[PATCH net] bridge: notify user space of fdb port change

Subsystems: ethernet bridge, networking [general], the rest

STALE4498d

3 messages, 2 authors, 2014-05-16 · open the first message on its own page

[PATCH net] bridge: notify user space of fdb port change

From: Jon Maxwell <hidden>
Date: 2014-05-16 08:09:24

From: Jon Maxwell <redacted>

There has been a number incidents recently where customers running KVM have 
reported that VM hosts on different Hypervisors are unreachable. Based on 
pcap traces we found that the bridge was broadcasting the ARP request out 
onto the network. However some NICs have an inbuilt switch which on occasions 
were broadcasting the VMs ARP request back through the physical NIC on the 
Hypervisor. This resulted in the bridge changing ports and incorrectly learning
that the VMs mac address was external. As a result the ARP reply was directed 
back onto the external network and VM never updated it's ARP cache. This patch 
will notify the bridge command to identify such port toggling.

Signed-off-by: Jon Maxwell <redacted>
---
 net/bridge/br_fdb.c | 2 ++
 1 file changed, 2 insertions(+)
diff --git a/net/bridge/br_fdb.c b/net/bridge/br_fdb.c
index 9203d5a..67480c2 100644
--- a/net/bridge/br_fdb.c
+++ b/net/bridge/br_fdb.c
@@ -511,6 +511,8 @@ void br_fdb_update(struct net_bridge *br, struct net_bridge_port *source,
 			fdb->updated = jiffies;
 			if (unlikely(added_by_user))
 				fdb->added_by_user = 1;
+			if (unlikely(source->port_no != fdb->dst->port_no))
+				fdb_notify(br, fdb, RTM_NEWNEIGH);
 		}
 	} else {
 		spin_lock(&br->hash_lock);
-- 
1.8.3.1

Re: [PATCH net] bridge: notify user space of fdb port change

From: Jon Maxwell <hidden>
Date: 2014-05-16 08:13:05

Please use this patch. My bad, the previous one 
incorrectly did the notify before fdb->added_by_user = 1.

----- Original Message -----
quoted hunk
From: "Jon Maxwell" <redacted>
To: stephen@networkplumber.org
Cc: davem@davemloft.net, "makita toshiaki" <redacted>, vyasevic@redhat.com,
bridge@lists.linux-foundation.org, netdev@vger.kernel.org, linux-kernel@vger.kernel.org, jpirko@redhat.com,
jmaxwell@redhat.com, "Jon Maxwell" [off-list ref]
Sent: Friday, May 16, 2014 6:08:39 PM
Subject: [PATCH net] bridge: notify user space of fdb port change

From: Jon Maxwell <redacted>

There has been a number incidents recently where customers running KVM have
reported that VM hosts on different Hypervisors are unreachable. Based on
pcap traces we found that the bridge was broadcasting the ARP request out
onto the network. However some NICs have an inbuilt switch which on occasions
were broadcasting the VMs ARP request back through the physical NIC on the
Hypervisor. This resulted in the bridge changing ports and incorrectly
learning
that the VMs mac address was external. As a result the ARP reply was directed
back onto the external network and VM never updated it's ARP cache. This
patch
will notify the bridge command to identify such port toggling.

Signed-off-by: Jon Maxwell <redacted>
---
 net/bridge/br_fdb.c | 2 ++
 1 file changed, 2 insertions(+)
diff --git a/net/bridge/br_fdb.c b/net/bridge/br_fdb.c
index 9203d5a..67480c2 100644
--- a/net/bridge/br_fdb.c
+++ b/net/bridge/br_fdb.c
@@ -511,6 +511,8 @@ void br_fdb_update(struct net_bridge *br, struct
net_bridge_port *source,
 			fdb->updated = jiffies;
 			if (unlikely(added_by_user))
 				fdb->added_by_user = 1;
+			if (unlikely(source->port_no != fdb->dst->port_no))
+				fdb_notify(br, fdb, RTM_NEWNEIGH);
 		}
 	} else {
 		spin_lock(&br->hash_lock);
--
1.8.3.1

Re: [PATCH net] bridge: notify user space of fdb port change

From: Jon Maxwell <hidden>
Date: 2014-05-16 08:54:38


----- Original Message -----
From: "Jon Maxwell" <redacted>
To: stephen@networkplumber.org
Cc: davem@davemloft.net, "makita toshiaki" <redacted>, vyasevic@redhat.com,
bridge@lists.linux-foundation.org, netdev@vger.kernel.org, linux-kernel@vger.kernel.org, jpirko@redhat.com
Sent: Friday, May 16, 2014 6:12:51 PM
Subject: Re: [PATCH net] bridge: notify user space of fdb port change

Please use this patch. My bad, the previous one
incorrectly did the notify before fdb->added_by_user = 1.
I just realized I did the port compare after fdb->dst = source;
So the notify will never trigger. It's been a long
day, I'll rewrite this tomorrow and resubmit after 
testing it on my reproducer. Please ignore this one
too.
----- Original Message -----
quoted
From: "Jon Maxwell" <redacted>
To: stephen@networkplumber.org
Cc: davem@davemloft.net, "makita toshiaki" <redacted>,
vyasevic@redhat.com,
bridge@lists.linux-foundation.org, netdev@vger.kernel.org,
linux-kernel@vger.kernel.org, jpirko@redhat.com,
jmaxwell@redhat.com, "Jon Maxwell" [off-list ref]
Sent: Friday, May 16, 2014 6:08:39 PM
Subject: [PATCH net] bridge: notify user space of fdb port change

From: Jon Maxwell <redacted>

There has been a number incidents recently where customers running KVM have
reported that VM hosts on different Hypervisors are unreachable. Based on
pcap traces we found that the bridge was broadcasting the ARP request out
onto the network. However some NICs have an inbuilt switch which on
occasions
were broadcasting the VMs ARP request back through the physical NIC on the
Hypervisor. This resulted in the bridge changing ports and incorrectly
learning
that the VMs mac address was external. As a result the ARP reply was
directed
back onto the external network and VM never updated it's ARP cache. This
patch
will notify the bridge command to identify such port toggling.

Signed-off-by: Jon Maxwell <redacted>
---
 net/bridge/br_fdb.c | 2 ++
 1 file changed, 2 insertions(+)
diff --git a/net/bridge/br_fdb.c b/net/bridge/br_fdb.c
index 9203d5a..67480c2 100644
--- a/net/bridge/br_fdb.c
+++ b/net/bridge/br_fdb.c
@@ -511,6 +511,8 @@ void br_fdb_update(struct net_bridge *br, struct
net_bridge_port *source,
 			fdb->updated = jiffies;
 			if (unlikely(added_by_user))
 				fdb->added_by_user = 1;
+			if (unlikely(source->port_no != fdb->dst->port_no))
+				fdb_notify(br, fdb, RTM_NEWNEIGH);
 		}
 	} else {
 		spin_lock(&br->hash_lock);
--
1.8.3.1
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help