Commit 4be5b041e679 for kernel

commit 4be5b041e679cbae7fdc22781888ba08df7f27bf
Merge: bfec39ff1484 21b5953e7494
Author: Jakub Kicinski <kuba@kernel.org>
Date:   Thu Aug 6 09:27:24 2026 -0700

    Merge branch 'net-fix-hard_header_len-races-in-packet-send-paths'

    Qihang Tang says:

    ====================
    net: fix hard_header_len races in packet send paths

    The packet socket TX paths read dev->hard_header_len independently for
    skb allocation and header construction. Concurrent netdevice
    reconfiguration (e.g. bonding device type changes) can change this value
    in between, leading to mismatched headroom and copy length, and in the
    SOCK_RAW case to out-of-bounds writes.

    Patch 1 removes the CAP_SYS_RAWIO zero-padding branch in
    dev_validate_header(). That branch sizes a memset against the live
    dev->hard_header_len while operating on an skb whose headroom was
    allocated from an earlier hard_header_len read, so a concurrent increase
    can write past the reserved buffer. Removing it first keeps the later
    snapshot fixes bisect-safe: they do not replace an earlier skb_under_panic
    with a silent overwrite.

    Patches 2 and 3 snapshot hard_header_len once per send and use it
    consistently for allocation and construction, in the non-ring and TX_RING
    paths respectively. The separate SOCK_DGRAM consistency problem between
    hard_header_len and header_ops->create remains out of scope, as noted in
    the commit messages.
    ====================

    Link: https://patch.msgid.link/20260805125729.19220-1-q.h.hack.winter@gmail.com
    Signed-off-by: Jakub Kicinski <kuba@kernel.org>