On Fri, Mar 06, 2026 at 12:51:19PM +0100, Laurent Vivier wrote: > Add a generic iov_truncate() function that truncates an IO vector to a > given number of bytes, returning the number of iov entries that contain > data after truncation. > > Use it in udp_vu_sock_recv() and tcp_vu_sock_recv() to replace the > open-coded truncation logic that adjusted iov entries after recvmsg(). > Also convert the direct iov_len assignment in tcp_vu_send_flag() to use > iov_truncate() for consistency. > > Add an ASSERT() in tcp_vu_data_from_sock() to quiet the Coverity error: > > passt/tcp_vu.c:457:3: > 19. overflow_const: Expression "dlen + hdrlen", where "dlen" is known to > be equal to -86, and "hdrlen" is known to be equal to 86, underflows > the type of "dlen + hdrlen", which is type "unsigned long". > > Signed-off-by: Laurent Vivier Reviewed-by: David Gibson > --- > > Notes: > v4: add ASSERT() to quiet the Coverity error > v3: use in tcp_vu_send_flag() too > v2: use iov_truncate() in udp_vu_sock_recv() too > > iov.c | 22 ++++++++++++++++++++++ > iov.h | 1 + > tcp_vu.c | 20 ++++++++------------ > udp_vu.c | 12 +++--------- > 4 files changed, 34 insertions(+), 21 deletions(-) > > diff --git a/iov.c b/iov.c > index ad726daa4cd8..31a3f5bc29e5 100644 > --- a/iov.c > +++ b/iov.c > @@ -147,6 +147,28 @@ size_t iov_size(const struct iovec *iov, size_t iov_cnt) > return len; > } > > +/** > + * iov_truncate() - Truncate an IO vector to a given number of bytes > + * @iov: IO vector (modified) > + * @iov_cnt: Number of entries in @iov > + * @size: Total number of bytes to keep > + * > + * Return: number of iov entries that contain data after truncation > + */ > +size_t iov_truncate(struct iovec *iov, size_t iov_cnt, size_t size) > +{ > + size_t i, offset; > + > + i = iov_skip_bytes(iov, iov_cnt, size, &offset); > + > + if (i < iov_cnt) { > + iov[i].iov_len = offset; > + i += !!offset; > + } > + > + return i; > +} > + > /** > * iov_tail_prune() - Remove any unneeded buffers from an IOV tail > * @tail: IO vector tail (modified) > diff --git a/iov.h b/iov.h > index d1ab91a94e22..b4e50b0fca5a 100644 > --- a/iov.h > +++ b/iov.h > @@ -29,6 +29,7 @@ size_t iov_from_buf(const struct iovec *iov, size_t iov_cnt, > size_t iov_to_buf(const struct iovec *iov, size_t iov_cnt, > size_t offset, void *buf, size_t bytes); > size_t iov_size(const struct iovec *iov, size_t iov_cnt); > +size_t iov_truncate(struct iovec *iov, size_t iov_cnt, size_t size); > > /* > * DOC: Theory of Operation, struct iov_tail > diff --git a/tcp_vu.c b/tcp_vu.c > index 88be232dca66..fd734e857b3b 100644 > --- a/tcp_vu.c > +++ b/tcp_vu.c > @@ -131,7 +131,7 @@ int tcp_vu_send_flag(const struct ctx *c, struct tcp_tap_conn *conn, int flags) > return ret; > } > > - flags_elem[0].in_sg[0].iov_len = hdrlen + optlen; > + iov_truncate(&flags_iov[0], 1, hdrlen + optlen); > payload = IOV_TAIL(flags_elem[0].in_sg, 1, hdrlen); > > if (flags & KEEPALIVE) > @@ -192,9 +192,9 @@ static ssize_t tcp_vu_sock_recv(const struct ctx *c, struct vu_virtq *vq, > struct msghdr mh_sock = { 0 }; > uint16_t mss = MSS_GET(conn); > int s = conn->sock; > - ssize_t ret, len; > size_t hdrlen; > int elem_cnt; > + ssize_t ret; > int i; > > *iov_cnt = 0; > @@ -247,15 +247,7 @@ static ssize_t tcp_vu_sock_recv(const struct ctx *c, struct vu_virtq *vq, > ret -= already_sent; > > /* adjust iov number and length of the last iov */ > - len = ret; > - for (i = 0; len && i < elem_cnt; i++) { > - struct iovec *iov = &elem[i].in_sg[0]; > - > - if (iov->iov_len > (size_t)len) > - iov->iov_len = len; > - > - len -= iov->iov_len; > - } > + i = iov_truncate(&iov_vu[DISCARD_IOV_NUM], elem_cnt, ret); > > /* adjust head count */ > while (*head_cnt > 0 && head[*head_cnt - 1] >= i) > @@ -448,10 +440,14 @@ int tcp_vu_data_from_sock(const struct ctx *c, struct tcp_tap_conn *conn) > for (i = 0, previous_dlen = -1, check = NULL; i < head_cnt; i++) { > struct iovec *iov = &elem[head[i]].in_sg[0]; > int buf_cnt = head[i + 1] - head[i]; > - ssize_t dlen = iov_size(iov, buf_cnt) - hdrlen; > + size_t frame_size = iov_size(iov, buf_cnt); > bool push = i == head_cnt - 1; > + ssize_t dlen; > size_t l2len; > > + ASSERT(frame_size >= hdrlen); > + > + dlen = frame_size - hdrlen; > vu_set_vnethdr(iov->iov_base, buf_cnt); > > /* The IPv4 header checksum varies only with dlen */ > diff --git a/udp_vu.c b/udp_vu.c > index 3520f89e5671..5effca777e0a 100644 > --- a/udp_vu.c > +++ b/udp_vu.c > @@ -71,9 +71,9 @@ static int udp_vu_sock_recv(const struct ctx *c, struct vu_virtq *vq, int s, > bool v6, ssize_t *dlen) > { > const struct vu_dev *vdev = c->vdev; > - int iov_cnt, idx, iov_used; > - size_t off, hdrlen, l2len; > struct msghdr msg = { 0 }; > + int iov_cnt, iov_used; > + size_t hdrlen, l2len; > > ASSERT(!c->no_udp); > > @@ -115,13 +115,7 @@ static int udp_vu_sock_recv(const struct ctx *c, struct vu_virtq *vq, int s, > iov_vu[0].iov_base = (char *)iov_vu[0].iov_base - hdrlen; > iov_vu[0].iov_len += hdrlen; > > - /* count the numbers of buffer filled by recvmsg() */ > - idx = iov_skip_bytes(iov_vu, iov_cnt, *dlen + hdrlen, &off); > - > - /* adjust last iov length */ > - if (idx < iov_cnt) > - iov_vu[idx].iov_len = off; > - iov_used = idx + !!off; > + iov_used = iov_truncate(iov_vu, iov_cnt, *dlen + hdrlen); > > /* pad frame to 60 bytes: first buffer is at least ETH_ZLEN long */ > l2len = *dlen + hdrlen - VNET_HLEN; > -- > 2.53.0 > -- David Gibson (he or they) | I'll have my music baroque, and my code david AT gibson.dropbear.id.au | minimalist, thank you, not the other way | around. http://www.ozlabs.org/~dgibson