From: Antony Antony <antony.antony@secunet.com>
To: Antony Antony <antony.antony@secunet.com>,
Steffen Klassert <steffen.klassert@secunet.com>,
Herbert Xu <herbert@gondor.apana.org.au>,
"David S. Miller" <davem@davemloft.net>,
Eric Dumazet <edumazet@google.com>,
Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
Simon Horman <horms@kernel.org>, David Ahern <dsahern@kernel.org>,
Jamal Hadi Salim <hadi@cyberus.ca>, Shuah Khan <shuah@kernel.org>,
Paul Chaignon <paul.chaignon@gmail.com>,
Louis DeLosSantos <louis.delos.devel@gmail.com>,
Jonathan Corbet <corbet@lwn.net>,
Shuah Khan <skhan@linuxfoundation.org>,
Randy Dunlap <rdunlap@infradead.org>
Cc: Sabrina Dubroca <sd@queasysnail.net>, <netdev@vger.kernel.org>,
Yan Yan <evitayan@google.com>,
Tobias Brunner <tobias@strongswan.org>,
Florian Westphal <fw@strlen.de>, <linux-doc@vger.kernel.org>,
<linux-kernel@vger.kernel.org>, <stable+noautosel@kernel.org>,
Sashiko <sashiko-bot@kernel.org>
Subject: [PATCH ipsec v4 0/9] xfrm: state: exact mark/mask match for control-plane SA lookups
Date: Tue, 6 Oct 2026 09:03:15 +0200 [thread overview]
Message-ID: <migrate-state-fixes-v4-0-d5054459fc78@secunet.com> (raw)
While looking into a XFRM_MSG_MIGRATE_STATE issue reported by Sashiko,
we found the underlying problem generalizes: xfrm allows multiple SAs
to coexist for the same (SPI, daddr, proto) differing only in mark,
and every netlink method that resolves "which SA" - xfrm get_sa(),
del_sa(), update, get_ae, new_ae, expire, migrate - uses the same
wildcard mark match the data path needs. A broader-mask SA can
silently shadow a more specific one:
# ip xfrm state add ... spi 0x1000 mark 1 mask 1 (SA_target)
# ip xfrm state add ... spi 0x1000 mark 0 mask 0
(SA_decoy, catch-all, added after -> bucket head)
# ip xfrm state delete dst ... proto esp spi 0x1000 mark 1 mask 1
-> deletes SA_decoy; SA_target survives, untouched
xfrm policy had the same bug, fixed in commit 4f47e8ab6ab7
("xfrm: policy: match with both mark and mask on user interfaces").
Netlink state lookups using spi use an exact mark/mask match except
for UPDSA; the wildcard match stays for the data path and state_add only.
This series applies that fix across every affected method,
not just XFRM_MSG_MIGRATE_STATE.
Also reject marks with value bits outside the mask (state add,
ALLOCSPI, policy add). These are misconfigurations anyway, since
the extra bits can never match, and break exact match added here.
This series does not touch PF_KEY, which no longer receives
non-critical fixes.
state_lookup_byaddr is out of scope. This is only fixing spi based
lookups.
---
v3->v4: add 3 patches to reject mark value bits outside the mask for state and policy
- Link to v3: https://patch.msgid.link/migrate-state-fixes-v3-6-836125bb53dd@secunet.com
v2->v3: mark match use only values and no mask in exact lookup
- Link to v2: https://lore.kernel.org/all/migrate-state-fixes-v2-0-c3e2767f0d96@secunet.com/
v1->v2: few more wildcard mark check reported by sashiko and Yan
- keep wildcard match in xfrm_state_update() (UPDSA)
- Link to v1: https://patch.msgid.link/migrate-state-fixes-v0-8-a69e8637ba3b@secunet.com
To: Steffen Klassert <steffen.klassert@secunet.com>
To: Herbert Xu <herbert@gondor.apana.org.au>
To: "David S. Miller" <davem@davemloft.net>
To: Eric Dumazet <edumazet@google.com>
To: Jakub Kicinski <kuba@kernel.org>
To: Paolo Abeni <pabeni@redhat.com>
To: Simon Horman <horms@kernel.org>
To: Paul Chaignon <paul.chaignon@gmail.com>
To: Louis DeLosSantos <louis.delos.devel@gmail.com>
To: Jamal Hadi Salim <hadi@cyberus.ca>
To: Antony Antony <antony.antony@secunet.com>
To: Sabrina Dubroca <sd@queasysnail.net>
To: Jonathan Corbet <corbet@lwn.net>
To: Shuah Khan <skhan@linuxfoundation.org>
To: Randy Dunlap <rdunlap@infradead.org>
Cc: netdev@vger.kernel.org
Cc: linux-kernel@vger.kernel.org
Cc: linux-doc@vger.kernel.org
---
Antony Antony (9):
xfrm: state: reject mark with bits outside its mask on add
xfrm: state: reject mark with bits outside its mask on ALLOCSPI
xfrm: policy: reject mark with bits outside its mask on add
xfrm: state: exact mark/mask match for SPI-keyed control-plane SA lookups
xfrm: fix use-after-free of migrated state in xfrm_do_migrate_state()
xfrm: fix hw offload state leak on xfrm_do_migrate_state() error path
xfrm: include mark in MIGRATE_STATE SA collision check
xfrm: pass extack through to xfrm_init_replay() from xfrm_init_state()
docs: xfrm: include mark in XFRM_MSG_MIGRATE_STATE EEXIST tuple
.../networking/xfrm/xfrm_migrate_state.rst | 25 +++--
include/net/xfrm.h | 7 ++
net/xfrm/xfrm_state.c | 101 +++++++++++++++++----
net/xfrm/xfrm_user.c | 81 ++++++++++++-----
4 files changed, 166 insertions(+), 48 deletions(-)
---
base-commit: 86de3a1118a16dbbbe5fabe9aa20ffb93c072ed5
change-id: migrate-state-fixes-063ee0342611
Best regards,
--
Antony Antony <antony.antony@secunet.com>
next reply other threads:[~2026-10-06 7:03 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-06 7:03 Antony Antony [this message]
2026-10-06 7:03 ` [PATCH ipsec v4 1/9] xfrm: state: reject mark with bits outside its mask on add Antony Antony
2026-10-06 7:04 ` [PATCH ipsec v4 2/9] xfrm: state: reject mark with bits outside its mask on ALLOCSPI Antony Antony
2026-10-06 7:04 ` [PATCH ipsec v4 3/9] xfrm: policy: reject mark with bits outside its mask on add Antony Antony
2026-10-06 7:05 ` [PATCH ipsec v4 4/9] xfrm: state: exact mark/mask match for SPI-keyed control-plane SA lookups Antony Antony
2026-10-06 7:05 ` [PATCH ipsec v4 5/9] xfrm: fix use-after-free of migrated state in xfrm_do_migrate_state() Antony Antony
2026-10-06 7:06 ` [PATCH ipsec v4 6/9] xfrm: fix hw offload state leak on xfrm_do_migrate_state() error path Antony Antony
2026-10-06 7:06 ` [PATCH ipsec v4 7/9] xfrm: include mark in MIGRATE_STATE SA collision check Antony Antony
2026-10-06 7:06 ` [PATCH ipsec v4 8/9] xfrm: pass extack through to xfrm_init_replay() from xfrm_init_state() Antony Antony
2026-10-06 7:06 ` [PATCH ipsec v4 9/9] docs: xfrm: include mark in XFRM_MSG_MIGRATE_STATE EEXIST tuple Antony Antony
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=migrate-state-fixes-v4-0-d5054459fc78@secunet.com \
--to=antony.antony@secunet.com \
--cc=corbet@lwn.net \
--cc=davem@davemloft.net \
--cc=dsahern@kernel.org \
--cc=edumazet@google.com \
--cc=evitayan@google.com \
--cc=fw@strlen.de \
--cc=hadi@cyberus.ca \
--cc=herbert@gondor.apana.org.au \
--cc=horms@kernel.org \
--cc=kuba@kernel.org \
--cc=linux-doc@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=louis.delos.devel@gmail.com \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=paul.chaignon@gmail.com \
--cc=rdunlap@infradead.org \
--cc=sashiko-bot@kernel.org \
--cc=sd@queasysnail.net \
--cc=shuah@kernel.org \
--cc=skhan@linuxfoundation.org \
--cc=stable+noautosel@kernel.org \
--cc=steffen.klassert@secunet.com \
--cc=tobias@strongswan.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®