WireGuard Archive on lore.kernel.org
 help / color / Atom feed
From: Quan Zhou <quan@posteo.net>
To: wireguard@lists.zx2c4.com
Subject: Re: [PATCH net] wireguard: device: provide sane limits for mtu setting
Date: Fri, 14 Feb 2020 18:11:54 +0800
Message-ID: <daa4be50-7883-a4ea-4b8e-3a32698ea0a9@posteo.net> (raw)
In-Reply-To: <E4D4DA63-F22C-47B4-A039-D787D70007A2@samirnassar.com>

Hi Samir,

I didn't realize this. You convinced me on this one. Thanks!

On 2/14/20 15:11, Samir Nassar wrote:
> Hello,
>
> from https://github.com/google/syzkaller/blob/master/docs/syzbot.md
>
> "syzbot system continuously fuzzes main Linux kernel branches and automatically reports found bugs to kernel mailing lists."
>
> As I understand it, fuzzing is applying changes to inputs to see what breaks and, in this case, fix it.
>
> It doesn't make sense to set an MTU to 0 so why allow the program to crash on setting the MTU to zero instead of giving back a useful error or preventing the crash in other ways.
>
> Providing dev->min_mtu and dev->max_mtu bounds is a nice thing to do.
>
> Samir
>
> On February 14, 2020 7:40:23 AM GMT+01:00, Quan Zhou <quan@posteo.net> wrote:
>> I'm just curious, under what circumstances would people set mtu to
>> zero?
>>
>> On 2/14/20 14:38, Eric Dumazet wrote:
>>> If wireguard device mtu is set to zero, a divide by zero
>>> crash happens in calculate_skb_padding().
>>>
>>> This patch provides dev->min_mtu and dev->max_mtu bounds.
>>>
>>> Fixes: e7096c131e51 ("net: WireGuard secure network tunnel")
>>> Signed-off-by: Eric Dumazet <edumazet@google.com>
>>> Reported-by: syzbot <syzkaller@googlegroups.com>
>>> Cc: Jason A. Donenfeld <Jason@zx2c4.com>
>>> Cc: wireguard@lists.zx2c4.com
>>> ---
>>>    drivers/net/wireguard/device.c | 5 +++++
>>>    1 file changed, 5 insertions(+)
>>>
>>> diff --git a/drivers/net/wireguard/device.c
>> b/drivers/net/wireguard/device.c
>>> index
>> 43db442b1373073eaf5e805cfe6cfee15875437a..c02b84cca122d92ee8a81c5efdcf67aada2554d6
>> 100644
>>> --- a/drivers/net/wireguard/device.c
>>> +++ b/drivers/net/wireguard/device.c
>>> @@ -271,9 +271,14 @@ static void wg_setup(struct net_device *dev)
>>>    	dev->features |= WG_NETDEV_FEATURES;
>>>    	dev->hw_features |= WG_NETDEV_FEATURES;
>>>    	dev->hw_enc_features |= WG_NETDEV_FEATURES;
>>> +
>>>    	dev->mtu = ETH_DATA_LEN - MESSAGE_MINIMUM_LENGTH -
>>>    		   sizeof(struct udphdr) -
>>>    		   max(sizeof(struct ipv6hdr), sizeof(struct iphdr));
>>> +	dev->min_mtu = MESSAGE_PADDING_MULTIPLE;
>>> +	dev->max_mtu = ETH_MAX_MTU - MESSAGE_MINIMUM_LENGTH -
>>> +		       sizeof(struct udphdr) -
>>> +		       max(sizeof(struct ipv6hdr), sizeof(struct iphdr));
>>>    
>>>    	SET_NETDEV_DEVTYPE(dev, &device_type);
>>>    
>> _______________________________________________
>> WireGuard mailing list
>> WireGuard@lists.zx2c4.com
>> https://lists.zx2c4.com/mailman/listinfo/wireguard
_______________________________________________
WireGuard mailing list
WireGuard@lists.zx2c4.com
https://lists.zx2c4.com/mailman/listinfo/wireguard

  reply index

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2020-02-14  6:38 Eric Dumazet
2020-02-14  6:40 ` Quan Zhou
2020-02-14  7:11   ` Samir Nassar
2020-02-14 10:11     ` Quan Zhou [this message]
2020-02-14  9:11 ` Jason A. Donenfeld

Reply instructions:

You may reply publically to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=daa4be50-7883-a4ea-4b8e-3a32698ea0a9@posteo.net \
    --to=quan@posteo.net \
    --cc=wireguard@lists.zx2c4.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link

WireGuard Archive on lore.kernel.org

Archives are clonable:
	git clone --mirror https://lore.kernel.org/wireguard/0 wireguard/git/0.git

	# If you have public-inbox 1.1+ installed, you may
	# initialize and index your mirror using the following commands:
	public-inbox-init -V2 wireguard wireguard/ https://lore.kernel.org/wireguard \
		wireguard@lists.zx2c4.com
	public-inbox-index wireguard

Example config snippet for mirrors

Newsgroup available over NNTP:
	nntp://nntp.lore.kernel.org/com.zx2c4.lists.wireguard


AGPL code for this site: git clone https://public-inbox.org/public-inbox.git