From mboxrd@z Thu Jan 1 00:00:00 1970 Authentication-Results: passt.top; dmarc=pass (p=none dis=none) header.from=redhat.com Authentication-Results: passt.top; dkim=pass (1024-bit key; unprotected) header.d=redhat.com header.i=@redhat.com header.a=rsa-sha256 header.s=mimecast20190719 header.b=V+rgDja/; dkim-atps=neutral Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) by passt.top (Postfix) with ESMTPS id 04E225A004E for ; Mon, 03 Feb 2025 20:00:56 +0100 (CET) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1738609255; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=2Wt5kNkGkGrE2SOnNR3Inz4Ef7cFH6a6oZKhq8ADELE=; b=V+rgDja/NkCRLbxek0q3AwBXc2RgF+mT3Jr7fxfkjfg2ZfAi9CD2A9cBvX0ovxxZmofx00 bw8pKtu6Rgtp/GG6PoTpP/bhLDREaM/1Z3CauGRWJ73ggDRtVw/ZHM52aEGe/4s0BCxw4M xDDaZte3q1GfMS5Qthr+1++mgWxhLSE= Received: from mail-wm1-f70.google.com (mail-wm1-f70.google.com [209.85.128.70]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-25-XDh-OQikMyihVIJbkEPDqA-1; Mon, 03 Feb 2025 14:00:54 -0500 X-MC-Unique: XDh-OQikMyihVIJbkEPDqA-1 X-Mimecast-MFC-AGG-ID: XDh-OQikMyihVIJbkEPDqA Received: by mail-wm1-f70.google.com with SMTP id 5b1f17b1804b1-4361efc9dc6so25331165e9.3 for ; Mon, 03 Feb 2025 11:00:54 -0800 (PST) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1738609253; x=1739214053; h=content-transfer-encoding:mime-version:organization:references :in-reply-to:message-id:subject:cc:to:from:date:x-gm-message-state :from:to:cc:subject:date:message-id:reply-to; bh=r0FFq/kaMUyI0UhnzPRC10RJFRMQh61zTrRkW4ex0TY=; b=qw9MJuy7l1BcBFE2/PaxuUOaoU+MuXp6amglnPpznVsX19yinWgrcyyYor95H72gIY xzHzuxeAYlmtxfd53ivnYRzDUdI2DPpLLLBsiU7hbzOJ274MaSh3AS0EnHxOjwc/E8Cq i89G3nOy3PkA7xoWj9p/nix/M3wQK2YrPOr8rTadAFSGVP03AtbzB2Jzbp0TC6qAucrd a3+K8PWgh2nNyrZipGUgzdioCZ0CuSgKwTHxRmbn4LHdx+phvViTv2CflXZc4W1Si5dv rnjOOpBUzNJH6URF7STaDGbs7CQhAGnyquAmPLhX1u/4spCXRYG4+UgmZ0w8dDqTKrIo QDZA== X-Forwarded-Encrypted: i=1; AJvYcCXb/s6U5qjBOvnTd2N8WSvLzquvie7KXMwoKlBsghZ5CfAe5F6Wunfk7WJ5GtH6pGgQPghlRkQm6yI=@passt.top X-Gm-Message-State: AOJu0YyW58B4PpqwkiyAWdq91g6m0jYFgbfkihe47QOq4BlxFTTrU8uW 0MoNZ7N5MfM/cN7FCcv+aQmzx7AsPW/91Da9HqtMa7Qpa3kMX2B6FnwikCH6tTnddlfExfI5WPF oaCi7eQ6KpBsLUnYilN8I6/ueKE2kzz/jVzN8bFH+Y9TTpXvizg== X-Gm-Gg: ASbGncuwbowvbnVTgmDswjMsX4FbFTbtMrsm1T/UgE8Cuip70wiQV/js+jsVkALnfw2 QKZ6kn0a9V3zosipzchwuRPlo9YFMdtwBgfAFStgXuD5kv/upjaZRtsw6G53AhEFTYZpCOeCd4C pDc0RO6W2IqYY64ADC87lxpBkKRaNCK0d4WglOMOksHrbHlCxBiTLCtCtL/3l7Lgekzotyefoa8 Ra/MjLhkJsupNxBnifqZxbNEH5qe9DTQeTxo52EpaJ/aaZTRjGmRr3D3DB3TW7kxQIyq31T+9U4 0Dntje0BLofrpY35 X-Received: by 2002:a05:600c:a089:b0:431:547e:81d0 with SMTP id 5b1f17b1804b1-438dc3bac30mr258633845e9.11.1738609253169; Mon, 03 Feb 2025 11:00:53 -0800 (PST) X-Google-Smtp-Source: AGHT+IHjy/tXV7Kwd6P6cXhjq9dTnoDWYX5XPm/4Dxq3jHDNxlstXBWAA8Sd08VSOezqk07hxtXUQw== X-Received: by 2002:a05:600c:a089:b0:431:547e:81d0 with SMTP id 5b1f17b1804b1-438dc3bac30mr258633425e9.11.1738609252830; Mon, 03 Feb 2025 11:00:52 -0800 (PST) Received: from maya.myfinge.rs (ifcgrfdd.trafficplex.cloud. [2a10:fc81:a806:d6a9::1]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-38c5c1cfa3dsm13777765f8f.93.2025.02.03.11.00.51 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 03 Feb 2025 11:00:52 -0800 (PST) Date: Mon, 3 Feb 2025 20:00:49 +0100 From: Stefano Brivio To: Enrique Llorente Pastora Subject: Re: [PATCH] dhcp: Don't re-use request message for reply Message-ID: <20250203200049.47a2efb8@elisabeth> In-Reply-To: References: <20250131145329.1835558-1-ellorent@redhat.com> <20250201141330.59af1324@elisabeth> Organization: Red Hat X-Mailer: Claws Mail 4.2.0 (GTK 3.24.41; x86_64-pc-linux-gnu) MIME-Version: 1.0 X-Mimecast-Spam-Score: 0 X-Mimecast-MFC-PROC-ID: XWl7fQVgfqzwyQltJ7gBNzjBFs5Ml8ygKz39U3pzCWo_1738609253 X-Mimecast-Originator: redhat.com Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable Message-ID-Hash: Y5FY3W7AC63Q7EE6ZN7TOS5M33CXOVCP X-Message-ID-Hash: Y5FY3W7AC63Q7EE6ZN7TOS5M33CXOVCP X-MailFrom: sbrivio@redhat.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header CC: David Gibson , passt-dev@passt.top X-Mailman-Version: 3.3.8 Precedence: list List-Id: Development discussion and patches for passt Archived-At: Archived-At: List-Archive: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: On Mon, 3 Feb 2025 10:53:26 +0100 Enrique Llorente Pastora wrote: > On Mon, Feb 3, 2025 at 10:29=E2=80=AFAM David Gibson > wrote: > > > > On Sat, Feb 01, 2025 at 02:13:30PM +0100, Stefano Brivio wrote: =20 > > > On Fri, 31 Jan 2025 15:53:29 +0100 > > > Enrique Llorente wrote: > > > =20 > > > > The logic composing the DHCP reply message is reusing the request > > > > message to compose the it, this kind be problematic from a security= =20 > > > > > > Does "be problematic" imply "would be ... once we add longer options"= ? > > > =20 > > > > context and may break the functionality. =20 > > > > > > Which one? This is important to know for distribution maintainers and= , > > > ultimately, users. =20 > > > > Right, as a general rule commit messages be specific and concrete > > about what the problem they're address is. >=20 > This looks about right ? To me yes, just: > The logic composing the DHCP reply message is reusing the request > message to compose it, future long options like FQDN may > exceed the request message limit making it go beyond the lower > bound. >=20 > This change create a new reply message with a fixed options size of 3= 08 creates > and fill it in with proper fields from requests adding on top the gen= erated fills > options, this way the reply lower bound does not depend on the reques= t. --=20 Stefano