mirror of
https://github.com/torvalds/linux
synced 2026-07-22 18:20:51 +09:00
netfilter: flowtable: support IPIP tunnel with direct xmit
The combination of IPIP tunnel with direct xmit, eg. bridge device,
breaks because no dst_entry is provided to check the skb headroom and to
set the iph->frag_off field. This leads to invalid dst usage and can
trigger a crash in the tunnel transmit path.
Fix this by moving dst_cache and dst_cookie out of the runtime union so
that they can be shared by neighbour, xfrm, and direct tunnel flows.
For FLOW_OFFLOAD_XMIT_DIRECT tuples carrying tunnel metadata, preserve
route state in these shared fields and release it through the common
dst release path.
Since dst_entry is now available to the three supported xmit modes and
dst_release() already deals with NULL dst, remove the xmit type check
in nft_flow_dst_release(). Moreover, skip the check if the dst entry
is NULL in nf_flow_dst_check() which is now the case for the direct
xmit case.
Based on patch from Rein Wei <n05ec@lzu.edu.cn>.
Fixes: d30301ba4b ("netfilter: flowtable: Add IPIP tx sw acceleration")
Cc: stable@vger.kernel.org
Reported-by: Yuan Tan <yuantan098@gmail.com>
Reported-by: Xin Liu <bird@lzu.edu.cn>
Reported-by: Zhengyang Chen <chzhengyang2023@lzu.edu.cn>
Reported-by: Ren Wei <n05ec@lzu.edu.cn>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Acked-by: Lorenzo Bianconi <lorenzo@kernel.org>
Signed-off-by: Florian Westphal <fw@strlen.de>
This commit is contained in:
committed by
Florian Westphal
parent
6c5dcab95f
commit
fa7395c02d
@@ -155,11 +155,12 @@ struct flow_offload_tuple {
|
||||
tun_num:2,
|
||||
in_vlan_ingress:2;
|
||||
u16 mtu;
|
||||
u32 dst_cookie;
|
||||
struct dst_entry *dst_cache;
|
||||
|
||||
union {
|
||||
struct {
|
||||
struct dst_entry *dst_cache;
|
||||
u32 ifidx;
|
||||
u32 dst_cookie;
|
||||
};
|
||||
struct {
|
||||
u32 ifidx;
|
||||
|
||||
@@ -127,12 +127,18 @@ static int flow_offload_fill_route(struct flow_offload *flow,
|
||||
|
||||
switch (route->tuple[dir].xmit_type) {
|
||||
case FLOW_OFFLOAD_XMIT_DIRECT:
|
||||
if (flow_tuple->tun_num) {
|
||||
flow_tuple->dst_cache = dst;
|
||||
flow_tuple->dst_cookie =
|
||||
flow_offload_dst_cookie(flow_tuple);
|
||||
}
|
||||
memcpy(flow_tuple->out.h_dest, route->tuple[dir].out.h_dest,
|
||||
ETH_ALEN);
|
||||
memcpy(flow_tuple->out.h_source, route->tuple[dir].out.h_source,
|
||||
ETH_ALEN);
|
||||
flow_tuple->out.ifidx = route->tuple[dir].out.ifindex;
|
||||
dst_release(dst);
|
||||
if (!flow_tuple->tun_num)
|
||||
dst_release(dst);
|
||||
break;
|
||||
case FLOW_OFFLOAD_XMIT_XFRM:
|
||||
case FLOW_OFFLOAD_XMIT_NEIGH:
|
||||
@@ -152,9 +158,7 @@ static int flow_offload_fill_route(struct flow_offload *flow,
|
||||
static void nft_flow_dst_release(struct flow_offload *flow,
|
||||
enum flow_offload_tuple_dir dir)
|
||||
{
|
||||
if (flow->tuplehash[dir].tuple.xmit_type == FLOW_OFFLOAD_XMIT_NEIGH ||
|
||||
flow->tuplehash[dir].tuple.xmit_type == FLOW_OFFLOAD_XMIT_XFRM)
|
||||
dst_release(flow->tuplehash[dir].tuple.dst_cache);
|
||||
dst_release(flow->tuplehash[dir].tuple.dst_cache);
|
||||
}
|
||||
|
||||
void flow_offload_route_init(struct flow_offload *flow,
|
||||
|
||||
@@ -299,8 +299,7 @@ static bool nf_flow_exceeds_mtu(const struct sk_buff *skb, unsigned int mtu)
|
||||
|
||||
static inline bool nf_flow_dst_check(struct flow_offload_tuple *tuple)
|
||||
{
|
||||
if (tuple->xmit_type != FLOW_OFFLOAD_XMIT_NEIGH &&
|
||||
tuple->xmit_type != FLOW_OFFLOAD_XMIT_XFRM)
|
||||
if (!tuple->dst_cache)
|
||||
return true;
|
||||
|
||||
return dst_check(tuple->dst_cache, tuple->dst_cookie);
|
||||
|
||||
Reference in New Issue
Block a user