From: Joas Antonio dos Santos <joasantonio108@gmail.com>
To: Paul Moore <paul@paul-moore.com>
Cc: David S. Miller <davem@davemloft.net>,
Eric Dumazet <edumazet@kernel.org>,
Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
Simon Horman <horms@kernel.org>,
netdev@vger.kernel.org, linux-security-module@vger.kernel.org
Subject: [PATCH net-next] calipso: hash the cache key, not the option start, in calipso_cache_add()
Date: Wed, 07 Oct 2026 12:25:00 -0300 [thread overview]
Message-ID: <179138670045.80227.16155454353416856947@gmail.com> (raw)
calipso_cache_add() stores calipso_ptr + 2 as the cache key, but
computes entry->hash over calipso_ptr, i.e. starting two bytes earlier
at the option type and length. calipso_opt_getattr() looks entries up
with calipso_cache_check(calipso + 2, calipso[1], ...), which hashes the
key itself.
The two hashes only match on a jhash collision, so the CALIPSO label
cache never hits and every labelled packet takes the full DOI lookup and
category conversion path. The memcmp() on the key keeps lookups
correct, so this is a performance bug only.
Hash the stored key, as cipso_v4_cache_add() does for CIPSO.
Fixes: 4fee5242bf41 ("calipso: Add a label cache.")
Signed-off-by: Joas Antonio dos Santos <joasantonio108@gmail.com>
Assisted-by: Claude:claude-opus-5-5
---
Found by code review. Compile-tested only (arm64, W=1); not runtime-tested.
net/ipv6/calipso.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/net/ipv6/calipso.c b/net/ipv6/calipso.c
index c072eca50..8c447d860 100644
--- a/net/ipv6/calipso.c
+++ b/net/ipv6/calipso.c
@@ -283,7 +283,7 @@ static int calipso_cache_add(const unsigned char *calipso_ptr,
goto cache_add_failure;
}
entry->key_len = calipso_ptr_len;
- entry->hash = calipso_map_cache_hash(calipso_ptr, calipso_ptr_len);
+ entry->hash = calipso_map_cache_hash(entry->key, calipso_ptr_len);
refcount_inc(&secattr->cache->refcount);
entry->lsm_data = secattr->cache;
next reply other threads:[~2026-10-07 15:25 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-07 15:25 Joas Antonio dos Santos [this message]
2026-10-09 11:42 ` [PATCH net-next] calipso: hash the cache key, not the option start, in calipso_cache_add() Daniel Machon
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=179138670045.80227.16155454353416856947@gmail.com \
--to=joasantonio108@gmail.com \
--cc=davem@davemloft.net \
--cc=edumazet@kernel.org \
--cc=horms@kernel.org \
--cc=kuba@kernel.org \
--cc=linux-security-module@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=paul@paul-moore.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox