[PATCH v3 net 1/5] vxlan: only migrate dynamic FDB entries
From: Stephen Hemminger <stephen@networkplumber.org>
Date: 2013-06-11 00:37:51
Only migrate dynamic forwarding table entries, don't modify static entries. If packet received from incorrect source IP address assume it is an imposter and drop it. Signed-off-by: Stephen Hemminger <stephen@networkplumber.org> --- v3 - fix indentation Should go to -stable as well.
--- a/drivers/net/vxlan.c 2013-06-10 15:04:56.392031305 -0700
+++ b/drivers/net/vxlan.c 2013-06-10 15:04:59.239993130 -0700@@ -603,8 +603,9 @@ skip: /* Watch incoming packets to learn mapping between Ethernet address * and Tunnel endpoint. + * Return true if packet is bogus and should be droppped. */ -static void vxlan_snoop(struct net_device *dev, +static bool vxlan_snoop(struct net_device *dev, __be32 src_ip, const u8 *src_mac) { struct vxlan_dev *vxlan = netdev_priv(dev);
@@ -614,7 +615,11 @@ static void vxlan_snoop(struct net_devic f = vxlan_find_mac(vxlan, src_mac); if (likely(f)) { if (likely(f->remote.remote_ip == src_ip)) - return; + return false; + + /* Don't migrate static entries, drop packets */ + if (!(f->flags & NTF_SELF)) + return true; if (net_ratelimit()) netdev_info(dev,
@@ -634,6 +639,8 @@ static void vxlan_snoop(struct net_devic 0, NTF_SELF); spin_unlock(&vxlan->hash_lock); } + + return false; }
@@ -766,8 +773,9 @@ static int vxlan_udp_encap_recv(struct s vxlan->dev->dev_addr) == 0) goto drop; - if (vxlan->flags & VXLAN_F_LEARN) - vxlan_snoop(skb->dev, oip->saddr, eth_hdr(skb)->h_source); + if ((vxlan->flags & VXLAN_F_LEARN) && + vxlan_snoop(skb->dev, oip->saddr, eth_hdr(skb)->h_source)) + goto drop; __skb_tunnel_rx(skb, vxlan->dev); skb_reset_network_header(skb);