5c22625 100644 > --- a/drivers/net/ethernet/intel/i40e/i40e_xsk.c > +++ b/drivers/net/ethernet/intel/i40e/i40e_xsk.c > @@ -3,6 +3,7 @@ > > #include <linux/bpf_trace.h> > #include <linux/unroll.h> > +#include <net/xdp.h> > #include <net/xdp_sock_drv.h> > #include "i40e_txrx_common.h" > #include "i40e_xsk.h" > @@ -277,70 +278,6 @@ bool i40e_alloc_rx_buffers_zc(struct i40e_ring *rx_ring, > u16 count) > return count == nb_buffs; > } > > -/** > - * i40e_construct_skb_zc - Create skbuff from zero-copy Rx buffer > - * @rx_ring: Rx ring > - * @xdp: xdp_buff > - * > - * This functions allocates a new skb from a zero-copy Rx buffer. > - * > - * Returns the skb, or NULL on failure. > - **/ > -static struct sk_buff *i40e_construct_skb_zc(struct i40e_ring *rx_ring, > - struct xdp_buff *xdp) > -{ > - unsigned int totalsize = xdp->data_end - xdp->data_meta; > - unsigned int metasize = xdp->data - xdp->data_meta; > - struct skb_shared_info *sinfo = NULL; > - struct sk_buff *skb; > - u32 nr_frags = 0; > - > - if (unlikely(xdp_buff_has_frags(xdp))) { > - sinfo = xdp_get_shared_info_from_buff(xdp); > - nr_frags = sinfo->nr_frags; > - } > - net_prefetch(xdp->data_meta); > - > - /* allocate a skb to store the frags */ > - skb = napi_alloc_skb(&rx_ring->q_vector->napi, totalsize); > - if (unlikely(!skb)) > - goto out; > - > - memcpy(__skb_put(skb, totalsize), xdp->data_meta, > - ALIGN(totalsize, sizeof(long))); > - > - if (metasize) { > - skb_metadata_set(skb, metasize); > - __skb_pull(skb, metasize); > - } > - > - if (likely(!xdp_buff_has_frags(xdp))) > - goto out; > - > - for (int i = 0; i < nr_frags; i++) { > - struct skb_shared_info *skinfo = skb_shinfo(skb); > - skb_frag_t *frag = &sinfo->frags[i]; > - struct page *page; > - void *addr; > - > - page = dev_alloc_page(); > - if (!page) { > - dev_kfree_skb(skb); > - return NULL; > - } > - addr = page_to_virt(page); > - > - memcpy(addr, skb_frag_page(frag), skb_frag_size(frag)); > - > - __skb_fill_page_desc_noacc(skinfo, skinfo->nr_frags++, > - addr, 0, skb_frag_size(frag)); > - } > - > -out: > - xsk_buff_free(xdp); > - return skb; > -} > - > static void i40e_handle_xdp_result_zc(struct i40e_ring *rx_ring, > struct xdp_buff *xdp_buff, > union i40e_rx_desc *rx_desc, > @@ -372,14 +309,20 @@ static void i40e_handle_xdp_result_zc(struct i40e_ring > *rx_ring, > * BIT(I40E_RXD_QW1_ERROR_SHIFT). This is due to that > * SBP is *not* set in PRT_SBPVSI (default not set). > */ > - skb = i40e_construct_skb_zc(rx_ring, xdp_buff); > + skb = xdp_build_skb_from_zc(xdp_buff); > if (!skb) { > + xsk_buff_free(xdp_buff); > rx_ring->rx_stats.alloc_buff_failed++; > *rx_packets = 0; > *rx_bytes = 0; > return; > } > > + /* xdp_build_skb_from_zc() already ran eth_type_trans(); > + * restore the header for eth_skb_pad()/process_skb_fields(). > + */ > + __skb_push(skb, skb->data - skb_mac_header(skb)); > + > if (eth_skb_pad(skb)) { > *rx_packets = 0; > *rx_bytes = 0; > -- > 2.25.1 > >
