Received: by 2002:a05:6a10:c604:0:0:0:0 with SMTP id y4csp3158113pxt; Mon, 9 Aug 2021 18:58:25 -0700 (PDT) X-Google-Smtp-Source: ABdhPJxTjBkxkEELe5AA4kiZdjyghDAxW3z9r/XQVzOfA+O8She6ed2B+MWDJwkoVt+h2qCRiUmh X-Received: by 2002:a5d:8907:: with SMTP id b7mr46594ion.124.1628560705438; Mon, 09 Aug 2021 18:58:25 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1628560705; cv=none; d=google.com; s=arc-20160816; b=LQKp+t1aJZ9yrODostb5mH9XKQYjlQ/7g7Gqn7nG0O7pKA7Aoa6Ax2ICpj6cX9xqJf YBE5HqFxafLJEkBrlkOL5TykTW0MTwh8SPaaW15OOxV9QohMesVDtmbqfdwITVY1fYFM 8rrZrbiAH9rj8NVUO0wWJWyyo12xjV5x4OfhYzrPHHZzcj+Afmc/6FiGHNgw9aYLDvDL 94XKUT5IBbFYtvKbqgcYyLy3ZbZp1qw8SYFTeHKIulQypAmm4+p3NKBakSjVqY9+v6PM hjgU0OD8ZZXFoJkt7Vi8bNnwtC6T6ygIRuSUyfRX5dyZdNXQjkptJ8aERzpFaD/vhR5L UtEQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:mime-version :references:in-reply-to:message-id:date:subject:cc:to:from :dkim-signature; bh=uG3oHTASBquJceLiOdEfcWQQkF/eH5moDohL/r9HsUw=; b=JxzwAHJRImuER70d40RMYVZulr6NiKhyyedqy/iKLgA9NYNGcBZPGEwxqOae0v9Ha9 7px+G9ZFeSM5PfzIKAkk9KlKFQBTy/yJSLcizWUecGcoVN+vw8Rvei4zER1BdN78DikB f5HTe2lqWnRUoUcCCCeZ5E9jmNbqMMlqY/BZ1LcCtuL3q/qzMVBIO5Q4beuvbHedHC8g 9Uq2XT/ZbBNoKJ7xkqdbUm1/ebMh0D2VxyUM0mYcqd27GfoZHX6El2wZMI335I0xgKOE jf7yBhFozsW9JGrUKgva4QYDdBhJ2NTJ7+nsGhEUw/+zkamUOa8lTCrE4UqV4qDfPMp6 ltnQ== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@gmail.com header.s=20161025 header.b=rcgmuQw6; spf=pass (google.com: domain of linux-crypto-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-crypto-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id x4si21996538ilj.71.2021.08.09.18.58.13; Mon, 09 Aug 2021 18:58:25 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-crypto-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; dkim=pass header.i=@gmail.com header.s=20161025 header.b=rcgmuQw6; spf=pass (google.com: domain of linux-crypto-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-crypto-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S236680AbhHIVgt (ORCPT + 99 others); Mon, 9 Aug 2021 17:36:49 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:58664 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S236517AbhHIVgY (ORCPT ); Mon, 9 Aug 2021 17:36:24 -0400 Received: from mail-ed1-x52f.google.com (mail-ed1-x52f.google.com [IPv6:2a00:1450:4864:20::52f]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id F10ABC0617A4; Mon, 9 Aug 2021 14:36:00 -0700 (PDT) Received: by mail-ed1-x52f.google.com with SMTP id f13so26778619edq.13; Mon, 09 Aug 2021 14:36:00 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:date:message-id:in-reply-to:references :mime-version:content-transfer-encoding; bh=uG3oHTASBquJceLiOdEfcWQQkF/eH5moDohL/r9HsUw=; b=rcgmuQw6H5q2JM/IgIbadWTq3WVWGRiwykKjM/MnB18T5J2L2R+Vj9MAujuT+uedO4 ChMLLu1nKya6brD5LiIMGPVoTNpTnC6UnxzfgJNq7tRuwYL5RFDxzJq79BglW8BHVpke avUQEeUQ0pb2pCJKp9UNjJ79KaXeusdkw7zSTsg9aMYKYyKKhiqgnOTINpfn98U7uR6M PCd8RDtZv9CgUijpeT0MO3KaVsXy4casrSuZbz0EtZfS65SuV/KvXWkEJ5Boce4BTK9a 2VEWY+px19NfwLPo3qOkJQcoeJgFA1QKpOD8WHi3cSeEoijMOEpOyKETPyBDzYjFLt2g JVBQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:mime-version:content-transfer-encoding; bh=uG3oHTASBquJceLiOdEfcWQQkF/eH5moDohL/r9HsUw=; b=Q5F0mK/EzZR6oRs89SsCMA7uJ6u0bCWCVdMgS5wvEL+gTV2mdbCNa069hQ5DA5B0x3 45MN4RMqO/eLxBusrRqi2YMJB/0HHqTjEIZaRE1UXYwWmd2GMgOHg4y5pf6qLgj7ulMq 0yPAXxjhl6PrNHorPF8aCz6LHiGXM+8pskGrb3tqpmYZsMJ14sn1rEFwhKSNF1no9wJ9 kDQAAAMmyrwN5KivT7gMJCUqGGWXedwEdWafQeez/65j76jCRO37T2ETpcvTxNC+esXM aN/vDKvexvr6RY4nJieoTsqj9mMuE/IhVooJm3SVzlb/b8V0gbqQLBF6Yg0e//Gs5XeP 97Ug== X-Gm-Message-State: AOAM53206pcGKAh95sYarvCALHeQ3FsPNrMhvGsYq0qpUQt3xsbObCoh lGxL6F+aWcAxFZ+lnWR6l0M= X-Received: by 2002:a50:ac82:: with SMTP id x2mr461232edc.350.1628544959642; Mon, 09 Aug 2021 14:35:59 -0700 (PDT) Received: from localhost.localdomain ([2a04:241e:502:1d80:688d:23e:82c6:84aa]) by smtp.gmail.com with ESMTPSA id v24sm5542932edt.41.2021.08.09.14.35.58 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 09 Aug 2021 14:35:59 -0700 (PDT) From: Leonard Crestez To: Eric Dumazet , "David S. Miller" , Herbert Xu , Kuniyuki Iwashima , David Ahern Cc: Hideaki YOSHIFUJI , Jakub Kicinski , Yuchung Cheng , Francesco Ruggeri , Mat Martineau , Christoph Paasch , Ivan Delalande , Priyaranjan Jha , Menglong Dong , linux-kernel@vger.kernel.org, linux-crypto@vger.kernel.org, netdev@vger.kernel.org Subject: [RFCv2 8/9] selftests: Initial TCP-AO support for nettest Date: Tue, 10 Aug 2021 00:35:37 +0300 Message-Id: <909135b0313fc7b4bb8dbbd7686770483887ccc1.1628544649.git.cdleonard@gmail.com> X-Mailer: git-send-email 2.25.1 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Precedence: bulk List-ID: X-Mailing-List: linux-crypto@vger.kernel.org Signed-off-by: Leonard Crestez --- tools/testing/selftests/net/nettest.c | 43 ++++++++++++++++++++++++++- 1 file changed, 42 insertions(+), 1 deletion(-) diff --git a/tools/testing/selftests/net/nettest.c b/tools/testing/selftests/net/nettest.c index bd6288302094..48d8f3a6eb27 100644 --- a/tools/testing/selftests/net/nettest.c +++ b/tools/testing/selftests/net/nettest.c @@ -100,10 +100,12 @@ struct sock_args { struct sockaddr_in v4; struct sockaddr_in6 v6; } md5_prefix; unsigned int prefix_len; + const char *authopt_password; + /* expected addresses and device index for connection */ const char *expected_dev; const char *expected_server_dev; int expected_ifindex; @@ -250,10 +252,36 @@ static int switch_ns(const char *ns) close(fd); return ret; } +static int tcp_set_authopt(int sd, struct sock_args *args) +{ + struct tcp_authopt info; + struct tcp_authopt_key key; + int rc; + + memset(&info, 0, sizeof(info)); + info.local_send_id = 1; + + rc = setsockopt(sd, IPPROTO_TCP, TCP_AUTHOPT, &info, sizeof(info)); + if (rc < 0) + log_err_errno("setsockopt(TCP_AUHTOPT_KEY)"); + + memset(&key, 0, sizeof(key)); + strcpy((char *)key.key, args->authopt_password); + key.keylen = strlen(args->authopt_password); + key.alg = TCP_AUTHOPT_ALG_HMAC_SHA_1_96; + key.local_id = 1; + + rc = setsockopt(sd, IPPROTO_TCP, TCP_AUTHOPT_KEY, &key, sizeof(key)); + if (rc < 0) + log_err_errno("setsockopt(TCP_AUHTOPT_KEY)"); + + return rc; +} + static int tcp_md5sig(int sd, void *addr, socklen_t alen, struct sock_args *args) { int keylen = strlen(args->password); struct tcp_md5sig md5sig = {}; int opt = TCP_MD5SIG; @@ -1508,10 +1536,15 @@ static int do_server(struct sock_args *args, int ipc_fd) if (args->password && tcp_md5_remote(lsd, args)) { close(lsd); goto err_exit; } + if (args->authopt_password && tcp_set_authopt(lsd, args)) { + close(lsd); + goto err_exit; + } + ipc_write(ipc_fd, 1); while (1) { log_msg("waiting for client connection.\n"); FD_ZERO(&rfds); FD_SET(lsd, &rfds); @@ -1630,10 +1663,13 @@ static int connectsock(void *addr, socklen_t alen, struct sock_args *args) goto out; if (args->password && tcp_md5sig(sd, addr, alen, args)) goto err; + if (args->authopt_password && tcp_set_authopt(sd, args)) + goto err; + if (args->bind_test_only) goto out; if (connect(sd, addr, alen) < 0) { if (errno != EINPROGRESS) { @@ -1819,11 +1855,11 @@ static int ipc_parent(int cpid, int fd, struct sock_args *args) wait(&status); return client_status; } -#define GETOPT_STR "sr:l:c:p:t:g:P:DRn:M:X:m:d:I:BN:O:SCi6xL:0:1:2:3:Fbq" +#define GETOPT_STR "sr:l:c:p:t:g:P:DRn:M:X:m:A:d:I:BN:O:SCi6xL:0:1:2:3:Fbq" static void print_usage(char *prog) { printf( "usage: %s OPTS\n" @@ -1856,10 +1892,12 @@ static void print_usage(char *prog) " -n num number of times to send message\n" "\n" " -M password use MD5 sum protection\n" " -X password MD5 password for client mode\n" " -m prefix/len prefix and length to use for MD5 key\n" + " -A password use RFC5925 TCP Authentication option\n" + "\n" " -g grp multicast group (e.g., 239.1.1.1)\n" " -i interactive mode (default is echo and terminate)\n" "\n" " -0 addr Expected local address\n" " -1 addr Expected remote address\n" @@ -1970,10 +2008,13 @@ int main(int argc, char *argv[]) args.client_pw = optarg; break; case 'm': args.md5_prefix_str = optarg; break; + case 'A': + args.authopt_password = optarg; + break; case 'S': args.use_setsockopt = 1; break; case 'C': args.use_cmsg = 1; -- 2.25.1