All of lore.kernel.org
 help / color / mirror / Atom feed
* [net:main 2/4] net/sctp/auth.c:412 sctp_auth_verify_cookie_params() warn: always true condition '(random->type != (-32766)) => (0-u16max != (-32766))'
@ 2026-08-10  0:41 kernel test robot
  0 siblings, 0 replies; only message in thread
From: kernel test robot @ 2026-08-10  0:41 UTC (permalink / raw)
  To:  Jérémy Jean; +Cc: oe-kbuild-all, netdev, Jakub Kicinski

tree:   https://git.kernel.org/pub/scm/linux/kernel/git/davem/net.git main
head:   dd057113ac7ba5bdd2aed3d9405305911152f911
commit: 3dbb44d88b1e94dd31fe43588af7437b34b44d56 [2/4] sctp: validate cookie AUTH state before use
config: arm-randconfig-r071-20260809 (https://download.01.org/0day-ci/archive/20260810/202608100747.D0iwjzi5-lkp@intel.com/config)
compiler: arm-linux-gnueabi-gcc (GCC) 8.5.0
smatch: v0.5.0-9187-g5189e3fb

If you fix the issue in a separate patch/commit (i.e. not just a new version of
the same patch/commit), kindly add following tags
| Reported-by: kernel test robot <lkp@intel.com>
| Closes: https://lore.kernel.org/oe-kbuild-all/202608100747.D0iwjzi5-lkp@intel.com/

New smatch warnings:
net/sctp/auth.c:412 sctp_auth_verify_cookie_params() warn: always true condition '(random->type != (-32766)) => (0-u16max != (-32766))'
net/sctp/auth.c:418 sctp_auth_verify_cookie_params() warn: always true condition '(hmacs->param_hdr.type != (-32764)) => (0-u16max != (-32764))'
net/sctp/auth.c:441 sctp_auth_verify_cookie_params() warn: always true condition '(chunks->param_hdr.type != (-32765)) => (0-u16max != (-32765))'

Old smatch warnings:
net/sctp/auth.c:1018 sctp_auth_init() warn: assigning (-32764) to unsigned variable 'auth_hmacs->param_hdr.type'
net/sctp/auth.c:1033 sctp_auth_init() warn: assigning (-32765) to unsigned variable 'auth_chunks->param_hdr.type'

vim +412 net/sctp/auth.c

   392	
   393	/* Verify AUTH parameters copied from a state cookie before they are restored
   394	 * into an association.  When cookie authentication is disabled these fields
   395	 * are peer-controlled, so they must satisfy the same constraints as locally
   396	 * generated AUTH parameters.
   397	 */
   398	bool sctp_auth_verify_cookie_params(const struct sctp_endpoint *ep,
   399					    const struct sctp_cookie *cookie)
   400	{
   401		const struct sctp_paramhdr *random;
   402		const struct sctp_hmac_algo_param *hmacs;
   403		const struct sctp_chunks_param *chunks;
   404		u16 hmacs_len, chunks_len;
   405		u16 n_hmacs, n_chunks, i;
   406		bool has_sha1 = false;
   407	
   408		if (sctp_sk(ep->base.sk)->cookie_auth_enable || !ep->auth_enable)
   409			return true;
   410	
   411		random = (const struct sctp_paramhdr *)cookie->auth_random;
 > 412		if (random->type != SCTP_PARAM_RANDOM ||
   413		    ntohs(random->length) != sizeof(*random) + SCTP_AUTH_RANDOM_LENGTH)
   414			return false;
   415	
   416		hmacs = (const struct sctp_hmac_algo_param *)cookie->auth_hmacs;
   417		hmacs_len = ntohs(hmacs->param_hdr.length);
 > 418		if (hmacs->param_hdr.type != SCTP_PARAM_HMAC_ALGO ||
   419		    hmacs_len < sizeof(struct sctp_paramhdr) +
   420				sizeof(hmacs->hmac_ids[0]) ||
   421		    hmacs_len > sizeof(cookie->auth_hmacs) ||
   422		    (hmacs_len - sizeof(struct sctp_paramhdr)) %
   423				sizeof(hmacs->hmac_ids[0]))
   424			return false;
   425	
   426		n_hmacs = (hmacs_len - sizeof(struct sctp_paramhdr)) /
   427			  sizeof(hmacs->hmac_ids[0]);
   428		for (i = 0; i < n_hmacs; i++) {
   429			u16 hmac_id = ntohs(hmacs->hmac_ids[i]);
   430	
   431			if (!sctp_hmac_supported(hmac_id))
   432				return false;
   433			if (hmac_id == SCTP_AUTH_HMAC_ID_SHA1)
   434				has_sha1 = true;
   435		}
   436		if (!has_sha1)
   437			return false;
   438	
   439		chunks = (const struct sctp_chunks_param *)cookie->auth_chunks;
   440		chunks_len = ntohs(chunks->param_hdr.length);
 > 441		if (chunks->param_hdr.type != SCTP_PARAM_CHUNKS ||
   442		    chunks_len < sizeof(struct sctp_paramhdr) ||
   443		    chunks_len > sizeof(cookie->auth_chunks))
   444			return false;
   445	
   446		n_chunks = chunks_len - sizeof(struct sctp_paramhdr);
   447		for (i = 0; i < n_chunks; i++) {
   448			if (sctp_auth_chunk_id_forbidden(chunks->chunks[i]))
   449				return false;
   450		}
   451	
   452		return true;
   453	}
   454	

--
0-DAY CI Kernel Test Service
https://github.com/intel/lkp-tests/wiki

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-08-10  0:42 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-10  0:41 [net:main 2/4] net/sctp/auth.c:412 sctp_auth_verify_cookie_params() warn: always true condition '(random->type != (-32766)) => (0-u16max != (-32766))' kernel test robot

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.