From: netdev-bot+sashiko@kernel.org
To: lucien.xin@gmail.com
Cc: netdev@vger.kernel.org, quic@lists.linux.dev,
davem@davemloft.net, kuba@kernel.org, edumazet@google.com,
pabeni@redhat.com, horms@kernel.org, metze@samba.org,
mbuhl@openbsd.org, tfanelli@redhat.com, hepengtao@xiaomi.com,
dreibh@simula.no, linux-cifs@vger.kernel.org, pc@manguebit.org,
linkinjeon@kernel.org, tom@talpey.com,
kernel-tls-handshake@lists.linux.dev, chuck.lever@oracle.com,
jlayton@kernel.org, steved@redhat.com, hare@suse.de,
aahringo@redhat.com, dhowells@redhat.com, matttbe@kernel.org,
mail@johnericson.me, xiyou.wangcong@gmail.com,
alibuda@linux.alibaba.com, jbaron@akamai.com,
illiliti@protonmail.com, sd@queasysnail.net,
marcelo.leitner@gmail.com, daniel@haxx.se,
andrew.gospodarek@broadcom.com, mef@scarletmail.rutgers.edu,
paul@jakma.org
Subject: Re: [PATCH net-next v15 12/15] quic: add crypto packet encryption and decryption
Date: Tue, 15 Sep 2026 19:50:53 +0000 [thread overview]
Message-ID: <178950185396.22033.4056258856263599395@kernel.org> (raw)
In-Reply-To: <06841ed60dda515dce3f3f16b4c3b31fdd7113fe.1789393775.git.lucien.xin@gmail.com>
Thank you for your contribution! Sashiko AI review found 4 potential
issue(s) to consider:
Critical: 0 · High: 0 · Medium: 2 · Low: 2
- [Medium] quic_crypto_encrypt() records crypto->key_update_send_time =
quic_ktime_get_us() *before* attempting to protect the packet…
- [Medium] The new packet protection paths
(quic_crypto_encrypt()/quic_crypto_decrypt() ->…
- [Low] The comments on the new token helpers describe an earlier
revision of the code and are now wrong in three ways.
- [Low] Reported concern: quic_crypto_generate_token() computes len =
sizeof(flag) + addrlen + sizeof(u64) + conn_id->len + QUIC_TAG_LEN and…
--
quic: add crypto packet encryption and decryption
This patch adds packet-level AEAD encryption and decryption for QUIC,
including header protection and its removal, plus helpers for the Retry
integrity tag and for generating and verifying address validation tokens.
A few questions on the new code below.
> diff --git a/net/quic/crypto.c b/net/quic/crypto.c
> index 910557b680524..d62c6c4bea7de 100644
> --- a/net/quic/crypto.c
> +++ b/net/quic/crypto.c
[ ... ]
> @@ -252,6 +253,457 @@ ciphers[QUIC_CIPHER_MAX + 1 - QUIC_CIPHER_MIN] = {
> "rfc7539(chacha20,poly1305)", "chacha20", "hmac(sha256)"),
> };
>
[ ... ]
> +/* AEAD Usage. */
> +static int quic_crypto_payload_protect(struct quic_crypto *crypto,
> + struct sk_buff *skb, bool enc, gfp_t gfp)
> +{
[ ... ]
> + aead_request_set_callback(req, CRYPTO_TFM_REQ_MAY_BACKLOG,
> + quic_crypto_done, skb);
> + *(struct quic_crypto **)ctx = crypto;
> + atomic_inc(&crypto->async_pending[phase]);
> + cb->crypto_ctx = ctx; /* Async free context for quic_crypto_done() */
> + err = enc ? crypto_aead_encrypt(req) : crypto_aead_decrypt(req);
[Severity: Medium]
This is the single place where every QUIC packet is protected or
unprotected, so it looks like the natural home for the AEAD usage limits
of rfc9001#section-6.6. Are those limits enforced anywhere?
struct quic_crypto in net/quic/crypto.h keeps secrets, IVs,
async_pending[], the key update timestamps and the bit flags, but has no
field for the number of packets protected with a key, nor for the number
of packets that failed authentication, and a grep over net/quic at the end
of the series finds no confidentiality or integrity limit check.
On the RX side quic_crypto_decrypt() just returns the AEAD error, so a
peer can keep submitting forgery attempts against the same key without the
connection ever being closed, which rfc9001#section-6.6 requires once the
integrity limit is reached:
err = quic_crypto_payload_protect(crypto, skb, false, gfp);
if (err) {
if (err == -EINPROGRESS)
return err;
...
return err;
}
TLS_CIPHER_AES_CCM_128 is supported here (quic_crypto_is_cipher_ccm() and
the "ccm(aes)" ciphers[] entry) and has the lowest integrity limit of the
QUIC AEADs. Is the intent to add the per-key counters and the limit checks
in a later patch?
> + if (err == -EINPROGRESS || err == -EBUSY) {
> + memzero_explicit(nonce, sizeof(nonce));
> + return -EINPROGRESS;
> + }
> + atomic_dec(&crypto->async_pending[phase]);
> + cb->crypto_ctx = NULL;
> +
> +out:
> + kfree_sensitive(ctx);
> + memzero_explicit(nonce, sizeof(nonce));
> + return err;
> +}
> +
> +/* Encrypts a QUIC packet before transmission. This function performs AEAD
> + * encryption of the packet payload and applies header protection. It handles
> + * key phase tracking and key update timing.
> + *
> + * Return: 0 on success, or a negative error code.
> + */
> +int quic_crypto_encrypt(struct quic_crypto *crypto, struct sk_buff *skb,
> + gfp_t gfp)
> +{
> + struct quic_skb_cb *cb = QUIC_SKB_CB(skb);
> + int err;
> +
> + /* Packet payload is already encrypted (e.g., resumed from async),
> + * proceed to header protection only.
> + */
> + if (cb->resume)
> + goto out;
> +
> + cb->key_phase = crypto->key_phase;
> + /* If a key update is pending and this is the first packet using the
> + * new key, save the current time. Later used to clear old keys after
> + * some time has passed (see quic_crypto_decrypt()).
> + */
> + if (crypto->key_pending && !crypto->key_update_send_time)
> + crypto->key_update_send_time = quic_ktime_get_us();
> +
> + err = quic_crypto_payload_protect(crypto, skb, true, gfp);
> + if (err)
> + return err;
[Severity: Medium]
Should key_update_send_time be committed only after the packet has actually
been protected?
Here the timestamp is stored before quic_crypto_payload_protect() runs, and
neither this error return nor the header protection failure below restores
it. If payload protection fails (skb_cow_data() returning -ENOMEM,
quic_crypto_aead_mem_alloc() returning -ENOMEM, an skb_to_sgvec() error, or
an AEAD error) the skb is dropped by the caller, but
crypto->key_update_send_time now records a time at which nothing was sent.
quic_crypto_decrypt() then uses that value as the start of the old key
retention window:
if (crypto->key_pending && cb->key_phase == crypto->key_phase) {
time = crypto->key_update_send_time;
if (time &&
quic_ktime_get_us() - time >= crypto->key_update_time) {
crypto->key_pending = 0;
Can the window therefore already be expired when the first packet in the
new phase is really received, so that key_pending is cleared immediately and
a later reordered old-phase packet is treated as a fresh key update
(phase != crypto->key_phase && !crypto->key_pending), overwriting the old
key slot before those packets can be decrypted?
> +out:
> + return quic_crypto_header_protect(crypto, skb, true, gfp);
> +}
> +
[ ... ]
> @@ -540,6 +992,238 @@ int quic_crypto_initial_keys_install(struct quic_crypto *crypto,
> return err;
> }
>
[ ... ]
> +/* Derives a key and IV using HKDF, configures the AEAD transform and performs
> + * AEAD encryption/decryption for the provided token.
> + */
> +static int quic_crypto_token_protect(struct quic_crypto *crypto, u8 *token,
> + u32 len, u32 adlen, bool enc)
> +{
> + /* Reuse TX AEAD (phase 1) in Initial crypto. */
> + struct crypto_aead *tfm = crypto->tx_tfm[1];
[Severity: Low]
Do these three comments still match the code after the v14 rework?
quic_crypto_token_protect() is documented as "Derives a key and IV using
HKDF, configures the AEAD transform", but the body has no HKDF call, no
crypto_aead_setkey() and no crypto_aead_setauthsize(); it only reuses the
key and IV that quic_crypto_set_token_secret() installed into
crypto->tx_tfm[1] and crypto->tx_iv[1]:
net/quic/crypto.c:quic_crypto_set_token_secret() {
...
err = crypto_aead_setauthsize(tfm, QUIC_TAG_LEN);
if (err)
goto out;
err = crypto_aead_setkey(tfm, key, TLS_CIPHER_AES_GCM_128_KEY_SIZE);
...
}
That also makes quic_crypto_set_token_secret() a hard prerequisite, since
crypto_aead_encrypt() returns -ENOKEY while CRYPTO_TFM_NEED_KEY is set.
Could the comment record that ordering requirement instead?
The quic_crypto_generate_token() comment says:
* Encrypts the token (excluding the first flag byte) using AES-GCM with a key
* and IV derived via HKDF.
but the call passes adlen = sizeof(flag) + addrlen + tslen, so the flag,
the client address and the timestamp are associated data, authenticated but
sent in the clear; only conn_id->len bytes of ODCID are encrypted.
The quic_crypto_verify_token() comment says:
* Decrypts the token using derived key and IV. Checks that the decrypted
* address matches the provided address, validates the embedded timestamp
* against current time with a version-specific timeout.
The address compared by crypto_memneq() is never encrypted, and the timeout
comes from the token flag (QUIC_TOKEN_FLAG_REGULAR versus the
QUIC_TOKEN_TIMEOUT_RETRY default), not from crypto->version.
> + u32 extra = enc ? QUIC_TAG_LEN : 0, tslen;
[ ... ]
> +/* Generate a token for Retry or address validation.
> + *
> + * Builds a token with the format: [flag][client address][timestamp][original
> + * DCID][auth tag]
> + *
[ ... ]
> +int quic_crypto_generate_token(struct quic_crypto *crypto, void *addr,
> + u32 addrlen, struct quic_conn_id *conn_id,
> + u8 *token, u32 *tlen)
> +{
> + u8 *token_buf, *p, flag = *token;
> + u64 ts = quic_ktime_get_us();
> + u32 len, tslen = sizeof(ts);
> + int err;
> +
> + len = sizeof(flag) + addrlen + tslen + conn_id->len + QUIC_TAG_LEN;
[ ... ]
> + memcpy(token, token_buf, len);
> + *tlen = len;
[Severity: Low]
This isn't a bug today, but the interface of quic_crypto_generate_token()
carries no capacity for the token buffer. len is computed from the
caller supplied addrlen and conn_id->len and then copied into token
without any bound, and *tlen is written only after the copy.
At the end of the series there is no caller at all
(quic_packet_retry_create_and_xmit() is still a stub returning
-EOPNOTSUPP), and the length is bounded in practice because conn_id->len
can only be set through quic_conn_id_update(), which rejects anything
larger than QUIC_CONN_ID_MAX_LEN:
net/quic/common.h:quic_conn_id_update() {
if (WARN_ON_ONCE(len > QUIC_CONN_ID_MAX_LEN))
return;
memcpy(conn_id->data, data, len);
conn_id->len = (u8)len;
}
Would it be worth passing the destination size in, so a future caller
cannot get this wrong? The flag byte being read back out of token[0] as
an in/out use of the output buffer is also not mentioned in the comment.
> +out:
> + kfree_sensitive(token_buf);
> + return err;
> +}
[ ... ]
--
Sashiko AI review · https://netdev-ai.bots.linux.dev/sashiko/#/patchset/cover.1789393775.git.lucien.xin%40gmail.com
next prev reply other threads:[~2026-09-15 19:50 UTC|newest]
Thread overview: 40+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-14 13:49 [PATCH net-next v15 00/15] net: introduce QUIC infrastructure and core subcomponents Xin Long
2026-09-14 13:49 ` [PATCH net-next v15 01/15] net: define IPPROTO_QUIC and SOL_QUIC constants Xin Long
2026-09-14 13:49 ` [PATCH net-next v15 02/15] net: build socket infrastructure for QUIC protocol Xin Long
2026-09-14 13:49 ` [PATCH net-next v15 03/15] quic: provide common utilities and data structures Xin Long
2026-09-15 19:50 ` netdev-bot+sashiko
2026-09-16 15:18 ` Xin Long
2026-09-14 13:49 ` [PATCH net-next v15 04/15] quic: provide family ops for address and protocol Xin Long
2026-09-14 13:49 ` [PATCH net-next v15 05/15] quic: provide quic.h header files for kernel and userspace Xin Long
2026-09-14 13:49 ` [PATCH net-next v15 06/15] quic: add stream management Xin Long
2026-09-15 19:50 ` netdev-bot+sashiko
2026-09-16 15:21 ` Xin Long
2026-09-14 13:49 ` [PATCH net-next v15 07/15] quic: add connection id management Xin Long
2026-09-14 13:49 ` [PATCH net-next v15 08/15] quic: add path management Xin Long
2026-09-15 19:50 ` netdev-bot+sashiko
2026-09-16 15:43 ` Xin Long
2026-09-14 13:49 ` [PATCH net-next v15 09/15] quic: add congestion control Xin Long
2026-09-15 19:50 ` netdev-bot+sashiko
2026-09-16 15:48 ` Xin Long
2026-09-14 13:49 ` [PATCH net-next v15 10/15] quic: add packet number space Xin Long
2026-09-14 13:49 ` [PATCH net-next v15 11/15] quic: add crypto key derivation and installation Xin Long
2026-09-15 19:50 ` netdev-bot+sashiko
2026-09-16 15:51 ` Xin Long
2026-09-14 13:49 ` [PATCH net-next v15 12/15] quic: add crypto packet encryption and decryption Xin Long
2026-09-15 19:50 ` netdev-bot+sashiko [this message]
2026-09-16 16:01 ` Xin Long
2026-09-14 13:49 ` [PATCH net-next v15 13/15] quic: add timer management Xin Long
2026-09-14 13:49 ` [PATCH net-next v15 14/15] quic: add packet builder base Xin Long
2026-09-15 19:50 ` netdev-bot+sashiko
2026-09-16 16:20 ` Xin Long
2026-09-14 13:49 ` [PATCH net-next v15 15/15] quic: add packet parser base Xin Long
2026-09-15 19:51 ` netdev-bot+sashiko
2026-09-15 21:34 ` Xin Long
2026-09-16 18:08 ` Xin Long
2026-09-16 23:46 ` Kuniyuki Iwashima
2026-09-17 13:38 ` Xin Long
2026-09-17 19:06 ` Kuniyuki Iwashima
2026-09-18 19:51 ` Xin Long
2026-09-16 18:33 ` [PATCH net-next v15 00/15] net: introduce QUIC infrastructure and core subcomponents Xin Long
2026-09-17 8:35 ` Paolo Abeni
2026-09-18 19:59 ` Xin Long
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=178950185396.22033.4056258856263599395@kernel.org \
--to=netdev-bot+sashiko@kernel.org \
--cc=aahringo@redhat.com \
--cc=alibuda@linux.alibaba.com \
--cc=andrew.gospodarek@broadcom.com \
--cc=chuck.lever@oracle.com \
--cc=daniel@haxx.se \
--cc=davem@davemloft.net \
--cc=dhowells@redhat.com \
--cc=dreibh@simula.no \
--cc=edumazet@google.com \
--cc=hare@suse.de \
--cc=hepengtao@xiaomi.com \
--cc=horms@kernel.org \
--cc=illiliti@protonmail.com \
--cc=jbaron@akamai.com \
--cc=jlayton@kernel.org \
--cc=kernel-tls-handshake@lists.linux.dev \
--cc=kuba@kernel.org \
--cc=linkinjeon@kernel.org \
--cc=linux-cifs@vger.kernel.org \
--cc=lucien.xin@gmail.com \
--cc=mail@johnericson.me \
--cc=marcelo.leitner@gmail.com \
--cc=matttbe@kernel.org \
--cc=mbuhl@openbsd.org \
--cc=mef@scarletmail.rutgers.edu \
--cc=metze@samba.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=paul@jakma.org \
--cc=pc@manguebit.org \
--cc=quic@lists.linux.dev \
--cc=sd@queasysnail.net \
--cc=steved@redhat.com \
--cc=tfanelli@redhat.com \
--cc=tom@talpey.com \
--cc=xiyou.wangcong@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox