Thread (32 messages) 32 messages, 6 authors, 2020-07-01

Re: [regression] TCP_MD5SIG on established sockets

From: Mathieu Desnoyers <mathieu.desnoyers@efficios.com>
Date: 2020-06-30 20:39:54
Also in: lkml

----- On Jun 30, 2020, at 4:30 PM, Eric Dumazet edumazet@google.com wrote:
On Tue, Jun 30, 2020 at 1:21 PM David Miller [off-list ref] wrote:
quoted
From: Linus Torvalds <torvalds@linux-foundation.org>
Date: Tue, 30 Jun 2020 12:43:21 -0700
quoted
If you're not willing to do the work to fix it, I will revert that
commit.
Please let me handle this situation instead of making threats, this
just got reported.

Thank you.
Also keep in mind the commit fixed a security issue, since we were
sending on the wire
garbage bytes from the kernel.

We can not simply revert it and hope for the best.

I find quite alarming vendors still use TCP MD5 "for security
reasons", but none of them have contributed to it in linux kernel
since 2018
(Time of the 'buggy patch')
I'm helping a customer increase their contributions and feedback to upstream.
As we can see, they have accumulated some backlog over time.

Clearly reverting a security fix is not acceptable here. Coming up with a
proper ABI-compatible fix should not be out of our reach though.

Thanks,

Mathieu

-- 
Mathieu Desnoyers
EfficiOS Inc.
http://www.efficios.com
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help