secure_seq: use the 64 bits of the siphash for port offset calculation
commit b2d057560b8107c633b39aabe517ff9d93f285e3 upstream.
SipHash replaced MD5 in secure_ipv{4,6}_port_ephemeral() via commit
7cd23e5300
("secure_seq: use SipHash in place of MD5"), but the output
remained truncated to 32-bit only. In order to exploit more bits from the
hash, let's make the functions return the full 64-bit of siphash_3u32().
We also make sure the port offset calculation in __inet_hash_connect()
remains done on 32-bit to avoid the need for div_u64_rem() and an extra
cost on 32-bit systems.
Cc: Jason A. Donenfeld <Jason@zx2c4.com>
Cc: Moshe Kol <moshe.kol@mail.huji.ac.il>
Cc: Yossi Gilad <yossi.gilad@mail.huji.ac.il>
Cc: Amit Klein <aksecurity@gmail.com>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Signed-off-by: Willy Tarreau <w@1wt.eu>
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
[SG: Adjusted context]
Signed-off-by: Stefan Ghinea <stefan.ghinea@windriver.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
This commit is contained in:

committed by
Greg Kroah-Hartman

parent
33f1b4a27a
commit
a5c68f457f
@@ -419,7 +419,7 @@ static inline void sk_rcv_saddr_set(struct sock *sk, __be32 addr)
|
|||||||
}
|
}
|
||||||
|
|
||||||
int __inet_hash_connect(struct inet_timewait_death_row *death_row,
|
int __inet_hash_connect(struct inet_timewait_death_row *death_row,
|
||||||
struct sock *sk, u32 port_offset,
|
struct sock *sk, u64 port_offset,
|
||||||
int (*check_established)(struct inet_timewait_death_row *,
|
int (*check_established)(struct inet_timewait_death_row *,
|
||||||
struct sock *, __u16,
|
struct sock *, __u16,
|
||||||
struct inet_timewait_sock **));
|
struct inet_timewait_sock **));
|
||||||
|
@@ -4,8 +4,8 @@
|
|||||||
|
|
||||||
#include <linux/types.h>
|
#include <linux/types.h>
|
||||||
|
|
||||||
u32 secure_ipv4_port_ephemeral(__be32 saddr, __be32 daddr, __be16 dport);
|
u64 secure_ipv4_port_ephemeral(__be32 saddr, __be32 daddr, __be16 dport);
|
||||||
u32 secure_ipv6_port_ephemeral(const __be32 *saddr, const __be32 *daddr,
|
u64 secure_ipv6_port_ephemeral(const __be32 *saddr, const __be32 *daddr,
|
||||||
__be16 dport);
|
__be16 dport);
|
||||||
u32 secure_tcp_seq(__be32 saddr, __be32 daddr,
|
u32 secure_tcp_seq(__be32 saddr, __be32 daddr,
|
||||||
__be16 sport, __be16 dport);
|
__be16 sport, __be16 dport);
|
||||||
|
@@ -96,7 +96,7 @@ u32 secure_tcpv6_seq(const __be32 *saddr, const __be32 *daddr,
|
|||||||
}
|
}
|
||||||
EXPORT_SYMBOL(secure_tcpv6_seq);
|
EXPORT_SYMBOL(secure_tcpv6_seq);
|
||||||
|
|
||||||
u32 secure_ipv6_port_ephemeral(const __be32 *saddr, const __be32 *daddr,
|
u64 secure_ipv6_port_ephemeral(const __be32 *saddr, const __be32 *daddr,
|
||||||
__be16 dport)
|
__be16 dport)
|
||||||
{
|
{
|
||||||
const struct {
|
const struct {
|
||||||
@@ -146,7 +146,7 @@ u32 secure_tcp_seq(__be32 saddr, __be32 daddr,
|
|||||||
}
|
}
|
||||||
EXPORT_SYMBOL_GPL(secure_tcp_seq);
|
EXPORT_SYMBOL_GPL(secure_tcp_seq);
|
||||||
|
|
||||||
u32 secure_ipv4_port_ephemeral(__be32 saddr, __be32 daddr, __be16 dport)
|
u64 secure_ipv4_port_ephemeral(__be32 saddr, __be32 daddr, __be16 dport)
|
||||||
{
|
{
|
||||||
net_secret_init();
|
net_secret_init();
|
||||||
return siphash_4u32((__force u32)saddr, (__force u32)daddr,
|
return siphash_4u32((__force u32)saddr, (__force u32)daddr,
|
||||||
|
@@ -504,7 +504,7 @@ not_unique:
|
|||||||
return -EADDRNOTAVAIL;
|
return -EADDRNOTAVAIL;
|
||||||
}
|
}
|
||||||
|
|
||||||
static u32 inet_sk_port_offset(const struct sock *sk)
|
static u64 inet_sk_port_offset(const struct sock *sk)
|
||||||
{
|
{
|
||||||
const struct inet_sock *inet = inet_sk(sk);
|
const struct inet_sock *inet = inet_sk(sk);
|
||||||
|
|
||||||
@@ -734,7 +734,7 @@ EXPORT_SYMBOL_GPL(inet_unhash);
|
|||||||
static u32 table_perturb[1 << INET_TABLE_PERTURB_SHIFT];
|
static u32 table_perturb[1 << INET_TABLE_PERTURB_SHIFT];
|
||||||
|
|
||||||
int __inet_hash_connect(struct inet_timewait_death_row *death_row,
|
int __inet_hash_connect(struct inet_timewait_death_row *death_row,
|
||||||
struct sock *sk, u32 port_offset,
|
struct sock *sk, u64 port_offset,
|
||||||
int (*check_established)(struct inet_timewait_death_row *,
|
int (*check_established)(struct inet_timewait_death_row *,
|
||||||
struct sock *, __u16, struct inet_timewait_sock **))
|
struct sock *, __u16, struct inet_timewait_sock **))
|
||||||
{
|
{
|
||||||
@@ -777,7 +777,9 @@ int __inet_hash_connect(struct inet_timewait_death_row *death_row,
|
|||||||
net_get_random_once(table_perturb, sizeof(table_perturb));
|
net_get_random_once(table_perturb, sizeof(table_perturb));
|
||||||
index = hash_32(port_offset, INET_TABLE_PERTURB_SHIFT);
|
index = hash_32(port_offset, INET_TABLE_PERTURB_SHIFT);
|
||||||
|
|
||||||
offset = (READ_ONCE(table_perturb[index]) + port_offset) % remaining;
|
offset = READ_ONCE(table_perturb[index]) + port_offset;
|
||||||
|
offset %= remaining;
|
||||||
|
|
||||||
/* In first pass we try ports of @low parity.
|
/* In first pass we try ports of @low parity.
|
||||||
* inet_csk_get_port() does the opposite choice.
|
* inet_csk_get_port() does the opposite choice.
|
||||||
*/
|
*/
|
||||||
@@ -854,7 +856,7 @@ ok:
|
|||||||
int inet_hash_connect(struct inet_timewait_death_row *death_row,
|
int inet_hash_connect(struct inet_timewait_death_row *death_row,
|
||||||
struct sock *sk)
|
struct sock *sk)
|
||||||
{
|
{
|
||||||
u32 port_offset = 0;
|
u64 port_offset = 0;
|
||||||
|
|
||||||
if (!inet_sk(sk)->inet_num)
|
if (!inet_sk(sk)->inet_num)
|
||||||
port_offset = inet_sk_port_offset(sk);
|
port_offset = inet_sk_port_offset(sk);
|
||||||
|
@@ -308,7 +308,7 @@ not_unique:
|
|||||||
return -EADDRNOTAVAIL;
|
return -EADDRNOTAVAIL;
|
||||||
}
|
}
|
||||||
|
|
||||||
static u32 inet6_sk_port_offset(const struct sock *sk)
|
static u64 inet6_sk_port_offset(const struct sock *sk)
|
||||||
{
|
{
|
||||||
const struct inet_sock *inet = inet_sk(sk);
|
const struct inet_sock *inet = inet_sk(sk);
|
||||||
|
|
||||||
@@ -320,7 +320,7 @@ static u32 inet6_sk_port_offset(const struct sock *sk)
|
|||||||
int inet6_hash_connect(struct inet_timewait_death_row *death_row,
|
int inet6_hash_connect(struct inet_timewait_death_row *death_row,
|
||||||
struct sock *sk)
|
struct sock *sk)
|
||||||
{
|
{
|
||||||
u32 port_offset = 0;
|
u64 port_offset = 0;
|
||||||
|
|
||||||
if (!inet_sk(sk)->inet_num)
|
if (!inet_sk(sk)->inet_num)
|
||||||
port_offset = inet6_sk_port_offset(sk);
|
port_offset = inet6_sk_port_offset(sk);
|
||||||
|
Reference in New Issue
Block a user