2026-09-27, 01:03:24 -0400, Haseeb Malik via B4 Relay wrote:
> From: Haseeb Malik <[email protected]>
> 
> An all-ones IFLA_MACSEC_SCI selects the default SCI derived from the
> MACsec device's MAC address and port 1. macsec_init_secy() resolves this
> value and stores the result in secy.sci, but macsec_newlink() checks for
> duplicates using the unchanged local sci argument.
> 
> Consequently, an all-ones request can create a second MACsec device with
> the same transmit SCI on the same lower device, while requesting that
> SCI explicitly returns -EBUSY.
> 
> Check the initialized SecY's SCI so that duplicate detection uses the
> value that the new device will actually use. Preserve the all-ones
> fallback when the resulting SCI is available.

Or move that fallback from macsec_init_secy to macsec_newlink? That'd
be a bit cleaner than hiding a rewrite of the value in some other
function, and then having to go fetch it.

Something like:

macsec_newlink()
{
        sci_t sci = MACSEC_UNDEF_SCI;

...
        if (data && data[IFLA_MACSEC_SCI])
                sci = nla_get_sci(data[IFLA_MACSEC_SCI]);
        else if (data && data[IFLA_MACSEC_PORT])
                sci = dev_to_sci(dev, nla_get_be16(data[IFLA_MACSEC_PORT]));

        if (sci == MACSEC_UNDEF_SCI)
                sci = dev_to_sci(dev, MACSEC_PORT_ES);
...
}



And after your previous patch, we could also move the sci_exists
check up after determining the sci, there's no reason to do it after
registering anymore. since I didn't notice that while reviewing your
previous patch, that should be done in net-next once net and this new
fix gets merged into it.

> Add regression tests for duplicate rejection using default, explicit and
> all-ones SCI requests, and for valid fallback and reuse after deletion.
> The same tests reproduce two failures before the fix and pass afterward.

Nice.

-- 
Sabrina

Reply via email to