* [PATCH net-next v2 0/3] net: consolidate devmem net_iov freelist and DMA handling
@ 2026-09-25 20:15 Stanislav Fomichev
2026-09-25 20:15 ` [PATCH net-next v2 1/3] net: netmem: move to index based freelist Stanislav Fomichev
` (3 more replies)
0 siblings, 4 replies; 8+ messages in thread
From: Stanislav Fomichev @ 2026-09-25 20:15 UTC (permalink / raw)
To: netdev
Cc: davem, edumazet, kuba, pabeni, horms, hawk, ilias.apalodimas,
sdf, bobbyeshleman, almasrymina, kaiyuanz, linux-kernel
Follow up on the recently merged devmem gen_pool removal by consolidating
devmem's net_iov freelist and DMA-address handling.
- move devmem freelist to index-based approach with push/pop helpers
- switch devmem to public memory-provider helpers and reject DMA
addresses that cannot be represented
- decode stored DMA addresses for TX on 32-bit systems with 64-bit
dma_addr_t
v2:
- drop io_uring conversion (Pavel)
Stanislav Fomichev (3):
net: netmem: move to index based freelist
net: devmem: use memory provider helpers for net_iovs
net: devmem: decode DMA addresses for TX
include/linux/skbuff.h | 7 ++-
include/net/netmem.h | 27 +++++++++++
include/net/page_pool/helpers.h | 10 +---
net/core/devmem.c | 81 ++++++++++++++++++++-------------
net/core/devmem.h | 4 +-
net/core/page_pool_priv.h | 14 +-----
6 files changed, 87 insertions(+), 56 deletions(-)
--
2.53.0-Meta
^ permalink raw reply [flat|nested] 8+ messages in thread
* [PATCH net-next v2 1/3] net: netmem: move to index based freelist
2026-09-25 20:15 [PATCH net-next v2 0/3] net: consolidate devmem net_iov freelist and DMA handling Stanislav Fomichev
@ 2026-09-25 20:15 ` Stanislav Fomichev
2026-09-25 20:15 ` [PATCH net-next v2 2/3] net: devmem: use memory provider helpers for net_iovs Stanislav Fomichev
` (2 subsequent siblings)
3 siblings, 0 replies; 8+ messages in thread
From: Stanislav Fomichev @ 2026-09-25 20:15 UTC (permalink / raw)
To: netdev
Cc: davem, edumazet, kuba, pabeni, horms, hawk, ilias.apalodimas,
sdf, bobbyeshleman, almasrymina, kaiyuanz, linux-kernel
Move devmem's freelist to an index-based approach similar to io_uring.
This halves the memory requirements for the freelist.
Reviewed-by: Mina Almasry <almasrymina@google.com>
Signed-off-by: Stanislav Fomichev <sdf@fomichev.me>
---
net/core/devmem.c | 50 ++++++++++++++++++++++++++++++++++++-----------
net/core/devmem.h | 4 ++--
2 files changed, 41 insertions(+), 13 deletions(-)
diff --git a/net/core/devmem.c b/net/core/devmem.c
index a9d86b5a5588..704d02bd8bc8 100644
--- a/net/core/devmem.c
+++ b/net/core/devmem.c
@@ -29,6 +29,29 @@ static DEFINE_XARRAY_FLAGS(net_devmem_dmabuf_bindings, XA_FLAGS_ALLOC1);
static const struct memory_provider_ops dmabuf_devmem_ops;
+static struct net_iov *net_iov_free_pop(struct net_iov_area *area,
+ u32 *freelist, u32 *free_count)
+{
+ u32 idx;
+
+ if (unlikely(!*free_count))
+ return NULL;
+
+ idx = freelist[--(*free_count)];
+ return &area->niovs[idx];
+}
+
+static void net_iov_free_push(struct net_iov_area *area,
+ u32 *freelist, u32 *free_count,
+ struct net_iov *niov)
+{
+ if (WARN_ON_ONCE(net_iov_owner(niov) != area ||
+ *free_count >= area->num_niovs))
+ return;
+
+ freelist[(*free_count)++] = net_iov_idx(niov);
+}
+
static void net_devmem_dmabuf_binding_release(struct percpu_ref *ref)
{
struct net_devmem_dmabuf_binding *binding =
@@ -44,7 +67,7 @@ void __net_devmem_dmabuf_binding_free(struct work_struct *wq)
if (binding->freelist)
WARN(binding->free_count != binding->area.num_niovs,
- "destroying dmabuf binding with outstanding net_iovs: total=%zu, free=%zu",
+ "destroying dmabuf binding with outstanding net_iovs: total=%zu, free=%u",
binding->area.num_niovs, binding->free_count);
kvfree(binding->area.niovs);
@@ -63,14 +86,15 @@ static unsigned int
net_devmem_alloc_dmabuf_bulk(struct net_devmem_dmabuf_binding *binding,
netmem_ref *netmems, unsigned int count)
{
+ struct net_iov *niov;
unsigned int i;
spin_lock_bh(&binding->freelist_lock);
- count = min_t(size_t, count, binding->free_count);
+ count = min(count, binding->free_count);
for (i = 0; i < count; i++) {
- struct net_iov *niov = binding->freelist[--binding->free_count];
-
+ niov = net_iov_free_pop(&binding->area, binding->freelist,
+ &binding->free_count);
netmems[i] = net_iov_to_netmem(niov);
}
@@ -84,12 +108,8 @@ void net_devmem_free_dmabuf(struct net_iov *niov)
struct net_devmem_dmabuf_binding *binding = net_devmem_iov_binding(niov);
spin_lock_bh(&binding->freelist_lock);
- if (WARN_ON_ONCE(binding->free_count >= binding->area.num_niovs)) {
- spin_unlock_bh(&binding->freelist_lock);
- return;
- }
-
- binding->freelist[binding->free_count++] = niov;
+ net_iov_free_push(&binding->area, binding->freelist,
+ &binding->free_count, niov);
spin_unlock_bh(&binding->freelist_lock);
}
@@ -228,6 +248,12 @@ net_devmem_bind_dmabuf(struct net_device *dev, void *vdev,
goto err_unmap;
}
+ if ((dmabuf->size >> niov_shift) > U32_MAX) {
+ err = -E2BIG;
+ NL_SET_ERR_MSG(extack, "dmabuf contains too many net_iovs");
+ goto err_unmap;
+ }
+
binding->area.base_virtual = 0;
binding->area.num_niovs = dmabuf->size >> niov_shift;
if (direction == DMA_TO_DEVICE) {
@@ -279,7 +305,9 @@ net_devmem_bind_dmabuf(struct net_device *dev, void *vdev,
if (direction == DMA_TO_DEVICE)
binding->tx_vec[niov_idx] = niov;
else
- binding->freelist[binding->free_count++] = niov;
+ net_iov_free_push(&binding->area,
+ binding->freelist,
+ &binding->free_count, niov);
dma_addr += niov_size;
}
}
diff --git a/net/core/devmem.h b/net/core/devmem.h
index f71d9a2bcb3d..28d6fa7bcb57 100644
--- a/net/core/devmem.h
+++ b/net/core/devmem.h
@@ -58,8 +58,8 @@ struct net_devmem_dmabuf_binding {
struct xarray bound_rxqs;
spinlock_t freelist_lock ____cacheline_aligned_in_smp;
- size_t free_count;
- struct net_iov **freelist;
+ u32 free_count;
+ u32 *freelist;
/* ID of this binding. Globally unique to all bindings currently
* active.
--
2.53.0-Meta
^ permalink raw reply [flat|nested] 8+ messages in thread
* [PATCH net-next v2 2/3] net: devmem: use memory provider helpers for net_iovs
2026-09-25 20:15 [PATCH net-next v2 0/3] net: consolidate devmem net_iov freelist and DMA handling Stanislav Fomichev
2026-09-25 20:15 ` [PATCH net-next v2 1/3] net: netmem: move to index based freelist Stanislav Fomichev
@ 2026-09-25 20:15 ` Stanislav Fomichev
2026-09-25 20:15 ` [PATCH net-next v2 3/3] net: devmem: decode DMA addresses for TX Stanislav Fomichev
2026-09-29 14:10 ` [PATCH net-next v2 0/3] net: consolidate devmem net_iov freelist and DMA handling patchwork-bot+netdevbpf
3 siblings, 0 replies; 8+ messages in thread
From: Stanislav Fomichev @ 2026-09-25 20:15 UTC (permalink / raw)
To: netdev
Cc: davem, edumazet, kuba, pabeni, horms, hawk, ilias.apalodimas,
sdf, bobbyeshleman, almasrymina, kaiyuanz, linux-kernel
Use public memory-provider helpers for DMA address storage and page-pool
association instead of open-coding page_pool state and accounting.
Zero the net_iov array because net_mp_niov_set_page_pool() ORs
PP_SIGNATURE into pp_magic. Reject DMA addresses that cannot be
represented in net_iov metadata.
Reviewed-by: Mina Almasry <almasrymina@google.com>
Signed-off-by: Stanislav Fomichev <sdf@fomichev.me>
---
net/core/devmem.c | 31 +++++++++++--------------------
1 file changed, 11 insertions(+), 20 deletions(-)
diff --git a/net/core/devmem.c b/net/core/devmem.c
index 704d02bd8bc8..71c83730d73d 100644
--- a/net/core/devmem.c
+++ b/net/core/devmem.c
@@ -17,11 +17,9 @@
#include <net/page_pool/memory_provider.h>
#include <net/sock.h>
#include <net/tcp.h>
-#include <trace/events/page_pool.h>
#include "devmem.h"
#include "mp_dmabuf_devmem.h"
-#include "page_pool_priv.h"
/* Device memory support */
@@ -273,7 +271,7 @@ net_devmem_bind_dmabuf(struct net_device *dev, void *vdev,
goto err_unmap;
}
}
- binding->area.niovs = kvmalloc_objs(*binding->area.niovs,
+ binding->area.niovs = kvzalloc_objs(*binding->area.niovs,
binding->area.num_niovs);
if (!binding->area.niovs) {
err = -ENOMEM;
@@ -300,8 +298,12 @@ net_devmem_bind_dmabuf(struct net_device *dev, void *vdev,
for (i = 0; i < nr_niovs; i++, niov_idx++) {
niov = &binding->area.niovs[niov_idx];
net_iov_init(niov, &binding->area, NET_IOV_DMABUF);
- page_pool_set_dma_addr_netmem(net_iov_to_netmem(niov),
- dma_addr);
+ if (net_mp_niov_set_dma_addr(niov, dma_addr)) {
+ err = -EFAULT;
+ NL_SET_ERR_MSG(extack,
+ "dmabuf DMA address cannot be represented");
+ goto err_free_niovs;
+ }
if (direction == DMA_TO_DEVICE)
binding->tx_vec[niov_idx] = niov;
else
@@ -467,19 +469,9 @@ netmem_ref mp_dmabuf_devmem_alloc_netmems(struct page_pool *pool, gfp_t gfp)
if (unlikely(!allocated))
return 0;
- for (i = 0; i < allocated; i++) {
- struct net_iov *niov = netmem_to_net_iov(netmems[i]);
-
- niov->desc.pp_magic = 0;
- niov->desc.pp = NULL;
- atomic_long_set(&niov->desc.pp_ref_count, 0);
-
- page_pool_set_pp_info(pool, netmems[i]);
-
- pool->pages_state_hold_cnt++;
- trace_page_pool_state_hold(pool, netmems[i],
- pool->pages_state_hold_cnt);
- }
+ for (i = 0; i < allocated; i++)
+ net_mp_niov_set_page_pool(pool,
+ netmem_to_net_iov(netmems[i]));
/* Return the last one, the rest stay in the page_pool cache. */
allocated--;
@@ -504,8 +496,7 @@ bool mp_dmabuf_devmem_release_page(struct page_pool *pool, netmem_ref netmem)
if (WARN_ON_ONCE(refcount != 1))
return false;
- page_pool_clear_pp_info(netmem);
-
+ net_mp_niov_clear_page_pool(netmem_to_net_iov(netmem));
net_devmem_free_dmabuf(netmem_to_net_iov(netmem));
/* We don't want the page pool put_page()ing our net_iovs. */
--
2.53.0-Meta
^ permalink raw reply [flat|nested] 8+ messages in thread
* [PATCH net-next v2 3/3] net: devmem: decode DMA addresses for TX
2026-09-25 20:15 [PATCH net-next v2 0/3] net: consolidate devmem net_iov freelist and DMA handling Stanislav Fomichev
2026-09-25 20:15 ` [PATCH net-next v2 1/3] net: netmem: move to index based freelist Stanislav Fomichev
2026-09-25 20:15 ` [PATCH net-next v2 2/3] net: devmem: use memory provider helpers for net_iovs Stanislav Fomichev
@ 2026-09-25 20:15 ` Stanislav Fomichev
2026-09-29 9:43 ` Paolo Abeni
2026-09-29 14:10 ` [PATCH net-next v2 0/3] net: consolidate devmem net_iov freelist and DMA handling patchwork-bot+netdevbpf
3 siblings, 1 reply; 8+ messages in thread
From: Stanislav Fomichev @ 2026-09-25 20:15 UTC (permalink / raw)
To: netdev
Cc: davem, edumazet, kuba, pabeni, horms, hawk, ilias.apalodimas,
sdf, bobbyeshleman, almasrymina, kaiyuanz, linux-kernel
On 32-bit architectures where dma_addr_t is wider than unsigned long,
page_pool_set_dma_addr_netmem() stores page-aligned DMA addresses shifted
by PAGE_SHIFT. The net_iov branch of __skb_frag_dma_map() adds byte offsets
to the encoded value, so the NIC is programmed with an invalid DMA address.
This can trigger an IOMMU fault or DMA from unintended memory.
Consolidate DMA address encoding, decoding, and representability checks in
netmem helpers. Use the common decoder from the page pool and net_iov TX
paths so both interpret stored addresses consistently.
Fixes: bd61848900bf ("net: devmem: Implement TX path")
Reviewed-by: Mina Almasry <almasrymina@google.com>
Signed-off-by: Stanislav Fomichev <sdf@fomichev.me>
---
include/linux/skbuff.h | 7 +++++--
include/net/netmem.h | 27 +++++++++++++++++++++++++++
include/net/page_pool/helpers.h | 10 +---------
net/core/page_pool_priv.h | 14 ++------------
4 files changed, 35 insertions(+), 23 deletions(-)
diff --git a/include/linux/skbuff.h b/include/linux/skbuff.h
index 84308498a3a8..38b7d7389452 100644
--- a/include/linux/skbuff.h
+++ b/include/linux/skbuff.h
@@ -3816,9 +3816,12 @@ static inline dma_addr_t __skb_frag_dma_map(struct device *dev,
size_t offset, size_t size,
enum dma_data_direction dir)
{
+ dma_addr_t addr;
+
if (skb_frag_is_net_iov(frag)) {
- return netmem_to_net_iov(frag->netmem)->desc.dma_addr +
- offset + frag->offset;
+ addr = netmem_dma_addr_decode(
+ netmem_get_dma_addr(frag->netmem));
+ return addr + offset + frag->offset;
}
return dma_map_page(dev, skb_frag_page(frag),
skb_frag_off(frag) + offset, size, dir);
diff --git a/include/net/netmem.h b/include/net/netmem.h
index bccacd21b6c3..cc97611632dc 100644
--- a/include/net/netmem.h
+++ b/include/net/netmem.h
@@ -358,6 +358,33 @@ static inline bool netmem_is_pfmemalloc(netmem_ref netmem)
return page_is_pfmemalloc(netmem_to_page(netmem));
}
+#define NETMEM_32BIT_ARCH_WITH_64BIT_DMA \
+ (sizeof(dma_addr_t) > sizeof(unsigned long))
+
+static inline unsigned long netmem_dma_addr_encode(dma_addr_t addr)
+{
+ if (NETMEM_32BIT_ARCH_WITH_64BIT_DMA)
+ addr >>= PAGE_SHIFT;
+
+ return addr;
+}
+
+static inline dma_addr_t netmem_dma_addr_decode(unsigned long addr)
+{
+ if (NETMEM_32BIT_ARCH_WITH_64BIT_DMA)
+ return (dma_addr_t)addr << PAGE_SHIFT;
+
+ return addr;
+}
+
+static inline bool netmem_dma_addr_fits(dma_addr_t addr)
+{
+ /* We assume page alignment to shave off bottom bits,
+ * if this "compression" doesn't work we need to drop.
+ */
+ return addr == netmem_dma_addr_decode(netmem_dma_addr_encode(addr));
+}
+
static inline unsigned long netmem_get_dma_addr(netmem_ref netmem)
{
return netmem_to_nmdesc(netmem)->dma_addr;
diff --git a/include/net/page_pool/helpers.h b/include/net/page_pool/helpers.h
index 87a4e13886e1..cd021832c3fa 100644
--- a/include/net/page_pool/helpers.h
+++ b/include/net/page_pool/helpers.h
@@ -408,9 +408,6 @@ static inline void page_pool_recycle_direct_netmem(struct page_pool *pool,
page_pool_put_full_netmem(pool, netmem, true);
}
-#define PAGE_POOL_32BIT_ARCH_WITH_64BIT_DMA \
- (sizeof(dma_addr_t) > sizeof(unsigned long))
-
/**
* page_pool_free_va() - free a va into the page_pool
* @pool: pool from which va was allocated
@@ -427,12 +424,7 @@ static inline void page_pool_free_va(struct page_pool *pool, void *va,
static inline dma_addr_t page_pool_get_dma_addr_netmem(netmem_ref netmem)
{
- dma_addr_t ret = netmem_get_dma_addr(netmem);
-
- if (PAGE_POOL_32BIT_ARCH_WITH_64BIT_DMA)
- ret <<= PAGE_SHIFT;
-
- return ret;
+ return netmem_dma_addr_decode(netmem_get_dma_addr(netmem));
}
/**
diff --git a/net/core/page_pool_priv.h b/net/core/page_pool_priv.h
index 2fb06d5f6d55..430b97cd88da 100644
--- a/net/core/page_pool_priv.h
+++ b/net/core/page_pool_priv.h
@@ -18,18 +18,8 @@ void page_pool_unlist(struct page_pool *pool);
static inline bool
page_pool_set_dma_addr_netmem(netmem_ref netmem, dma_addr_t addr)
{
- if (PAGE_POOL_32BIT_ARCH_WITH_64BIT_DMA) {
- netmem_set_dma_addr(netmem, addr >> PAGE_SHIFT);
-
- /* We assume page alignment to shave off bottom bits,
- * if this "compression" doesn't work we need to drop.
- */
- return addr != (dma_addr_t)netmem_get_dma_addr(netmem)
- << PAGE_SHIFT;
- }
-
- netmem_set_dma_addr(netmem, addr);
- return false;
+ netmem_set_dma_addr(netmem, netmem_dma_addr_encode(addr));
+ return !netmem_dma_addr_fits(addr);
}
static inline bool page_pool_set_dma_addr(struct page *page, dma_addr_t addr)
--
2.53.0-Meta
^ permalink raw reply [flat|nested] 8+ messages in thread
* Re: [PATCH net-next v2 3/3] net: devmem: decode DMA addresses for TX
2026-09-25 20:15 ` [PATCH net-next v2 3/3] net: devmem: decode DMA addresses for TX Stanislav Fomichev
@ 2026-09-29 9:43 ` Paolo Abeni
2026-09-29 13:39 ` Paolo Abeni
0 siblings, 1 reply; 8+ messages in thread
From: Paolo Abeni @ 2026-09-29 9:43 UTC (permalink / raw)
To: Stanislav Fomichev, netdev
Cc: davem, edumazet, kuba, horms, hawk, ilias.apalodimas, sdf,
bobbyeshleman, almasrymina, kaiyuanz, linux-kernel
On 9/25/26 22:15, Stanislav Fomichev wrote:
> On 32-bit architectures where dma_addr_t is wider than unsigned long,
> page_pool_set_dma_addr_netmem() stores page-aligned DMA addresses shifted
> by PAGE_SHIFT. The net_iov branch of __skb_frag_dma_map() adds byte offsets
> to the encoded value, so the NIC is programmed with an invalid DMA address.
> This can trigger an IOMMU fault or DMA from unintended memory.
>
> Consolidate DMA address encoding, decoding, and representability checks in
> netmem helpers. Use the common decoder from the page pool and net_iov TX
> paths so both interpret stored addresses consistently.
>
> Fixes: bd61848900bf ("net: devmem: Implement TX path")
> Reviewed-by: Mina Almasry <almasrymina@google.com>
> Signed-off-by: Stanislav Fomichev <sdf@fomichev.me>
Fixes tag for net-next patches pointing to old code are highly discouraged.
My understanding is that netem on 32 bits is mostly a theoretical thing,
i.e. no actual usage.
Would you be ok to strip the tag? No need to repost, just reply here.
Thanks,
Paolo
^ permalink raw reply [flat|nested] 8+ messages in thread
* Re: [PATCH net-next v2 3/3] net: devmem: decode DMA addresses for TX
2026-09-29 9:43 ` Paolo Abeni
@ 2026-09-29 13:39 ` Paolo Abeni
2026-09-29 15:55 ` Stanislav Fomichev
0 siblings, 1 reply; 8+ messages in thread
From: Paolo Abeni @ 2026-09-29 13:39 UTC (permalink / raw)
To: Stanislav Fomichev, netdev
Cc: davem, edumazet, kuba, horms, hawk, ilias.apalodimas, sdf,
bobbyeshleman, almasrymina, kaiyuanz, linux-kernel
On 9/29/26 11:43, Paolo Abeni wrote:
> On 9/25/26 22:15, Stanislav Fomichev wrote:
>> On 32-bit architectures where dma_addr_t is wider than unsigned long,
>> page_pool_set_dma_addr_netmem() stores page-aligned DMA addresses shifted
>> by PAGE_SHIFT. The net_iov branch of __skb_frag_dma_map() adds byte offsets
>> to the encoded value, so the NIC is programmed with an invalid DMA address.
>> This can trigger an IOMMU fault or DMA from unintended memory.
>>
>> Consolidate DMA address encoding, decoding, and representability checks in
>> netmem helpers. Use the common decoder from the page pool and net_iov TX
>> paths so both interpret stored addresses consistently.
>>
>> Fixes: bd61848900bf ("net: devmem: Implement TX path")
>> Reviewed-by: Mina Almasry <almasrymina@google.com>
>> Signed-off-by: Stanislav Fomichev <sdf@fomichev.me>
> Fixes tag for net-next patches pointing to old code are highly discouraged.
> My understanding is that netem on 32 bits is mostly a theoretical thing,
> i.e. no actual usage.
> Would you be ok to strip the tag? No need to repost, just reply here.
Actually the above is more FYI than a real request. I'll apply the
series stripping the tag.
/P
^ permalink raw reply [flat|nested] 8+ messages in thread
* Re: [PATCH net-next v2 0/3] net: consolidate devmem net_iov freelist and DMA handling
2026-09-25 20:15 [PATCH net-next v2 0/3] net: consolidate devmem net_iov freelist and DMA handling Stanislav Fomichev
` (2 preceding siblings ...)
2026-09-25 20:15 ` [PATCH net-next v2 3/3] net: devmem: decode DMA addresses for TX Stanislav Fomichev
@ 2026-09-29 14:10 ` patchwork-bot+netdevbpf
3 siblings, 0 replies; 8+ messages in thread
From: patchwork-bot+netdevbpf @ 2026-09-29 14:10 UTC (permalink / raw)
To: Stanislav Fomichev
Cc: netdev, davem, edumazet, kuba, pabeni, horms, hawk,
ilias.apalodimas, sdf, bobbyeshleman, almasrymina, kaiyuanz,
linux-kernel
Hello:
This series was applied to netdev/net-next.git (main)
by Paolo Abeni <pabeni@redhat.com>:
On Fri, 25 Sep 2026 13:15:19 -0700 you wrote:
> Follow up on the recently merged devmem gen_pool removal by consolidating
> devmem's net_iov freelist and DMA-address handling.
>
> - move devmem freelist to index-based approach with push/pop helpers
> - switch devmem to public memory-provider helpers and reject DMA
> addresses that cannot be represented
> - decode stored DMA addresses for TX on 32-bit systems with 64-bit
> dma_addr_t
>
> [...]
Here is the summary with links:
- [net-next,v2,1/3] net: netmem: move to index based freelist
https://git.kernel.org/netdev/net-next/c/1cf2f913b3dd
- [net-next,v2,2/3] net: devmem: use memory provider helpers for net_iovs
https://git.kernel.org/netdev/net-next/c/5bdeb89ec5b0
- [net-next,v2,3/3] net: devmem: decode DMA addresses for TX
https://git.kernel.org/netdev/net-next/c/5c729e6c71f1
You are awesome, thank you!
--
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html
^ permalink raw reply [flat|nested] 8+ messages in thread
* Re: [PATCH net-next v2 3/3] net: devmem: decode DMA addresses for TX
2026-09-29 13:39 ` Paolo Abeni
@ 2026-09-29 15:55 ` Stanislav Fomichev
0 siblings, 0 replies; 8+ messages in thread
From: Stanislav Fomichev @ 2026-09-29 15:55 UTC (permalink / raw)
To: Paolo Abeni
Cc: netdev, davem, edumazet, kuba, horms, hawk, ilias.apalodimas,
sdf, bobbyeshleman, almasrymina, kaiyuanz, linux-kernel
On 09/29, Paolo Abeni wrote:
> On 9/29/26 11:43, Paolo Abeni wrote:
> > On 9/25/26 22:15, Stanislav Fomichev wrote:
> > > On 32-bit architectures where dma_addr_t is wider than unsigned long,
> > > page_pool_set_dma_addr_netmem() stores page-aligned DMA addresses shifted
> > > by PAGE_SHIFT. The net_iov branch of __skb_frag_dma_map() adds byte offsets
> > > to the encoded value, so the NIC is programmed with an invalid DMA address.
> > > This can trigger an IOMMU fault or DMA from unintended memory.
> > >
> > > Consolidate DMA address encoding, decoding, and representability checks in
> > > netmem helpers. Use the common decoder from the page pool and net_iov TX
> > > paths so both interpret stored addresses consistently.
> > >
> > > Fixes: bd61848900bf ("net: devmem: Implement TX path")
> > > Reviewed-by: Mina Almasry <almasrymina@google.com>
> > > Signed-off-by: Stanislav Fomichev <sdf@fomichev.me>
> > Fixes tag for net-next patches pointing to old code are highly discouraged.
> > My understanding is that netem on 32 bits is mostly a theoretical thing,
> > i.e. no actual usage.
> > Would you be ok to strip the tag? No need to repost, just reply here.
> Actually the above is more FYI than a real request. I'll apply the
> series stripping the tag.
Yes, agreed, this does not look like a real issue to me either. Thanks!
^ permalink raw reply [flat|nested] 8+ messages in thread
end of thread, other threads:[~2026-09-29 16:12 UTC | newest]
Thread overview: 8+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-25 20:15 [PATCH net-next v2 0/3] net: consolidate devmem net_iov freelist and DMA handling Stanislav Fomichev
2026-09-25 20:15 ` [PATCH net-next v2 1/3] net: netmem: move to index based freelist Stanislav Fomichev
2026-09-25 20:15 ` [PATCH net-next v2 2/3] net: devmem: use memory provider helpers for net_iovs Stanislav Fomichev
2026-09-25 20:15 ` [PATCH net-next v2 3/3] net: devmem: decode DMA addresses for TX Stanislav Fomichev
2026-09-29 9:43 ` Paolo Abeni
2026-09-29 13:39 ` Paolo Abeni
2026-09-29 15:55 ` Stanislav Fomichev
2026-09-29 14:10 ` [PATCH net-next v2 0/3] net: consolidate devmem net_iov freelist and DMA handling patchwork-bot+netdevbpf
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®