From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pl1-f181.google.com (mail-pl1-f181.google.com [209.85.214.181]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 185AB2153C9 for ; Thu, 9 Jan 2025 09:37:00 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.181 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1736415424; cv=none; b=J7xma3vFKYAsSIsy64FsIe1ehYfUcIj9CCU1ZIIzfH9TKhZf3K2qjBRu7hFUOITp3Rg0aTOSgfsg9ZQO/N8U9Q1kRnu2f8hzviormO0ZQ6QuBw9sBWNPqY32d4ZWydHX2vMQ6kgKIiE9sKExQjMitKT168X7LfZblb/k93od0Uc= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1736415424; c=relaxed/simple; bh=/Y7vshFyp+S1ZNQo5QoPrTX6A5Pvuo7WfnstfrwZxZI=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=iJxDCzDf2OBXe2YG7nmq+XqRADLCjkE5iKTQzEs9FRSe0L0RH2cd6/R3P/W30VwCHzWfIWGxAXjNexYSlD08IFZ2SvO628esnu8b5DhQyHBBGBU65PlTusQewtYEwHOEiUvSAbtCZEdQyQFvDa/xkN8tsfY/olZVcEMK/iw58S4= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=daynix.com; spf=pass smtp.mailfrom=daynix.com; dkim=pass (2048-bit key) header.d=daynix-com.20230601.gappssmtp.com header.i=@daynix-com.20230601.gappssmtp.com header.b=URXqYp9L; arc=none smtp.client-ip=209.85.214.181 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=daynix.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=daynix.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=daynix-com.20230601.gappssmtp.com header.i=@daynix-com.20230601.gappssmtp.com header.b="URXqYp9L" Received: by mail-pl1-f181.google.com with SMTP id d9443c01a7336-21670dce0a7so13677675ad.1 for ; Thu, 09 Jan 2025 01:37:00 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=daynix-com.20230601.gappssmtp.com; s=20230601; t=1736415420; x=1737020220; darn=vger.kernel.org; h=content-transfer-encoding:in-reply-to:from:content-language :references:cc:to:subject:user-agent:mime-version:date:message-id :from:to:cc:subject:date:message-id:reply-to; bh=XcSbx1LF493qhjKry/nZNlaGERbQhtYPTAQgAOWQyVg=; b=URXqYp9LJnEWi/WJgrOpmKW2PJ+7wHscm3opYsrG+hIK3Ikuz0ZbAd21gFLG4thsj9 o5wtEmuuL9YxRLA/6cyacKVEPSg3jiqpDp8WeMPDK9bszK0d1BQ9pcjT8LmyPYcpZzJg BBrbCwRok37Bkb06Nq7gfIsWQit+B51/tmLpf3rB7yWN+8dzQ10TCmx6pvOkYEVcGqsX JeZ/C/AjuZCKWUWOhRzwDEhM3zUC9muX/8gaLZupF2uOD/lBSY/ExbTPmwxDkLFJR05p zlNEwHW1oVirqcj6rimIA7SH/hq5YXmFyZDErfKMDxNhuFGcY5y3JNJLJ1Ffkwek/bSe 25Aw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1736415420; x=1737020220; h=content-transfer-encoding:in-reply-to:from:content-language :references:cc:to:subject:user-agent:mime-version:date:message-id :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=XcSbx1LF493qhjKry/nZNlaGERbQhtYPTAQgAOWQyVg=; b=Phd+Q3axCqQLTLJKe/p6QLLb9i+4kRZgOqmxJksEMO4EfT9t4u81FpUCYipaqnVqRJ U2EevwnCKota4epJwwmzR6KqnwTWeAsS7yr7gWylqcRnChSu//idluIHoqS7VSkUhPVC nl+Bc3a3gEu/MoEVC2HV508anflNmwM04pmN7YlBIUqlnyZB8GO6S1MkMalZw8pgmr/9 3HW3ZJ9TpWLkazaqvfmmjAmDk9yweEWloVn3g59dDb6MuABbZjz93SqPdqrlEgTBciAy tc6jw2LAC0Hj60jmRyMJqBllA69s3m3vzw4un81GKbgr82doRPT0Mx3Ke8cG84vNb9NE tDAA== X-Forwarded-Encrypted: i=1; AJvYcCU26toOj/Jz8V2jKiRnDGDxQkEJ40KWqKiD6Msh5P04w6/vGDwaqOL2Vp3y9d3sAzcQzCDwG5k=@vger.kernel.org X-Gm-Message-State: AOJu0YwLAJDbk6Vd1vnIntX1aT6bAO45ikogm2IWG1ig+UFWlvBuq6v4 6rMPQllAQ1p+3B3V4zE0ZEQL+zdcrLai1AfJ8o1ORiFdDy1IHz0OpGqi0HzdOfI= X-Gm-Gg: ASbGncuYRyW2TcaYefUzK6MDQ7agBR0oKbVf7XbFlYvi673ummuCwI80QCcAcayPO5o rsg/uxYKE/3jxsq2m0V5fg9QpFEEmh7Sz5J7YvbU2I5rFlqKdKlBeN+aelhW4qhhqLMxrWxTEmn P6lZKh5AHUgyCe68A5WQxG4ky/xYpav+On+LShqs/N32agNRutWn8fG7S+A2ReuyB1MCaLDJwj9 QZZ9wSo5RN+1qY+10JN6KdysdkBRF5HtztnIn2zF/yCDuvnr8LMhnvmOprZgpI8QV0= X-Google-Smtp-Source: AGHT+IGojiWk/1gT/7D4/Bn9x5ciCyKBW6DXVbq8kH6J+vNptBrJUgGdPyWUs9OwXpei8EJsrIl0sg== X-Received: by 2002:a05:6a20:8411:b0:1e1:a434:2964 with SMTP id adf61e73a8af0-1e88cf63b7bmr10109548637.2.1736415420397; Thu, 09 Jan 2025 01:37:00 -0800 (PST) Received: from [157.82.203.37] ([157.82.203.37]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-72aad8dbab4sm36620666b3a.94.2025.01.09.01.36.54 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Thu, 09 Jan 2025 01:36:59 -0800 (PST) Message-ID: <6f33c048-81ad-4d15-872d-187e965e6d79@daynix.com> Date: Thu, 9 Jan 2025 18:36:52 +0900 Precedence: bulk X-Mailing-List: netdev@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH v2 2/3] tun: Pad virtio header with zero To: "Michael S. Tsirkin" , Alexander Viro , Christian Brauner , Jan Kara , linux-fsdevel@vger.kernel.org, "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , netdev@vger.kernel.org Cc: Jonathan Corbet , Willem de Bruijn , Jason Wang , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Xuan Zhuo , Shuah Khan , linux-doc@vger.kernel.org, linux-kernel@vger.kernel.org, netdev@vger.kernel.org, kvm@vger.kernel.org, virtualization@lists.linux-foundation.org, linux-kselftest@vger.kernel.org, Yuri Benditovich , Andrew Melnychenko , Stephen Hemminger , gur.stavi@huawei.com, devel@daynix.com References: <20250109-tun-v2-0-388d7d5a287a@daynix.com> <20250109-tun-v2-2-388d7d5a287a@daynix.com> <20250109023056-mutt-send-email-mst@kernel.org> <571a2d61-5fbe-4e49-b4d1-6bf0c7604a57@daynix.com> <20250109024247-mutt-send-email-mst@kernel.org> Content-Language: en-US From: Akihiko Odaki In-Reply-To: <20250109024247-mutt-send-email-mst@kernel.org> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit On 2025/01/09 16:43, Michael S. Tsirkin wrote: > On Thu, Jan 09, 2025 at 04:41:50PM +0900, Akihiko Odaki wrote: >> On 2025/01/09 16:31, Michael S. Tsirkin wrote: >>> On Thu, Jan 09, 2025 at 03:58:44PM +0900, Akihiko Odaki wrote: >>>> tun used to simply advance iov_iter when it needs to pad virtio header, >>>> which leaves the garbage in the buffer as is. This is especially >>>> problematic when tun starts to allow enabling the hash reporting >>>> feature; even if the feature is enabled, the packet may lack a hash >>>> value and may contain a hole in the virtio header because the packet >>>> arrived before the feature gets enabled or does not contain the >>>> header fields to be hashed. If the hole is not filled with zero, it is >>>> impossible to tell if the packet lacks a hash value. >>>> >>>> In theory, a user of tun can fill the buffer with zero before calling >>>> read() to avoid such a problem, but leaving the garbage in the buffer is >>>> awkward anyway so fill the buffer in tun. >>>> >>>> Signed-off-by: Akihiko Odaki >>> >>> But if the user did it, you have just overwritten his value, >>> did you not? >> >> Yes. but that means the user expects some part of buffer is not filled after >> read() or recvmsg(). I'm a bit worried that not filling the buffer may break >> assumptions others (especially the filesystem and socket infrastructures in >> the kernel) may have. >> >> If we are really confident that it will not cause problems, this behavior >> can be opt-in based on a flag or we can just write some documentation >> warning userspace programmers to initialize the buffer. > > It's been like this for years, I'd say we wait until we know there's a problem? Perhaps we can just leave it as is. Let me ask filesystem and networking people: Is it OK to leave some part of buffer uninitialized with read_iter() or recvmsg()? > >>> >>>> --- >>>> drivers/net/tun_vnet.c | 3 ++- >>>> 1 file changed, 2 insertions(+), 1 deletion(-) >>>> >>>> diff --git a/drivers/net/tun_vnet.c b/drivers/net/tun_vnet.c >>>> index fe842df9e9ef..ffb2186facd3 100644 >>>> --- a/drivers/net/tun_vnet.c >>>> +++ b/drivers/net/tun_vnet.c >>>> @@ -138,7 +138,8 @@ int tun_vnet_hdr_put(int sz, struct iov_iter *iter, >>>> if (copy_to_iter(hdr, sizeof(*hdr), iter) != sizeof(*hdr)) >>>> return -EFAULT; >>>> - iov_iter_advance(iter, sz - sizeof(*hdr)); >>>> + if (iov_iter_zero(sz - sizeof(*hdr), iter) != sz - sizeof(*hdr)) >>>> + return -EFAULT; >>>> return 0; >>>> } >>>> >>>> -- >>>> 2.47.1 >>> >