Commit 125755776bc6 for kernel

commit 125755776bc6d4dd53eaf551c87e3d460625d638
Author: Pavel Begunkov <asml.silence@gmail.com>
Date:   Fri Sep 4 14:43:07 2026 +0100

    tcp: reject non zerocopy devmem tx

    Devmem tcp tx doesn't work without zero-copy, however it's not currently
    enforced if NETIF_F_SG isn't present. In this case, tcp_sendmsg_locked()
    will try the copy path and try to copy data from an iovec which consists
    of offsets into the dma-buf and would normally fail. Moreover,
    d9c56501c72fd ("net: tcp: block mixing readable and unreadable frags")
    relies on that and assumes that the devmem binding is present IFF we're
    using the zero-copy path, which can be used to mix net-iov and pages in
    a single skb, and break invariants. Let's reject devmem tx without
    zero-copy.

    Note, the parameter check the patch is modifying is too loose, we can
    create an io_uring request with dmabuf_id and all ZC flags, but which
    won't have the binding. We replace it with stricter validation.

    Fixes: bd61848900bff ("net: devmem: Implement TX path")
    Fixes: d9c56501c72fd ("net: tcp: block mixing readable and unreadable frags")
    Signed-off-by: Pavel Begunkov <asml.silence@gmail.com>
    Reviewed-by: Mina Almasry <almasrymina@google.com>
    Link: https://patch.msgid.link/fdc2478d8f21268d7078556409887d8e6ba0ad32.1788529053.git.asml.silence@gmail.com
    Signed-off-by: Paolo Abeni <pabeni@redhat.com>

diff --git a/net/ipv4/tcp.c b/net/ipv4/tcp.c
index 1c867a302444..562752352afe 100644
--- a/net/ipv4/tcp.c
+++ b/net/ipv4/tcp.c
@@ -1169,8 +1169,7 @@ int tcp_sendmsg_locked(struct sock *sk, struct msghdr *msg, size_t size)
 			zc = MSG_SPLICE_PAGES;
 	}

-	if (!sockc_err && sockc.dmabuf_id &&
-	    (!(flags & MSG_ZEROCOPY) || !sock_flag(sk, SOCK_ZEROCOPY))) {
+	if (!sockc_err && sockc.dmabuf_id && (zc != MSG_ZEROCOPY || !binding)) {
 		err = -EINVAL;
 		goto out_err;
 	}