mirror of
https://github.com/torvalds/linux.git
synced 2026-09-22 12:44:03 +02:00
sctp: distinguish sequence zero from wildcard in reconf lookup
Zero is a valid response sequence after strreset_outseq wraps, but
sctp_chunk_lookup_strreset_param() currently treats it as a wildcard.
Add match_seq so response lookups match zero exactly while the one
type-only lookup can still ignore the sequence.
Fixes: 50a41591f1 ("sctp: implement receiver-side procedures for the Add Outgoing Streams Request Parameter")
Cc: stable@kernel.org
Suggested-by: Simon Horman <horms@kernel.org>
Acked-by: Xin Long <lucien.xin@gmail.com>
Signed-off-by: Jun Yang <junvyyang@tencent.com>
Link: https://patch.msgid.link/20260824081832.98717-2-juny24602@gmail.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
This commit is contained in:
parent
a687f2ae99
commit
63f44178f0
|
|
@ -482,7 +482,7 @@ int sctp_send_add_streams(struct sctp_association *asoc,
|
|||
|
||||
static struct sctp_paramhdr *sctp_chunk_lookup_strreset_param(
|
||||
struct sctp_association *asoc, __be32 resp_seq,
|
||||
__be16 type)
|
||||
__be16 type, bool match_seq)
|
||||
{
|
||||
struct sctp_chunk *chunk = asoc->strreset_chunk;
|
||||
struct sctp_reconf_chunk *hdr;
|
||||
|
|
@ -499,7 +499,7 @@ static struct sctp_paramhdr *sctp_chunk_lookup_strreset_param(
|
|||
*/
|
||||
struct sctp_strreset_tsnreq *req = param.v;
|
||||
|
||||
if ((!resp_seq || req->request_seq == resp_seq) &&
|
||||
if ((!match_seq || req->request_seq == resp_seq) &&
|
||||
(!type || type == req->param_hdr.type))
|
||||
return param.v;
|
||||
}
|
||||
|
|
@ -564,7 +564,7 @@ struct sctp_chunk *sctp_process_strreset_outreq(
|
|||
if (asoc->strreset_chunk) {
|
||||
if (!sctp_chunk_lookup_strreset_param(
|
||||
asoc, outreq->response_seq,
|
||||
SCTP_PARAM_RESET_IN_REQUEST)) {
|
||||
SCTP_PARAM_RESET_IN_REQUEST, true)) {
|
||||
/* same process with outstanding isn't 0 */
|
||||
result = SCTP_STRRESET_ERR_IN_PROGRESS;
|
||||
goto out;
|
||||
|
|
@ -816,7 +816,7 @@ struct sctp_chunk *sctp_process_strreset_addstrm_out(
|
|||
|
||||
if (asoc->strreset_chunk) {
|
||||
if (!sctp_chunk_lookup_strreset_param(
|
||||
asoc, 0, SCTP_PARAM_RESET_ADD_IN_STREAMS)) {
|
||||
asoc, 0, SCTP_PARAM_RESET_ADD_IN_STREAMS, false)) {
|
||||
/* same process with outstanding isn't 0 */
|
||||
result = SCTP_STRRESET_ERR_IN_PROGRESS;
|
||||
goto out;
|
||||
|
|
@ -927,7 +927,8 @@ struct sctp_chunk *sctp_process_strreset_resp(
|
|||
struct sctp_paramhdr *req;
|
||||
__u32 result;
|
||||
|
||||
req = sctp_chunk_lookup_strreset_param(asoc, resp->response_seq, 0);
|
||||
req = sctp_chunk_lookup_strreset_param(asoc, resp->response_seq, 0,
|
||||
true);
|
||||
if (!req)
|
||||
return NULL;
|
||||
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user