From: netdev-bot+sashiko@kernel.org
To: daniel.zahka@gmail.com
Cc: kuba@kernel.org, willemdebruijn.kernel@gmail.com,
davem@davemloft.net, edumazet@kernel.org, pabeni@redhat.com,
horms@kernel.org, corbet@lwn.net, skhan@linuxfoundation.org,
rdunlap@infradead.org, donald.hunter@gmail.com,
andrew+netdev@lunn.ch, shuah@kernel.org, netdev@vger.kernel.org,
linux-kernel@vger.kernel.org, linux-doc@vger.kernel.org,
linux-kselftest@vger.kernel.org
Subject: Re: [PATCH net-next v2 1/7] psp: support rx rekey operation
Date: Sat, 10 Oct 2026 21:43:40 +0000 [thread overview]
Message-ID: <179166862015.434549.17532933495669454971@kernel.org> (raw)
In-Reply-To: <20261009-psp-v2-1-5596ab50f677@gmail.com>
Thank you for your contribution! Sashiko AI review found more severe
issue(s) in other patches of this series. This mail is only an FYI, in case
you want to address the nit picks below when you respin.
Low priority / nit picks for your consideration:
- [Low] Data race on the new field psp_assoc::prev_generation.
--
psp: support rx rekey operation
This commit lets a socket that already has PSP state install a new rx
key. The new psp_assoc copies the existing tx state and keeps the
previous rx spi and generation as a fallback. Packets matching either
the current or the previous rx spi/generation are accepted.
> diff --git a/include/net/psp/functions.h b/include/net/psp/functions.h
> index b23c30898389c..fb80e15e43681 100644
> --- a/include/net/psp/functions.h
> +++ b/include/net/psp/functions.h
> @@ -77,10 +77,12 @@ psp_is_allowed_nondata(struct sk_buff *skb, struct psp_assoc *pas)
> static inline bool
> psp_pse_matches_pas(struct psp_skb_ext *pse, struct psp_assoc *pas)
> {
> - return pse && pas->rx.spi == pse->spi &&
> - pas->generation == pse->generation &&
> - pas->version == pse->version &&
> - pas->dev_id == pse->dev_id;
> + return pse && pas->version == pse->version &&
> + pas->dev_id == pse->dev_id &&
> + ((pas->rx.spi == pse->spi &&
> + pas->generation == pse->generation) ||
> + (pas->prev_spi && pas->prev_spi == pse->spi &&
> + pas->prev_generation == pse->generation));
> }
[ ... ]
> diff --git a/net/psp/psp_sock.c b/net/psp/psp_sock.c
> index a6b1c42dd626f..b5887171c84e7 100644
> --- a/net/psp/psp_sock.c
> +++ b/net/psp/psp_sock.c
[ ... ]
> @@ -304,6 +338,10 @@ void psp_assocs_key_rotated(struct psp_dev *psd)
> pas->generation |= ~PSP_GEN_VALID_MASK;
> psd->stats.stales++;
> }
> +
> + list_for_each_entry(pas, &psd->active_assocs, assocs_list)
> + pas->prev_generation |= ~PSP_GEN_VALID_MASK;
> +
[Severity: Low]
Is this new write to prev_generation racing with the reader in
psp_pse_matches_pas()?
psp_assocs_key_rotated() runs with only psd->lock held, which is taken
in the key-rotate pre_doit before psp_nl_key_rotate_doit() calls it.
It does a plain read-modify-write on associations that are already
published through sk->psp_assoc.
The new prev_generation comparison in psp_pse_matches_pas() runs on the
receive path without psd->lock:
tcp_v4_do_rcv() / tcp_v6_do_rcv()
psp_sk_rx_policy_check()
__psp_sk_rx_policy_check()
psp_pse_matches_pas()
psp_twsk_rx_policy_check() also reads it with only RCU held.
Neither side uses READ_ONCE()/WRITE_ONCE() or data_race(). KCSAN would
probably report this whenever a device key rotation overlaps PSP rx on
a socket that has been rekeyed. Since this is a u8 there is no tearing,
so the worst effect is that a reader briefly still accepts packets on
the previous spi during a rotation.
pas->generation already has the same unannotated pattern, but this
patch adds a second field and a new write loop over active, published
associations. Should these new accesses be annotated with
WRITE_ONCE()/READ_ONCE() or data_race()?
> list_splice_init(&psd->prev_assocs, &psd->stale_assocs);
> list_splice_init(&psd->active_assocs, &psd->prev_assocs);
--
Sashiko AI review · https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20261009-psp-v2-0-5596ab50f677%40gmail.com
next prev parent reply other threads:[~2026-10-10 21:43 UTC|newest]
Thread overview: 14+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-09 20:46 [PATCH net-next v2 0/7] psp: support rekeying psp protected tcp connections Daniel Zahka
2026-10-09 20:46 ` [PATCH net-next v2 1/7] psp: support rx rekey operation Daniel Zahka
2026-10-10 21:43 ` netdev-bot+sashiko [this message]
2026-10-09 20:46 ` [PATCH net-next v2 2/7] psp: support tx " Daniel Zahka
2026-10-10 21:43 ` netdev-bot+sashiko
2026-10-09 20:46 ` [PATCH net-next v2 3/7] psp: defer tx key deletions for SADB drivers Daniel Zahka
2026-10-10 21:43 ` netdev-bot+sashiko
2026-10-09 20:46 ` [PATCH net-next v2 4/7] psp: add core tracked stat for outstanding tx keys Daniel Zahka
2026-10-10 21:43 ` netdev-bot+sashiko
2026-10-09 20:46 ` [PATCH net-next v2 5/7] selftests: drv-net: psp: factor out psp connection setup Daniel Zahka
2026-10-10 21:43 ` netdev-bot+sashiko
2026-10-09 20:46 ` [PATCH net-next v2 6/7] selftests: drv-net: psp: add rekey tests Daniel Zahka
2026-10-10 21:43 ` netdev-bot+sashiko
2026-10-09 20:46 ` [PATCH net-next v2 7/7] selftests: drv-net: psp: add a tx rekey drain test for SADB drivers Daniel Zahka
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=179166862015.434549.17532933495669454971@kernel.org \
--to=netdev-bot+sashiko@kernel.org \
--cc=andrew+netdev@lunn.ch \
--cc=corbet@lwn.net \
--cc=daniel.zahka@gmail.com \
--cc=davem@davemloft.net \
--cc=donald.hunter@gmail.com \
--cc=edumazet@kernel.org \
--cc=horms@kernel.org \
--cc=kuba@kernel.org \
--cc=linux-doc@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-kselftest@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=rdunlap@infradead.org \
--cc=shuah@kernel.org \
--cc=skhan@linuxfoundation.org \
--cc=willemdebruijn.kernel@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®