ip6gre_init_net() links the fallback device ip6gre0 to
ign->tunnels_wc[0] after publishing it by register_netdev().
While ip6_gre module is being loaded, there is a small race window.
If ioctl(SIOCADDTUNNEL) is called before ip6gre0 is linked to
the hash table, a new device could be linked to ign->tunnels_wc[0].
Then, the fallback device overwrites ign->tunnels_wc[0], and the new
device will be no longer found by ip6gre_tunnel_lookup(), resulting
in no RX.
Let's link the fallback device before register_netdev().
Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
---
day 1 bug since 2012, not worth backporting, but if we want
Fixes: c12b395a4664 ("gre: Support GRE over IPv6")
---
net/ipv6/ip6_gre.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
diff --git a/net/ipv6/ip6_gre.c b/net/ipv6/ip6_gre.c
index 8ebda0b6a78b..183218100d69 100644
--- a/net/ipv6/ip6_gre.c
+++ b/net/ipv6/ip6_gre.c
@@ -1607,12 +1607,13 @@ static int __net_init ip6gre_init_net(struct net *net)
ip6gre_fb_tunnel_init(ign->fb_tunnel_dev);
ign->fb_tunnel_dev->rtnl_link_ops = &ip6gre_link_ops;
+ rcu_assign_pointer(ign->tunnels_wc[0],
+ netdev_priv(ign->fb_tunnel_dev));
+
err = register_netdev(ign->fb_tunnel_dev);
if (err)
goto err_reg_dev;
- rcu_assign_pointer(ign->tunnels_wc[0],
- netdev_priv(ign->fb_tunnel_dev));
return 0;
err_reg_dev:
--
2.55.0.1082.g2b9226bbc0-goog