Date: Thu, 2 Oct 2014 09:32:34 +0200 From: Michael Tuexen <Michael.Tuexen@lurchi.franken.de> To: Bryan Venteicher <bryanv@daemoninthecloset.org> Cc: FreeBSD Net <freebsd-net@freebsd.org> Subject: Re: UDP/IPv6 handling Message-ID: <6AF1921D-BAFB-4969-80EF-C1CE37446D65@lurchi.franken.de> In-Reply-To: <CAMo0n6Q56yvHYp8XUG499gkkxL0=QRdTVDvph9jA=kNL4%2BS-1A@mail.gmail.com> References: <B30E0A41-51B0-442C-9476-0D9E99C0D37C@lurchi.franken.de> <CAMo0n6Q56yvHYp8XUG499gkkxL0=QRdTVDvph9jA=kNL4%2BS-1A@mail.gmail.com>
index | next in thread | previous in thread | raw e-mail
On 02 Oct 2014, at 05:51, Bryan Venteicher <bryanv@daemoninthecloset.org> wrote:
>
>
> On Wed, Oct 1, 2014 at 11:58 AM, Michael Tuexen <Michael.Tuexen@lurchi.franken.de> wrote:
> Dear all,
>
> in udp6_input() we have the following code:
>
> if (nxt == IPPROTO_UDP && plen != ulen) {
> UDPSTAT_INC(udps_badlen);
> goto badunlocked;
> }
> /*
> * Checksum extended UDP header and data.
> */
> if (uh->uh_sum == 0) {
> if (ulen > plen || ulen < sizeof(struct udphdr)) {
> UDPSTAT_INC(udps_nosum);
> goto badunlocked;
> }
> }
>
> I'm trying to understand the UDP code path...
>
>
> ​I too was recently confused by this code. ​I pointed out one issue to kevlo@ recently, but it still kind of seemed like the UDP-Lite was mismerged to IPv6.
I have a patch (to be committed soon which fixes UDPLite/IPv6).
>
> So (ulen > plen) can't be true. I'm wondering why do we only check the ulen is not too
> short only in the case when the UDP checksum is zero. A zero checksum should also never happen.
Yepp.
>
>
> ​I hope to have a patch for ​RFC6935 [1] soon so a zero checksum may be allowed if the inp/udpcb is configured for it.
Great. However, we need to check that ulen is at least sizeof(struct udphdr) in any case.
>
>
> I think we should check for ulen < sizeof(struct udphdr) in any case.
>
>
> ​I think previously, the checks in ip6_input(), IP6_EXTHDR_CHECK(), and plen == ulen made this unnecessary. I think we'd want to do it for UDP-Lite if ulen was not initially zero.
But IP6_EXTHDR_CHECK doesn't check any fields in the packet. So it can happen that plen == ulen and ulen < sizeof(struct udphdr)...
Best regards
Michael
> ​[1] - http://tools.ietf.org/html/rfc6935​
>
> Opinions?
>
> Best regards
> Michael
> _______________________________________________
> freebsd-net@freebsd.org mailing list
> http://lists.freebsd.org/mailman/listinfo/freebsd-net
> To unsubscribe, send any mail to "freebsd-net-unsubscribe@freebsd.org"
>
help
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?6AF1921D-BAFB-4969-80EF-C1CE37446D65>
