* [PATCH] aoe: pull in the headers each received packet type reads
@ 2026-10-07 17:52 Josef Bacik
2026-10-07 19:23 ` Jens Axboe
2026-10-08 10:00 ` Christoph Hellwig
0 siblings, 2 replies; 5+ messages in thread
From: Josef Bacik @ 2026-10-07 17:52 UTC (permalink / raw)
To: Justin Sanders, Jens Axboe; +Cc: linux-block, linux-kernel, stable, Josef Bacik
aoenet_rcv() only pulls the AoE and ATA headers into the skb head when
the packet is long enough to hold both. A shorter packet goes through
unpulled, and aoenet_rcv() reads the AoE header from it anyway. CFG
responses go on to aoecmd_cfg_rsp(), which reads the config header
after it, and ATA responses get queued for ktiocomplete(), which
skb_pull()s both headers. Ethernet pads frames to 60 bytes, so this
mostly takes a virtual link, but nothing stops a short frame from
getting here.
Pull the AoE header up front and drop the packet if it isn't there,
then pull the ATA or config header in the switch arm that hands the
packet on, so each path gets the headers it reads. This also replaces
the open-coded __pskb_pull_tail() with pskb_may_pull().
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Josef Bacik <josef@toxicpanda.com>
---
Tested by sending AoE responses at a veth pair. Without this patch a
26 byte CFG response and a 20 byte frame cut off inside the AoE header
each created an aoe device from bytes past the end of the packet. With
it they're dropped, and a normal CFG response still creates the
device and gets an ATA identify back.
Thanks,
Josef
---
drivers/block/aoe/aoenet.c | 14 ++++++--------
1 file changed, 6 insertions(+), 8 deletions(-)
diff --git a/drivers/block/aoe/aoenet.c b/drivers/block/aoe/aoenet.c
index 66e617664c14..cd7c735bb43b 100644
--- a/drivers/block/aoe/aoenet.c
+++ b/drivers/block/aoe/aoenet.c
@@ -131,9 +131,7 @@ static int
aoenet_rcv(struct sk_buff *skb, struct net_device *ifp, struct packet_type *pt, struct net_device *orig_dev)
{
struct aoe_hdr *h;
- struct aoe_atahdr *ah;
u32 n;
- int sn;
if (dev_net(ifp) != &init_net)
goto exit;
@@ -144,12 +142,8 @@ aoenet_rcv(struct sk_buff *skb, struct net_device *ifp, struct packet_type *pt,
if (!is_aoe_netif(ifp))
goto exit;
skb_push(skb, ETH_HLEN); /* (1) */
- sn = sizeof(*h) + sizeof(*ah);
- if (skb->len >= sn) {
- sn -= skb_headlen(skb);
- if (sn > 0 && !__pskb_pull_tail(skb, sn))
- goto exit;
- }
+ if (!pskb_may_pull(skb, sizeof(*h)))
+ goto exit;
h = (struct aoe_hdr *) skb->data;
n = get_unaligned_be32(&h->tag);
if ((h->verfl & AOEFL_RSP) == 0 || (n & 1<<31))
@@ -171,10 +165,14 @@ aoenet_rcv(struct sk_buff *skb, struct net_device *ifp, struct packet_type *pt,
switch (h->cmd) {
case AOECMD_ATA:
+ if (!pskb_may_pull(skb, sizeof(*h) + sizeof(struct aoe_atahdr)))
+ goto exit;
/* ata_rsp may keep skb for later processing or give it back */
skb = aoecmd_ata_rsp(skb);
break;
case AOECMD_CFG:
+ if (!pskb_may_pull(skb, sizeof(*h) + sizeof(struct aoe_cfghdr)))
+ goto exit;
aoecmd_cfg_rsp(skb);
break;
default:
---
base-commit: a3b346d7b1730db9900bb9e17f5bb8ea27e6ae2c
change-id: 20261006-b4-aoe-short-packets-f3e7d3580849
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH] aoe: pull in the headers each received packet type reads
2026-10-07 17:52 [PATCH] aoe: pull in the headers each received packet type reads Josef Bacik
@ 2026-10-07 19:23 ` Jens Axboe
2026-10-08 10:00 ` Christoph Hellwig
1 sibling, 0 replies; 5+ messages in thread
From: Jens Axboe @ 2026-10-07 19:23 UTC (permalink / raw)
To: Justin Sanders, Josef Bacik; +Cc: linux-block, linux-kernel, stable
On Wed, 07 Oct 2026 17:52:29 +0000, Josef Bacik wrote:
> aoenet_rcv() only pulls the AoE and ATA headers into the skb head when
> the packet is long enough to hold both. A shorter packet goes through
> unpulled, and aoenet_rcv() reads the AoE header from it anyway. CFG
> responses go on to aoecmd_cfg_rsp(), which reads the config header
> after it, and ATA responses get queued for ktiocomplete(), which
> skb_pull()s both headers. Ethernet pads frames to 60 bytes, so this
> mostly takes a virtual link, but nothing stops a short frame from
> getting here.
>
> [...]
Applied, thanks!
[1/1] aoe: pull in the headers each received packet type reads
commit: e1274a6bc40a4618f6fbaebbdc51cca865d51bed
Best regards,
--
Jens Axboe
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH] aoe: pull in the headers each received packet type reads
2026-10-07 17:52 [PATCH] aoe: pull in the headers each received packet type reads Josef Bacik
2026-10-07 19:23 ` Jens Axboe
@ 2026-10-08 10:00 ` Christoph Hellwig
2026-10-09 9:59 ` Damien Le Moal
2026-10-09 14:40 ` Jens Axboe
1 sibling, 2 replies; 5+ messages in thread
From: Christoph Hellwig @ 2026-10-08 10:00 UTC (permalink / raw)
To: Josef Bacik; +Cc: Justin Sanders, Jens Axboe, linux-block, linux-kernel, stable
Can we plus just kill the aoe driver given how buggy both the driver
and the protocol is instead of playing whack-a-mole?
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH] aoe: pull in the headers each received packet type reads
2026-10-08 10:00 ` Christoph Hellwig
@ 2026-10-09 9:59 ` Damien Le Moal
2026-10-09 14:40 ` Jens Axboe
1 sibling, 0 replies; 5+ messages in thread
From: Damien Le Moal @ 2026-10-09 9:59 UTC (permalink / raw)
To: Christoph Hellwig, Josef Bacik
Cc: Justin Sanders, Jens Axboe, linux-block, linux-kernel, stable
On 2026/10/08 12:00, Christoph Hellwig wrote:
> Can we plus just kill the aoe driver given how buggy both the driver
> and the protocol is instead of playing whack-a-mole?
+1
--
Damien Le Moal
Western Digital Research
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH] aoe: pull in the headers each received packet type reads
2026-10-08 10:00 ` Christoph Hellwig
2026-10-09 9:59 ` Damien Le Moal
@ 2026-10-09 14:40 ` Jens Axboe
1 sibling, 0 replies; 5+ messages in thread
From: Jens Axboe @ 2026-10-09 14:40 UTC (permalink / raw)
To: Christoph Hellwig, Josef Bacik
Cc: Justin Sanders, linux-block, linux-kernel, stable
On 10/8/26 4:00 AM, Christoph Hellwig wrote:
> Can we plus just kill the aoe driver given how buggy both the driver
> and the protocol is instead of playing whack-a-mole?
I'd love to, but not sure it's feasible. I'll have to go search emails
for details, but I know there are people using this driver still,
unfortunately.
--
Jens Axboe
^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2026-10-09 14:40 UTC | newest]
Thread overview: 5+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-07 17:52 [PATCH] aoe: pull in the headers each received packet type reads Josef Bacik
2026-10-07 19:23 ` Jens Axboe
2026-10-08 10:00 ` Christoph Hellwig
2026-10-09 9:59 ` Damien Le Moal
2026-10-09 14:40 ` Jens Axboe
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®