[PATCH ipsec v4 0/9] xfrm: state: exact mark/mask match for control-plane SA lookups

From: Antony Antony

Date: Tue Oct 06 2026 - 03:04:22 EST


While looking into a XFRM_MSG_MIGRATE_STATE issue reported by Sashiko,
we found the underlying problem generalizes: xfrm allows multiple SAs
to coexist for the same (SPI, daddr, proto) differing only in mark,
and every netlink method that resolves "which SA" - xfrm get_sa(),
del_sa(), update, get_ae, new_ae, expire, migrate - uses the same
wildcard mark match the data path needs. A broader-mask SA can
silently shadow a more specific one:

# ip xfrm state add ... spi 0x1000 mark 1 mask 1 (SA_target)
# ip xfrm state add ... spi 0x1000 mark 0 mask 0
(SA_decoy, catch-all, added after -> bucket head)
# ip xfrm state delete dst ... proto esp spi 0x1000 mark 1 mask 1
-> deletes SA_decoy; SA_target survives, untouched

xfrm policy had the same bug, fixed in commit 4f47e8ab6ab7
("xfrm: policy: match with both mark and mask on user interfaces").

Netlink state lookups using spi use an exact mark/mask match except
for UPDSA; the wildcard match stays for the data path and state_add only.
This series applies that fix across every affected method,
not just XFRM_MSG_MIGRATE_STATE.

Also reject marks with value bits outside the mask (state add,
ALLOCSPI, policy add). These are misconfigurations anyway, since
the extra bits can never match, and break exact match added here.

This series does not touch PF_KEY, which no longer receives
non-critical fixes.

state_lookup_byaddr is out of scope. This is only fixing spi based
lookups.

---
v3->v4: add 3 patches to reject mark value bits outside the mask for state and policy

- Link to v3: https://patch.msgid.link/migrate-state-fixes-v3-6-836125bb53dd@xxxxxxxxxxx

v2->v3: mark match use only values and no mask in exact lookup

- Link to v2: https://lore.kernel.org/all/migrate-state-fixes-v2-0-c3e2767f0d96@xxxxxxxxxxx/
v1->v2: few more wildcard mark check reported by sashiko and Yan
- keep wildcard match in xfrm_state_update() (UPDSA)

- Link to v1: https://patch.msgid.link/migrate-state-fixes-v0-8-a69e8637ba3b@xxxxxxxxxxx

To: Steffen Klassert <steffen.klassert@xxxxxxxxxxx>
To: Herbert Xu <herbert@xxxxxxxxxxxxxxxxxxx>
To: "David S. Miller" <davem@xxxxxxxxxxxxx>
To: Eric Dumazet <edumazet@xxxxxxxxxx>
To: Jakub Kicinski <kuba@xxxxxxxxxx>
To: Paolo Abeni <pabeni@xxxxxxxxxx>
To: Simon Horman <horms@xxxxxxxxxx>
To: Paul Chaignon <paul.chaignon@xxxxxxxxx>
To: Louis DeLosSantos <louis.delos.devel@xxxxxxxxx>
To: Jamal Hadi Salim <hadi@xxxxxxxxxx>
To: Antony Antony <antony.antony@xxxxxxxxxxx>
To: Sabrina Dubroca <sd@xxxxxxxxxxxxxxx>
To: Jonathan Corbet <corbet@xxxxxxx>
To: Shuah Khan <skhan@xxxxxxxxxxxxxxxxxxx>
To: Randy Dunlap <rdunlap@xxxxxxxxxxxxx>
Cc: netdev@xxxxxxxxxxxxxxx
Cc: linux-kernel@xxxxxxxxxxxxxxx
Cc: linux-doc@xxxxxxxxxxxxxxx

---
Antony Antony (9):
xfrm: state: reject mark with bits outside its mask on add
xfrm: state: reject mark with bits outside its mask on ALLOCSPI
xfrm: policy: reject mark with bits outside its mask on add
xfrm: state: exact mark/mask match for SPI-keyed control-plane SA lookups
xfrm: fix use-after-free of migrated state in xfrm_do_migrate_state()
xfrm: fix hw offload state leak on xfrm_do_migrate_state() error path
xfrm: include mark in MIGRATE_STATE SA collision check
xfrm: pass extack through to xfrm_init_replay() from xfrm_init_state()
docs: xfrm: include mark in XFRM_MSG_MIGRATE_STATE EEXIST tuple

.../networking/xfrm/xfrm_migrate_state.rst | 25 +++--
include/net/xfrm.h | 7 ++
net/xfrm/xfrm_state.c | 101 +++++++++++++++++----
net/xfrm/xfrm_user.c | 81 ++++++++++++-----
4 files changed, 166 insertions(+), 48 deletions(-)
---
base-commit: 86de3a1118a16dbbbe5fabe9aa20ffb93c072ed5
change-id: migrate-state-fixes-063ee0342611

Best regards,
--
Antony Antony <antony.antony@xxxxxxxxxxx>