[PATCH net 1/1] net/sched: act_ct: Fix flow table lookup after ct clear or switching zones

Subsystems: networking [general], tc subsystem, the rest

STALE1679d

3 messages, 3 authors, 2022-02-18 · open the first message on its own page

[PATCH net 1/1] net/sched: act_ct: Fix flow table lookup after ct clear or switching zones

From: Paul Blakey <hidden>
Date: 2022-02-17 09:32:02

Flow table lookup is skipped if packet either went through ct clear
action (which set the IP_CT_UNTRACKED flag on the packet), or while
switching zones and there is already a connection associated with
the packet. This will result in no SW offload of the connection,
and the and connection not being removed from flow table with
TCP teardown (fin/rst packet).

To fix the above, remove these unneccary checks in flow
table lookup.

Fixes: 46475bb20f4b ("net/sched: act_ct: Software offload of established flows")
Signed-off-by: Paul Blakey <redacted>
---
 net/sched/act_ct.c | 5 -----
 1 file changed, 5 deletions(-)
diff --git a/net/sched/act_ct.c b/net/sched/act_ct.c
index f99247fc6468..33e70d60f0bf 100644
--- a/net/sched/act_ct.c
+++ b/net/sched/act_ct.c
@@ -533,11 +533,6 @@ static bool tcf_ct_flow_table_lookup(struct tcf_ct_params *p,
 	struct nf_conn *ct;
 	u8 dir;
 
-	/* Previously seen or loopback */
-	ct = nf_ct_get(skb, &ctinfo);
-	if ((ct && !nf_ct_is_template(ct)) || ctinfo == IP_CT_UNTRACKED)
-		return false;
-
 	switch (family) {
 	case NFPROTO_IPV4:
 		if (!tcf_ct_flow_table_fill_tuple_ipv4(skb, &tuple, &tcph))
-- 
2.30.1

Re: [PATCH net 1/1] net/sched: act_ct: Fix flow table lookup after ct clear or switching zones

From: Marcelo Ricardo Leitner <marcelo.leitner@gmail.com>
Date: 2022-02-17 23:10:06

On Thu, Feb 17, 2022 at 11:30:48AM +0200, Paul Blakey wrote:
Flow table lookup is skipped if packet either went through ct clear
action (which set the IP_CT_UNTRACKED flag on the packet), or while
switching zones and there is already a connection associated with
the packet. This will result in no SW offload of the connection,
and the and connection not being removed from flow table with
TCP teardown (fin/rst packet).

To fix the above, remove these unneccary checks in flow
table lookup.

Fixes: 46475bb20f4b ("net/sched: act_ct: Software offload of established flows")
Signed-off-by: Paul Blakey <redacted>
Acked-by: Marcelo Ricardo Leitner <marcelo.leitner@gmail.com>

Re: [PATCH net 1/1] net/sched: act_ct: Fix flow table lookup after ct clear or switching zones

From: patchwork-bot+netdevbpf@kernel.org
Date: 2022-02-18 11:10:20

Hello:

This patch was applied to netdev/net.git (master)
by David S. Miller [off-list ref]:

On Thu, 17 Feb 2022 11:30:48 +0200 you wrote:
Flow table lookup is skipped if packet either went through ct clear
action (which set the IP_CT_UNTRACKED flag on the packet), or while
switching zones and there is already a connection associated with
the packet. This will result in no SW offload of the connection,
and the and connection not being removed from flow table with
TCP teardown (fin/rst packet).

[...]
Here is the summary with links:
  - [net,1/1] net/sched: act_ct: Fix flow table lookup after ct clear or switching zones
    https://git.kernel.org/netdev/net/c/2f131de361f6

You are awesome, thank you!
-- 
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html

Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help