From: Jakub Kicinski <kuba@kernel.org>
To: davem@davemloft.net
Cc: netdev@vger.kernel.org, edumazet@google.com, pabeni@redhat.com,
andrew+netdev@lunn.ch, horms@kernel.org,
Jakub Kicinski <kuba@kernel.org>,
cel@kernel.org, donald.hunter@gmail.com,
kernel-tls-handshake@lists.linux.dev
Subject: [PATCH net-next 1/2] netlink: specs: handshake: type the remaining key serials s32
Date: Fri, 4 Sep 2026 12:04:09 -0700 [thread overview]
Message-ID: <20260904190410.3864660-1-kuba@kernel.org> (raw)
include/linux/key.h has "typedef int32_t key_serial_t" and commit
160f404495aa ("handshake: Fix sign of key_serial_t fields") converted
x509.cert and x509.privkey to s32, but accept.peer-identity,
accept.keyring and done.remote-auth were left as u32 - the same
quantity typed both ways inside one family, and a generated user space
struct with __s32 cert next to __u32 keyring. All three come from
key_serial_t storage in net/handshake/tlshd.c (treq->th_peerid[],
treq->th_keyring), and special keyrings are legitimately negative
(KEY_SPEC_PROCESS_KEYRING is -2).
NLA_U32 and NLA_S32 have the same length and no range check here, so
the only wire effect is how the value is printed.
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
---
CC: cel@kernel.org
CC: donald.hunter@gmail.com
CC: kernel-tls-handshake@lists.linux.dev
---
Documentation/netlink/specs/handshake.yaml | 6 +++---
net/handshake/genl.c | 2 +-
2 files changed, 4 insertions(+), 4 deletions(-)
diff --git a/Documentation/netlink/specs/handshake.yaml b/Documentation/netlink/specs/handshake.yaml
index ffec12b46759..9ab46da04c49 100644
--- a/Documentation/netlink/specs/handshake.yaml
+++ b/Documentation/netlink/specs/handshake.yaml
@@ -67,7 +67,7 @@ doc: Netlink protocol to request a transport layer security handshake.
enum: auth
-
name: peer-identity
- type: u32
+ type: s32
multi-attr: true
-
name: certificate
@@ -79,7 +79,7 @@ doc: Netlink protocol to request a transport layer security handshake.
type: string
-
name: keyring
- type: u32
+ type: s32
-
name: done
attributes:
@@ -93,7 +93,7 @@ doc: Netlink protocol to request a transport layer security handshake.
type: s32
-
name: remote-auth
- type: u32
+ type: s32
multi-attr: true
operations:
diff --git a/net/handshake/genl.c b/net/handshake/genl.c
index feac1ad063ee..58606c2a4600 100644
--- a/net/handshake/genl.c
+++ b/net/handshake/genl.c
@@ -21,7 +21,7 @@ static const struct nla_policy handshake_accept_nl_policy[HANDSHAKE_A_ACCEPT_HAN
static const struct nla_policy handshake_done_nl_policy[HANDSHAKE_A_DONE_REMOTE_AUTH + 1] = {
[HANDSHAKE_A_DONE_STATUS] = NLA_POLICY_MAX(NLA_U32, MAX_ERRNO),
[HANDSHAKE_A_DONE_SOCKFD] = { .type = NLA_S32, },
- [HANDSHAKE_A_DONE_REMOTE_AUTH] = { .type = NLA_U32, },
+ [HANDSHAKE_A_DONE_REMOTE_AUTH] = { .type = NLA_S32, },
};
/* Ops table for handshake */
--
2.55.0
next reply other threads:[~2026-09-04 19:04 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-04 19:04 Jakub Kicinski [this message]
2026-09-04 19:04 ` [PATCH net-next 2/2] netlink: specs: handshake: do not accept the handler-class sentinel Jakub Kicinski
2026-09-06 20:19 ` Asbjørn Sloth Tønnesen
2026-09-06 20:23 ` [PATCH net-next 1/2] netlink: specs: handshake: type the remaining key serials s32 Asbjørn Sloth Tønnesen
2026-09-06 23:35 ` Chuck Lever
2026-09-09 21:00 ` patchwork-bot+netdevbpf
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260904190410.3864660-1-kuba@kernel.org \
--to=kuba@kernel.org \
--cc=andrew+netdev@lunn.ch \
--cc=cel@kernel.org \
--cc=davem@davemloft.net \
--cc=donald.hunter@gmail.com \
--cc=edumazet@google.com \
--cc=horms@kernel.org \
--cc=kernel-tls-handshake@lists.linux.dev \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.