Netdev List
 help / color / mirror / Atom feed
From: Jakub Kicinski <kuba@kernel.org>
To: davem@davemloft.net
Cc: netdev@vger.kernel.org, edumazet@google.com, pabeni@redhat.com,
	andrew+netdev@lunn.ch, horms@kernel.org, jiri@resnulli.us,
	tariqt@nvidia.com, moshe@nvidia.com, donald.hunter@gmail.com,
	Jakub Kicinski <kuba@kernel.org>
Subject: [PATCH net-next v2 9/9] devlink: validate the port index in the rate set request
Date: Tue, 15 Sep 2026 09:13:41 -0700	[thread overview]
Message-ID: <20260915161341.1053476-10-kuba@kernel.org> (raw)
In-Reply-To: <20260915161341.1053476-1-kuba@kernel.org>

port-index is the only way rate-set can address a leaf (port) rate object,
but it was never listed in the request, so the generated policy has no
entry for it. The op declares .maxattr = DEVLINK_ATTR_PARENT_DEV, so the
attribute still reaches info->attrs[], validated against a zeroed slot -
NLA_UNSPEC, length 0 - which GENL_DONT_VALIDATE_STRICT accepts at any
length.

devlink_port_get_from_attrs() then runs nla_get_u32() on it. Handed a
zero-length port-index the kernel reads the four bytes past the payload,
which are the next attribute's header, and acts on the port index those
spell out. Since we're reading a linear skb the OOB read is still
within the same memory allocation, it's just garbage. We also do not
echo the garbage back to the user so it's not an info leak either.
Hence not treating this is a real bug fix.

rate-new is left alone on purpose. It creates rate nodes, resolved by
name through devlink_rate_node_get_from_attrs(), and never looks at
port-index.

Signed-off-by: Jakub Kicinski <kuba@kernel.org>
---
v2: new patch
---
 Documentation/netlink/specs/devlink.yaml | 1 +
 net/devlink/netlink_gen.c                | 1 +
 2 files changed, 2 insertions(+)

diff --git a/Documentation/netlink/specs/devlink.yaml b/Documentation/netlink/specs/devlink.yaml
index 4fb64e71063d..1de0daa0f921 100644
--- a/Documentation/netlink/specs/devlink.yaml
+++ b/Documentation/netlink/specs/devlink.yaml
@@ -2447,6 +2447,7 @@ doc: Partial family for Devlink.
             - bus-name
             - dev-name
             - index
+            - port-index
             - rate-node-name
             - rate-tx-share
             - rate-tx-max
diff --git a/net/devlink/netlink_gen.c b/net/devlink/netlink_gen.c
index 43ef6864d462..9e1b4c081a7b 100644
--- a/net/devlink/netlink_gen.c
+++ b/net/devlink/netlink_gen.c
@@ -618,6 +618,7 @@ static const struct nla_policy devlink_rate_set_nl_policy[DEVLINK_ATTR_PARENT_DE
 	[DEVLINK_ATTR_BUS_NAME] = { .type = NLA_NUL_STRING, },
 	[DEVLINK_ATTR_DEV_NAME] = { .type = NLA_NUL_STRING, },
 	[DEVLINK_ATTR_INDEX] = NLA_POLICY_FULL_RANGE(NLA_UINT, &devlink_attr_index_range),
+	[DEVLINK_ATTR_PORT_INDEX] = { .type = NLA_U32, },
 	[DEVLINK_ATTR_RATE_NODE_NAME] = { .type = NLA_NUL_STRING, },
 	[DEVLINK_ATTR_RATE_TX_SHARE] = { .type = NLA_U64, },
 	[DEVLINK_ATTR_RATE_TX_MAX] = { .type = NLA_U64, },
-- 
2.55.0


  parent reply	other threads:[~2026-09-15 16:13 UTC|newest]

Thread overview: 21+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-15 16:13 [PATCH net-next v2 0/9] devlink: netlink spec fixes Jakub Kicinski
2026-09-15 16:13 ` [PATCH net-next v2 1/9] devlink: fix the enum behind DEVLINK_ATTR_RELOAD_LIMITS Jakub Kicinski
2026-09-16 19:15   ` netdev-bot+sashiko
2026-09-18  1:19     ` Jakub Kicinski
2026-09-15 16:13 ` [PATCH net-next v2 2/9] netlink: specs: devlink: drop the stale port dump reply value Jakub Kicinski
2026-09-15 16:13 ` [PATCH net-next v2 3/9] netlink: specs: devlink: describe DEVLINK_ATTR_NESTED_DEVLINK Jakub Kicinski
2026-09-16 19:15   ` netdev-bot+sashiko
2026-09-18  1:21     ` Jakub Kicinski
2026-09-15 16:13 ` [PATCH net-next v2 4/9] netlink: specs: devlink: complete the port function nest Jakub Kicinski
2026-09-16 19:15   ` netdev-bot+sashiko
2026-09-15 16:13 ` [PATCH net-next v2 5/9] devlink: generate the port function policy from the spec Jakub Kicinski
2026-09-15 16:13 ` [PATCH net-next v2 6/9] netlink: specs: devlink: populate multi-attr attrs for region read and line card Jakub Kicinski
2026-09-16 19:15   ` netdev-bot+sashiko
2026-09-15 16:13 ` [PATCH net-next v2 7/9] netlink: specs: devlink: describe the netns id in the parent-dev nest Jakub Kicinski
2026-09-16 19:15   ` netdev-bot+sashiko
2026-09-18  1:23     ` Jakub Kicinski
2026-09-15 16:13 ` [PATCH net-next v2 8/9] netlink: specs: devlink: add pad to the subsets carrying padded u64s Jakub Kicinski
2026-09-16 19:15   ` netdev-bot+sashiko
2026-09-15 16:13 ` Jakub Kicinski [this message]
2026-09-16 19:15   ` [PATCH net-next v2 9/9] devlink: validate the port index in the rate set request netdev-bot+sashiko
2026-09-18  1:40 ` [PATCH net-next v2 0/9] devlink: netlink spec fixes patchwork-bot+netdevbpf

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260915161341.1053476-10-kuba@kernel.org \
    --to=kuba@kernel.org \
    --cc=andrew+netdev@lunn.ch \
    --cc=davem@davemloft.net \
    --cc=donald.hunter@gmail.com \
    --cc=edumazet@google.com \
    --cc=horms@kernel.org \
    --cc=jiri@resnulli.us \
    --cc=moshe@nvidia.com \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    --cc=tariqt@nvidia.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox