mirror of
https://github.com/torvalds/linux.git
synced 2026-09-11 20:13:02 +02:00
vdpa_sim_net: check TX pull result before RX copy
vringh_iov_pull_iotlb() returns a signed byte count. A failed TX pull is
currently added to the unsigned byte counter and then passed as a size_t
length to receive_filter() and vringh_iov_push_iotlb(). A negative error
can therefore become a large length in the RX path.
Handle non-positive pull results before every length use. Count the TX
error and complete the consumed TX descriptor with zero bytes.
I found this bug myself, though the patch was written with AI assistance.
Fixes: cfe2268929 ("vdpa_sim: filter destination mac address")
Assisted-by: OpenAI-Codex:GPT-5
Signed-off-by: Linfeng Sun <linfeng.sun.dev@gmail.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <20260901094842.25875-1-linfeng.sun.dev@gmail.com>
This commit is contained in:
parent
0a8693f00c
commit
0d195797a8
|
|
@ -225,10 +225,15 @@ static void vdpasim_net_work(struct vdpasim *vdpasim)
|
|||
break;
|
||||
}
|
||||
|
||||
++tx_pkts;
|
||||
read = vringh_iov_pull_iotlb(&txq->vring, &txq->out_iov,
|
||||
net->buffer, PAGE_SIZE);
|
||||
if (read <= 0) {
|
||||
++tx_errors;
|
||||
vdpasim_net_complete(txq, 0);
|
||||
continue;
|
||||
}
|
||||
|
||||
++tx_pkts;
|
||||
tx_bytes += read;
|
||||
|
||||
if (!receive_filter(vdpasim, read)) {
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user