From: Simon Horman <horms@verge.net.au> Date: 2012-01-27 01:45:26
Hi Pablo,
please consider pulling
git://git.kernel.org/pub/scm/linux/kernel/git/horms/ipvs.git master
to get the following fix from Julian.
The bug in question has been present since 2.6.37 and accordingly I would
like the fix considered for both 3.3 and stable. I have confirmed that it
applies and builds against your net tree, 3.2.2, 3.1.10, 3.0.18 and 2.6.39.4.
Julian Anastasov (1):
ipvs: fix matching of fwmark templates during scheduling
net/netfilter/ipvs/ip_vs_core.c | 2 +-
1 files changed, 1 insertions(+), 1 deletions(-)
From: Simon Horman <horms@verge.net.au> Date: 2012-01-27 01:45:27
From: Julian Anastasov <ja@ssi.bg>
Commit f11017ec2d1859c661f4e2b12c4a8d250e1f47cf (2.6.37)
moved the fwmark variable in subcontext that is invalidated before
reaching the ip_vs_ct_in_get call. As vaddr is provided as pointer
in the param structure make sure the fwmark variable is in
same context. As the fwmark templates can not be matched,
more and more template connections are created and the
controlled connections can not go to single real server.
Signed-off-by: Julian Anastasov <ja@ssi.bg>
Cc: stable@vger.kernel.org
Signed-off-by: Simon Horman <horms@verge.net.au>
---
net/netfilter/ipvs/ip_vs_core.c | 2 +-
1 files changed, 1 insertions(+), 1 deletions(-)
@@ -232,6 +232,7 @@ ip_vs_sched_persist(struct ip_vs_service *svc,__be16dport=0;/* destination port to forward */unsignedintflags;structip_vs_conn_paramparam;+constunionnf_inet_addrfwmark={.ip=htonl(svc->fwmark)};unionnf_inet_addrsnet;/* source network of the client,aftermasking*/
From: Pablo Neira Ayuso <pablo@netfilter.org> Date: 2012-02-09 15:15:07
On Fri, Jan 27, 2012 at 10:45:27AM +0900, Simon Horman wrote:
From: Julian Anastasov <ja@ssi.bg>
Commit f11017ec2d1859c661f4e2b12c4a8d250e1f47cf (2.6.37)
moved the fwmark variable in subcontext that is invalidated before
reaching the ip_vs_ct_in_get call. As vaddr is provided as pointer
in the param structure make sure the fwmark variable is in
same context. As the fwmark templates can not be matched,
more and more template connections are created and the
controlled connections can not go to single real server.
Signed-off-by: Julian Anastasov <ja@ssi.bg>
Cc: stable@vger.kernel.org
Signed-off-by: Simon Horman <horms@verge.net.au>
Applied, thanks. I'll pass it to davem.
I'll pass it to stable once this hits Linus tree.
From: Simon Horman <horms@verge.net.au> Date: 2012-02-13 02:33:33
On Thu, Feb 09, 2012 at 04:15:07PM +0100, Pablo Neira Ayuso wrote:
On Fri, Jan 27, 2012 at 10:45:27AM +0900, Simon Horman wrote:
quoted
From: Julian Anastasov <ja@ssi.bg>
Commit f11017ec2d1859c661f4e2b12c4a8d250e1f47cf (2.6.37)
moved the fwmark variable in subcontext that is invalidated before
reaching the ip_vs_ct_in_get call. As vaddr is provided as pointer
in the param structure make sure the fwmark variable is in
same context. As the fwmark templates can not be matched,
more and more template connections are created and the
controlled connections can not go to single real server.
Signed-off-by: Julian Anastasov <ja@ssi.bg>
Cc: stable@vger.kernel.org
Signed-off-by: Simon Horman <horms@verge.net.au>
Applied, thanks. I'll pass it to davem.
I'll pass it to stable once this hits Linus tree.