From: Dmitry Safonov <dima@arista.com>
To: David Ahern <dsahern@kernel.org>,
Eric Dumazet <edumazet@google.com>,
Paolo Abeni <pabeni@redhat.com>, Jakub Kicinski <kuba@kernel.org>,
"David S. Miller" <davem@davemloft.net>
Cc: linux-kernel@vger.kernel.org, Dmitry Safonov <dima@arista.com>,
Dmitry Safonov <0x7f454c46@gmail.com>,
Francesco Ruggeri <fruggeri05@gmail.com>,
Salam Noureddine <noureddine@arista.com>,
Simon Horman <horms@kernel.org>,
netdev@vger.kernel.org
Subject: [PATCH v5 0/7] TCP-AO fixes
Date: Mon, 4 Dec 2023 19:00:39 +0000 [thread overview]
Message-ID: <20231204190044.450107-1-dima@arista.com> (raw)
Hi,
Changes from v4:
- Dropped 2 patches on which there's no consensus. They will require
more work TBD if they may made acceptable. Those are:
o "net/tcp: Allow removing current/rnext TCP-AO keys on TCP_LISTEN sockets"
o "net/tcp: Store SNEs + SEQs on ao_info"
Changes from v3:
- Don't restrict adding any keys on TCP-AO connection in VRF, but only
the ones that don't match l3index (David)
Changes from v2:
- rwlocks are problematic in net code (Paolo)
Changed the SNE code to avoid spin/rw locks on RX/TX fastpath by
double-accounting SEQ numbers for TCP-AO enabled connections.
Changes from v1:
- Use tcp_can_repair_sock() helper to limit TCP_AO_REPAIR (Eric)
- Instead of hook to listen() syscall, allow removing current/rnext keys
on TCP_LISTEN (addressing Eric's objection)
- Add sne_lock to protect snd_sne/rcv_sne
- Don't move used_tcp_ao in struct tcp_request_sock (Eric)
I've been working on TCP-AO key-rotation selftests and as a result
exercised some corner-cases that are not usually met in production.
Here are a bunch of semi-related fixes:
- Documentation typo (reported by Markus Elfring)
- Proper alignment for TCP-AO option in TCP header that has MAC length
of non 4 bytes (now a selftest with randomized maclen/algorithm/etc
passes)
- 3 uAPI restricting patches that disallow more things to userspace in
order to prevent it shooting itself in any parts of the body
- SNEs READ_ONCE()/WRITE_ONCE() that went missing by my human factor
- Avoid storing MAC length from SYN header as SYN-ACK will use
rnext_key.maclen (drops an extra check that fails on new selftests)
Please, consider applying/pulling.
The following changes since commit 33cc938e65a98f1d29d0a18403dbbee050dcad9a:
Linux 6.7-rc4 (2023-12-03 18:52:56 +0900)
are available in the Git repository at:
git@github.com:0x7f454c46/linux.git tcp-ao-post-merge-v5
for you to fetch changes up to 13504cef7e321700d930e9c005db6759c21981a3:
net/tcp: Don't store TCP-AO maclen on reqsk (2023-12-04 18:23:30 +0000)
----------------------------------------------------------------
Thanks,
Dmitry
Cc: David Ahern <dsahern@kernel.org>
Cc: "David S. Miller" <davem@davemloft.net>
Cc: Dmitry Safonov <0x7f454c46@gmail.com>
Cc: Eric Dumazet <edumazet@google.com>
Cc: Francesco Ruggeri <fruggeri05@gmail.com>
Cc: Jakub Kicinski <kuba@kernel.org>
Cc: Paolo Abeni <pabeni@redhat.com>
Cc: Salam Noureddine <noureddine@arista.com>
Cc: Simon Horman <horms@kernel.org>
Cc: netdev@vger.kernel.org
Cc: linux-kernel@vger.kernel.org
Dmitry Safonov (5):
Documentation/tcp: Fix an obvious typo
net/tcp: Consistently align TCP-AO option in the header
net/tcp: Limit TCP_AO_REPAIR to non-listen sockets
net/tcp: Don't add key with non-matching VRF on connected sockets
net/tcp: Don't store TCP-AO maclen on reqsk
Documentation/networking/tcp_ao.rst | 2 +-
include/linux/tcp.h | 8 ++------
include/net/tcp_ao.h | 6 ++++++
net/ipv4/tcp.c | 6 ++++++
net/ipv4/tcp_ao.c | 17 +++++++++++++----
net/ipv4/tcp_input.c | 5 +++--
net/ipv4/tcp_ipv4.c | 4 ++--
net/ipv4/tcp_minisocks.c | 2 +-
net/ipv4/tcp_output.c | 15 ++++++---------
net/ipv6/tcp_ipv6.c | 2 +-
10 files changed, 41 insertions(+), 26 deletions(-)
base-commit: 33cc938e65a98f1d29d0a18403dbbee050dcad9a
--
2.43.0
next reply other threads:[~2023-12-04 19:01 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2023-12-04 19:00 Dmitry Safonov [this message]
2023-12-04 19:00 ` [PATCH v5 1/5] Documentation/tcp: Fix an obvious typo Dmitry Safonov
2023-12-06 11:50 ` patchwork-bot+netdevbpf
2023-12-04 19:00 ` [PATCH v5 2/5] net/tcp: Consistently align TCP-AO option in the header Dmitry Safonov
2023-12-04 19:00 ` [PATCH v5 3/5] net/tcp: Limit TCP_AO_REPAIR to non-listen sockets Dmitry Safonov
2023-12-04 19:00 ` [PATCH v5 4/5] net/tcp: Don't add key with non-matching VRF on connected sockets Dmitry Safonov
2023-12-04 19:00 ` [PATCH v5 5/5] net/tcp: Don't store TCP-AO maclen on reqsk Dmitry Safonov
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20231204190044.450107-1-dima@arista.com \
--to=dima@arista.com \
--cc=0x7f454c46@gmail.com \
--cc=davem@davemloft.net \
--cc=dsahern@kernel.org \
--cc=edumazet@google.com \
--cc=fruggeri05@gmail.com \
--cc=horms@kernel.org \
--cc=kuba@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=noureddine@arista.com \
--cc=pabeni@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.