On Tue, Jun 30, 2026 at 12:42 AM Peter Maydell <[email protected]> wrote:
>
> In qemu_receive_packet() we check to see if we should pad a short
> packet.  This is doing the wrong test: because this function is used
> when the device adds a packet to its own incoming queue (i.e.  for
> loopback), we should be checking the NetClientState's own do_not_pad
> flag, not that for its peer.
>
> We didn't notice this earlier, because at the moment all the real
> peers of a network device (i.e.  the network backends) do not set
> do_not_pad, so net_peer_needs_padding() always returns true except in
> the corner case where the network device has no peer at all.
>
> The effect of this is that if a network device has no peer (e.g.
> because QEMU was started with -net none or with -nodefaults) then we
> can still let through the kind of "guest misprograms the network
> device to loopback-transmit a short packet and then we mishandle it
> in the receive path" bug like #3043 which commit a01344d9d78 was
> trying to fix.
>
> Since the distinction between "we should check nc->do_not_pad"
> and "we should check nc->peer->do_not_pad" is a bit subtle, add
> enough documentation commentary to make it more obvious.
>
> Cc: [email protected]
> Fixes: a01344d9d78 ("net: pad packets to minimum length in 
> qemu_receive_packet()")
> Suggested-by: Bin Meng <[email protected]>
> Signed-off-by: Peter Maydell <[email protected]>
> ---
>  include/net/net.h | 23 +++++++++++++++++++++++
>  net/net.c         |  2 +-
>  2 files changed, 24 insertions(+), 1 deletion(-)
>

Reviewed-by: Bin Meng <[email protected]>

Reply via email to