All of lore.kernel.org
 help / color / mirror / Atom feed
From: Jakub Kicinski <kuba@kernel.org>
To: davem@davemloft.net
Cc: netdev@vger.kernel.org, edumazet@google.com, pabeni@redhat.com,
	andrew+netdev@lunn.ch, horms@kernel.org,
	Jakub Kicinski <kuba@kernel.org>,
	cel@kernel.org, donald.hunter@gmail.com, ast@fiberby.net,
	matttbe@kernel.org, kernel-tls-handshake@lists.linux.dev
Subject: [PATCH net-next 2/2] netlink: specs: handshake: do not accept the handler-class sentinel
Date: Fri,  4 Sep 2026 12:04:10 -0700	[thread overview]
Message-ID: <20260904190410.3864660-2-kuba@kernel.org> (raw)
In-Reply-To: <20260904190410.3864660-1-kuba@kernel.org>

"max" is the exclusive upper bound of enum handshake_handler_class, not
a class a handler can ask for, but the spec lists it as a plain entry.
_init_checks() derives the policy limit from the highest entry, so the
generated policy came out as NLA_POLICY_MAX(NLA_U32, 2) and
handshake_nl_accept_doit() takes class 2 all the way into
handshake_req_next(), which walks hn_requests under hn_lock before
returning -EAGAIN instead of the -EINVAL a bad class deserves.

render-max is how YNL spells this, and unlike a hand written limit it
stays correct when a second handler class is added.

It does change what HANDSHAKE_HANDLER_CLASS_MAX means - the highest
valid class rather than one past it, as in every other Netlink/YNL
family - with the count left as __HANDSHAKE_HANDLER_CLASS_MAX.
The constant is uAPI, but I could not find any user space user,
this constant seems to have been added for kernel's benefit.

I think the risk of changing this is worth taking, having MAX
with different semantics than the rest of Netlink is very confusing.

Signed-off-by: Jakub Kicinski <kuba@kernel.org>
---
CC: cel@kernel.org
CC: donald.hunter@gmail.com
CC: ast@fiberby.net
CC: matttbe@kernel.org
CC: kernel-tls-handshake@lists.linux.dev
---
 Documentation/netlink/specs/handshake.yaml | 3 ++-
 include/uapi/linux/handshake.h             | 5 ++++-
 net/handshake/genl.c                       | 2 +-
 net/handshake/handshake-test.c             | 2 +-
 net/handshake/request.c                    | 2 +-
 5 files changed, 9 insertions(+), 5 deletions(-)

diff --git a/Documentation/netlink/specs/handshake.yaml b/Documentation/netlink/specs/handshake.yaml
index 9ab46da04c49..0498ada2dd97 100644
--- a/Documentation/netlink/specs/handshake.yaml
+++ b/Documentation/netlink/specs/handshake.yaml
@@ -22,7 +22,8 @@ doc: Netlink protocol to request a transport layer security handshake.
     type: enum
     name: handler-class
     value-start: 0
-    entries: [none, tlshd, max]
+    entries: [none, tlshd]
+    render-max: true
   -
     type: enum
     name: msg-type
diff --git a/include/uapi/linux/handshake.h b/include/uapi/linux/handshake.h
index d7e40f594888..f907aa082520 100644
--- a/include/uapi/linux/handshake.h
+++ b/include/uapi/linux/handshake.h
@@ -13,7 +13,10 @@
 enum handshake_handler_class {
 	HANDSHAKE_HANDLER_CLASS_NONE,
 	HANDSHAKE_HANDLER_CLASS_TLSHD,
-	HANDSHAKE_HANDLER_CLASS_MAX,
+
+	/* private: */
+	__HANDSHAKE_HANDLER_CLASS_MAX,
+	HANDSHAKE_HANDLER_CLASS_MAX = (__HANDSHAKE_HANDLER_CLASS_MAX - 1)
 };
 
 enum handshake_msg_type {
diff --git a/net/handshake/genl.c b/net/handshake/genl.c
index 58606c2a4600..26e3efec64ca 100644
--- a/net/handshake/genl.c
+++ b/net/handshake/genl.c
@@ -14,7 +14,7 @@
 
 /* HANDSHAKE_CMD_ACCEPT - do */
 static const struct nla_policy handshake_accept_nl_policy[HANDSHAKE_A_ACCEPT_HANDLER_CLASS + 1] = {
-	[HANDSHAKE_A_ACCEPT_HANDLER_CLASS] = NLA_POLICY_MAX(NLA_U32, 2),
+	[HANDSHAKE_A_ACCEPT_HANDLER_CLASS] = NLA_POLICY_MAX(NLA_U32, 1),
 };
 
 /* HANDSHAKE_CMD_DONE - do */
diff --git a/net/handshake/handshake-test.c b/net/handshake/handshake-test.c
index 3dd507470d5f..4b99acd9f9c7 100644
--- a/net/handshake/handshake-test.c
+++ b/net/handshake/handshake-test.c
@@ -42,7 +42,7 @@ static struct handshake_proto handshake_req_alloc_proto_2 = {
 };
 
 static struct handshake_proto handshake_req_alloc_proto_3 = {
-	.hp_handler_class	= HANDSHAKE_HANDLER_CLASS_MAX,
+	.hp_handler_class	= __HANDSHAKE_HANDLER_CLASS_MAX,
 };
 
 static struct handshake_proto handshake_req_alloc_proto_4 = {
diff --git a/net/handshake/request.c b/net/handshake/request.c
index cd30d54d0501..ff739ee81cb8 100644
--- a/net/handshake/request.c
+++ b/net/handshake/request.c
@@ -115,7 +115,7 @@ struct handshake_req *handshake_req_alloc(const struct handshake_proto *proto,
 		return NULL;
 	if (proto->hp_handler_class <= HANDSHAKE_HANDLER_CLASS_NONE)
 		return NULL;
-	if (proto->hp_handler_class >= HANDSHAKE_HANDLER_CLASS_MAX)
+	if (proto->hp_handler_class > HANDSHAKE_HANDLER_CLASS_MAX)
 		return NULL;
 	if (!proto->hp_accept || !proto->hp_done)
 		return NULL;
-- 
2.55.0


  reply	other threads:[~2026-09-04 19:04 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-04 19:04 [PATCH net-next 1/2] netlink: specs: handshake: type the remaining key serials s32 Jakub Kicinski
2026-09-04 19:04 ` Jakub Kicinski [this message]
2026-09-06 20:19   ` [PATCH net-next 2/2] netlink: specs: handshake: do not accept the handler-class sentinel Asbjørn Sloth Tønnesen
2026-09-06 20:23 ` [PATCH net-next 1/2] netlink: specs: handshake: type the remaining key serials s32 Asbjørn Sloth Tønnesen
2026-09-06 23:35   ` Chuck Lever
2026-09-09 21:00 ` patchwork-bot+netdevbpf

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260904190410.3864660-2-kuba@kernel.org \
    --to=kuba@kernel.org \
    --cc=andrew+netdev@lunn.ch \
    --cc=ast@fiberby.net \
    --cc=cel@kernel.org \
    --cc=davem@davemloft.net \
    --cc=donald.hunter@gmail.com \
    --cc=edumazet@google.com \
    --cc=horms@kernel.org \
    --cc=kernel-tls-handshake@lists.linux.dev \
    --cc=matttbe@kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.