]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
net: ipv6_stub: use ip6_dst_lookup_flow instead of ip6_dst_lookup
authorSabrina Dubroca <sd@queasysnail.net>
Wed, 4 Dec 2019 14:35:53 +0000 (15:35 +0100)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Wed, 20 May 2020 06:15:30 +0000 (08:15 +0200)
commit 6c8991f41546c3c472503dff1ea9daaddf9331c2 upstream.

ipv6_stub uses the ip6_dst_lookup function to allow other modules to
perform IPv6 lookups. However, this function skips the XFRM layer
entirely.

All users of ipv6_stub->ip6_dst_lookup use ip_route_output_flow (via the
ip_route_output_key and ip_route_output helpers) for their IPv4 lookups,
which calls xfrm_lookup_route(). This patch fixes this inconsistent
behavior by switching the stub to ip6_dst_lookup_flow, which also calls
xfrm_lookup_route().

This requires some changes in all the callers, as these two functions
take different arguments and have different return types.

Fixes: 5f81bd2e5d80 ("ipv6: export a stub for IPv6 symbols used by vxlan")
Reported-by: Xiumei Mu <xmu@redhat.com>
Signed-off-by: Sabrina Dubroca <sd@queasysnail.net>
Signed-off-by: David S. Miller <davem@davemloft.net>
[bwh: Backported to 4.9:
 - Drop changes in lwt_bpf.c and mlx5
 - Initialise "dst" in drivers/infiniband/core/addr.c:addr_resolve()
   to avoid introducing a spurious "may be used uninitialised" warning
 - Adjust filename, context, indentation]
Signed-off-by: Ben Hutchings <ben.hutchings@codethink.co.uk>
Signed-off-by: Sasha Levin <sashal@kernel.org>
drivers/infiniband/core/addr.c
drivers/infiniband/sw/rxe/rxe_net.c
drivers/net/geneve.c
drivers/net/vxlan.c
include/net/addrconf.h
net/ipv6/addrconf_core.c
net/ipv6/af_inet6.c
net/mpls/af_mpls.c
net/tipc/udp_media.c

index f7d23c1081dc489adf297c3ce504642c2a572e0d..68eed45b8600304cd749aae8a7a1299728b8c387 100644 (file)
@@ -453,16 +453,15 @@ static int addr6_resolve(struct sockaddr_in6 *src_in,
        struct flowi6 fl6;
        struct dst_entry *dst;
        struct rt6_info *rt;
-       int ret;
 
        memset(&fl6, 0, sizeof fl6);
        fl6.daddr = dst_in->sin6_addr;
        fl6.saddr = src_in->sin6_addr;
        fl6.flowi6_oif = addr->bound_dev_if;
 
-       ret = ipv6_stub->ipv6_dst_lookup(addr->net, NULL, &dst, &fl6);
-       if (ret < 0)
-               return ret;
+       dst = ipv6_stub->ipv6_dst_lookup_flow(addr->net, NULL, &fl6, NULL);
+       if (IS_ERR(dst))
+               return PTR_ERR(dst);
 
        rt = (struct rt6_info *)dst;
        if (ipv6_addr_any(&src_in->sin6_addr)) {
@@ -552,6 +551,7 @@ static int addr_resolve(struct sockaddr *src_in,
                const struct sockaddr_in6 *dst_in6 =
                        (const struct sockaddr_in6 *)dst_in;
 
+               dst = NULL;
                ret = addr6_resolve((struct sockaddr_in6 *)src_in,
                                    dst_in6, addr,
                                    &dst);
index f4f3942ebbd133ac1606e7381bcdccd0f3604726..d19e003e8381e4c0d8e97c35e33e8210744591a6 100644 (file)
@@ -182,10 +182,12 @@ static struct dst_entry *rxe_find_route6(struct net_device *ndev,
        memcpy(&fl6.daddr, daddr, sizeof(*daddr));
        fl6.flowi6_proto = IPPROTO_UDP;
 
-       if (unlikely(ipv6_stub->ipv6_dst_lookup(sock_net(recv_sockets.sk6->sk),
-                                               recv_sockets.sk6->sk, &ndst, &fl6))) {
+       ndst = ipv6_stub->ipv6_dst_lookup_flow(sock_net(recv_sockets.sk6->sk),
+                                              recv_sockets.sk6->sk, &fl6,
+                                              NULL);
+       if (unlikely(IS_ERR(ndst))) {
                pr_err_ratelimited("no route to %pI6\n", daddr);
-               goto put;
+               return NULL;
        }
 
        if (unlikely(ndst->error)) {
index 92ad43e53c722e3a6cef8feb17cc9a6d078e21b1..35d8c636de1237b1dbcc9849345d743e1ace7f5c 100644 (file)
@@ -835,7 +835,9 @@ static struct dst_entry *geneve_get_v6_dst(struct sk_buff *skb,
                        return dst;
        }
 
-       if (ipv6_stub->ipv6_dst_lookup(geneve->net, gs6->sock->sk, &dst, fl6)) {
+       dst = ipv6_stub->ipv6_dst_lookup_flow(geneve->net, gs6->sock->sk, fl6,
+                                             NULL);
+       if (IS_ERR(dst)) {
                netdev_dbg(dev, "no route to %pI6\n", &fl6->daddr);
                return ERR_PTR(-ENETUNREACH);
        }
index bc4542d9a08d33c04b67e73fa4f114a7a65e454d..58ddb6c90418506bc9d6eaea8f408847341c308f 100644 (file)
@@ -1881,7 +1881,6 @@ static struct dst_entry *vxlan6_get_route(struct vxlan_dev *vxlan,
        bool use_cache = ip_tunnel_dst_cache_usable(skb, info);
        struct dst_entry *ndst;
        struct flowi6 fl6;
-       int err;
 
        if (!sock6)
                return ERR_PTR(-EIO);
@@ -1902,11 +1901,10 @@ static struct dst_entry *vxlan6_get_route(struct vxlan_dev *vxlan,
        fl6.flowi6_mark = skb->mark;
        fl6.flowi6_proto = IPPROTO_UDP;
 
-       err = ipv6_stub->ipv6_dst_lookup(vxlan->net,
-                                        sock6->sock->sk,
-                                        &ndst, &fl6);
-       if (err < 0)
-               return ERR_PTR(err);
+       ndst = ipv6_stub->ipv6_dst_lookup_flow(vxlan->net, sock6->sock->sk,
+                                              &fl6, NULL);
+       if (unlikely(IS_ERR(ndst)))
+               return ERR_PTR(-ENETUNREACH);
 
        *saddr = fl6.saddr;
        if (use_cache)
index b8ee8a113e324a31eaa3b1e116755f6b7eeecfe8..019b06c035a84b803268b2977a6190c8297547de 100644 (file)
@@ -206,8 +206,10 @@ struct ipv6_stub {
                                 const struct in6_addr *addr);
        int (*ipv6_sock_mc_drop)(struct sock *sk, int ifindex,
                                 const struct in6_addr *addr);
-       int (*ipv6_dst_lookup)(struct net *net, struct sock *sk,
-                              struct dst_entry **dst, struct flowi6 *fl6);
+       struct dst_entry *(*ipv6_dst_lookup_flow)(struct net *net,
+                                                 const struct sock *sk,
+                                                 struct flowi6 *fl6,
+                                                 const struct in6_addr *final_dst);
        void (*udpv6_encap_enable)(void);
        void (*ndisc_send_na)(struct net_device *dev, const struct in6_addr *daddr,
                              const struct in6_addr *solicited_addr,
index bfa941fc1165002903b5a0364e5584b075469e2e..129324b36fb60aef87a03a810befcf433d7a2ec8 100644 (file)
@@ -107,15 +107,16 @@ int inet6addr_notifier_call_chain(unsigned long val, void *v)
 }
 EXPORT_SYMBOL(inet6addr_notifier_call_chain);
 
-static int eafnosupport_ipv6_dst_lookup(struct net *net, struct sock *u1,
-                                       struct dst_entry **u2,
-                                       struct flowi6 *u3)
+static struct dst_entry *eafnosupport_ipv6_dst_lookup_flow(struct net *net,
+                                                          const struct sock *sk,
+                                                          struct flowi6 *fl6,
+                                                          const struct in6_addr *final_dst)
 {
-       return -EAFNOSUPPORT;
+       return ERR_PTR(-EAFNOSUPPORT);
 }
 
 const struct ipv6_stub *ipv6_stub __read_mostly = &(struct ipv6_stub) {
-       .ipv6_dst_lookup = eafnosupport_ipv6_dst_lookup,
+       .ipv6_dst_lookup_flow = eafnosupport_ipv6_dst_lookup_flow,
 };
 EXPORT_SYMBOL_GPL(ipv6_stub);
 
index 2e91637c9d4912554e6c6d842355acb0a80e0310..c6746aaf7fbfb947d20abede33855d483d4608c0 100644 (file)
@@ -860,7 +860,7 @@ static struct pernet_operations inet6_net_ops = {
 static const struct ipv6_stub ipv6_stub_impl = {
        .ipv6_sock_mc_join = ipv6_sock_mc_join,
        .ipv6_sock_mc_drop = ipv6_sock_mc_drop,
-       .ipv6_dst_lookup = ip6_dst_lookup,
+       .ipv6_dst_lookup_flow = ip6_dst_lookup_flow,
        .udpv6_encap_enable = udpv6_encap_enable,
        .ndisc_send_na = ndisc_send_na,
        .nd_tbl = &nd_tbl,
index ffab94d61e1da4c123f3dc437e09bdc4838c75a1..eab9c1d70856b162395196563eff243cb3e3c7fd 100644 (file)
@@ -497,16 +497,15 @@ static struct net_device *inet6_fib_lookup_dev(struct net *net,
        struct net_device *dev;
        struct dst_entry *dst;
        struct flowi6 fl6;
-       int err;
 
        if (!ipv6_stub)
                return ERR_PTR(-EAFNOSUPPORT);
 
        memset(&fl6, 0, sizeof(fl6));
        memcpy(&fl6.daddr, addr, sizeof(struct in6_addr));
-       err = ipv6_stub->ipv6_dst_lookup(net, NULL, &dst, &fl6);
-       if (err)
-               return ERR_PTR(err);
+       dst = ipv6_stub->ipv6_dst_lookup_flow(net, NULL, &fl6, NULL);
+       if (IS_ERR(dst))
+               return ERR_CAST(dst);
 
        dev = dst->dev;
        dev_hold(dev);
index 05033ab05b8f334db9831f5b80f6054b6538c166..c6ff3de1de37bd77cfe0b10243e877f0281c5c5f 100644 (file)
@@ -187,10 +187,13 @@ static int tipc_udp_xmit(struct net *net, struct sk_buff *skb,
                        .saddr = src->ipv6,
                        .flowi6_proto = IPPROTO_UDP
                };
-               err = ipv6_stub->ipv6_dst_lookup(net, ub->ubsock->sk, &ndst,
-                                                &fl6);
-               if (err)
+               ndst = ipv6_stub->ipv6_dst_lookup_flow(net,
+                                                      ub->ubsock->sk,
+                                                      &fl6, NULL);
+               if (IS_ERR(ndst)) {
+                       err = PTR_ERR(ndst);
                        goto tx_error;
+               }
                ttl = ip6_dst_hoplimit(ndst);
                err = udp_tunnel6_xmit_skb(ndst, ub->ubsock->sk, skb, NULL,
                                           &src->ipv6, &dst->ipv6, 0, ttl, 0,