mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH ipsec v4 0/9] xfrm: state: exact mark/mask match for control-plane SA lookups
@ 2026-10-06  7:03 Antony Antony
  2026-10-06  7:03 ` [PATCH ipsec v4 1/9] xfrm: state: reject mark with bits outside its mask on add Antony Antony
                   ` (8 more replies)
  0 siblings, 9 replies; 10+ messages in thread
From: Antony Antony @ 2026-10-06  7:03 UTC (permalink / raw)
  To: Antony Antony, Steffen Klassert, Herbert Xu, David S. Miller,
	Eric Dumazet, Jakub Kicinski, Paolo Abeni, Simon Horman,
	David Ahern, Jamal Hadi Salim, Shuah Khan, Paul Chaignon,
	Louis DeLosSantos, Jonathan Corbet, Shuah Khan, Randy Dunlap
  Cc: Sabrina Dubroca, netdev, Yan Yan, Tobias Brunner,
	Florian Westphal, linux-doc, linux-kernel, stable+noautosel,
	Sashiko

While looking into a XFRM_MSG_MIGRATE_STATE issue reported by Sashiko,
we found the underlying problem generalizes: xfrm allows multiple SAs
to coexist for the same (SPI, daddr, proto) differing only in mark,
and every netlink method that resolves "which SA" - xfrm get_sa(),
del_sa(), update, get_ae, new_ae, expire, migrate - uses the same
wildcard mark match the data path needs. A broader-mask SA can
silently shadow a more specific one:

  # ip xfrm state add ... spi 0x1000 mark 1 mask 1 (SA_target)
  # ip xfrm state add ... spi 0x1000 mark 0 mask 0
    (SA_decoy, catch-all, added after -> bucket head)
  # ip xfrm state delete dst ... proto esp spi 0x1000 mark 1 mask 1
    -> deletes SA_decoy; SA_target survives, untouched

xfrm policy had the same bug, fixed in commit 4f47e8ab6ab7
("xfrm: policy: match with both mark and mask on user interfaces").

Netlink state lookups using spi use an exact mark/mask match except
for UPDSA; the wildcard match stays for the data path and state_add only.
This series applies that fix across every affected method,
not just XFRM_MSG_MIGRATE_STATE.

Also reject marks with value bits outside the mask (state add,
ALLOCSPI, policy add). These are misconfigurations anyway, since
the extra bits can never match, and break exact match added here.

This series does not touch PF_KEY, which no longer receives
non-critical fixes.

state_lookup_byaddr is out of scope. This is only fixing spi based
lookups.

---
v3->v4: add 3 patches to reject mark value bits outside the mask for state and policy

- Link to v3: https://patch.msgid.link/migrate-state-fixes-v3-6-836125bb53dd@secunet.com

v2->v3: mark match use only values and no mask in exact lookup

- Link to v2: https://lore.kernel.org/all/migrate-state-fixes-v2-0-c3e2767f0d96@secunet.com/
v1->v2: few more wildcard mark check reported by sashiko and Yan
      - keep wildcard match in xfrm_state_update() (UPDSA)

- Link to v1: https://patch.msgid.link/migrate-state-fixes-v0-8-a69e8637ba3b@secunet.com

To: Steffen Klassert <steffen.klassert@secunet.com>
To: Herbert Xu <herbert@gondor.apana.org.au>
To: "David S. Miller" <davem@davemloft.net>
To: Eric Dumazet <edumazet@google.com>
To: Jakub Kicinski <kuba@kernel.org>
To: Paolo Abeni <pabeni@redhat.com>
To: Simon Horman <horms@kernel.org>
To: Paul Chaignon <paul.chaignon@gmail.com>
To: Louis DeLosSantos <louis.delos.devel@gmail.com>
To: Jamal Hadi Salim <hadi@cyberus.ca>
To: Antony Antony <antony.antony@secunet.com>
To: Sabrina Dubroca <sd@queasysnail.net>
To: Jonathan Corbet <corbet@lwn.net>
To: Shuah Khan <skhan@linuxfoundation.org>
To: Randy Dunlap <rdunlap@infradead.org>
Cc: netdev@vger.kernel.org
Cc: linux-kernel@vger.kernel.org
Cc: linux-doc@vger.kernel.org

---
Antony Antony (9):
      xfrm: state: reject mark with bits outside its mask on add
      xfrm: state: reject mark with bits outside its mask on ALLOCSPI
      xfrm: policy: reject mark with bits outside its mask on add
      xfrm: state: exact mark/mask match for SPI-keyed control-plane SA lookups
      xfrm: fix use-after-free of migrated state in xfrm_do_migrate_state()
      xfrm: fix hw offload state leak on xfrm_do_migrate_state() error path
      xfrm: include mark in MIGRATE_STATE SA collision check
      xfrm: pass extack through to xfrm_init_replay() from xfrm_init_state()
      docs: xfrm: include mark in XFRM_MSG_MIGRATE_STATE EEXIST tuple

 .../networking/xfrm/xfrm_migrate_state.rst         |  25 +++--
 include/net/xfrm.h                                 |   7 ++
 net/xfrm/xfrm_state.c                              | 101 +++++++++++++++++----
 net/xfrm/xfrm_user.c                               |  81 ++++++++++++-----
 4 files changed, 166 insertions(+), 48 deletions(-)
---
base-commit: 86de3a1118a16dbbbe5fabe9aa20ffb93c072ed5
change-id: migrate-state-fixes-063ee0342611

Best regards,
--  
Antony Antony <antony.antony@secunet.com>


^ permalink raw reply	[flat|nested] 10+ messages in thread

end of thread, other threads:[~2026-10-06  7:06 UTC | newest]

Thread overview: 10+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-06  7:03 [PATCH ipsec v4 0/9] xfrm: state: exact mark/mask match for control-plane SA lookups Antony Antony
2026-10-06  7:03 ` [PATCH ipsec v4 1/9] xfrm: state: reject mark with bits outside its mask on add Antony Antony
2026-10-06  7:04 ` [PATCH ipsec v4 2/9] xfrm: state: reject mark with bits outside its mask on ALLOCSPI Antony Antony
2026-10-06  7:04 ` [PATCH ipsec v4 3/9] xfrm: policy: reject mark with bits outside its mask on add Antony Antony
2026-10-06  7:05 ` [PATCH ipsec v4 4/9] xfrm: state: exact mark/mask match for SPI-keyed control-plane SA lookups Antony Antony
2026-10-06  7:05 ` [PATCH ipsec v4 5/9] xfrm: fix use-after-free of migrated state in xfrm_do_migrate_state() Antony Antony
2026-10-06  7:06 ` [PATCH ipsec v4 6/9] xfrm: fix hw offload state leak on xfrm_do_migrate_state() error path Antony Antony
2026-10-06  7:06 ` [PATCH ipsec v4 7/9] xfrm: include mark in MIGRATE_STATE SA collision check Antony Antony
2026-10-06  7:06 ` [PATCH ipsec v4 8/9] xfrm: pass extack through to xfrm_init_replay() from xfrm_init_state() Antony Antony
2026-10-06  7:06 ` [PATCH ipsec v4 9/9] docs: xfrm: include mark in XFRM_MSG_MIGRATE_STATE EEXIST tuple Antony Antony

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®