mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH net v2] cipso: adjust cached option offsets when removing CIPSO
@ 2026-10-06  3:51 Daehyeon Ko
  2026-10-06  3:53 ` netdev-bot+sinfo
                   ` (2 more replies)
  0 siblings, 3 replies; 4+ messages in thread
From: Daehyeon Ko @ 2026-10-06  3:51 UTC (permalink / raw)
  To: Paul Moore, Ondrej Mosnáček
  Cc: David S . Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni,
	Simon Horman, netdev, linux-security-module, linux-kernel,
	Daehyeon Ko

cipso_v4_skbuff_delattr() removes the CIPSO bytes but does not adjust
cached offsets for options that follow them.

For example, with a valid 10-byte CIPSO option followed by a seven-byte
RR option, parsing records rr at offset 30.  Removing CIPSO moves RR to
offset 20, while the cached offset remains 30.  Consumers such as
ip_forward_options() and __ip_options_echo() then access the wrong bytes;
the latter may interpret packet data as the option length and copy it into
fixed-size option storage.

Mirror cipso_v4_delopt() and subtract cipso_len from the srr, rr, ts and
router_alert offsets when they follow CIPSO.  cipso_len is the distance
the first memmove() shifts those options.  The later header move and
network-header reset relocate the bytes and their offset base together.

Fixes: 89aa3619d141 ("cipso: make cipso_v4_skbuff_delattr() fully remove the CIPSO options")
Cc: stable@vger.kernel.org
Reviewed-by: Ondrej Mosnáček <omosnacek@gmail.com>
Assisted-by: LLM
Signed-off-by: Daehyeon Ko <4ncienth@gmail.com>
---
Changes in v2:
- Replace the parser-invalid 8-byte example with a valid 10-byte one.
- Move the offset updates beside the other option metadata updates.

Link: https://lore.kernel.org/netdev/20260930140400.2955466-1-4ncienth@gmail.com/

 net/ipv4/cipso_ipv4.c | 8 ++++++++
 1 file changed, 8 insertions(+)

diff --git a/net/ipv4/cipso_ipv4.c b/net/ipv4/cipso_ipv4.c
index a05aa075de1a5b..1aacbbeffbc647 100644
--- a/net/ipv4/cipso_ipv4.c
+++ b/net/ipv4/cipso_ipv4.c
@@ -2287,6 +2287,14 @@ int cipso_v4_skbuff_delattr(struct sk_buff *skb)
 	       new_hdr_len - new_hdr_len_actual);
 
 	opt->optlen -= hdr_len_delta;
+	if (opt->srr > opt->cipso)
+		opt->srr -= cipso_len;
+	if (opt->rr > opt->cipso)
+		opt->rr -= cipso_len;
+	if (opt->ts > opt->cipso)
+		opt->ts -= cipso_len;
+	if (opt->router_alert > opt->cipso)
+		opt->router_alert -= cipso_len;
 	opt->cipso = 0;
 	opt->is_changed = 1;
 	if (hdr_len_delta != 0) {

base-commit: d5a007b9b457c915ab1a53227e8939e4018aa97a
-- 
2.55.0

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH net v2] cipso: adjust cached option offsets when removing CIPSO
  2026-10-06  3:51 [PATCH net v2] cipso: adjust cached option offsets when removing CIPSO Daehyeon Ko
@ 2026-10-06  3:53 ` netdev-bot+sinfo
  2026-10-06 12:14 ` Paul Moore
  2026-10-08  2:30 ` patchwork-bot+netdevbpf
  2 siblings, 0 replies; 4+ messages in thread
From: netdev-bot+sinfo @ 2026-10-06  3:53 UTC (permalink / raw)
  To: Daehyeon Ko
  Cc: Paul Moore, Ondrej Mosnáček, David S . Miller,
	Eric Dumazet, Jakub Kicinski, Paolo Abeni, Simon Horman, netdev,
	linux-security-module, linux-kernel

Hi!

This is an automated message. This series looks like a fix, but its
commit messages seem to be missing some information:

 - Whether the issue was actually triggered, or is only theoretical
   (e.g. found by code inspection). If it was triggered please include
   the symptoms, like the stack trace or error messages.

Please do not repost the series just to address the above. Instead,
reply to this email with the missing information, so that reviewers
can take it into account. If the series needs another revision for
other reasons, please include the information in the commit messages
then.

The evaluation is done by an LLM so it may be wrong, if you think
that is the case please reply and explain.

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH net v2] cipso: adjust cached option offsets when removing CIPSO
  2026-10-06  3:51 [PATCH net v2] cipso: adjust cached option offsets when removing CIPSO Daehyeon Ko
  2026-10-06  3:53 ` netdev-bot+sinfo
@ 2026-10-06 12:14 ` Paul Moore
  2026-10-08  2:30 ` patchwork-bot+netdevbpf
  2 siblings, 0 replies; 4+ messages in thread
From: Paul Moore @ 2026-10-06 12:14 UTC (permalink / raw)
  To: Daehyeon Ko
  Cc: Ondrej Mosnáček, David S . Miller, Eric Dumazet,
	Jakub Kicinski, Paolo Abeni, Simon Horman, netdev,
	linux-security-module, linux-kernel

On Mon, Oct 5, 2026 at 11:51 PM Daehyeon Ko <4ncienth@gmail.com> wrote:
>
> cipso_v4_skbuff_delattr() removes the CIPSO bytes but does not adjust
> cached offsets for options that follow them.
>
> For example, with a valid 10-byte CIPSO option followed by a seven-byte
> RR option, parsing records rr at offset 30.  Removing CIPSO moves RR to
> offset 20, while the cached offset remains 30.  Consumers such as
> ip_forward_options() and __ip_options_echo() then access the wrong bytes;
> the latter may interpret packet data as the option length and copy it into
> fixed-size option storage.
>
> Mirror cipso_v4_delopt() and subtract cipso_len from the srr, rr, ts and
> router_alert offsets when they follow CIPSO.  cipso_len is the distance
> the first memmove() shifts those options.  The later header move and
> network-header reset relocate the bytes and their offset base together.
>
> Fixes: 89aa3619d141 ("cipso: make cipso_v4_skbuff_delattr() fully remove the CIPSO options")
> Cc: stable@vger.kernel.org
> Reviewed-by: Ondrej Mosnáček <omosnacek@gmail.com>
> Assisted-by: LLM
> Signed-off-by: Daehyeon Ko <4ncienth@gmail.com>
> ---
> Changes in v2:
> - Replace the parser-invalid 8-byte example with a valid 10-byte one.
> - Move the offset updates beside the other option metadata updates.
>
> Link: https://lore.kernel.org/netdev/20260930140400.2955466-1-4ncienth@gmail.com/
>
>  net/ipv4/cipso_ipv4.c | 8 ++++++++
>  1 file changed, 8 insertions(+)

Acked-by: Paul Moore <paul@paul-moore.com>

-- 
paul-moore.com

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH net v2] cipso: adjust cached option offsets when removing CIPSO
  2026-10-06  3:51 [PATCH net v2] cipso: adjust cached option offsets when removing CIPSO Daehyeon Ko
  2026-10-06  3:53 ` netdev-bot+sinfo
  2026-10-06 12:14 ` Paul Moore
@ 2026-10-08  2:30 ` patchwork-bot+netdevbpf
  2 siblings, 0 replies; 4+ messages in thread
From: patchwork-bot+netdevbpf @ 2026-10-08  2:30 UTC (permalink / raw)
  To: Daehyeon Ko
  Cc: paul, omosnacek, davem, edumazet, kuba, pabeni, horms, netdev,
	linux-security-module, linux-kernel

Hello:

This patch was applied to netdev/net.git (main)
by Jakub Kicinski <kuba@kernel.org>:

On Tue,  6 Oct 2026 12:51:08 +0900 you wrote:
> cipso_v4_skbuff_delattr() removes the CIPSO bytes but does not adjust
> cached offsets for options that follow them.
> 
> For example, with a valid 10-byte CIPSO option followed by a seven-byte
> RR option, parsing records rr at offset 30.  Removing CIPSO moves RR to
> offset 20, while the cached offset remains 30.  Consumers such as
> ip_forward_options() and __ip_options_echo() then access the wrong bytes;
> the latter may interpret packet data as the option length and copy it into
> fixed-size option storage.
> 
> [...]

Here is the summary with links:
  - [net,v2] cipso: adjust cached option offsets when removing CIPSO
    https://git.kernel.org/netdev/net/c/6d25ffca055a

You are awesome, thank you!
-- 
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html



^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-10-08  2:30 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-06  3:51 [PATCH net v2] cipso: adjust cached option offsets when removing CIPSO Daehyeon Ko
2026-10-06  3:53 ` netdev-bot+sinfo
2026-10-06 12:14 ` Paul Moore
2026-10-08  2:30 ` patchwork-bot+netdevbpf

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®