netdev.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* [PATCH] net: rtnetlink: be more strict when setting MAC address
@ 2015-08-17 21:06 Phil Sutter
  2015-08-17 21:09 ` David Miller
  0 siblings, 1 reply; 3+ messages in thread
From: Phil Sutter @ 2015-08-17 21:06 UTC (permalink / raw)
  To: netdev; +Cc: David Miller, Thomas Graf

Upon evaluation of IFLA_ADDRESS and IFLA_BROADCAST messages, make sure
the passed argument length matches dev->addr_len exactly.

This fixes dubious behaviour of 'ip link set eth0 addr <MAC>' where
'<MAC>' is too long, e.g. '00:11:22:33:44:55:66:77'. Called like this,
'ip' would return successfully and the kernel sets eth0's MAC address to
the leading six octets of the passed argument.

Signed-off-by: Phil Sutter <phil@nwl.cc>
---
 net/core/rtnetlink.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/net/core/rtnetlink.c b/net/core/rtnetlink.c
index 788ceed..1d61cd1 100644
--- a/net/core/rtnetlink.c
+++ b/net/core/rtnetlink.c
@@ -1456,11 +1456,11 @@ static int validate_linkmsg(struct net_device *dev, struct nlattr *tb[])
 {
 	if (dev) {
 		if (tb[IFLA_ADDRESS] &&
-		    nla_len(tb[IFLA_ADDRESS]) < dev->addr_len)
+		    nla_len(tb[IFLA_ADDRESS]) != dev->addr_len)
 			return -EINVAL;
 
 		if (tb[IFLA_BROADCAST] &&
-		    nla_len(tb[IFLA_BROADCAST]) < dev->addr_len)
+		    nla_len(tb[IFLA_BROADCAST]) != dev->addr_len)
 			return -EINVAL;
 	}
 
-- 
2.1.2

^ permalink raw reply related	[flat|nested] 3+ messages in thread

* Re: [PATCH] net: rtnetlink: be more strict when setting MAC address
  2015-08-17 21:06 [PATCH] net: rtnetlink: be more strict when setting MAC address Phil Sutter
@ 2015-08-17 21:09 ` David Miller
  2015-08-17 23:23   ` Phil Sutter
  0 siblings, 1 reply; 3+ messages in thread
From: David Miller @ 2015-08-17 21:09 UTC (permalink / raw)
  To: phil; +Cc: netdev, tgraf

From: Phil Sutter <phil@nwl.cc>
Date: Mon, 17 Aug 2015 23:06:47 +0200

> Upon evaluation of IFLA_ADDRESS and IFLA_BROADCAST messages, make sure
> the passed argument length matches dev->addr_len exactly.
> 
> This fixes dubious behaviour of 'ip link set eth0 addr <MAC>' where
> '<MAC>' is too long, e.g. '00:11:22:33:44:55:66:77'. Called like this,
> 'ip' would return successfully and the kernel sets eth0's MAC address to
> the leading six octets of the passed argument.
> 
> Signed-off-by: Phil Sutter <phil@nwl.cc>

I don't think this behavior is very "dubious" and making the check more
strict risks breaking things that have worked for a very long time.

I'm not applying this, sorry.

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] net: rtnetlink: be more strict when setting MAC address
  2015-08-17 21:09 ` David Miller
@ 2015-08-17 23:23   ` Phil Sutter
  0 siblings, 0 replies; 3+ messages in thread
From: Phil Sutter @ 2015-08-17 23:23 UTC (permalink / raw)
  To: David Miller; +Cc: netdev, tgraf, Stephen Hemminger

On Mon, Aug 17, 2015 at 02:09:33PM -0700, David Miller wrote:
> From: Phil Sutter <phil@nwl.cc>
> Date: Mon, 17 Aug 2015 23:06:47 +0200
> 
> > Upon evaluation of IFLA_ADDRESS and IFLA_BROADCAST messages, make sure
> > the passed argument length matches dev->addr_len exactly.
> > 
> > This fixes dubious behaviour of 'ip link set eth0 addr <MAC>' where
> > '<MAC>' is too long, e.g. '00:11:22:33:44:55:66:77'. Called like this,
> > 'ip' would return successfully and the kernel sets eth0's MAC address to
> > the leading six octets of the passed argument.
> > 
> > Signed-off-by: Phil Sutter <phil@nwl.cc>
> 
> I don't think this behavior is very "dubious" and making the check more
> strict risks breaking things that have worked for a very long time.
> 
> I'm not applying this, sorry.

No problem. I was already afraid of this breaking something as commit
1840bb1, which introduces validate_linkmsg(), already mentions something
in that direction. Therefore I appreciate your feedback clarifying this
for me, although it is not quite the outcome I had wished for.

Seeing that the kernel checks the minimum length already, shifting the
maximum length check to kernel space felt like a natural choice.

Nevertheless, I think iproute2 should not behave this way. Stephen, do
you think it is reasonable to add a similar logic to iplink_parse() as
done in do_set() (i.e., finding out which is the correct length of LL
address for a given interface and validating input based on this)? If
so, is it appropriate to recycle get_address() function or should the
information come from netlink?

Thanks, Phil

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2015-08-17 23:23 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2015-08-17 21:06 [PATCH] net: rtnetlink: be more strict when setting MAC address Phil Sutter
2015-08-17 21:09 ` David Miller
2015-08-17 23:23   ` Phil Sutter

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).