On 8/21/26 9:38 AM, Rastislav Szabo wrote:
> TCP-AO keys with TCP_AO_KEYF_IFINDEX store the VRF L3 interface index in
> l3index. tcp_ao_del_cmd() validates the supplied ifindex, but does not
> assign it to its local l3index before matching keys.
> 
> As a result, deleting a key scoped to a non-default VRF always fails with
> ENOENT because it is matched against l3index 0.
> 
> Fixes: 248411b8cb89 ("net/tcp: Wire up l3index to TCP-AO")
> Cc: [email protected]
> Signed-off-by: Rastislav Szabo <[email protected]>
> ---
>  net/ipv4/tcp_ao.c | 3 +++
>  1 file changed, 3 insertions(+)
> 
> diff --git a/net/ipv4/tcp_ao.c b/net/ipv4/tcp_ao.c
> index 5094267447ae..26864621e6de 100644
> --- a/net/ipv4/tcp_ao.c
> +++ b/net/ipv4/tcp_ao.c
> @@ -1834,6 +1834,9 @@ static int tcp_ao_del_cmd(struct sock *sk, unsigned 
> short int family,
>       if (cmd.ifindex && !(cmd.keyflags & TCP_AO_KEYF_IFINDEX))
>               return -EINVAL;
>  
> +     if (cmd.keyflags & TCP_AO_KEYF_IFINDEX)
> +             l3index = cmd.ifindex;
> +
>       ao_info = setsockopt_ao_info(sk);
>       if (IS_ERR(ao_info))
>               return PTR_ERR(ao_info);
> 
> base-commit: 746fc0787f616da418ffc04a110296fe95d53491

Looks correct to me. Dmitry?

Reviewed-by: David Ahern <[email protected]>


Reply via email to