1) Fix a sysbot reported shift-out-of-bounds in xfrm_get_default.
From Pavel Skripkin.
2) Fix XFRM_MSG_MAPPING ABI breakage. The new XFRM_MSG_MAPPING
messages were accidentally not paced at the end.
Fix by Eugene Syromiatnikov.
3) Fix the uapi for the default policy, use explicit field and macros
and make it accessible to userland.
From Nicolas Dichtel.
4) Fix a missing rcu lock in xfrm_notify_userpolicy().
From Nicolas Dichtel.
Please pull or let me know if there are problems.
Thanks!
The following changes since commit 626bf91a292e2035af5b9d9cce35c5c138dfe06d:
Merge tag 'net-5.15-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net (2021-09-07 14:02:58 -0700)
are available in the Git repository at:
git://git.kernel.org/pub/scm/linux/kernel/git/klassert/ipsec.git master
for you to fetch changes up to 93ec1320b0170d7a207eda2d119c669b673401ed:
xfrm: fix rcu lock in xfrm_notify_userpolicy() (2021-09-23 10:11:12 +0200)
----------------------------------------------------------------
Eugene Syromiatnikov (1):
include/uapi/linux/xfrm.h: Fix XFRM_MSG_MAPPING ABI breakage
Nicolas Dichtel (3):
xfrm: make user policy API complete
xfrm: notify default policy on update
xfrm: fix rcu lock in xfrm_notify_userpolicy()
Pavel Skripkin (1):
net: xfrm: fix shift-out-of-bounds in xfrm_get_default
Steffen Klassert (1):
Merge branch 'xfrm: fix uapi for the default policy'
include/uapi/linux/xfrm.h | 15 ++++++----
net/xfrm/xfrm_user.c | 67 +++++++++++++++++++++++++++++++++++++--------
security/selinux/nlmsgtab.c | 4 ++-
3 files changed, 67 insertions(+), 19 deletions(-)
From: Nicolas Dichtel <redacted>
This configuration knob is very sensible, it should be notified when
changing.
Fixes: 2d151d39073a ("xfrm: Add possibility to set the default to block if we have no policy")
Signed-off-by: Nicolas Dichtel <redacted>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
---
net/xfrm/xfrm_user.c | 31 +++++++++++++++++++++++++++++++
1 file changed, 31 insertions(+)
From: Pavel Skripkin <redacted>
Syzbot hit shift-out-of-bounds in xfrm_get_default. The problem was in
missing validation check for user data.
up->dirmask comes from user-space, so we need to check if this value
is less than XFRM_USERPOLICY_DIRMASK_MAX to avoid shift-out-of-bounds bugs.
Fixes: 2d151d39073a ("xfrm: Add possibility to set the default to block if we have no policy")
Reported-and-tested-by: syzbot+b2be9dd8ca6f6c73ee2d@syzkaller.appspotmail.com
Signed-off-by: Pavel Skripkin <redacted>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
---
net/xfrm/xfrm_user.c | 5 +++++
1 file changed, 5 insertions(+)
From: Eugene Syromiatnikov <redacted>
Commit 2d151d39073a ("xfrm: Add possibility to set the default to block
if we have no policy") broke ABI by changing the value of the XFRM_MSG_MAPPING
enum item, thus also evading the build-time check
in security/selinux/nlmsgtab.c:selinux_nlmsg_lookup for presence of proper
security permission checks in nlmsg_xfrm_perms. Fix it by placing
XFRM_MSG_SETDEFAULT/XFRM_MSG_GETDEFAULT to the end of the enum, right before
__XFRM_MSG_MAX, and updating the nlmsg_xfrm_perms accordingly.
Fixes: 2d151d39073a ("xfrm: Add possibility to set the default to block if we have no policy")
References: https://lore.kernel.org/netdev/20210901151402.GA2557@altlinux.org/
Signed-off-by: Eugene Syromiatnikov <redacted>
Acked-by: Antony Antony <redacted>
Acked-by: Nicolas Dichtel <redacted>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
---
include/uapi/linux/xfrm.h | 6 +++---
security/selinux/nlmsgtab.c | 4 +++-
2 files changed, 6 insertions(+), 4 deletions(-)
From a userland POV, this API was based on some magic values:
- dirmask and action were bitfields but meaning of bits
(XFRM_POL_DEFAULT_*) are not exported;
- action is confusing, if a bit is set, does it mean drop or accept?
Let's try to simplify this uapi by using explicit field and macros.
Fixes: 2d151d39073a ("xfrm: Add possibility to set the default to block if we have no policy")
Signed-off-by: Nicolas Dichtel <redacted>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
---
include/uapi/linux/xfrm.h | 9 ++++++---
net/xfrm/xfrm_user.c | 36 +++++++++++++++++++-----------------
2 files changed, 25 insertions(+), 20 deletions(-)
From: Nicolas Dichtel <redacted>
As stated in the comment above xfrm_nlmsg_multicast(), rcu read lock must
be held before calling this function.
Reported-by: syzbot+3d9866419b4aa8f985d6@syzkaller.appspotmail.com
Fixes: 703b94b93c19 ("xfrm: notify default policy on update")
Signed-off-by: Nicolas Dichtel <redacted>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
---
net/xfrm/xfrm_user.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
@@ -1967,6 +1967,7 @@ static int xfrm_notify_userpolicy(struct net *net)intlen=NLMSG_ALIGN(sizeof(*up));structnlmsghdr*nlh;structsk_buff*skb;+interr;skb=nlmsg_new(len,GFP_ATOMIC);if(skb==NULL)
@@ -1988,7 +1989,11 @@ static int xfrm_notify_userpolicy(struct net *net)nlmsg_end(skb,nlh);-returnxfrm_nlmsg_multicast(net,skb,0,XFRMNLGRP_POLICY);+rcu_read_lock();+err=xfrm_nlmsg_multicast(net,skb,0,XFRMNLGRP_POLICY);+rcu_read_unlock();++returnerr;}staticintxfrm_set_default(structsk_buff*skb,structnlmsghdr*nlh,
Hello:
This pull request was applied to netdev/net.git (refs/heads/master)
by Steffen Klassert [off-list ref]:
On Thu, 7 Oct 2021 07:55:19 +0200 you wrote:
1) Fix a sysbot reported shift-out-of-bounds in xfrm_get_default.
From Pavel Skripkin.
2) Fix XFRM_MSG_MAPPING ABI breakage. The new XFRM_MSG_MAPPING
messages were accidentally not paced at the end.
Fix by Eugene Syromiatnikov.
[...]