No description
  • C 98.2%
  • Assembly 1%
  • Makefile 0.3%
  • Shell 0.2%
  • Python 0.1%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Paul Chaignon 86df072c74 xfrm: Sanitize marks before insert
[ Upstream commit 0b91fda3a1f044141e1e615456ff62508c32b202 ]

Prior to this patch, the mark is sanitized (applying the state's mask to
the state's value) only on inserts when checking if a conflicting XFRM
state or policy exists.

We discovered in Cilium that this same sanitization does not occur
in the hot-path __xfrm_state_lookup. In the hot-path, the sk_buff's mark
is simply compared to the state's value:

    if ((mark & x->mark.m) != x->mark.v)
        continue;

Therefore, users can define unsanitized marks (ex. 0xf42/0xf00) which will
never match any packet.

This commit updates __xfrm_state_insert and xfrm_policy_insert to store
the sanitized marks, thus removing this footgun.

This has the side effect of changing the ip output, as the
returned mark will have the mask applied to it when printed.

Fixes: 3d6acfa764 ("xfrm: SA lookups with mark")
Signed-off-by: Paul Chaignon <paul.chaignon@gmail.com>
Signed-off-by: Louis DeLosSantos <louis.delos.devel@gmail.com>
Co-developed-by: Louis DeLosSantos <louis.delos.devel@gmail.com>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-06-04 14:32:35 +02:00
arch MIPS: pm-cps: Use per-CPU variables as per-CPU, not per-core 2025-06-04 14:32:33 +02:00
block
certs
crypto crypto: null - Use spin lock instead of mutex 2025-05-02 07:39:27 +02:00
Documentation x86/bugs: Make spectre user default depend on MITIGATION_SPECTRE_V2 2025-06-04 14:32:32 +02:00
drivers xenbus: Allow PVH dom0 a non-local xenstore 2025-06-04 14:32:35 +02:00
fs __legitimize_mnt(): check for MNT_SYNC_UMOUNT should be under mount_lock 2025-06-04 14:32:35 +02:00
include btrfs: correct the order of prelim_ref arguments in btrfs__prelim_ref 2025-06-04 14:32:35 +02:00
init sched/isolation: Make CONFIG_CPU_ISOLATION depend on CONFIG_SMP 2025-05-02 07:39:28 +02:00
ipc
kernel rcu: handle quiescent states for PREEMPT_RCU=n, PREEMPT_COUNT=y 2025-06-04 14:32:34 +02:00
lib dql: Fix dql->limit value when reset. 2025-06-04 14:32:30 +02:00
LICENSES
mm
net xfrm: Sanitize marks before insert 2025-06-04 14:32:35 +02:00
samples
scripts kbuild: fix argument parsing in scripts/config 2025-06-04 14:32:31 +02:00
security smack: recognize ipv4 CIPSO w/o categories 2025-06-04 14:32:33 +02:00
sound ASoC: Intel: bytcr_rt5640: Add DMI quirk for Acer Aspire SW3-013 2025-06-04 14:32:35 +02:00
tools bpftool: Fix readlink usage in get_fd_type 2025-06-04 14:32:34 +02:00
usr
virt
.clang-format
.cocciconfig
.get_maintainer.ignore
.gitattributes
.gitignore
.mailmap
COPYING
CREDITS
Kbuild
Kconfig
MAINTAINERS
Makefile Linux 5.4.293 2025-05-02 07:39:30 +02:00
README

Linux kernel
============

There are several guides for kernel developers and users. These guides can
be rendered in a number of formats, like HTML and PDF. Please read
Documentation/admin-guide/README.rst first.

In order to build the documentation, use ``make htmldocs`` or
``make pdfdocs``.  The formatted documentation can also be read online at:

    https://www.kernel.org/doc/html/latest/

There are various text files in the Documentation/ subdirectory,
several of them using the Restructured Text markup notation.

Please read the Documentation/process/changes.rst file, as it contains the
requirements for building and running the kernel, and information about
the problems which may result by upgrading your kernel.