From: Steffen Klassert <steffen.klassert@secunet.com>
To: Herbert Xu <herbert@gondor.apana.org.au>
Cc: Christian Langrock <christian.langrock@secunet.com>,
<davem@davemloft.net>, <edumazet@google.com>, <kuba@kernel.org>,
<pabeni@redhat.com>, <netdev@vger.kernel.org>,
<linux-kernel@vger.kernel.org>
Subject: Re: [PATCH ipsec v6] xfrm: replay: Fix ESN wrap around for GSO
Date: Thu, 13 Oct 2022 08:16:33 +0200 [thread overview]
Message-ID: <20221013061633.GS2950045@gauss3.secunet.de> (raw)
In-Reply-To: <Y0aI2bGb24M5vA7B@gondor.apana.org.au>
On Wed, Oct 12, 2022 at 05:28:57PM +0800, Herbert Xu wrote:
> On Fri, Oct 07, 2022 at 04:50:15PM +0200, Christian Langrock wrote:
> > When using GSO it can happen that the wrong seq_hi is used for the last
> > packets before the wrap around. This can lead to double usage of a
> > sequence number. To avoid this, we should serialize this last GSO
> > packet.
> >
> > Fixes: d7dbefc45cf5 ("xfrm: Add xfrm_replay_overflow functions for offloading")
> > Co-developed-by: Steffen Klassert <steffen.klassert@secunet.com>
> > Signed-off-by: Christian Langrock <christian.langrock@secunet.com>
> > ---
> > Changes in v6:
> > - move overflow check to offloading path to avoid locking issues
> >
> > Changes in v5:
> > - Fix build
> >
> > Changes in v4:
> > - move changelog within comment
> > - add reviewer
> >
> > Changes in v3:
> > - fix build
> > - remove wrapper function
> >
> > Changes in v2:
> > - switch to bool as return value
> > - remove switch case in wrapper function
> > ---
> > net/ipv4/esp4_offload.c | 3 +++
> > net/ipv6/esp6_offload.c | 3 +++
> > net/xfrm/xfrm_device.c | 15 ++++++++++++++-
> > net/xfrm/xfrm_replay.c | 2 +-
> > 4 files changed, 21 insertions(+), 2 deletions(-)
>
> Could you please explain how this code restructure makes it safe
> with respect to multiple users of the same xfrm_state?
That is because with this patch, the sequence number from the xfrm_state
is assigned to the skb and advanced by the number of segments while
holding the state lock, as it was before. The sequence numbers this
patch operates on are exclusive and private to that skb (and its
segments). The next skb will checkout the correct number from the
xfrm_state regardless on which cpu it comes.
next prev parent reply other threads:[~2022-10-13 6:16 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2022-10-07 14:50 Christian Langrock
2022-10-12 8:44 ` Steffen Klassert
2022-10-12 9:28 ` Herbert Xu
2022-10-13 6:16 ` Steffen Klassert [this message]
2022-10-13 8:04 ` Herbert Xu
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20221013061633.GS2950045@gauss3.secunet.de \
--to=steffen.klassert@secunet.com \
--cc=christian.langrock@secunet.com \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=herbert@gondor.apana.org.au \
--cc=kuba@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®