Thread (5 messages) 5 messages, 3 authors, 26d ago

[PATCH net-next 1/2] netlink: specs: tcp_metrics: fix the attribute length checks

flat view
COLD26d IN NET-NEXT

From: Jakub Kicinski <kuba@kernel.org>
Date: 2026-09-12 23:43:42
Subsystem: networking [general], the rest, yaml netlink (ynl) · Maintainers: "David S. Miller", Eric Dumazet, Jakub Kicinski, Paolo Abeni, Linus Torvalds, Donald Hunter

Queued in net-next as 4358a3e8e7cc on 2026-09-15.

TCP_FASTOPEN_COOKIE_MAX is the longest cookie we accept, not the shortest
one. Cookies are even sized, from 4 bytes up, and the ones Linux itself
generates are 8 bytes, so a 16 byte minimum declares all but the longest
cookie invalid. The reference policy kept under #if 0 in tcp_metrics.c
spells it as a maximum, which is what .len means for NLA_BINARY.

The IPv6 addresses err the other way. The policy uses
NLA_POLICY_EXACT_LEN() for both, so a request carrying a longer address is
rejected with -ERANGE, even though the spec advertises 16 bytes as a mere
minimum. Were the policy generated from this spec, as kernel-policy: global
promises, the check would turn into NLA_POLICY_MIN_LEN() and start
accepting over-long addresses, of which nla_get_in6_addr() would take the
first 16 bytes.

Nothing generated changes. fopen-cookie is reply-only so it never gets a
policy entry, and exact-len only feeds the policy (and the fixed size array
form, which needs a sub-type).

Signed-off-by: Jakub Kicinski <kuba@kernel.org>
---
 Documentation/netlink/specs/tcp_metrics.yaml | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/Documentation/netlink/specs/tcp_metrics.yaml b/Documentation/netlink/specs/tcp_metrics.yaml
index 13144aeed31a..1d365908084d 100644
--- a/Documentation/netlink/specs/tcp_metrics.yaml
+++ b/Documentation/netlink/specs/tcp_metrics.yaml
@@ -32,7 +32,7 @@ kernel-policy: global
         name: addr-ipv6
         type: binary
         checks:
-          min-len: 16
+          exact-len: 16
         byte-order: big-endian
         display-hint: ipv6
       -
@@ -63,7 +63,7 @@ kernel-policy: global
         name: fopen-cookie
         type: binary
         checks:
-          min-len: tcp-fastopen-cookie-max
+          max-len: tcp-fastopen-cookie-max
       -
         name: saddr-ipv4
         type: u32
@@ -73,7 +73,7 @@ kernel-policy: global
         name: saddr-ipv6
         type: binary
         checks:
-          min-len: 16
+          exact-len: 16
         byte-order: big-endian
         display-hint: ipv6
       -
-- 
2.55.0
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help