mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH net 0/2] Fix UDP splice checksum alignment across fragments
@ 2026-09-24 13:00 Alireza Asgari via B4 Relay
  2026-09-24 13:00 ` [PATCH net 1/2] net: fix checksum offsets in skb_splice_from_iter() Alireza Asgari via B4 Relay
                   ` (2 more replies)
  0 siblings, 3 replies; 4+ messages in thread
From: Alireza Asgari via B4 Relay @ 2026-09-24 13:00 UTC (permalink / raw)
  To: David S. Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni,
	Simon Horman, David Howells, Shuah Khan
  Cc: netdev, linux-kernel, linux-kselftest, Alireza Asgari

When skb_splice_from_iter() appends several pipe fragments, it updates
skb->len only after the loop. The software-checksum helper nevertheless
uses that unchanged length as the checksum position for each fragment.
An odd number of bytes already appended during the call therefore gives
later fragments the wrong checksum alignment.

A standalone reproducer primes a UDP socket with sendto(MSG_MORE), splices
distinct pipe buffers, then uncorks the datagram. The send succeeds, but
the receiver drops the packet and increments its checksum-error counter.

Patch 1 passes the actual cumulative offset to the checksum helper without
changing the final length update or partial-progress handling. Patch 2
adds a loopback selftest covering IPv4, IPv6, IPv4-mapped destinations,
connected and unconnected sockets, prefixes and fragment boundaries.

Based on net/main at e47a1958e12abc3a17b5231a4f21c8f1bf662e08.
Validation on x86-64 with GCC 11.4.0:

  - Unmodified net kernel: 12 passes, 42 failures; 28 IPv4 and 14 IPv6
    checksum errors. Patched kernel: all 54 pass, zero checksum errors.
  - Ubuntu 6.8.0-138-generic reproduces the same failures. The host's
    5.15.0-187-generic kernel passes all cases.
  - Patched kernel with restricted pipe growth: 42 passes, 12 expected
    skips, no failures or checksum errors.
  - Complete small runtime kernels built and boot-tested before and after
    the fix. net/core/skbuff.o built under allmodconfig and allyesconfig.
  - Full x86-64 allmodconfig build and link completed with W=1 and
    CONFIG_WERROR disabled. The initial strict builds encountered unrelated
    warnings also reproduced on the unpatched base. No warning was emitted
    for the changed kernel object.
  - The full allyesconfig build was interrupted and I chose not to complete
    it because of the additional build time. Only the changed object has
    completed that configuration; no full allyesconfig pass is claimed.
  - Standalone and kernel-Makefile selftest builds pass. Checkpatch finds
    only the generic new-file MAINTAINERS warning for the selftest;
    existing networking/selftest ownership covers it.
  - After converting the selftest to kselftest result helpers, rebuilt it
    separately and repeated the host and before/after VM runs using the
    existing kernels, with unchanged case outcomes. Also checked mixed
    pass/skip and all-skipped runs in isolated network namespaces; the
    latter reports exactly 54 skips and exits with status 4.

AI assistance: Codex and Astra were used during investigation,
implementation, selftest development, validation, and preparation of the
submission text. I reviewed the resulting changes and take responsibility
for the submission.

---
Alireza Asgari (2):
      net: fix checksum offsets in skb_splice_from_iter()
      selftests: net: cover UDP splice checksum fragment alignment

 net/core/skbuff.c                                 |   8 +-
 tools/testing/selftests/net/.gitignore            |   1 +
 tools/testing/selftests/net/Makefile              |   1 +
 tools/testing/selftests/net/udp_splice_checksum.c | 378 ++++++++++++++++++++++
 4 files changed, 385 insertions(+), 3 deletions(-)
---
base-commit: e47a1958e12abc3a17b5231a4f21c8f1bf662e08
change-id: 20260924-fix-udp-splice-checksum-7f7b53728c0e

Best regards,
--  
Alireza Asgari <alireza@asgari.net>



^ permalink raw reply	[flat|nested] 4+ messages in thread

* [PATCH net 1/2] net: fix checksum offsets in skb_splice_from_iter()
  2026-09-24 13:00 [PATCH net 0/2] Fix UDP splice checksum alignment across fragments Alireza Asgari via B4 Relay
@ 2026-09-24 13:00 ` Alireza Asgari via B4 Relay
  2026-09-24 13:00 ` [PATCH net 2/2] selftests: net: cover UDP splice checksum fragment alignment Alireza Asgari via B4 Relay
  2026-09-30  0:20 ` [PATCH net 0/2] Fix UDP splice checksum alignment across fragments patchwork-bot+netdevbpf
  2 siblings, 0 replies; 4+ messages in thread
From: Alireza Asgari via B4 Relay @ 2026-09-24 13:00 UTC (permalink / raw)
  To: David S. Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni,
	Simon Horman, David Howells, Shuah Khan
  Cc: netdev, linux-kernel, linux-kselftest, Alireza Asgari

From: Alireza Asgari <alireza@asgari.net>

skb_splice_from_iter() appends multiple page fragments before updating
skb->len. However, skb_splice_csum_page() uses that unchanged length as the
offset for every fragment checksum. If bytes already appended during the
call have an odd total length, a later fragment's checksum is combined
with the wrong parity.

For example, prime a UDP socket with sendto(MSG_MORE) and splice two
distinct pipe buffers containing "abc" and "DEFGH". Uncorking reports
success, but the receiver discards the packet for a bad checksum.
This also affects IPv6 and fragments beginning near a page boundary.

Pass the initial skb length plus the bytes already spliced to the checksum
helper. Keep the existing final length update and partial-progress error
handling unchanged. CHECKSUM_PARTIAL does not use this helper and remains
unaffected.

Fixes: 2e910b95329c ("net: Add a function to splice pages into an skbuff for MSG_SPLICE_PAGES")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Alireza Asgari <alireza@asgari.net>
---
 net/core/skbuff.c | 8 +++++---
 1 file changed, 5 insertions(+), 3 deletions(-)

diff --git a/net/core/skbuff.c b/net/core/skbuff.c
index b4edbd0665..38783953db 100644
--- a/net/core/skbuff.c
+++ b/net/core/skbuff.c
@@ -7403,7 +7403,8 @@ nodefer:	kfree_skb_napi_cache(skb);
 }
 
 static void skb_splice_csum_page(struct sk_buff *skb, struct page *page,
-				 size_t offset, size_t len)
+				 size_t offset, size_t len,
+				 unsigned int csum_offset)
 {
 	const char *kaddr;
 	__wsum csum;
@@ -7411,7 +7412,7 @@ static void skb_splice_csum_page(struct sk_buff *skb, struct page *page,
 	kaddr = kmap_local_page(page);
 	csum = csum_partial(kaddr + offset, len, 0);
 	kunmap_local(kaddr);
-	skb->csum = csum_block_add(skb->csum, csum, skb->len);
+	skb->csum = csum_block_add(skb->csum, csum, csum_offset);
 }
 
 /**
@@ -7471,7 +7472,8 @@ ssize_t skb_splice_from_iter(struct sk_buff *skb, struct iov_iter *iter,
 			}
 
 			if (skb->ip_summed == CHECKSUM_NONE)
-				skb_splice_csum_page(skb, page, off, part);
+				skb_splice_csum_page(skb, page, off, part,
+						     skb->len + spliced);
 
 			off = 0;
 			spliced += part;

-- 
2.34.1



^ permalink raw reply	[flat|nested] 4+ messages in thread

* [PATCH net 2/2] selftests: net: cover UDP splice checksum fragment alignment
  2026-09-24 13:00 [PATCH net 0/2] Fix UDP splice checksum alignment across fragments Alireza Asgari via B4 Relay
  2026-09-24 13:00 ` [PATCH net 1/2] net: fix checksum offsets in skb_splice_from_iter() Alireza Asgari via B4 Relay
@ 2026-09-24 13:00 ` Alireza Asgari via B4 Relay
  2026-09-30  0:20 ` [PATCH net 0/2] Fix UDP splice checksum alignment across fragments patchwork-bot+netdevbpf
  2 siblings, 0 replies; 4+ messages in thread
From: Alireza Asgari via B4 Relay @ 2026-09-24 13:00 UTC (permalink / raw)
  To: David S. Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni,
	Simon Horman, David Howells, Shuah Khan
  Cc: netdev, linux-kernel, linux-kselftest, Alireza Asgari

From: Alireza Asgari <alireza@asgari.net>

Exercise software UDP checksums when splice() transfers multiple pipe
fragments into a corked datagram. Use separate source pipes so short writes
cannot merge, and use odd fragment lengths to expose checksum-position
errors between fragments.

Cover IPv4, IPv6 and IPv4-mapped destinations, connected and unconnected
sockets, resident prefixes, even and odd fragment lengths, and a fragment
starting near a page boundary. Ordinary sends provide a control. Check the
complete payload and reject extra datagrams after a successful send.

Keep receive waits bounded and skip unavailable address families or pipe
capacities. The test uses only loopback sockets with ephemeral ports and
has no dependency on the application that exposed the regression.

Assisted-by: LLM
Signed-off-by: Alireza Asgari <alireza@asgari.net>
---
 tools/testing/selftests/net/.gitignore            |   1 +
 tools/testing/selftests/net/Makefile              |   1 +
 tools/testing/selftests/net/udp_splice_checksum.c | 378 ++++++++++++++++++++++
 3 files changed, 380 insertions(+)

diff --git a/tools/testing/selftests/net/.gitignore b/tools/testing/selftests/net/.gitignore
index c9f46031ac..dacd36ed84 100644
--- a/tools/testing/selftests/net/.gitignore
+++ b/tools/testing/selftests/net/.gitignore
@@ -55,6 +55,7 @@ tools
 tun
 txring_overwrite
 txtimestamp
+udp_splice_checksum
 udpgso
 udpgso_bench_rx
 udpgso_bench_tx
diff --git a/tools/testing/selftests/net/Makefile b/tools/testing/selftests/net/Makefile
index 3ee3378f8b..590b33e16d 100644
--- a/tools/testing/selftests/net/Makefile
+++ b/tools/testing/selftests/net/Makefile
@@ -199,6 +199,7 @@ TEST_GEN_PROGS := \
 	tap \
 	tcp_port_share \
 	tls \
+	udp_splice_checksum \
 # end of TEST_GEN_PROGS
 
 TEST_FILES := \
diff --git a/tools/testing/selftests/net/udp_splice_checksum.c b/tools/testing/selftests/net/udp_splice_checksum.c
new file mode 100644
index 0000000000..dc61444e64
--- /dev/null
+++ b/tools/testing/selftests/net/udp_splice_checksum.c
@@ -0,0 +1,378 @@
+// SPDX-License-Identifier: GPL-2.0-only
+/*
+ * Exercise UDP software checksums over multiple spliced pipe fragments.
+ * All traffic stays on loopback; no privileges or external services are needed.
+ * Exit status: 0 = pass, 1 = failure, 4 = all cases skipped.
+ */
+#define _GNU_SOURCE
+
+#include <arpa/inet.h>
+#include <errno.h>
+#include <fcntl.h>
+#include <poll.h>
+#include <stdbool.h>
+#include <stdio.h>
+#include <stdlib.h>
+#include <string.h>
+#include <sys/socket.h>
+#include <time.h>
+#include <unistd.h>
+
+#include "kselftest.h"
+
+#define TIMEOUT_MS 200
+
+struct test_case {
+	const char *name;
+	const char *body;
+	const char *prefix;
+	size_t fragments[3];
+	bool ordinary;
+	bool page_tail;
+};
+
+static const struct test_case cases[] = {
+	{ "ordinary-control", "abcDEFGH", "", { 3, 5 }, true, false },
+	{ "uniform-odd-fragments", "BBBBBBBB", "", { 3, 5 }, false, false },
+	{ "even-fragments", "abcdEFGH", "", { 4, 4 }, false, false },
+	{ "odd-fragments", "abcDEFGH", "", { 3, 5 }, false, false },
+	{ "odd-prefix-odd-fragments", "abcDEFGH", "P", { 3, 5 }, false, false },
+	{ "even-prefix-odd-fragments", "abcDEFGH", "PQ", { 3, 5 }, false, false },
+	{ "page-tail-odd-fragments", "abcDEFGH", "", { 3, 5 }, false, true },
+	{ "three-fragments", "abcDEFGhijkl", "", { 3, 4, 5 }, false, false },
+	{ "odd-prefix-three-fragments",
+	  "abcDEFGhijkl",
+	  "P",
+	  { 3, 4, 5 },
+	  false,
+	  false },
+};
+
+static const char *const families[] = { "IPv4", "IPv6", "IPv4-mapped" };
+
+static int error(const char *what)
+{
+	ksft_perror(what);
+	return 1;
+}
+
+static bool unavailable(void)
+{
+	return errno == EAFNOSUPPORT || errno == EPROTONOSUPPORT ||
+	       errno == EADDRNOTAVAIL;
+}
+
+static long long now_ms(void)
+{
+	struct timespec ts;
+
+	if (clock_gettime(CLOCK_MONOTONIC, &ts))
+		ksft_exit_fail_perror("clock_gettime");
+	return (long long)ts.tv_sec * 1000 + ts.tv_nsec / 1000000;
+}
+
+static int receive_one(int fd, const char *expected, size_t length)
+{
+	struct pollfd pfd = { .fd = fd, .events = POLLIN };
+	long long deadline = now_ms() + TIMEOUT_MS;
+	int remaining, ret;
+	char received[64];
+	ssize_t count;
+
+	for (;;) {
+		remaining = deadline - now_ms();
+		if (remaining < 0)
+			remaining = 0;
+		ret = poll(&pfd, 1, remaining);
+		if (ret < 0) {
+			if (errno == EINTR)
+				continue;
+			return error("poll");
+		}
+		if (!ret) {
+			ksft_print_msg("no datagram within %d ms after send\n",
+				       TIMEOUT_MS);
+			return 1;
+		}
+		count = recv(fd, received, sizeof(received),
+			     MSG_DONTWAIT | MSG_TRUNC);
+		if (count < 0) {
+			if (errno == EINTR || errno == EAGAIN)
+				continue;
+			return error("recv");
+		}
+		break;
+	}
+	if (count != (ssize_t)length || memcmp(received, expected, length)) {
+		ksft_print_msg("received %zd bytes; expected %zu matching\n",
+			       count, length);
+		return 1;
+	}
+	count = recv(fd, received, sizeof(received), MSG_DONTWAIT | MSG_TRUNC);
+	if (count >= 0) {
+		ksft_print_msg("unexpected extra datagram (%zd bytes)\n",
+			       count);
+		return 1;
+	}
+	if (errno != EAGAIN)
+		return error("extra-datagram check");
+	return 0;
+}
+
+/* Separate source pipes prevent adjacent small writes merging into one buffer. */
+static int append_fragment(int dest, const char *data, size_t length)
+{
+	int source[2], ret = 1;
+
+	if (pipe2(source, O_NONBLOCK | O_CLOEXEC))
+		return error("source pipe");
+	if (write(source[1], data, length) != (ssize_t)length) {
+		error("source write");
+		goto out;
+	}
+	if (splice(source[0], NULL, dest, NULL, length, SPLICE_F_NONBLOCK) !=
+	    (ssize_t)length) {
+		error("pipe-to-pipe splice");
+		goto out;
+	}
+	ret = 0;
+out:
+	close(source[0]);
+	close(source[1]);
+	return ret;
+}
+
+static int pipe_capacity(int fd, unsigned int slots, const char **skip_reason)
+{
+	long required = slots * sysconf(_SC_PAGESIZE);
+	int capacity = fcntl(fd, F_GETPIPE_SZ);
+
+	if (capacity < 0)
+		return error("query pipe capacity");
+	if (capacity >= required ||
+	    fcntl(fd, F_SETPIPE_SZ, required) >= required)
+		return 0;
+	ksft_print_msg("cannot reserve %u pipe slots: %s\n", slots,
+		       strerror(errno));
+	*skip_reason = "required pipe capacity unavailable";
+	return KSFT_SKIP;
+}
+
+/* Leave three bytes at a page's end, followed by five bytes on the next page. */
+static int append_page_tail(int dest, const char *body,
+			    const char **skip_reason)
+{
+	long page = sysconf(_SC_PAGESIZE);
+	int source[2], ret = 1;
+	char *data;
+
+	if (page < 8) {
+		ksft_print_msg("invalid page size %ld\n", page);
+		return 1;
+	}
+	data = malloc(page + 5);
+	if (!data)
+		return error("malloc");
+	memset(data, 'x', page - 3);
+	memcpy(data + page - 3, body, 8);
+	if (pipe2(source, O_NONBLOCK | O_CLOEXEC)) {
+		error("page-tail source pipe");
+		goto free_data;
+	}
+	ret = pipe_capacity(source[1], 2, skip_reason);
+	if (ret)
+		goto out;
+	ret = 1;
+	if (write(source[1], data, page + 5) != page + 5) {
+		error("page-tail write");
+		goto out;
+	}
+	if (read(source[0], data, page - 3) != page - 3) {
+		error("page-tail discard");
+		goto out;
+	}
+	if (splice(source[0], NULL, dest, NULL, 8, SPLICE_F_NONBLOCK) != 8) {
+		error("page-tail pipe-to-pipe splice");
+		goto out;
+	}
+	ret = 0;
+out:
+	close(source[0]);
+	close(source[1]);
+free_data:
+	free(data);
+	return ret;
+}
+
+static int run_case(unsigned int family, bool connected,
+		    const struct test_case *test, const char **skip_reason)
+{
+	size_t body_length = strlen(test->body), offset = 0;
+	int tx_family = family == 0 ? AF_INET : AF_INET6;
+	int rx_family = family == 1 ? AF_INET6 : AF_INET;
+	int rx = -1, tx = -1, pipefd[2] = { -1, -1 };
+	size_t prefix_length = strlen(test->prefix);
+	struct sockaddr_storage address = { 0 };
+	socklen_t address_length;
+	struct sockaddr_in6 *v6;
+	struct sockaddr_in *v4;
+	int ret = 1, zero = 0;
+	char expected[64];
+	unsigned int i;
+	ssize_t count;
+
+	v4 = (struct sockaddr_in *)&address;
+	v6 = (struct sockaddr_in6 *)&address;
+	*skip_reason = "address family unavailable";
+	memcpy(expected, test->prefix, prefix_length);
+	memcpy(expected + prefix_length, test->body, body_length);
+	rx = socket(rx_family, SOCK_DGRAM | SOCK_CLOEXEC, 0);
+	if (rx < 0) {
+		ret = unavailable() ? KSFT_SKIP : error("receive socket");
+		goto out;
+	}
+	if (rx_family == AF_INET) {
+		v4->sin_family = AF_INET;
+		v4->sin_addr.s_addr = htonl(INADDR_LOOPBACK);
+		address_length = sizeof(*v4);
+	} else {
+		v6->sin6_family = AF_INET6;
+		v6->sin6_addr = in6addr_loopback;
+		address_length = sizeof(*v6);
+	}
+	if (bind(rx, (struct sockaddr *)&address, address_length)) {
+		ret = unavailable() ? KSFT_SKIP : error("bind loopback");
+		goto out;
+	}
+	if (getsockname(rx, (struct sockaddr *)&address, &address_length)) {
+		error("getsockname");
+		goto out;
+	}
+	if (family == 2) {
+		unsigned short port = v4->sin_port;
+
+		memset(&address, 0, sizeof(address));
+		v6->sin6_family = AF_INET6;
+		v6->sin6_port = port;
+		inet_pton(AF_INET6, "::ffff:127.0.0.1", &v6->sin6_addr);
+		address_length = sizeof(*v6);
+	}
+	tx = socket(tx_family, SOCK_DGRAM | SOCK_CLOEXEC, 0);
+	if (tx < 0) {
+		ret = unavailable() ? KSFT_SKIP : error("send socket");
+		goto out;
+	}
+	if (family == 2 &&
+	    setsockopt(tx, IPPROTO_IPV6, IPV6_V6ONLY, &zero, sizeof(zero))) {
+		error("disable IPV6_V6ONLY");
+		goto out;
+	}
+	if (connected &&
+	    connect(tx, (struct sockaddr *)&address, address_length)) {
+		error("connect");
+		goto out;
+	}
+	if (test->ordinary) {
+		count = sendto(tx, expected, prefix_length + body_length, 0,
+			       (struct sockaddr *)&address, address_length);
+		if (count != (ssize_t)(prefix_length + body_length)) {
+			error("ordinary sendto");
+			goto out;
+		}
+	} else {
+		if (pipe2(pipefd, O_NONBLOCK | O_CLOEXEC)) {
+			error("assembled pipe");
+			goto out;
+		}
+		ret = pipe_capacity(pipefd[1], test->fragments[2] ? 3 : 2,
+				    skip_reason);
+		if (ret)
+			goto out;
+		ret = 1;
+		if (test->page_tail) {
+			ret = append_page_tail(pipefd[1], test->body,
+					       skip_reason);
+			if (ret)
+				goto out;
+			ret = 1;
+		} else {
+			for (i = 0; i < ARRAY_SIZE(test->fragments); i++) {
+				if (!test->fragments[i])
+					break;
+				if (append_fragment(pipefd[1],
+						    test->body + offset,
+						    test->fragments[i]))
+					goto out;
+				offset += test->fragments[i];
+			}
+		}
+		/* Even an empty prefix establishes the destination and UDP cork. */
+		count = sendto(tx, test->prefix, prefix_length, MSG_MORE,
+			       (struct sockaddr *)&address, address_length);
+		if (count != (ssize_t)prefix_length) {
+			error("prime sendto(MSG_MORE)");
+			goto out;
+		}
+		count = splice(pipefd[0], NULL, tx, NULL, body_length,
+			       SPLICE_F_NONBLOCK | SPLICE_F_MORE);
+		if (count != (ssize_t)body_length) {
+			ksft_print_msg("socket splice: %zd, expected %zu: %s\n",
+				       count, body_length,
+				       count < 0 ? strerror(errno) :
+						   "short transfer");
+			goto out;
+		}
+		if (sendto(tx, "", 0, 0, (struct sockaddr *)&address,
+			   address_length)) {
+			error("commit sendto");
+			goto out;
+		}
+	}
+	ret = receive_one(rx, expected, prefix_length + body_length);
+out:
+	if (pipefd[0] >= 0) {
+		close(pipefd[0]);
+		close(pipefd[1]);
+	}
+	if (tx >= 0)
+		close(tx);
+	if (rx >= 0)
+		close(rx);
+	return ret;
+}
+
+int main(void)
+{
+	unsigned int family, connected, i;
+	const char *connection, *skip;
+	int ret;
+
+	ksft_print_header();
+	ksft_set_plan(ARRAY_SIZE(families) * 2 * ARRAY_SIZE(cases));
+	for (family = 0; family < ARRAY_SIZE(families); family++) {
+		for (connected = 0; connected < 2; connected++) {
+			connection = connected ? "connected" : "unconnected";
+			for (i = 0; i < ARRAY_SIZE(cases); i++) {
+				ret = run_case(family, connected, &cases[i],
+					       &skip);
+				if (ret == KSFT_SKIP)
+					ksft_test_result_skip("%s %s %s: %s\n",
+							      families[family],
+							      connection,
+							      cases[i].name,
+							      skip);
+				else
+					ksft_test_result(!ret, "%s %s %s\n",
+							 families[family],
+							 connection,
+							 cases[i].name);
+			}
+		}
+	}
+	if (!ksft_get_pass_cnt() && !ksft_get_fail_cnt()) {
+		/* ksft_exit_skip() would add a result beyond the plan. */
+		ksft_print_cnts();
+		return KSFT_SKIP;
+	}
+	ksft_finished();
+}

-- 
2.34.1



^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH net 0/2] Fix UDP splice checksum alignment across fragments
  2026-09-24 13:00 [PATCH net 0/2] Fix UDP splice checksum alignment across fragments Alireza Asgari via B4 Relay
  2026-09-24 13:00 ` [PATCH net 1/2] net: fix checksum offsets in skb_splice_from_iter() Alireza Asgari via B4 Relay
  2026-09-24 13:00 ` [PATCH net 2/2] selftests: net: cover UDP splice checksum fragment alignment Alireza Asgari via B4 Relay
@ 2026-09-30  0:20 ` patchwork-bot+netdevbpf
  2 siblings, 0 replies; 4+ messages in thread
From: patchwork-bot+netdevbpf @ 2026-09-30  0:20 UTC (permalink / raw)
  To: Alireza Asgari
  Cc: davem, edumazet, kuba, pabeni, horms, dhowells, shuah, netdev,
	linux-kernel, linux-kselftest

Hello:

This series was applied to netdev/net.git (main)
by Jakub Kicinski <kuba@kernel.org>:

On Thu, 24 Sep 2026 13:00:23 +0000 you wrote:
> When skb_splice_from_iter() appends several pipe fragments, it updates
> skb->len only after the loop. The software-checksum helper nevertheless
> uses that unchanged length as the checksum position for each fragment.
> An odd number of bytes already appended during the call therefore gives
> later fragments the wrong checksum alignment.
> 
> A standalone reproducer primes a UDP socket with sendto(MSG_MORE), splices
> distinct pipe buffers, then uncorks the datagram. The send succeeds, but
> the receiver drops the packet and increments its checksum-error counter.
> 
> [...]

Here is the summary with links:
  - [net,1/2] net: fix checksum offsets in skb_splice_from_iter()
    https://git.kernel.org/netdev/net/c/febec6a70764
  - [net,2/2] selftests: net: cover UDP splice checksum fragment alignment
    https://git.kernel.org/netdev/net/c/1221246d3bd0

You are awesome, thank you!
-- 
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html



^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-09-30  0:20 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-24 13:00 [PATCH net 0/2] Fix UDP splice checksum alignment across fragments Alireza Asgari via B4 Relay
2026-09-24 13:00 ` [PATCH net 1/2] net: fix checksum offsets in skb_splice_from_iter() Alireza Asgari via B4 Relay
2026-09-24 13:00 ` [PATCH net 2/2] selftests: net: cover UDP splice checksum fragment alignment Alireza Asgari via B4 Relay
2026-09-30  0:20 ` [PATCH net 0/2] Fix UDP splice checksum alignment across fragments patchwork-bot+netdevbpf

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®