Commit c0b98ac1 authored by Eric Dumazet's avatar Eric Dumazet Committed by Jakub Kicinski

ipv6: sr: block BH in seg6_output_core() and seg6_input_core()

As explained in commit 13788174 ("tipc: block BH
before using dst_cache"), net/core/dst_cache.c
helpers need to be called with BH disabled.

Disabling preemption in seg6_output_core() is not good enough,
because seg6_output_core() is called from process context,
lwtunnel_output() only uses rcu_read_lock().

We might be interrupted by a softirq, re-enter seg6_output_core()
and corrupt dst_cache data structures.

Fix the race by using local_bh_disable() instead of
preempt_disable().

Apply a similar change in seg6_input_core().

Fixes: fa79581e ("ipv6: sr: fix several BUGs when preemption is enabled")
Fixes: 6c8702c6 ("ipv6: sr: add support for SRH encapsulation and injection with lwtunnels")
Signed-off-by: default avatarEric Dumazet <edumazet@google.com>
Cc: David Lebrun <dlebrun@google.com>
Acked-by: default avatarPaolo Abeni <pabeni@redhat.com>
Link: https://lore.kernel.org/r/20240531132636.2637995-4-edumazet@google.comSigned-off-by: default avatarJakub Kicinski <kuba@kernel.org>
parent db0090c6
...@@ -464,23 +464,21 @@ static int seg6_input_core(struct net *net, struct sock *sk, ...@@ -464,23 +464,21 @@ static int seg6_input_core(struct net *net, struct sock *sk,
slwt = seg6_lwt_lwtunnel(orig_dst->lwtstate); slwt = seg6_lwt_lwtunnel(orig_dst->lwtstate);
preempt_disable(); local_bh_disable();
dst = dst_cache_get(&slwt->cache); dst = dst_cache_get(&slwt->cache);
preempt_enable();
if (!dst) { if (!dst) {
ip6_route_input(skb); ip6_route_input(skb);
dst = skb_dst(skb); dst = skb_dst(skb);
if (!dst->error) { if (!dst->error) {
preempt_disable();
dst_cache_set_ip6(&slwt->cache, dst, dst_cache_set_ip6(&slwt->cache, dst,
&ipv6_hdr(skb)->saddr); &ipv6_hdr(skb)->saddr);
preempt_enable();
} }
} else { } else {
skb_dst_drop(skb); skb_dst_drop(skb);
skb_dst_set(skb, dst); skb_dst_set(skb, dst);
} }
local_bh_enable();
err = skb_cow_head(skb, LL_RESERVED_SPACE(dst->dev)); err = skb_cow_head(skb, LL_RESERVED_SPACE(dst->dev));
if (unlikely(err)) if (unlikely(err))
...@@ -536,9 +534,9 @@ static int seg6_output_core(struct net *net, struct sock *sk, ...@@ -536,9 +534,9 @@ static int seg6_output_core(struct net *net, struct sock *sk,
slwt = seg6_lwt_lwtunnel(orig_dst->lwtstate); slwt = seg6_lwt_lwtunnel(orig_dst->lwtstate);
preempt_disable(); local_bh_disable();
dst = dst_cache_get(&slwt->cache); dst = dst_cache_get(&slwt->cache);
preempt_enable(); local_bh_enable();
if (unlikely(!dst)) { if (unlikely(!dst)) {
struct ipv6hdr *hdr = ipv6_hdr(skb); struct ipv6hdr *hdr = ipv6_hdr(skb);
...@@ -558,9 +556,9 @@ static int seg6_output_core(struct net *net, struct sock *sk, ...@@ -558,9 +556,9 @@ static int seg6_output_core(struct net *net, struct sock *sk,
goto drop; goto drop;
} }
preempt_disable(); local_bh_disable();
dst_cache_set_ip6(&slwt->cache, dst, &fl6.saddr); dst_cache_set_ip6(&slwt->cache, dst, &fl6.saddr);
preempt_enable(); local_bh_enable();
} }
skb_dst_drop(skb); skb_dst_drop(skb);
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment