m_defrag() has pointer-return ownership semantics: success frees the
original chain and returns a replacement, while failure returns NULL and
leaves the original owned by the caller. rge_encap() compared that
pointer as an integer status and could return failure after success,
causing rge_tx_task() to free its stale old head.
Pass the mbuf by reference, retain the replacement returned by
m_defrag(), and publish it to the caller before retrying DMA mapping. A
later mapping failure is then cleaned up through the current chain, and
a successful transmission uses that same chain for BPF and TX ownership.
An unprivileged process can reach the EFBIG branch in mapped-sendfile
mode.