When run ipvs in two different network namespace at the same host, and one
ipvs transport network traffic to the other network namespace ipvs.
'ipvs_property' flag will make the second ipvs take no effect. So we should
clear 'ipvs_property' when SKB network namespace changed.
Signed-off-by: Ye Yin <redacted>
Signed-off-by: Wei Zhou <redacted>
---
include/linux/skbuff.h | 7 +++++++
net/core/skbuff.c | 1 +
2 files changed, 8 insertions(+)
@@ -3770,6 +3770,13 @@ static inline void nf_reset_trace(struct sk_buff *skb)#endif}+staticinlinevoidipvs_reset(structsk_buff*skb)+{+#if IS_ENABLED(CONFIG_IP_VS)+skb->ipvs_property=0;+#endif+}+/* Note: This doesn't put any conntrack and bridge info in dst. */staticinlinevoid__nf_copy(structsk_buff*dst,conststructsk_buff*src,boolcopy)
When run ipvs in two different network namespace at the same host, and one
ipvs transport network traffic to the other network namespace ipvs.
'ipvs_property' flag will make the second ipvs take no effect. So we should
clear 'ipvs_property' when SKB network namespace changed.
Signed-off-by: Ye Yin <redacted>
Signed-off-by: Wei Zhou <redacted>
Patch looks good to me. ipvs_property was added long ago
but skb_scrub_packet() is more recent (3.11), so:
Fixes: 621e84d6f373 ("dev: introduce skb_scrub_packet()")
Signed-off-by: Julian Anastasov <ja@ssi.bg>
I guess, DaveM can apply it directly as a bugfix
to the net tree.
@@ -3770,6 +3770,13 @@ static inline void nf_reset_trace(struct sk_buff *skb)#endif}+staticinlinevoidipvs_reset(structsk_buff*skb)+{+#if IS_ENABLED(CONFIG_IP_VS)+skb->ipvs_property=0;+#endif+}+/* Note: This doesn't put any conntrack and bridge info in dst. */staticinlinevoid__nf_copy(structsk_buff*dst,conststructsk_buff*src,boolcopy)
From: Simon Horman <horms@verge.net.au> Date: 2017-11-02 14:46:56
On Sat, Oct 28, 2017 at 01:33:09PM +0300, Julian Anastasov wrote:
Hello,
On Thu, 26 Oct 2017, Ye Yin wrote:
quoted
When run ipvs in two different network namespace at the same host, and one
ipvs transport network traffic to the other network namespace ipvs.
'ipvs_property' flag will make the second ipvs take no effect. So we should
clear 'ipvs_property' when SKB network namespace changed.
Signed-off-by: Ye Yin <redacted>
Signed-off-by: Wei Zhou <redacted>
Patch looks good to me. ipvs_property was added long ago
but skb_scrub_packet() is more recent (3.11), so:
Fixes: 621e84d6f373 ("dev: introduce skb_scrub_packet()")
Signed-off-by: Julian Anastasov <ja@ssi.bg>
I guess, DaveM can apply it directly as a bugfix
to the net tree.
Sounds like a good plan to me, Dave?
Signed-off-by: Simon Horman <horms@verge.net.au>
From: David Miller <davem@davemloft.net> Date: 2017-11-04 13:38:33
From: Simon Horman <horms@verge.net.au>
Date: Thu, 2 Nov 2017 15:46:50 +0100
On Sat, Oct 28, 2017 at 01:33:09PM +0300, Julian Anastasov wrote:
quoted
Hello,
On Thu, 26 Oct 2017, Ye Yin wrote:
quoted
When run ipvs in two different network namespace at the same host, and one
ipvs transport network traffic to the other network namespace ipvs.
'ipvs_property' flag will make the second ipvs take no effect. So we should
clear 'ipvs_property' when SKB network namespace changed.
Signed-off-by: Ye Yin <redacted>
Signed-off-by: Wei Zhou <redacted>
Patch looks good to me. ipvs_property was added long ago
but skb_scrub_packet() is more recent (3.11), so:
Fixes: 621e84d6f373 ("dev: introduce skb_scrub_packet()")
Signed-off-by: Julian Anastasov <ja@ssi.bg>
I guess, DaveM can apply it directly as a bugfix
to the net tree.
Sounds like a good plan to me, Dave?
Signed-off-by: Simon Horman <horms@verge.net.au>