Re: [PATCH net 1/2] net/iucv: drop HiperSockets frames from other network namespaces

Alexandra Winter <[email protected]>
Newsgroups org.kernel.vger.linux-s390,org.kernel.vger.linux-kernel,org.kernel.vger.netdev
Message-ID <[email protected]>

On 21.08.26 13:42, Bryam Vargas wrote:
> Alexandra,
> 
>> I am wondering whether a check of
>> +		if (iucv_sk(sk)->hs_dev != dev)
>> +			continue;
>>
>> would cover a broader range of issues.
> 
> It does, and I'd rather have yours than mine. It covers three things at
> once: the namespace case, since hs_dev can only come from the init_net scan
> in iucv_sock_bind(); the transport case the earlier patch went after, since
> classic sockets have hs_dev == NULL and drop out of the walk; and delivery
> to a socket bound to a different HiperSockets device.
> 
> I went looking for the regression it could carry -- an accept-queue child
> left without hs_dev, which would break connection setup -- and it isn't
> there. The child inherits at af_iucv.c:1908.
> 
> One thing it doesn't reach, and it's why I'm not dropping both: the check
> sits after EBCASC() has already rewritten the transport header in place at
> :2073-2076, and a SYN matching no socket still takes the !iucv branch at
> :1872-1877, which swaps the frame and hands it to dev_queue_xmit(). So it
> replaces 1/2 and stays complementary to 2/2.
> 
> Send yours and I'll drop 1/2.
> 
> Thanks,
> Bryam
> 


Thank you very much Bryam, I fully agree.

I've sent R-b for 2/2, and propose to take it as it is.

See https://lore.kernel.org/netdev/[email protected]/
for my proposal that should supersede 1/2.
Your review would be highly appreciated.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.