[net PATCH v3 0/1] tc reclassification needs to consider ether protocol changes

STALE3854d

Revision v3 of 2 in this series.

4 messages, 3 authors, 2016-02-18 · open the first message on its own page

[net PATCH v3 0/1] tc reclassification needs to consider ether protocol changes

From: Jamal Hadi Salim <jhs@mojatatu.com>
Date: 2016-02-18 12:38:13

From: Jamal Hadi Salim <jhs@mojatatu.com>

v3:
Cong says this needs to go to -net. And to put back the removed new line

v2:
Use Daniel's suggestion on when to set the skb proto

v1:
fix compile error found by build bot when CONFIG_NET_CLS_ACT was off

Jamal Hadi Salim (1):
  net_sched fix: reclassification needs to consider ether protocol
    changes

 net/sched/sch_api.c | 1 +
 1 file changed, 1 insertion(+)

-- 
1.9.1

[net PATCH v3 1/1] net_sched fix: reclassification needs to consider ether protocol changes

From: Jamal Hadi Salim <jhs@mojatatu.com>
Date: 2016-02-18 12:38:16

From: Jamal Hadi Salim <jhs@mojatatu.com>

actions could change the etherproto in particular with ethernet
tunnelled data. Typically such actions, after peeling the outer header,
will ask for the packet to be  reclassified. We then need to restart
the classification with the new proto header.

Example setup used to catch this:
sudo tc qdisc add dev $ETH ingress
sudo $TC filter add dev $ETH parent ffff: pref 1 protocol 802.1Q \
u32 match u32 0 0 flowid 1:1 \
action  vlan pop reclassify

Fixes: 3b3ae880266d ("net: sched: consolidate tc_classify{,_compat}")
Signed-off-by: Jamal Hadi Salim <jhs@mojatatu.com>
---
 net/sched/sch_api.c | 1 +
 1 file changed, 1 insertion(+)
diff --git a/net/sched/sch_api.c b/net/sched/sch_api.c
index b5c2cf2..af1acf0 100644
--- a/net/sched/sch_api.c
+++ b/net/sched/sch_api.c
@@ -1852,6 +1852,7 @@ reset:
 	}
 
 	tp = old_tp;
+	protocol = tc_skb_protocol(skb);
 	goto reclassify;
 #endif
 }
-- 
1.9.1

Re: [net PATCH v3 1/1] net_sched fix: reclassification needs to consider ether protocol changes

From: Daniel Borkmann <daniel@iogearbox.net>
Date: 2016-02-18 12:43:23

On 02/18/2016 01:38 PM, Jamal Hadi Salim wrote:
From: Jamal Hadi Salim <jhs@mojatatu.com>

actions could change the etherproto in particular with ethernet
tunnelled data. Typically such actions, after peeling the outer header,
will ask for the packet to be  reclassified. We then need to restart
the classification with the new proto header.

Example setup used to catch this:
sudo tc qdisc add dev $ETH ingress
sudo $TC filter add dev $ETH parent ffff: pref 1 protocol 802.1Q \
u32 match u32 0 0 flowid 1:1 \
action  vlan pop reclassify

Fixes: 3b3ae880266d ("net: sched: consolidate tc_classify{,_compat}")
Signed-off-by: Jamal Hadi Salim <jhs@mojatatu.com>
Acked-by: Daniel Borkmann <daniel@iogearbox.net>

Re: [net PATCH v3 1/1] net_sched fix: reclassification needs to consider ether protocol changes

From: David Miller <davem@davemloft.net>
Date: 2016-02-18 16:15:15

From: Jamal Hadi Salim <jhs@mojatatu.com>
Date: Thu, 18 Feb 2016 07:38:04 -0500
From: Jamal Hadi Salim <jhs@mojatatu.com>

actions could change the etherproto in particular with ethernet
tunnelled data. Typically such actions, after peeling the outer header,
will ask for the packet to be  reclassified. We then need to restart
the classification with the new proto header.

Example setup used to catch this:
sudo tc qdisc add dev $ETH ingress
sudo $TC filter add dev $ETH parent ffff: pref 1 protocol 802.1Q \
u32 match u32 0 0 flowid 1:1 \
action  vlan pop reclassify

Fixes: 3b3ae880266d ("net: sched: consolidate tc_classify{,_compat}")
Signed-off-by: Jamal Hadi Salim <jhs@mojatatu.com>
Applied and queued up for -stable, thanks Jamal.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help