From: Matthieu Baerts <matthieu.baerts@tessares.net>
To: Mat Martineau <mathew.j.martineau@linux.intel.com>
Cc: mptcp@lists.linux.dev, Paolo Abeni <pabeni@redhat.com>
Subject: Re: [PATCH mptcp-next] mptcp: full fully established support after ADD_ADDR
Date: Fri, 13 Aug 2021 13:06:37 +0200 [thread overview]
Message-ID: <e8ce0aa4-c8a5-8907-396e-be420aec6fe4@tessares.net> (raw)
In-Reply-To: <cb97b91e-99d-d7b-4338-a83ddba4e83b@linux.intel.com>
Hi Mat,
Thank you for your review!
On 13/08/2021 00:30, Mat Martineau wrote:
> On Thu, 12 Aug 2021, Matthieu Baerts wrote:
>
>> If directly after an MP_CAPABLE 3WHS, the client receives a valid
>> ADD_ADDR from the server, it is enough to prove exchanged MPTCP options
>> are valid. Indeed, the ADD_ADDR contains an HMAC generated using both
>> the client and server keys.
>
> The ADD_ADDR HMAC is validated after the call to
> check_fully_established(), so I'm not sure this condition is fully met
> with the patch as-is. Looks like an ADD_ADDR with a bad HMAC could
> change the fully_established flag when it shouldn't.
That's a very good point.
If I'm not mistaken, we have the same issue when receiving a DATA_ACK:
here we just check if one is present, not if it is valid, no?
Should we delay when we mark subflows and msks as "fully established" or
is it not an issue to be in "fully established" too soon?
Cheers,
Matt
--
Tessares | Belgium | Hybrid Access Solutions
www.tessares.net
next prev parent reply other threads:[~2021-08-13 11:06 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2021-08-12 16:27 [PATCH mptcp-next] mptcp: full fully established support after ADD_ADDR Matthieu Baerts
2021-08-12 16:33 ` Paolo Abeni
2021-08-12 22:30 ` Mat Martineau
2021-08-13 11:06 ` Matthieu Baerts [this message]
2021-08-13 14:14 ` Paolo Abeni
2021-08-14 0:37 ` Mat Martineau
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=e8ce0aa4-c8a5-8907-396e-be420aec6fe4@tessares.net \
--to=matthieu.baerts@tessares.net \
--cc=mathew.j.martineau@linux.intel.com \
--cc=mptcp@lists.linux.dev \
--cc=pabeni@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox