]> Gentwo Git Trees - linux/.git/commit
wireguard: netlink: enable strict genetlink validation
authorAsbjørn Sloth Tønnesen <ast@fiberby.net>
Wed, 5 Nov 2025 18:32:12 +0000 (18:32 +0000)
committerJason A. Donenfeld <Jason@zx2c4.com>
Mon, 1 Dec 2025 02:25:08 +0000 (03:25 +0100)
commite0e1b6db2e4b8fae44e222c188d3e96259d00c8e
tree28fe620d6898adefc950e5f635f379ac04083654
parent0177f0f07886e54e12c6f18fa58f63e63ddd3c58
wireguard: netlink: enable strict genetlink validation

WireGuard is a modern enough genetlink family, that it doesn't need
resv_start_op. It already had policies in place when it was first
merged, it has also never used the reserved field, or other things
toggled by resv_start_op.

wireguard-tools have always used zero initialized memory, and have never
touched the reserved field, neither have any other clients I have
checked. Closed-source clients are much more likely to use the
embeddedable library from wireguard-tools, than a DIY implementation
using uninitialized memory.

Signed-off-by: Asbjørn Sloth Tønnesen <ast@fiberby.net>
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
drivers/net/wireguard/netlink.c