From: Jamal Hadi Salim <jhs@mojatatu.com> Date: 2016-02-17 11:37:47
From: Jamal Hadi Salim <jhs@mojatatu.com>
v2:
Use Daniel's suggestion on when to set the skb proto
v1:
fix compile error found by build bot when CONFIG_NET_CLS_ACT was off
Jamal Hadi Salim (1):
net_sched fix: reclassification needs to consider ether protocol
changes
net/sched/sch_api.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--
1.9.1
From: Jamal Hadi Salim <jhs@mojatatu.com> Date: 2016-02-17 11:37:53
From: Jamal Hadi Salim <jhs@mojatatu.com>
actions could change the etherproto in particular with ethernet
tunnelled data. Typically such actions, after peeling the outer header,
will ask for the packet to be reclassified. We then need to restart
the classification with the new proto header.
Example setup used to catch this:
sudo tc qdisc add dev $ETH ingress
sudo $TC filter add dev $ETH parent ffff: pref 1 protocol 802.1Q \
u32 match u32 0 0 flowid 1:1 \
action vlan pop reclassify
Fixes: 3b3ae880266d ("net: sched: consolidate tc_classify{,_compat}")
Signed-off-by: Jamal Hadi Salim <jhs@mojatatu.com>
---
net/sched/sch_api.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
From: Cong Wang <hidden> Date: 2016-02-17 17:27:07
On Wed, Feb 17, 2016 at 3:37 AM, Jamal Hadi Salim [off-list ref] wrote:
quoted hunk
From: Jamal Hadi Salim <jhs@mojatatu.com>
actions could change the etherproto in particular with ethernet
tunnelled data. Typically such actions, after peeling the outer header,
will ask for the packet to be reclassified. We then need to restart
the classification with the new proto header.
Example setup used to catch this:
sudo tc qdisc add dev $ETH ingress
sudo $TC filter add dev $ETH parent ffff: pref 1 protocol 802.1Q \
u32 match u32 0 0 flowid 1:1 \
action vlan pop reclassify
Fixes: 3b3ae880266d ("net: sched: consolidate tc_classify{,_compat}")
Signed-off-by: Jamal Hadi Salim <jhs@mojatatu.com>
---
net/sched/sch_api.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
Why remove this empty line? I think it is still useful. :)
Also your patch should be targeted to -net instead of -net-next, since it
fixes a bug.
Thanks.
From: Daniel Borkmann <daniel@iogearbox.net> Date: 2016-02-18 11:53:20
On 02/17/2016 06:27 PM, Cong Wang wrote:
On Wed, Feb 17, 2016 at 3:37 AM, Jamal Hadi Salim [off-list ref] wrote:
quoted
From: Jamal Hadi Salim <jhs@mojatatu.com>
actions could change the etherproto in particular with ethernet
tunnelled data. Typically such actions, after peeling the outer header,
will ask for the packet to be reclassified. We then need to restart
the classification with the new proto header.
Example setup used to catch this:
sudo tc qdisc add dev $ETH ingress
sudo $TC filter add dev $ETH parent ffff: pref 1 protocol 802.1Q \
u32 match u32 0 0 flowid 1:1 \
action vlan pop reclassify
Fixes: 3b3ae880266d ("net: sched: consolidate tc_classify{,_compat}")
Signed-off-by: Jamal Hadi Salim <jhs@mojatatu.com>
---
net/sched/sch_api.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)