]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
net: Do not route unicast IP packets twice
authorIdo Schimmel <idosch@mellanox.com>
Tue, 4 Dec 2018 08:15:11 +0000 (08:15 +0000)
committerDavid S. Miller <davem@davemloft.net>
Tue, 4 Dec 2018 16:36:36 +0000 (08:36 -0800)
Packets marked with 'offload_l3_fwd_mark' were already forwarded by a
capable device and should not be forwarded again by the kernel.
Therefore, have the kernel consume them.

The check is performed in ip{,6}_forward_finish() in order to allow the
kernel to process such packets in ip{,6}_forward() and generate required
exceptions. For example, ICMP redirects.

Signed-off-by: Ido Schimmel <idosch@mellanox.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
net/ipv4/ip_forward.c
net/ipv6/ip6_output.c

index 32662e9e5d218868341169bba1dc3ab430952c58..06ee4696703c0ce72ea914403b739839e60f1584 100644 (file)
@@ -69,6 +69,13 @@ static int ip_forward_finish(struct net *net, struct sock *sk, struct sk_buff *s
        __IP_INC_STATS(net, IPSTATS_MIB_OUTFORWDATAGRAMS);
        __IP_ADD_STATS(net, IPSTATS_MIB_OUTOCTETS, skb->len);
 
+#ifdef CONFIG_NET_SWITCHDEV
+       if (skb->offload_l3_fwd_mark) {
+               consume_skb(skb);
+               return 0;
+       }
+#endif
+
        if (unlikely(opt->optlen))
                ip_forward_options(skb);
 
index ec8c235ea891a7dfdc978e61fa71aee0d5abcd17..6592a39e5ec10442356641ed5ad125026aa0c194 100644 (file)
@@ -378,6 +378,13 @@ static inline int ip6_forward_finish(struct net *net, struct sock *sk,
        __IP6_INC_STATS(net, ip6_dst_idev(dst), IPSTATS_MIB_OUTFORWDATAGRAMS);
        __IP6_ADD_STATS(net, ip6_dst_idev(dst), IPSTATS_MIB_OUTOCTETS, skb->len);
 
+#ifdef CONFIG_NET_SWITCHDEV
+       if (skb->offload_l3_fwd_mark) {
+               consume_skb(skb);
+               return 0;
+       }
+#endif
+
        return dst_output(net, sk, skb);
 }