Patch "net: ipv4: Fix multipath selection with vrf" has been added to the 4.9-stable tree
From: <gregkh@linuxfoundation.org>
Date: 2017-01-12 20:48:28
This is a note to let you know that I've just added the patch titled
net: ipv4: Fix multipath selection with vrf
to the 4.9-stable tree which can be found at:
http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary
The filename of the patch is:
net-ipv4-fix-multipath-selection-with-vrf.patch
and it can be found in the queue-4.9 subdirectory.
If you, or anyone else, feels it should not be added to the stable tree,
please let [off-list ref] know about it.
From foo@baz Thu Jan 12 21:37:26 CET 2017
From: David Ahern <redacted>
Date: Tue, 10 Jan 2017 14:37:35 -0800
Subject: net: ipv4: Fix multipath selection with vrf
From: David Ahern <redacted>
[ Upstream commit 7a18c5b9fb31a999afc62b0e60978aa896fc89e9 ]
fib_select_path does not call fib_select_multipath if oif is set in the
flow struct. For VRF use cases oif is always set, so multipath route
selection is bypassed. Use the FLOWI_FLAG_SKIP_NH_OIF to skip the oif
check similar to what is done in fib_table_lookup.
Add saddr and proto to the flow struct for the fib lookup done by the
VRF driver to better match hash computation for a flow.
Fixes: 613d09b30f8b ("net: Use VRF device index for lookups on TX")
Signed-off-by: David Ahern <redacted>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/vrf.c | 2 ++
net/ipv4/fib_semantics.c | 9 +++++++--
2 files changed, 9 insertions(+), 2 deletions(-)
--- a/drivers/net/vrf.c
+++ b/drivers/net/vrf.c@@ -263,7 +263,9 @@ static netdev_tx_t vrf_process_v4_outbou .flowi4_iif = LOOPBACK_IFINDEX, .flowi4_tos = RT_TOS(ip4h->tos), .flowi4_flags = FLOWI_FLAG_ANYSRC | FLOWI_FLAG_SKIP_NH_OIF, + .flowi4_proto = ip4h->protocol, .daddr = ip4h->daddr, + .saddr = ip4h->saddr, }; struct net *net = dev_net(vrf_dev); struct rtable *rt; --- a/net/ipv4/fib_semantics.c +++ b/net/ipv4/fib_semantics.c
@@ -1617,8 +1617,13 @@ void fib_select_multipath(struct fib_res void fib_select_path(struct net *net, struct fib_result *res, struct flowi4 *fl4, int mp_hash) { + bool oif_check; + + oif_check = (fl4->flowi4_oif == 0 || + fl4->flowi4_flags & FLOWI_FLAG_SKIP_NH_OIF); + #ifdef CONFIG_IP_ROUTE_MULTIPATH - if (res->fi->fib_nhs > 1 && fl4->flowi4_oif == 0) { + if (res->fi->fib_nhs > 1 && oif_check) { if (mp_hash < 0) mp_hash = get_hash_from_flowi4(fl4) >> 1;
@@ -1628,7 +1633,7 @@ void fib_select_path(struct net *net, st #endif if (!res->prefixlen && res->table->tb_num_default > 1 && - res->type == RTN_UNICAST && !fl4->flowi4_oif) + res->type == RTN_UNICAST && oif_check) fib_select_default(fl4, res); if (!fl4->saddr)
Patches currently in stable-queue which might be from dsa@cumulusnetworks.com are queue-4.9/net-vrf-drop-conntrack-data-after-pass-through-vrf-device-on-tx.patch queue-4.9/net-ipv4-fix-multipath-selection-with-vrf.patch queue-4.9/net-ipv4-dst-for-local-input-routes-should-use-l3mdev-if-relevant.patch queue-4.9/net-vrf-add-missing-rx-counters.patch queue-4.9/net-vrf-do-not-allow-table-id-0.patch queue-4.9/net-vrf-fix-nat-within-a-vrf.patch queue-4.9/net-fix-incorrect-original-ingress-device-index-in-pktinfo.patch