Thread (7 messages) 7 messages, 2 authors, 2024-02-22

[PATCH net 3/5] netfilter: nft_flow_offload: release dst in case direct xmit path is used

flat view
STALE959d

From: Pablo Neira Ayuso <pablo@netfilter.org>
Date: 2024-02-22 00:08:52
Also in: netfilter-devel
Subsystem: netfilter, networking [general], the rest · Maintainers: Pablo Neira Ayuso, Florian Westphal, "David S. Miller", Eric Dumazet, Jakub Kicinski, Paolo Abeni, Linus Torvalds

Revision v1 of 205 in this series.

Revisions (205)
  1. v1
  2. v1
  3. v1
  4. v1
  5. v1
  6. v1
  7. v1
  8. v1
  9. v1
  10. v1
  11. v1
  12. v1
  13. v1
  14. v1
  15. v1
  16. v1
  17. v1
  18. v1
  19. v1
  20. v1
  21. v1
  22. v1
  23. v1
  24. v1
  25. v1
  26. v1
  27. v1
  28. v1
  29. v1
  30. v1
  31. v1
  32. v1
  33. v1
  34. v1
  35. v1
  36. v1
  37. v1
  38. v1
  39. v1
  40. v1
  41. v1
  42. v1
  43. v1
  44. v1
  45. v1
  46. v1
  47. v1
  48. v1
  49. v1
  50. v1
  51. v1
  52. v1
  53. v1
  54. v1
  55. v1
  56. v1
  57. v1
  58. v1
  59. v1
  60. v1
  61. v1
  62. v1
  63. v1
  64. v1
  65. v1
  66. v1
  67. v1
  68. v1
  69. v1
  70. v1
  71. v1
  72. v1
  73. v1
  74. v1
  75. v1
  76. v1
  77. v1
  78. v1
  79. v1
  80. v1
  81. v1
  82. v1
  83. v1
  84. v1
  85. v1
  86. v1
  87. v1
  88. v1
  89. v1
  90. v1
  91. v1
  92. v1
  93. v1
  94. v1
  95. v1
  96. v1
  97. v1
  98. v1
  99. v1
  100. v1
  101. v1
  102. v1
  103. v1
  104. v1
  105. v1
  106. v1
  107. v1
  108. v1
  109. v1
  110. v1
  111. v2 [diff vs current]
  112. v1
  113. v1
  114. v1
  115. v1
  116. v1
  117. v1
  118. v1
  119. v1
  120. v1
  121. v1
  122. v1
  123. v2 [diff vs current]
  124. v1
  125. v1
  126. v1
  127. v1
  128. v1
  129. v1
  130. v1
  131. v1
  132. v1
  133. v1
  134. v1
  135. v1
  136. v1
  137. v1
  138. v1
  139. v1
  140. v1
  141. v1
  142. v1
  143. v1
  144. v1
  145. v1
  146. v1
  147. v1
  148. v1
  149. v1
  150. v1
  151. v1
  152. v1
  153. v1
  154. v1
  155. v1
  156. v1
  157. v1
  158. v1
  159. v1
  160. v2 [diff vs current]
  161. v1
  162. v1
  163. v1
  164. v2 [diff vs current]
  165. v1
  166. v1 current
  167. v1
  168. v1
  169. v2 [diff vs current]
  170. v1
  171. v1
  172. v1
  173. v1
  174. v3 [diff vs current]
  175. v1
  176. v1
  177. v1
  178. v1
  179. v1
  180. v2 [diff vs current]
  181. v1
  182. v1
  183. v1
  184. v1
  185. v1
  186. v2 [diff vs current]
  187. v1
  188. v1
  189. v1
  190. v1
  191. v1
  192. v1
  193. v1
  194. v2 [diff vs current]
  195. v1
  196. v2 [diff vs current]
  197. v1
  198. v1
  199. v1
  200. v1
  201. v2 [diff vs current]
  202. v1
  203. v1
  204. v2 [diff vs current]
  205. v2 [diff vs current]
Direct xmit does not use it since it calls dev_queue_xmit() to send
packets, hence it calls dst_release().

kmemleak reports:

unreferenced object 0xffff88814f440900 (size 184):
  comm "softirq", pid 0, jiffies 4294951896
  hex dump (first 32 bytes):
    00 60 5b 04 81 88 ff ff 00 e6 e8 82 ff ff ff ff  .`[.............
    21 0b 50 82 ff ff ff ff 00 00 00 00 00 00 00 00  !.P.............
  backtrace (crc cb2bf5d6):
    [<000000003ee17107>] kmem_cache_alloc+0x286/0x340
    [<0000000021a5de2c>] dst_alloc+0x43/0xb0
    [<00000000f0671159>] rt_dst_alloc+0x2e/0x190
    [<00000000fe5092c9>] __mkroute_output+0x244/0x980
    [<000000005fb96fb0>] ip_route_output_flow+0xc0/0x160
    [<0000000045367433>] nf_ip_route+0xf/0x30
    [<0000000085da1d8e>] nf_route+0x2d/0x60
    [<00000000d1ecd1cb>] nft_flow_route+0x171/0x6a0 [nft_flow_offload]
    [<00000000d9b2fb60>] nft_flow_offload_eval+0x4e8/0x700 [nft_flow_offload]
    [<000000009f447dbb>] expr_call_ops_eval+0x53/0x330 [nf_tables]
    [<00000000072e1be6>] nft_do_chain+0x17c/0x840 [nf_tables]
    [<00000000d0551029>] nft_do_chain_inet+0xa1/0x210 [nf_tables]
    [<0000000097c9d5c6>] nf_hook_slow+0x5b/0x160
    [<0000000005eccab1>] ip_forward+0x8b6/0x9b0
    [<00000000553a269b>] ip_rcv+0x221/0x230
    [<00000000412872e5>] __netif_receive_skb_one_core+0xfe/0x110

Fixes: fa502c865666 ("netfilter: flowtable: simplify route logic")
Reported-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
---
 net/netfilter/nf_flow_table_core.c | 1 +
 1 file changed, 1 insertion(+)
diff --git a/net/netfilter/nf_flow_table_core.c b/net/netfilter/nf_flow_table_core.c
index 7502d6d73a60..a0571339239c 100644
--- a/net/netfilter/nf_flow_table_core.c
+++ b/net/netfilter/nf_flow_table_core.c
@@ -132,6 +132,7 @@ static int flow_offload_fill_route(struct flow_offload *flow,
 		       ETH_ALEN);
 		flow_tuple->out.ifidx = route->tuple[dir].out.ifindex;
 		flow_tuple->out.hw_ifidx = route->tuple[dir].out.hw_ifindex;
+		dst_release(dst);
 		break;
 	case FLOW_OFFLOAD_XMIT_XFRM:
 	case FLOW_OFFLOAD_XMIT_NEIGH:
-- 
2.30.2
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help