From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-ej2-f12.google.com (mail-ej2-f12.google.com [74.125.228.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 17C514A0929 for ; Mon, 21 Sep 2026 13:57:57 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.228.140 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789999082; cv=none; b=PA8loToOoKXlRbu/EWJTZ860CxuClOjh5Kk1fMhQJv6TubpaWyVTIqqt5yolTCNAN3UmDuER7CNWhwvQWOn0uUFKDk/CL50xU4KmnfTB2d5RzQsVSS9u4xrHEACt99XJaOmT0BrLRou7F8NgvBDQ7nKvkJJkg7WRbBQqAwv+JIM= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789999082; c=relaxed/simple; bh=scCajsGDahX0/C42DoxVM831Xi0Na9KZ5VIUIH33XnA=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=U5nX6qY3+9eAf34x+c06uqg3rEtxHN7vE1hXKHwfWoCl/dtCOE2YnGdm+R9EGoulJGC90trYA75ke/UPYnpjR68zNjfEDG44YDCb9HpTRNW4xEmLrTvP6Z1kq8kLfFmRsvub7BToHp3GVLSjHG1DqElPVqs86blsKZwtBKmSwtY= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=cellusys.com; spf=pass smtp.mailfrom=cellusys.com; dkim=pass (2048-bit key) header.d=cellusys.com header.i=@cellusys.com header.b=OTj8RqEG; arc=none smtp.client-ip=74.125.228.140 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=cellusys.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=cellusys.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=cellusys.com header.i=@cellusys.com header.b="OTj8RqEG" Received: by mail-ej2-f12.google.com with SMTP id a640c23a62f3a-c254f6c7a58so454052066b.2 for ; Mon, 21 Sep 2026 06:57:57 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cellusys.com; s=google; t=1789999076; x=1790603876; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=EYb9djJ650f+j77K71sOdKHCCKyIjN5iGG67MyIXzHI=; b=OTj8RqEGF+l7bCcbT5hmWzczPcMMCF04cVxsA9gd8KK9TkWoWZaTjN8rAcrIV9djmR KuUDyAGWBG9Upx0+NyW0m7phkvCSPBelDgHxyra+2VIHQWaiWpZlzT3gHbNqtpK+rMYV GZSsUF9GASy/7ger6mdq1WWdjsBvVBf/5ZhKIQHQX8Rryz2j9r2ySIXAOak/xegY0Tm/ JOUl9HDSegQU3C6kLhEgY3Q9pFVZ+H/FXdF4f/nsumDThPlKH7KjCPMoOxSvnFRyClzI /3DqWw7OxSk2+FN7IzoturcTIB5J6s8xdMiBS2u2OSlHeCcZmBROeAbapk6nNZQf5wxp 9Z0g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789999076; x=1790603876; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=EYb9djJ650f+j77K71sOdKHCCKyIjN5iGG67MyIXzHI=; b=utFQUM6CjA56Z7ZpVzpdFCpICsZ8byNJj2mi68u7Aw3cR036kjRXr4pAhJTSvVm6Ta bnI6aoLcZSacF2vXxXvAjPrgYEB55rybe1KRGvQJ28jzb9jOnPn+a2mrPuAJ7KSZecw4 1UIg+bAYFWSpl026/ck3YX6lIQxmqMEiD4uR/WPzcWmTiBauia0MxVXaUnylOm/CNTqv dVr2oE32hrhBKsbT1B9rX3Vyjxa905G917K2tt5Lt7Y03ZcGWF38LRsVl0r8OYaXLaar 2ep4xAMPZ4ElQjHSFHpBR+BoQ6FykhpoJO2xCI0HLyjD2M8IwOZVQCy6HuXHUJ/v4aL6 /tKg== X-Forwarded-Encrypted: i=1; AKwUvByPlZsIjjh+JBJq9JMUt+NeH40Mm5Eu/YydllUpr/2bMdpyFVZ1I0fIVY2L2RuR5xDjL8Z7U5CTaUKyRfA=@vger.kernel.org X-Gm-Message-State: AFuF++l1qncwpAyrt8AzMXIJZSOkDHPVkAqkF1LUfxr9bTXb51eFFfb2 Q7CVMeKtKqwxvU+wddoiTNlAWRdhaKXpnYyM8w4e7YQkga4+DMgA+DbfVBm2tmwOQ6s= X-Gm-Gg: AYBFou0e3f6iljA3wmkcppBNrpavu0SXHHJniyOwDujKLGGIh5+CwvpYyb0miVT0i/2 zoGsTkLXbDaZjj7hQIys5v4jdgdS9k2ms251WOB/FPQw87cuAhISCXglHX4ZaXMTCLgBaBLYWzh +/9aN4wuRxkaHyPTGClbvitRXFBLYRWOS6fbJEM0bMJrjDP2SUhYsYSib9sl1DhDn+OFs+NxT1/ mvlWUEsY9SF+bXreQ3mo2tvMjKhbjjGGjxNMgA8Ic749FC+XaILR7ldZky5JYj4IMEfONAqjVlJ 27833hdB1ksZyZtFTezDUu1M5NvNH3RFRNo9kX22wNwtg87cn907vGBHr1RemP/9zuT7lYTrTU9 Es0jUm4KUuwt65Qn/W0WDr1+9f4S+23EQ65JTxdc/0mjCKPljdz9Gv3dkbxlLOEmWqAhSEN7r25 5pTX/nZezkcZA3yrol/HX0zODvfKdqk+wRt9vtfxONWEm1+oROFnc21YmBCR1O5Sb0X7lXY2sjm fR/N0UAm/dnaJsr2WaL0nkeZKRj5UV1m+NzitndomZe4Ri3VLb8HWPW X-Received: by 2002:a17:906:f5a8:b0:c29:c356:6984 with SMTP id a640c23a62f3a-c2a1578857bmr907019266b.8.1789999076248; Mon, 21 Sep 2026 06:57:56 -0700 (PDT) Received: from dscRocky-build.localdomain (ip-83-147-170-154.wfd.metro.digiweb.ie. [83.147.170.154]) by smtp.gmail.com with ESMTPSA id a640c23a62f3a-c2a35745cfesm323987366b.38.2026.09.21.06.57.55 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 21 Sep 2026 06:57:55 -0700 (PDT) From: Warren Briggs To: Marcelo Ricardo Leitner , Xin Long , "David S . Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman Cc: linux-sctp@vger.kernel.org, netdev@vger.kernel.org, linux-kernel@vger.kernel.org, Warren Briggs Subject: [PATCH net v3] sctp: carry peer capabilities across an INIT collision Date: Mon, 21 Sep 2026 09:57:33 -0400 Message-ID: <20260921135733.577647-1-wbriggs@cellusys.com> X-Mailer: git-send-email 2.43.7 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit sctp_assoc_update() folds a temporary association into the existing one when an INIT collision is resolved. It copies asoc->c, peer.rwnd, peer.sack_needed, peer.auth_capable and peer.i, and nothing else. The remaining peer capability bits therefore keep whatever the surviving association was given when it was created, rather than what the peer advertised in the INIT that caused the collision. Forward TSN is the visible case. The INIT-ACK is built from the temporary association, so it advertises Forward-TSN-Supported; once the collision is resolved the surviving association holds peer.prsctp_capable == 0, and the first FORWARD TSN chunk the peer sends is answered with ERROR "Unrecognized chunk type". The peer does not expect this, having been told the capability was supported. ecn_capable, asconf_capable, reconf_capable and intl_capable are lost in the same way. The two address flags fail the other way round. sctp_process_param() clears ipv4_address and ipv6_address and sets them from the peer's Supported Address Types, but only on the temporary association. The surviving association keeps the permissive defaults from sctp_association_init(), so it can believe a peer supports an address family that peer never advertised. peer.auth_capable is already carried, added by commit 1be9a950c646 ("net: sctp: inherit auth_capable on INIT collisions") for the same reason. This extends that to the rest of the block. Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") Signed-off-by: Warren Briggs --- Changes since v2: - dropped asoc->peer.hostname_address. The field no longer exists, removed by commit bd4b28189469 ("sctp: delete the obsolete code for the host name address param"). - wrapped the commit message at 75 columns. - added the Fixes tag. - retargeted at net, subject prefix corrected. Changes since v1: - added ecn_capable, asconf_capable, reconf_capable and intl_capable, the missing fields identified in review of v1. - also added ipv4_address and ipv6_address, which are set from the peer's Supported Address Types on the temporary association and are lost at the merge in the same way. Testing. An INIT collision was resolved between two sockets on one host and the resulting association's peer capabilities read back, with a second, non-collided association created in the same run as a control, on an unpatched and a patched kernel: prsctp_capable SCTP_PR_SUPPORTED unpatched 0, patched 1 reconf_capable SCTP_RECONFIG_SUPPORTED unpatched 0, patched 1 intl_capable SCTP_INTERLEAVING_SUPPORTED unpatched 0, patched 1 asconf_capable SCTP_ASCONF_SUPPORTED unpatched 0, patched 1 ecn_capable SCTP_ECN_SUPPORTED unpatched 0, patched 1 ipv4_address sctp_diag sctpi_peer_capable unpatched 1, patched 0, with the peer advertising IPv6 only ipv6_address sctp_diag sctpi_peer_capable unpatched 1, patched 0, with the peer advertising IPv4 only Three of those were also confirmed on the wire. An unpatched kernel that has advertised Forward-TSN-Supported in its INIT-ACK answers a FORWARD TSN chunk with ERROR cause 6; a patched one accepts it. SCTP_RESET_STREAMS and sctp_bindx(SCTP_BINDX_ADD_ADDR) put a RE-CONFIG and an ASCONF on the wire on a patched kernel and produce nothing on an unpatched one. diff --git a/net/sctp/associola.c b/net/sctp/associola.c index 4521be3..0bd0a66 100644 --- a/net/sctp/associola.c +++ b/net/sctp/associola.c @@ -1107,6 +1107,13 @@ int sctp_assoc_update(struct sctp_association *asoc, asoc->peer.rwnd = new->peer.rwnd; asoc->peer.sack_needed = new->peer.sack_needed; asoc->peer.auth_capable = new->peer.auth_capable; + asoc->peer.prsctp_capable = new->peer.prsctp_capable; + asoc->peer.ecn_capable = new->peer.ecn_capable; + asoc->peer.asconf_capable = new->peer.asconf_capable; + asoc->peer.reconf_capable = new->peer.reconf_capable; + asoc->peer.intl_capable = new->peer.intl_capable; + asoc->peer.ipv4_address = new->peer.ipv4_address; + asoc->peer.ipv6_address = new->peer.ipv6_address; asoc->peer.i = new->peer.i; if (!sctp_tsnmap_init(&asoc->peer.tsn_map, SCTP_TSN_MAP_INITIAL,