From: Dmitry Safonov <dima@arista.com>
To: linux-kernel@vger.kernel.org, David Ahern <dsahern@kernel.org>,
Eric Dumazet <edumazet@google.com>,
Paolo Abeni <pabeni@redhat.com>, Jakub Kicinski <kuba@kernel.org>,
"David S. Miller" <davem@davemloft.net>
Cc: Dmitry Safonov <dima@arista.com>,
Andy Lutomirski <luto@amacapital.net>,
Ard Biesheuvel <ardb@kernel.org>,
Bob Gilligan <gilligan@arista.com>,
Dan Carpenter <dan.carpenter@oracle.com>,
David Laight <David.Laight@aculab.com>,
Dmitry Safonov <0x7f454c46@gmail.com>,
Eric Biggers <ebiggers@kernel.org>,
"Eric W. Biederman" <ebiederm@xmission.com>,
Francesco Ruggeri <fruggeri05@gmail.com>,
Herbert Xu <herbert@gondor.apana.org.au>,
Hideaki YOSHIFUJI <yoshfuji@linux-ipv6.org>,
Ivan Delalande <colona@arista.com>,
Leonard Crestez <cdleonard@gmail.com>,
Salam Noureddine <noureddine@arista.com>,
netdev@vger.kernel.org, Francesco Ruggeri <fruggeri@arista.com>
Subject: [PATCH v4 17/21] net/tcp: Add option for TCP-AO to (not) hash header
Date: Wed, 15 Feb 2023 18:33:31 +0000 [thread overview]
Message-ID: <20230215183335.800122-18-dima@arista.com> (raw)
In-Reply-To: <20230215183335.800122-1-dima@arista.com>
Provide setsockopt() key flag that makes TCP-AO exclude hashing TCP
header for peers that match the key. This is needed for interraction
with middleboxes that may change TCP options, see RFC5925 (9.2).
Co-developed-by: Francesco Ruggeri <fruggeri@arista.com>
Signed-off-by: Francesco Ruggeri <fruggeri@arista.com>
Co-developed-by: Salam Noureddine <noureddine@arista.com>
Signed-off-by: Salam Noureddine <noureddine@arista.com>
Signed-off-by: Dmitry Safonov <dima@arista.com>
---
include/uapi/linux/tcp.h | 5 +++++
net/ipv4/tcp_ao.c | 8 +++++---
2 files changed, 10 insertions(+), 3 deletions(-)
diff --git a/include/uapi/linux/tcp.h b/include/uapi/linux/tcp.h
index 6c8b4dcc51ee..323ee886634f 100644
--- a/include/uapi/linux/tcp.h
+++ b/include/uapi/linux/tcp.h
@@ -354,6 +354,11 @@ struct tcp_diag_md5sig {
#define TCP_AO_MAXKEYLEN 80
#define TCP_AO_KEYF_IFINDEX (1 << 0) /* L3 ifindex for VRF */
+#define TCP_AO_KEYF_EXCLUDE_OPT (1 << 1) /* "Indicates whether TCP
+ * options other than TCP-AO
+ * are included in the MAC
+ * calculation"
+ */
#define TCP_AO_CMDF_CURR (1 << 0) /* Only checks field sndid */
#define TCP_AO_CMDF_NEXT (1 << 1) /* Only checks field rcvid */
diff --git a/net/ipv4/tcp_ao.c b/net/ipv4/tcp_ao.c
index 07935e8a1066..d335023a1619 100644
--- a/net/ipv4/tcp_ao.c
+++ b/net/ipv4/tcp_ao.c
@@ -589,7 +589,8 @@ int tcp_ao_hash_hdr(unsigned short int family, char *ao_hash,
WARN_ON_ONCE(1);
goto clear_hash;
}
- if (tcp_ao_hash_header(&hp, th, false,
+ if (tcp_ao_hash_header(&hp, th,
+ !!(key->keyflags & TCP_AO_KEYF_EXCLUDE_OPT),
ao_hash, hash_offset, tcp_ao_maclen(key)))
goto clear_hash;
ahash_request_set_crypt(hp.req, NULL, ao_hash, 0);
@@ -631,7 +632,8 @@ int tcp_ao_hash_skb(unsigned short int family,
goto clear_hash;
if (tcp_ao_hash_pseudoheader(family, sk, skb, &hp, skb->len))
goto clear_hash;
- if (tcp_ao_hash_header(&hp, th, false,
+ if (tcp_ao_hash_header(&hp, th,
+ !!(key->keyflags & TCP_AO_KEYF_EXCLUDE_OPT),
ao_hash, hash_offset, tcp_ao_maclen(key)))
goto clear_hash;
if (tcp_ao_hash_skb_data(&hp, skb, th->doff << 2))
@@ -1498,7 +1500,7 @@ static inline bool tcp_ao_mkt_overlap_v6(struct tcp_ao *cmd,
}
#endif
-#define TCP_AO_KEYF_ALL (0)
+#define TCP_AO_KEYF_ALL (TCP_AO_KEYF_EXCLUDE_OPT)
#define TCP_AO_CMDF_ADDMOD_VALID \
(TCP_AO_CMDF_CURR | TCP_AO_CMDF_NEXT | TCP_AO_CMDF_ACCEPT_ICMP)
#define TCP_AO_CMDF_DEL_VALID \
--
2.39.1
next prev parent reply other threads:[~2023-02-15 18:36 UTC|newest]
Thread overview: 28+ messages / expand[flat|nested] mbox.gz Atom feed top
2023-02-15 18:33 [PATCH v4 00/21] net/tcp: Add TCP-AO support Dmitry Safonov
2023-02-15 18:33 ` [PATCH v4 01/21] net/tcp: Prepare tcp_md5sig_pool for TCP-AO Dmitry Safonov
2023-02-20 9:41 ` Herbert Xu
2023-02-20 16:57 ` Dmitry Safonov
2023-02-21 2:43 ` Herbert Xu
2023-02-21 14:52 ` Dmitry Safonov
2023-02-15 18:33 ` [PATCH v4 02/21] tcp: Add TCP-AO config and structures Dmitry Safonov
2023-02-15 18:33 ` [PATCH v4 03/21] net/tcp: Introduce TCP_AO setsockopt()s Dmitry Safonov
2023-02-15 18:33 ` [PATCH v4 04/21] net/tcp: Prevent TCP-MD5 with TCP-AO being set Dmitry Safonov
2023-02-15 18:33 ` [PATCH v4 05/21] net/tcp: Calculate TCP-AO traffic keys Dmitry Safonov
2023-02-15 22:50 ` kernel test robot
2023-02-15 18:33 ` [PATCH v4 06/21] net/tcp: Add TCP-AO sign to outgoing packets Dmitry Safonov
2023-02-15 18:33 ` [PATCH v4 07/21] net/tcp: Add tcp_parse_auth_options() Dmitry Safonov
2023-02-15 18:33 ` [PATCH v4 08/21] net/tcp: Add AO sign to RST packets Dmitry Safonov
2023-02-15 18:33 ` [PATCH v4 09/21] net/tcp: Add TCP-AO sign to twsk Dmitry Safonov
2023-02-15 18:33 ` [PATCH v4 10/21] net/tcp: Wire TCP-AO to request sockets Dmitry Safonov
2023-02-15 18:33 ` [PATCH v4 11/21] net/tcp: Sign SYN-ACK segments with TCP-AO Dmitry Safonov
2023-02-15 18:33 ` [PATCH v4 12/21] net/tcp: Verify inbound TCP-AO signed segments Dmitry Safonov
2023-02-16 0:22 ` kernel test robot
2023-02-15 18:33 ` [PATCH v4 13/21] net/tcp: Add TCP-AO segments counters Dmitry Safonov
2023-02-15 18:33 ` [PATCH v4 14/21] net/tcp: Add TCP-AO SNE support Dmitry Safonov
2023-02-15 18:33 ` [PATCH v4 15/21] net/tcp: Add tcp_hash_fail() ratelimited logs Dmitry Safonov
2023-02-15 18:33 ` [PATCH v4 16/21] net/tcp: Ignore specific ICMPs for TCP-AO connections Dmitry Safonov
2023-02-15 18:33 ` Dmitry Safonov [this message]
2023-02-15 18:33 ` [PATCH v4 18/21] net/tcp: Add getsockopt(TCP_AO_GET) Dmitry Safonov
2023-02-15 18:33 ` [PATCH v4 19/21] net/tcp: Allow asynchronous delete for TCP-AO keys (MKTs) Dmitry Safonov
2023-02-15 18:33 ` [PATCH v4 20/21] net/tcp-ao: Add static_key for TCP-AO Dmitry Safonov
2023-02-15 18:33 ` [PATCH v4 21/21] net/tcp-ao: Wire up l3index to TCP-AO Dmitry Safonov
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20230215183335.800122-18-dima@arista.com \
--to=dima@arista.com \
--cc=0x7f454c46@gmail.com \
--cc=David.Laight@aculab.com \
--cc=ardb@kernel.org \
--cc=cdleonard@gmail.com \
--cc=colona@arista.com \
--cc=dan.carpenter@oracle.com \
--cc=davem@davemloft.net \
--cc=dsahern@kernel.org \
--cc=ebiederm@xmission.com \
--cc=ebiggers@kernel.org \
--cc=edumazet@google.com \
--cc=fruggeri05@gmail.com \
--cc=fruggeri@arista.com \
--cc=gilligan@arista.com \
--cc=herbert@gondor.apana.org.au \
--cc=kuba@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=luto@amacapital.net \
--cc=netdev@vger.kernel.org \
--cc=noureddine@arista.com \
--cc=pabeni@redhat.com \
--cc=yoshfuji@linux-ipv6.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).