* [PATCH] net: cxgb: Fix skb reference leak in espibug_workaround_t204()
@ 2026-09-17 10:54 Wentao Liang
2026-09-17 14:36 ` Jakub Kicinski
0 siblings, 1 reply; 2+ messages in thread
From: Wentao Liang @ 2026-09-17 10:54 UTC (permalink / raw)
To: andrew+netdev
Cc: davem, edumazet, jeff, kuba, linux-kernel, netdev, pabeni,
stephen, Wentao Liang, stable
The timer handler takes an extra reference with skb_get() before handing
the skb to t1_sge_tx(), so that the skb survives until the DMA has
completed. When the command queue is full, t1_sge_tx() returns
NETDEV_TX_BUSY without queueing the skb, and the return value is
ignored, so the extra reference is never dropped.
Free the skb when t1_sge_tx() reports that it did not consume it.
Fixes: f1d3d38af757 ("[PATCH] chelsio: add support for other 10G boards")
Cc: stable@vger.kernel.org
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
---
drivers/net/ethernet/chelsio/cxgb/sge.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/chelsio/cxgb/sge.c b/drivers/net/ethernet/chelsio/cxgb/sge.c
index d8fca697874a..d4677c5b8d74 100644
--- a/drivers/net/ethernet/chelsio/cxgb/sge.c
+++ b/drivers/net/ethernet/chelsio/cxgb/sge.c
@@ -2052,7 +2052,8 @@ static void espibug_workaround_t204(struct timer_list *t)
* the skb once the DMA has completed.
*/
skb = skb_get(skb);
- t1_sge_tx(skb, adapter, 0, adapter->port[i].dev);
+ if (t1_sge_tx(skb, adapter, 0, adapter->port[i].dev))
+ dev_kfree_skb_any(skb);
}
}
mod_timer(&sge->espibug_timer, jiffies + sge->espibug_timeout);
--
2.34.1
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: [PATCH] net: cxgb: Fix skb reference leak in espibug_workaround_t204()
2026-09-17 10:54 [PATCH] net: cxgb: Fix skb reference leak in espibug_workaround_t204() Wentao Liang
@ 2026-09-17 14:36 ` Jakub Kicinski
0 siblings, 0 replies; 2+ messages in thread
From: Jakub Kicinski @ 2026-09-17 14:36 UTC (permalink / raw)
To: Wentao Liang
Cc: andrew+netdev, davem, edumazet, jeff, linux-kernel, netdev,
pabeni, stephen, stable
On Thu, 17 Sep 2026 10:54:25 +0000 Wentao Liang wrote:
> The timer handler takes an extra reference with skb_get() before handing
> the skb to t1_sge_tx(), so that the skb survives until the DMA has
> completed. When the command queue is full, t1_sge_tx() returns
> NETDEV_TX_BUSY without queueing the skb, and the return value is
> ignored, so the extra reference is never dropped.
You have sent way too many patches at once. We have a hard limit of
15 patches per person, but really if you're sending low value garbage
you should not send more than 8. So that you can apply the feedback
you receive to later postings.
You may repost new version of the patches to which you receive feedback.
But I don't want to see any new patches from @iscas.ac.cn for
drivers/net and net/ for a month.
Please tell your coworkers/friends.
--
pv-bot: 15cnt
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-09-17 14:36 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-17 10:54 [PATCH] net: cxgb: Fix skb reference leak in espibug_workaround_t204() Wentao Liang
2026-09-17 14:36 ` Jakub Kicinski
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®