Tested this patch v2 again,everything works fine.

Tested-by: Lei Yang <leiy...@redhat.com>

On Wed, Jul 16, 2025 at 3:29 PM Vladimir Sementsov-Ogievskiy <
vsement...@yandex-team.ru> wrote:

> Theoretically tap_read_packet() may return size less than
> s->host_vnet_hdr_len, and next, we'll work with negative size
> (in case of !s->using_vnet_hdr). Let's avoid it.
>
> Don't proceed with size == s->host_vnet_hdr_len as well in case
> of !s->using_vnet_hdr, it doesn't make sense.
>
> Signed-off-by: Vladimir Sementsov-Ogievskiy <vsement...@yandex-team.ru>
> ---
>
> v2: change "<" -> "<="
>
>  net/tap.c | 5 +++++
>  1 file changed, 5 insertions(+)
>
> diff --git a/net/tap.c b/net/tap.c
> index 23536c09b46..2a859360193 100644
> --- a/net/tap.c
> +++ b/net/tap.c
> @@ -190,6 +190,11 @@ static void tap_send(void *opaque)
>              break;
>          }
>
> +        if (s->host_vnet_hdr_len && size <= s->host_vnet_hdr_len) {
> +            /* Invalid packet */
> +            break;
> +        }
> +
>          if (s->host_vnet_hdr_len && !s->using_vnet_hdr) {
>              buf  += s->host_vnet_hdr_len;
>              size -= s->host_vnet_hdr_len;
> --
> 2.48.1
>
>

Reply via email to