From: Willem de Bruijn <[email protected]>

The receiver process uses a PF_PACKET socket to verify incoming packets
and test hardware checksum offload. While the socket filter matches the
protocol and destination port, packet verification did not validate the
packet source address or source port.

If background traffic arrives at the destination port from an unrelated
sender, the receiver attempts to verify it. During tests expecting an
invalid checksum (-E), any legitimate background packet with a valid
checksum causes the receiver to report a checksum error and fail the test.

Add source address and source port verification in recv_verify_packet_*:
Non-matching packets return -1 and are skipped.

Also
- add an inter-packet delay to avoid drops from bursts.
- remove a comment that is no longer correct.

Fixes: 91a7de85600d ("selftests/net: add csum offload test")
Signed-off-by: Willem de Bruijn <[email protected]>
---
 tools/testing/selftests/net/lib/csum.c | 18 ++++++++++++++++--
 1 file changed, 16 insertions(+), 2 deletions(-)

diff --git a/tools/testing/selftests/net/lib/csum.c 
b/tools/testing/selftests/net/lib/csum.c
index e28884ce3ab3..139465054f85 100644
--- a/tools/testing/selftests/net/lib/csum.c
+++ b/tools/testing/selftests/net/lib/csum.c
@@ -2,8 +2,7 @@
 
 /* Test hardware checksum offload: Rx + Tx, IPv4 + IPv6, TCP + UDP.
  *
- * The test runs on two machines to exercise the NIC. For this reason it
- * is not integrated in kselftests.
+ * The test runs on two machines to exercise the NIC.
  *
  *     CMD=$((./csum -[46] -[tu] -S $SADDR -D $DADDR -[RT] -r 1 $EXTRA_ARGS))
  *
@@ -620,6 +619,9 @@ static int recv_verify_packet_tcp(void *th, int len)
        if (len < sizeof(*tcph) || tcph->dest != htons(cfg_port_dst))
                return -1;
 
+       if (tcph->source != htons(cfg_port_src))
+               return -1;
+
        return recv_verify_csum(th, len, ntohs(tcph->source), tcph->check);
 }
 
@@ -647,6 +649,9 @@ static int recv_verify_packet_udp(void *th, int len)
                return recv_verify_packet_udp_encap(udph + 1,
                                                    len - sizeof(*udph));
 
+       if (!cfg_zero_sum && udph->source != htons(cfg_port_src))
+               return -1;
+
        return recv_verify_csum(th, len, ntohs(udph->source), udph->check);
 }
 
@@ -659,6 +664,9 @@ static int recv_verify_packet_ipv4(void *nh, int len)
        if (len < sizeof(*iph) || iph->protocol != proto)
                return -1;
 
+       if (iph->saddr != cfg_saddr4.sin_addr.s_addr)
+               return -1;
+
        ip_len = ntohs(iph->tot_len);
        if (ip_len > len || ip_len < sizeof(*iph))
                return -1;
@@ -680,6 +688,9 @@ static int recv_verify_packet_ipv6(void *nh, int len)
        if (len < sizeof(*ip6h) || ip6h->nexthdr != proto)
                return -1;
 
+       if (memcmp(&ip6h->saddr, &cfg_saddr6.sin6_addr, sizeof(ip6h->saddr)))
+               return -1;
+
        payload_len = ntohs(ip6h->payload_len);
        if (payload_len > len - sizeof(*ip6h))
                return -1;
@@ -940,6 +951,9 @@ static void do_tx(void)
                        cfg_payload_len = rand() % MAX_PAYLOAD_LEN;
                        buf = build_packet(_buf, sizeof(_buf), &len);
                }
+
+               /* avoid bursting */
+               usleep(20);
        }
 
        if (close(fd))
-- 
2.55.0.897.gb25b4bd76c-goog


Reply via email to