Re: [PATCH net v2] tcp: initialize standalone TCP-AO response padding
From: Eric Dumazet
Date: Tue Jul 14 2026 - 05:05:06 EST
On Mon, Jul 13, 2026 at 12:56 PM Yizhou Zhao
<zhaoyz24@xxxxxxxxxxxxxxxxxxxxx> wrote:
>
> tcp_v4_send_ack() and tcp_v6_send_response() construct standalone TCP
> responses with TCP-AO options. The option length carries the actual MAC
> length, but the TCP header length includes the option rounded up to a
> four-byte boundary.
>
> tcp_ao_hash_hdr() writes the MAC only. Thus, when the MAC length is not
> four-byte aligned, the one to three bytes after the MAC are left
> uninitialized and may be transmitted. For the normal TCP-AO hashing
> mode, those bytes also have to be initialized before computing the MAC.
>
> Initialize only the alignment padding in the TCP-AO branches, before
> hashing the header. Use TCPOPT_NOP, as in the normal TCP-AO output path.
> This avoids adding work to non-AO TCP responses while preserving a valid
> authenticated header.
>
Reviewed-by: Eric Dumazet <edumazet@xxxxxxxxxx>