diff options
| author | Andrew Griffiths <andrew@calif.io> | 2026-09-29 20:11:31 +0000 |
|---|---|---|
| committer | Mark Johnston <markj@FreeBSD.org> | 2026-09-29 20:14:12 +0000 |
| commit | 669cd0d90ee7b5bed794ded5fa00b6be854a6598 (patch) | |
| tree | ecbdfa5daaa8d23e44b63f9a29660952ca12ba20 /tools/regression/sysvsem/Makefile | |
| parent | 18e9f60602c43c85a65446568206b73fba55c286 (diff) | |
m_defrag() has pointer-return ownership semantics: success frees the
original chain and returns a replacement, while failure returns NULL and
leaves the original owned by the caller. rge_encap() compared that
pointer as an integer status and could return failure after success,
causing rge_tx_task() to free its stale old head.
Pass the mbuf by reference, retain the replacement returned by
m_defrag(), and publish it to the caller before retrying DMA mapping. A
later mapping failure is then cleaned up through the current chain, and
a successful transmission uses that same chain for BPF and TX ownership.
An unprivileged process can reach the EFBIG branch in mapped-sendfile
mode.
Signed-off-by: Andrew Griffiths <andrew@calif.io>
Reviewed by: adrian, markj
MFC after: 1 week
Differential Revision: https://reviews.freebsd.org/D60142
Diffstat (limited to 'tools/regression/sysvsem/Makefile')
0 files changed, 0 insertions, 0 deletions
