From: Petr Vorel <pvorel@suse.cz>
To: Andrea Cervesato <andrea.cervesato@suse.de>
Cc: Linux Test Project <ltp@lists.linux.it>
Subject: Re: [LTP] [PATCH] cve/sctphantom: fix EINVAL on pre-v4.19 kernels
Date: Tue, 25 Aug 2026 17:07:49 +0200 [thread overview]
Message-ID: <20260825150749.GA86472@pevik> (raw)
In-Reply-To: <20260825-sctphantom_fix-v1-1-6504f91fd7f5@suse.com>
Hi Andrea,
> The test passed its 156 byte mirror of struct sctp_paddrparams, which
> includes the spp_ipv6_flowlabel and spp_dscp tail, to
> SCTP_PEER_ADDR_PARAMS. Kernels older than v4.19 only accept
> optlen == sizeof(struct sctp_paddrparams), which is 152 there, so the
> setsockopt() failed and the test broke:
> sctphantom.c:361: TBROK: setsockopt(6, 132, 9, 0x..., 156) failed: EINVAL (22)
> Drop the tail fields from the mirrored struct so that the option length
> matches the pre-v4.19 layout. That length is also accepted by v4.19 and
> newer kernels as the compat size introduced along with the tail fields
> by upstream commit 0b0dce7a36fb ("sctp: add spp_ipv6_flowlabel and
> spp_dscp for sctp_paddrparams"), provided the SPP_DSCP and
> SPP_IPV6_FLOWLABEL flags are not set, which the test never does.
Indeed, it was added in 0b0dce7a36fb ("sctp: add spp_ipv6_flowlabel and spp_dscp
for sctp_paddrparams") in v4.19-rc1. Thanks!
Reviewed-by: Petr Vorel <pvorel@suse.cz>
> -/* Mirror of the uapi struct sctp_paddrparams */
> +/*
> + * Mirror of the uapi struct sctp_paddrparams without the spp_ipv6_flowlabel
> + * and spp_dscp tail added in v4.19: older kernels require optlen == 152,
> + * while v4.19 and newer also accept the pre-v4.19 length.
> + */
> struct tst_sctp_paddrparams {
> - int32_t spp_assoc_id;
> + int32_t spp_assoc_id;
> struct sockaddr_storage spp_address;
> - uint32_t spp_hbinterval;
> - uint16_t spp_pathmaxrxt;
> - uint32_t spp_pathmtu;
> - uint32_t spp_sackdelay;
> - uint32_t spp_flags;
> - uint32_t spp_ipv6_flowlabel;
> - uint8_t spp_dscp;
> + uint32_t spp_hbinterval;
> + uint16_t spp_pathmaxrxt;
> + uint32_t spp_pathmtu;
> + uint32_t spp_sackdelay;
> + uint32_t spp_flags;
> } __attribute__((packed, aligned(4)));
nit: I suppose you copy paste the older struct, which used a different
whitespace. But how about (before merge) just remove spp_ipv6_flowlabel and
spp_dscp? Without touching whitespace of the other members is change more
visible even without using --ignore-space-change.
Kind regards,
Petr
+++ testcases/cve/sctphantom.c
@@ -62,7 +62,11 @@
#define ADDR_DUMMY "127.0.0.254" /* third path to keep transport_count > 1 */
#define ADDR_SPOOF "127.0.0.3" /* forged ASCONF packet source */
-/* Mirror of the uapi struct sctp_paddrparams */
+/*
+ * Mirror of the uapi struct sctp_paddrparams without the spp_ipv6_flowlabel
+ * and spp_dscp tail added in v4.19: older kernels require optlen == 152,
+ * while v4.19 and newer also accept the pre-v4.19 length.
+ */
struct tst_sctp_paddrparams {
int32_t spp_assoc_id;
struct sockaddr_storage spp_address;
@@ -71,8 +75,6 @@ struct tst_sctp_paddrparams {
uint32_t spp_pathmtu;
uint32_t spp_sackdelay;
uint32_t spp_flags;
- uint32_t spp_ipv6_flowlabel;
- uint8_t spp_dscp;
} __attribute__((packed, aligned(4)));
/* Mirror of the uapi struct sctp_paddrinfo */
--
Mailing list info: https://lists.linux.it/listinfo/ltp
next prev parent reply other threads:[~2026-08-25 15:08 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-25 12:44 [LTP] [PATCH] cve/sctphantom: fix EINVAL on pre-v4.19 kernels Andrea Cervesato
2026-08-25 15:04 ` Cyril Hrubis
2026-08-25 15:07 ` Petr Vorel [this message]
2026-08-25 17:18 ` Andrea Cervesato via ltp
2026-08-25 17:21 ` Andrea Cervesato via ltp
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260825150749.GA86472@pevik \
--to=pvorel@suse.cz \
--cc=andrea.cervesato@suse.de \
--cc=ltp@lists.linux.it \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.