Patch 1/2 fixes the issue reported by Nikita where a MAC address
wouldn't match if given as first field of a set, and patch 2/2 adds
the corresponding test.
Stefano Brivio (2):
nft_set_pipapo: Fix bucket load in AVX2 lookup routine for six 8-bit
groups
selftests: netfilter: Add correctness test for mac,net set type
net/netfilter/nft_set_pipapo_avx2.c | 2 +-
.../selftests/netfilter/nft_concat_range.sh | 24 ++++++++++++++++---
2 files changed, 22 insertions(+), 4 deletions(-)
--
2.30.2
The sixth byte of packet data has to be looked up in the sixth group,
not in the seventh one, even if we load the bucket data into ymm6
(and not ymm5, for convenience of tracking stalls).
Without this fix, matching on a MAC address as first field of a set,
if 8-bit groups are selected (due to a small set size) would fail,
that is, the given MAC address would never match.
Reported-by: Nikita Yushchenko <redacted>
Cc: <redacted> # 5.6.x
Fixes: 7400b063969b ("nft_set_pipapo: Introduce AVX2-based lookup implementation")
Signed-off-by: Stefano Brivio <redacted>
---
net/netfilter/nft_set_pipapo_avx2.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
@@ -886,7 +886,7 @@ static int nft_pipapo_avx2_lookup_8b_6(unsigned long *map, unsigned long *fill,NFT_PIPAPO_AVX2_BUCKET_LOAD8(4,lt,4,pkt[4],bsize);NFT_PIPAPO_AVX2_AND(5,0,1);-NFT_PIPAPO_AVX2_BUCKET_LOAD8(6,lt,6,pkt[5],bsize);+NFT_PIPAPO_AVX2_BUCKET_LOAD8(6,lt,5,pkt[5],bsize);NFT_PIPAPO_AVX2_AND(7,2,3);/* Stall */
The existing net,mac test didn't cover the issue recently reported
by Nikita Yushchenko, where MAC addresses wouldn't match if given
as first field of a concatenated set with AVX2 and 8-bit groups,
because there's a different code path covering the lookup of six
8-bit groups (MAC addresses) if that's the first field.
Add a similar mac,net test, with MAC address and IPv4 address
swapped in the set specification.
Signed-off-by: Stefano Brivio <redacted>
---
.../selftests/netfilter/nft_concat_range.sh | 24 ++++++++++++++++---
1 file changed, 21 insertions(+), 3 deletions(-)
@@ -23,8 +23,8 @@ TESTS="reported_issues correctness concurrency timeout"# Set types, defined by TYPE_ variables belowTYPES="net_port port_net net6_port port_proto net6_port_mac net6_port_mac_proto-net_port_netnet_macnet_mac_icmpnet6_mac_icmpnet6_port_net6_port-net_port_mac_proto_net"+net_port_netnet_macmac_netnet_mac_icmpnet6_mac_icmp+net6_port_net6_portnet_port_mac_proto_net"# Reported bugs, also described by TYPE_ variables belowBUGS="flush_remove_add"
On Sat, Nov 27, 2021 at 11:33:38AM +0100, Stefano Brivio wrote:
The existing net,mac test didn't cover the issue recently reported
by Nikita Yushchenko, where MAC addresses wouldn't match if given
as first field of a concatenated set with AVX2 and 8-bit groups,
because there's a different code path covering the lookup of six
8-bit groups (MAC addresses) if that's the first field.
Add a similar mac,net test, with MAC address and IPv4 address
swapped in the set specification.
Signed-off-by: Stefano Brivio <redacted>
---
.../selftests/netfilter/nft_concat_range.sh | 24 ++++++++++++++++---
1 file changed, 21 insertions(+), 3 deletions(-)
Hi Greg,
On Sat, 27 Nov 2021 12:22:39 +0100
Greg KH [off-list ref] wrote:
On Sat, Nov 27, 2021 at 11:33:38AM +0100, Stefano Brivio wrote:
quoted
The existing net,mac test didn't cover the issue recently reported
by Nikita Yushchenko, where MAC addresses wouldn't match if given
as first field of a concatenated set with AVX2 and 8-bit groups,
because there's a different code path covering the lookup of six
8-bit groups (MAC addresses) if that's the first field.
Add a similar mac,net test, with MAC address and IPv4 address
swapped in the set specification.
Signed-off-by: Stefano Brivio <redacted>
---
.../selftests/netfilter/nft_concat_range.sh | 24 ++++++++++++++++---
1 file changed, 21 insertions(+), 3 deletions(-)
The sixth byte of packet data has to be looked up in the sixth group,
not in the seventh one, even if we load the bucket data into ymm6
(and not ymm5, for convenience of tracking stalls).
Without this fix, matching on a MAC address as first field of a set,
if 8-bit groups are selected (due to a small set size) would fail,
that is, the given MAC address would never match.
Reported-by: Nikita Yushchenko <redacted>
Cc: <redacted> # 5.6.x
Fixes: 7400b063969b ("nft_set_pipapo: Introduce AVX2-based lookup implementation")
Signed-off-by: Stefano Brivio <redacted>
Tried it. The issue is indeed fixed.
Tested-By: Nikita Yushchenko <redacted>
From: Pablo Neira Ayuso <pablo@netfilter.org> Date: 2021-12-08 00:25:58
On Sat, Nov 27, 2021 at 11:33:36AM +0100, Stefano Brivio wrote:
Patch 1/2 fixes the issue reported by Nikita where a MAC address
wouldn't match if given as first field of a set, and patch 2/2 adds
the corresponding test.