aboutsummaryrefslogtreecommitdiffstats
path: root/target/linux/generic/hack-5.4
diff options
context:
space:
mode:
authorJason A. Donenfeld <Jason@zx2c4.com>2020-03-20 20:12:53 -0600
committerHans Dedecker <dedeckeh@gmail.com>2020-03-21 09:42:07 +0100
commit2bd56595a65b8aea3fe1bff8493787065a24f9b8 (patch)
treef2512f2a05a450c3fa434cf00238cd8c394637db /target/linux/generic/hack-5.4
parent858c6b17c8e679f2c2113f942894f2bdaec81ad1 (diff)
downloadupstream-2bd56595a65b8aea3fe1bff8493787065a24f9b8.tar.gz
upstream-2bd56595a65b8aea3fe1bff8493787065a24f9b8.tar.bz2
upstream-2bd56595a65b8aea3fe1bff8493787065a24f9b8.zip
wireguard: bump to 0.0.20200318
WireGuard had a brief professional security audit. The auditors didn't find any vulnerabilities, but they did suggest one defense-in-depth suggestion to protect against potential API misuse down the road, mentioned below. This compat snapshot corresponds with the patches I just pushed to Dave for 5.6-rc7. * curve25519-x86_64: avoid use of r12 This buys us 100 extra cycles, which isn't much, but it winds up being even faster on PaX kernels, which use r12 as a RAP register. * wireguard: queueing: account for skb->protocol==0 This is the defense-in-depth change. We deal with skb->protocol==0 just fine, but the advice to deal explicitly with it seems like a good idea. * receive: remove dead code from default packet type case A default case of a particular switch statement should never be hit, so instead of printing a pretty debug message there, we full-on WARN(), so that we get bug reports. * noise: error out precomputed DH during handshake rather than config All peer keys will now be addable, even if they're low order. However, no handshake messages will be produced successfully. This is a more consistent behavior with other low order keys, where the handshake just won't complete if they're being used anywhere. * send: use normaler alignment formula from upstream We're trying to keep a minimal delta with upstream for the compat backport. Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
Diffstat (limited to 'target/linux/generic/hack-5.4')
0 files changed, 0 insertions, 0 deletions