Re: [PATCH net 1/2] net/tcp: fix TCP-AO key deletion in VRFs

David Ahern <[email protected]>
Newsgroups org.kernel.vger.linux-kselftest,org.kernel.vger.netdev
Message-ID <[email protected]>
On 8/21/26 9:38 AM, Rastislav Szabo wrote:
> TCP-AO keys with TCP_AO_KEYF_IFINDEX store the VRF L3 interface index in
> l3index. tcp_ao_del_cmd() validates the supplied ifindex, but does not
> assign it to its local l3index before matching keys.
> 
> As a result, deleting a key scoped to a non-default VRF always fails with
> ENOENT because it is matched against l3index 0.
> 
> Fixes: 248411b8cb89 ("net/tcp: Wire up l3index to TCP-AO")
> Cc: [email protected]
> Signed-off-by: Rastislav Szabo <[email protected]>
> ---
>  net/ipv4/tcp_ao.c | 3 +++
>  1 file changed, 3 insertions(+)
> 
> diff --git a/net/ipv4/tcp_ao.c b/net/ipv4/tcp_ao.c
> index 5094267447ae..26864621e6de 100644
> --- a/net/ipv4/tcp_ao.c
> +++ b/net/ipv4/tcp_ao.c
> @@ -1834,6 +1834,9 @@ static int tcp_ao_del_cmd(struct sock *sk, unsigned short int family,
>  	if (cmd.ifindex && !(cmd.keyflags & TCP_AO_KEYF_IFINDEX))
>  		return -EINVAL;
>  
> +	if (cmd.keyflags & TCP_AO_KEYF_IFINDEX)
> +		l3index = cmd.ifindex;
> +
>  	ao_info = setsockopt_ao_info(sk);
>  	if (IS_ERR(ao_info))
>  		return PTR_ERR(ao_info);
> 
> base-commit: 746fc0787f616da418ffc04a110296fe95d53491

Looks correct to me. Dmitry?

Reviewed-by: David Ahern <[email protected]>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.