mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Julian Anastasov <ja@ssi.bg>
To: Philo Lu <lulie@linux.alibaba.com>
Cc: netdev@vger.kernel.org, davem@davemloft.net, edumazet@google.com,
	kuba@kernel.org, pabeni@redhat.com, horms@kernel.org,
	asml.silence@gmail.com, willemb@google.com,
	almasrymina@google.com, chopps@labn.net,
	aleksander.lobakin@intel.com, nicolas.dichtel@6wind.com,
	dust.li@linux.alibaba.com, hustcat@gmail.com, horms@verge.net.au,
	bpf@vger.kernel.org, linux-kernel@vger.kernel.org
Subject: Re: [PATCHv2 net] ipvs: Always clear ipvs_property flag in skb_scrub_packet()
Date: Tue, 25 Feb 2025 12:55:40 +0200 (EET)	[thread overview]
Message-ID: <61a40de5-3b11-e84b-90a5-fefd8da3bb23@ssi.bg> (raw)
In-Reply-To: <20250222033518.126087-1-lulie@linux.alibaba.com>


	Hello,

On Sat, 22 Feb 2025, Philo Lu wrote:

> We found an issue when using bpf_redirect with ipvs NAT mode after
> commit ff70202b2d1a ("dev_forward_skb: do not scrub skb mark within
> the same name space"). Particularly, we use bpf_redirect to return
> the skb directly back to the netif it comes from, i.e., xnet is
> false in skb_scrub_packet(), and then ipvs_property is preserved
> and SNAT is skipped in the rx path.
> 
> ipvs_property has been already cleared when netns is changed in
> commit 2b5ec1a5f973 ("netfilter/ipvs: clear ipvs_property flag when
> SKB net namespace changed"). This patch just clears it in spite of
> netns.
> 
> Fixes: 2b5ec1a5f973 ("netfilter/ipvs: clear ipvs_property flag when SKB net namespace changed")
> Signed-off-by: Philo Lu <lulie@linux.alibaba.com>

	Looks good to me, thanks!

Acked-by: Julian Anastasov <ja@ssi.bg>

	It was safer to reset the flag when netns changes but
it has role only before output device is reached or while
packet is looped over lo device. New tunnel headers should
be safe to reset it because nf ct and dst are dropped too.

> ---
> v1 -> v2:
>  - Add Fixes tag as suggested by Julian Anastasov
> ---
>  net/core/skbuff.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/net/core/skbuff.c b/net/core/skbuff.c
> index 7b03b64fdcb2..b1c81687e9d8 100644
> --- a/net/core/skbuff.c
> +++ b/net/core/skbuff.c
> @@ -6033,11 +6033,11 @@ void skb_scrub_packet(struct sk_buff *skb, bool xnet)
>  	skb->offload_fwd_mark = 0;
>  	skb->offload_l3_fwd_mark = 0;
>  #endif
> +	ipvs_reset(skb);
>  
>  	if (!xnet)
>  		return;
>  
> -	ipvs_reset(skb);
>  	skb->mark = 0;
>  	skb_clear_tstamp(skb);
>  }
> -- 
> 2.32.0.3.g01195cf9f

Regards

--
Julian Anastasov <ja@ssi.bg>


  reply	other threads:[~2025-02-25 10:56 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-02-22  3:35 Philo Lu
2025-02-25 10:55 ` Julian Anastasov [this message]
2025-02-25 12:30 ` patchwork-bot+netdevbpf

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=61a40de5-3b11-e84b-90a5-fefd8da3bb23@ssi.bg \
    --to=ja@ssi.bg \
    --cc=aleksander.lobakin@intel.com \
    --cc=almasrymina@google.com \
    --cc=asml.silence@gmail.com \
    --cc=bpf@vger.kernel.org \
    --cc=chopps@labn.net \
    --cc=davem@davemloft.net \
    --cc=dust.li@linux.alibaba.com \
    --cc=edumazet@google.com \
    --cc=horms@kernel.org \
    --cc=horms@verge.net.au \
    --cc=hustcat@gmail.com \
    --cc=kuba@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=lulie@linux.alibaba.com \
    --cc=netdev@vger.kernel.org \
    --cc=nicolas.dichtel@6wind.com \
    --cc=pabeni@redhat.com \
    --cc=willemb@google.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®