From: Jakub Kicinski <kuba@kernel.org>
To: Sabrina Dubroca <sd@queasysnail.net>
Cc: netdev@vger.kernel.org
Subject: Re: [PATCH net-next v2 06/13] macsec: use NLA_UINT for MACSEC_SA_ATTR_PN
Date: Wed, 27 Aug 2025 18:55:40 -0700 [thread overview]
Message-ID: <20250827185540.3e42dbcc@kernel.org> (raw)
In-Reply-To: <20250827185415.68d178c3@kernel.org>
On Wed, 27 Aug 2025 18:54:15 -0700 Jakub Kicinski wrote:
> On Tue, 26 Aug 2025 15:16:24 +0200 Sabrina Dubroca wrote:
> > MACSEC_SA_ATTR_PN is either a u32 or a u64, we can now use NLA_UINT
> > for this instead of a custom binary type. We can then use a min check
> > within the policy.
> >
> > We need to keep the length checks done in macsec_{add,upd}_{rx,tx}sa
> > based on whether the device is set up for XPN (with 64b PNs instead of
> > 32b).
> >
> > On the dump side, keep the existing custom code as userspace may
> > expect a u64 when using XPN, and nla_put_uint may only output a u32
> > attribute if the value fits.
>
> I think this is a slight functional change on big endian.
> I suppose we don't care..
we don't care == the change is not intentional, so in the unlikely case
BE users exist aligning with LE is better in the first place.
next prev parent reply other threads:[~2025-08-28 1:55 UTC|newest]
Thread overview: 34+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-08-26 13:16 [PATCH net-next v2 00/13] macsec: replace custom netlink attribute checks with policy-level checks Sabrina Dubroca
2025-08-26 13:16 ` [PATCH net-next v2 01/13] macsec: replace custom checks on MACSEC_SA_ATTR_AN with NLA_POLICY_MAX Sabrina Dubroca
2025-08-27 16:53 ` Simon Horman
2025-08-26 13:16 ` [PATCH net-next v2 02/13] macsec: replace custom checks on MACSEC_*_ATTR_ACTIVE " Sabrina Dubroca
2025-08-27 16:53 ` Simon Horman
2025-08-26 13:16 ` [PATCH net-next v2 03/13] macsec: replace custom checks on MACSEC_SA_ATTR_SALT with NLA_POLICY_EXACT_LEN Sabrina Dubroca
2025-08-27 16:54 ` Simon Horman
2025-08-26 13:16 ` [PATCH net-next v2 04/13] macsec: replace custom checks on MACSEC_SA_ATTR_KEYID " Sabrina Dubroca
2025-08-27 16:54 ` Simon Horman
2025-08-26 13:16 ` [PATCH net-next v2 05/13] macsec: use NLA_POLICY_MAX_LEN for MACSEC_SA_ATTR_KEY Sabrina Dubroca
2025-08-27 16:54 ` Simon Horman
2025-08-26 13:16 ` [PATCH net-next v2 06/13] macsec: use NLA_UINT for MACSEC_SA_ATTR_PN Sabrina Dubroca
2025-08-27 16:54 ` Simon Horman
2025-08-28 1:54 ` Jakub Kicinski
2025-08-28 1:55 ` Jakub Kicinski [this message]
2025-08-28 14:25 ` Sabrina Dubroca
2025-08-28 14:31 ` Jakub Kicinski
2025-08-26 13:16 ` [PATCH net-next v2 07/13] macsec: remove validate_add_rxsc Sabrina Dubroca
2025-08-27 16:55 ` Simon Horman
2025-08-26 13:16 ` [PATCH net-next v2 08/13] macsec: add NLA_POLICY_MAX for MACSEC_OFFLOAD_ATTR_TYPE and IFLA_MACSEC_OFFLOAD Sabrina Dubroca
2025-08-27 16:55 ` Simon Horman
2025-08-28 1:51 ` Jakub Kicinski
2025-08-28 12:15 ` Sabrina Dubroca
2025-08-26 13:16 ` [PATCH net-next v2 09/13] macsec: replace custom checks on IFLA_MACSEC_ICV_LEN with NLA_POLICY_RANGE Sabrina Dubroca
2025-08-27 16:55 ` Simon Horman
2025-08-26 13:16 ` [PATCH net-next v2 10/13] macsec: use NLA_POLICY_VALIDATE_FN to validate IFLA_MACSEC_CIPHER_SUITE Sabrina Dubroca
2025-08-27 16:56 ` Simon Horman
2025-08-26 13:16 ` [PATCH net-next v2 11/13] macsec: validate IFLA_MACSEC_VALIDATION with NLA_POLICY_MAX Sabrina Dubroca
2025-08-27 16:56 ` Simon Horman
2025-08-26 13:16 ` [PATCH net-next v2 12/13] macsec: replace custom checks for IFLA_MACSEC_* flags " Sabrina Dubroca
2025-08-27 16:57 ` Simon Horman
2025-08-26 13:16 ` [PATCH net-next v2 13/13] macsec: replace custom check on IFLA_MACSEC_ENCODING_SA " Sabrina Dubroca
2025-08-27 16:57 ` Simon Horman
2025-08-28 2:00 ` [PATCH net-next v2 00/13] macsec: replace custom netlink attribute checks with policy-level checks patchwork-bot+netdevbpf
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20250827185540.3e42dbcc@kernel.org \
--to=kuba@kernel.org \
--cc=netdev@vger.kernel.org \
--cc=sd@queasysnail.net \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).