Netdev List
 help / color / mirror / Atom feed
* [PATCH net-next] calipso: hash the cache key, not the option start, in calipso_cache_add()
@ 2026-10-07 15:25 Joas Antonio dos Santos
  2026-10-09 11:42 ` Daniel Machon
  0 siblings, 1 reply; 2+ messages in thread
From: Joas Antonio dos Santos @ 2026-10-07 15:25 UTC (permalink / raw)
  To: Paul Moore
  Cc: David S. Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni,
	Simon Horman, netdev, linux-security-module

calipso_cache_add() stores calipso_ptr + 2 as the cache key, but
computes entry->hash over calipso_ptr, i.e. starting two bytes earlier
at the option type and length.  calipso_opt_getattr() looks entries up
with calipso_cache_check(calipso + 2, calipso[1], ...), which hashes the
key itself.

The two hashes only match on a jhash collision, so the CALIPSO label
cache never hits and every labelled packet takes the full DOI lookup and
category conversion path.  The memcmp() on the key keeps lookups
correct, so this is a performance bug only.

Hash the stored key, as cipso_v4_cache_add() does for CIPSO.

Fixes: 4fee5242bf41 ("calipso: Add a label cache.")
Signed-off-by: Joas Antonio dos Santos <joasantonio108@gmail.com>
Assisted-by: Claude:claude-opus-5-5
---
Found by code review.  Compile-tested only (arm64, W=1); not runtime-tested.

 net/ipv6/calipso.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/net/ipv6/calipso.c b/net/ipv6/calipso.c
index c072eca50..8c447d860 100644
--- a/net/ipv6/calipso.c
+++ b/net/ipv6/calipso.c
@@ -283,7 +283,7 @@ static int calipso_cache_add(const unsigned char *calipso_ptr,
 		goto cache_add_failure;
 	}
 	entry->key_len = calipso_ptr_len;
-	entry->hash = calipso_map_cache_hash(calipso_ptr, calipso_ptr_len);
+	entry->hash = calipso_map_cache_hash(entry->key, calipso_ptr_len);
 	refcount_inc(&secattr->cache->refcount);
 	entry->lsm_data = secattr->cache;
 

^ permalink raw reply related	[flat|nested] 2+ messages in thread

* Re: [PATCH net-next] calipso: hash the cache key, not the option start, in calipso_cache_add()
  2026-10-07 15:25 [PATCH net-next] calipso: hash the cache key, not the option start, in calipso_cache_add() Joas Antonio dos Santos
@ 2026-10-09 11:42 ` Daniel Machon
  0 siblings, 0 replies; 2+ messages in thread
From: Daniel Machon @ 2026-10-09 11:42 UTC (permalink / raw)
  To: Joas Antonio dos Santos
  Cc: Paul Moore, David S. Miller, Eric Dumazet, Jakub Kicinski,
	Paolo Abeni, Simon Horman, netdev, linux-security-module

> calipso_cache_add() stores calipso_ptr + 2 as the cache key, but
> computes entry->hash over calipso_ptr, i.e. starting two bytes earlier
> at the option type and length.  calipso_opt_getattr() looks entries up
> with calipso_cache_check(calipso + 2, calipso[1], ...), which hashes the
> key itself.
> 
> The two hashes only match on a jhash collision, so the CALIPSO label
> cache never hits and every labelled packet takes the full DOI lookup and
> category conversion path.  The memcmp() on the key keeps lookups
> correct, so this is a performance bug only.
> 
> Hash the stored key, as cipso_v4_cache_add() does for CIPSO.

FWIW:

I tested this with a small throwaway KUnit test: put 16 labels into the cache,
then look each one up again the same way the kernel does when a packet arrives.
Without the patch none of them were found (0/16), with it all of them were
(16/16).

Reviewed-by: Daniel Machon <daniel.machon@microchip.com>

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-10-09 11:42 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-07 15:25 [PATCH net-next] calipso: hash the cache key, not the option start, in calipso_cache_add() Joas Antonio dos Santos
2026-10-09 11:42 ` Daniel Machon

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox