From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mx1.secunet.com (mx1.secunet.com [62.96.220.36]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4A32A38DC74; Tue, 8 Sep 2026 06:50:09 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=62.96.220.36 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788850211; cv=none; b=nKndUAzzLw2hnaGwF+A4iZKfoMq5PAP6fKVM8AAgLNZFPBuRbpKzIDE+1bDmcpDpEj72JI2AVxR1HbIPE5Ik9JAd3d6HFP4Kw5ZvubeiUO1sEw+/EO5h+EUN6CY+0dBX7OG5Px/HWDIssCsxQcIn3U734e5Uxe/t4swZDhyWDI0= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788850211; c=relaxed/simple; bh=SZ68U2pHvzoh4mgAqvi/cFtzsqDHGsxht2QZlrU72uQ=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=KCva0ND+tWIFx26Wd0/VoAhZD4LSZUx5F+HlZP7rcXNpOCZrPVL4jhiojf/rOOGq8cRGOLmAjfi852I1tFPBHw9+GwNxSww0xs4EGDggipvGLiryYdiTi/4he4rRaSE1QjYKYybBdYwh4P98G2JM/1X+bQAUCPbuvBlK81JMr+U= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=secunet.com; spf=pass smtp.mailfrom=secunet.com; dkim=pass (2048-bit key) header.d=secunet.com header.i=@secunet.com header.b=DwKZfLNO; arc=none smtp.client-ip=62.96.220.36 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=secunet.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=secunet.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=secunet.com header.i=@secunet.com header.b="DwKZfLNO" Received: from localhost (localhost [127.0.0.1]) by mx1.secunet.com (Postfix) with ESMTP id 147B4205E3; Tue, 8 Sep 2026 08:50:07 +0200 (CEST) X-Virus-Scanned: by secunet Received: from mx1.secunet.com ([127.0.0.1]) by localhost (mx1.secunet.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Jhu4iWEQs24C; Tue, 8 Sep 2026 08:50:06 +0200 (CEST) Received: from EXCH-02.secunet.de (rl2.secunet.de [10.32.0.232]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mx1.secunet.com (Postfix) with ESMTPS id 7280A201E2; Tue, 8 Sep 2026 08:50:06 +0200 (CEST) DKIM-Filter: OpenDKIM Filter v2.11.0 mx1.secunet.com 7280A201E2 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=secunet.com; s=202301; t=1788850206; bh=yiSVaxv6xbbcHUAJ59C228Y1I2uaZGNKrSxi/aFqWFI=; h=From:To:CC:Subject:Date:In-Reply-To:References:From; b=DwKZfLNOIIjPCkLfx1X1b2k1hJKR8uiIJnXM/8OzCU1xc7drX8WK5uQeuZ8e0G3F4 hy+Gssf8w8knzRql+/A65ru33WivdxlS+eFyoMnuVgK/1mzXLGDvXryuKU7Uuo7rVz TRgCkv/SvrAfhgKq52qKkRmsrxYsSADxcEQq5MDbYPNDLtMfhI9mH05qXKe/VUJnJd BGZfnn6HdGmwvVLvr/51/QtX4MihPZRZdJmGgQxmj74CS4SSwlLyfGQVcdXj5F7Tq3 sZCQ2XZjokHWhR5ocrq7TH9RW68bmTsMwXpSahsKTYGMaH9vId5vJBTYB4ag+3tfQk +1F0j+RSiodcA== Received: from moon.secunet.de (172.18.149.1) by EXCH-02.secunet.de (10.32.0.172) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.37; Tue, 8 Sep 2026 08:50:05 +0200 From: Antony Antony To: Antony Antony , Steffen Klassert , Herbert Xu , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , David Ahern , Jamal Hadi Salim , Shuah Khan CC: Sabrina Dubroca , , Yan Yan , Tobias Brunner , Florian Westphal , , Subject: [PATCH ipsec v2 6/6] docs: xfrm: include mark in XFRM_MSG_MIGRATE_STATE EEXIST tuple Date: Tue, 8 Sep 2026 08:49:55 +0200 Message-ID: X-Mailer: git-send-email 2.39.5 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-doc@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" X-Mailer: b4 0.16-dev Content-Transfer-Encoding: 8bit X-ClientProxiedBy: EXCH-04.secunet.de (10.32.0.184) To EXCH-02.secunet.de (10.32.0.172) Document mark as part of the EEXIST tuple and update the SA lookup description to match. Fixes: c13c0cc6f52e ("xfrm: add documentation for XFRM_MSG_MIGRATE_STATE") Signed-off-by: Antony Antony --- .../networking/xfrm/xfrm_migrate_state.rst | 23 ++++++++++++++-------- 1 file changed, 15 insertions(+), 8 deletions(-) diff --git a/Documentation/networking/xfrm/xfrm_migrate_state.rst b/Documentation/networking/xfrm/xfrm_migrate_state.rst index 9d53cb22b007..0412a3c0ecf7 100644 --- a/Documentation/networking/xfrm/xfrm_migrate_state.rst +++ b/Documentation/networking/xfrm/xfrm_migrate_state.rst @@ -27,15 +27,18 @@ SA Identification ================= The struct is defined in ``include/uapi/linux/xfrm.h``. The SA is looked -up using ``xfrm_state_lookup()`` with ``id.spi``, -``id.daddr``, ``id.proto``, ``id.family``, and -``old_mark.v & old_mark.m`` as the mark key:: +up using ``xfrm_state_lookup_exact()`` with ``id.spi``, ``id.daddr``, +``id.proto``, ``id.family``, and an exact match against ``old_mark.v`` +and ``old_mark.m``. Unlike the data path, which uses a masked +comparison, this requires the SA's mark and mask to equal ``old_mark`` +exactly, so a broad-mask SA is never matched when a more specific one +was intended. If no such SA exists, ``-ESRCH`` is returned.:: struct xfrm_user_migrate_state { struct xfrm_usersa_id id; /* spi, daddr, proto, family */ xfrm_address_t new_daddr; xfrm_address_t new_saddr; - struct xfrm_mark old_mark; /* SA lookup: key = v & m */ + struct xfrm_mark old_mark; /* SA lookup key (exact v/m match) */ struct xfrm_selector new_sel; /* new selector (see Flags) */ __u32 new_reqid; __u32 flags; /* XFRM_MIGRATE_STATE_* */ @@ -72,8 +75,8 @@ inherits the value from the existing SA (omit-to-inherit). - Description * - ``XFRMA_MARK`` - Mark on the migrated SA (``struct xfrm_mark``). Absent inherits - ``old_mark``. To use no mark on the new SA, send ``XFRMA_MARK`` - with ``{0, 0}``. + the mark of the existing SA. To use no mark on the new SA, send + ``XFRMA_MARK`` with ``{0, 0}``. * - ``XFRMA_ENCAP`` - UDP encapsulation template; only ``UDP_ENCAP_ESPINUDP`` is supported. Set ``encap_type=0`` to remove encap. @@ -259,8 +262,12 @@ Attributes in the notification Error Handling ============== -If the target SA tuple (new daddr, SPI, proto, new family) is already -occupied, the operation returns ``-EEXIST`` before the migration begins. +If the target SA tuple (new daddr, SPI, proto, new family, mark) is +already occupied, the operation returns ``-EEXIST`` before the migration +begins. "Occupied" includes wildcard shadowing: an existing SA with a +broader mask (e.g. mark 0/0) claims every mark value, so it blocks +migrating to any more specific mark at the same tuple, not just an +exact mark/mask duplicate. The old SA remains intact and the operation is safe to retry after resolving the conflict. -- 2.47.3