Paul Blakey
d0251c38df
openvswitch: Fix setting ipv6 fields causing hw csum failure
commit d9b5ae5c1b241b91480aa30408be12fe91af834a upstream.
Ipv6 ttl, label and tos fields are modified without first
pulling/pushing the ipv6 header, which would have updated
the hw csum (if available). This might cause csum validation
when sending the packet to the stack, as can be seen in
the trace below.
Fix this by updating skb->csum if available.
Trace resulted by ipv6 ttl dec and then sending packet
to conntrack [actions: set(ipv6(hlimit=63)),ct(zone=99)]:
[295241.900063] s_pf0vf2: hw csum failure
[295241.923191] Call Trace:
[295241.925728] <IRQ>
[295241.927836] dump_stack+0x5c/0x80
[295241.931240] __skb_checksum_complete+0xac/0xc0
[295241.935778] nf_conntrack_tcp_packet+0x398/0xba0 [nf_conntrack]
[295241.953030] nf_conntrack_in+0x498/0x5e0 [nf_conntrack]
[295241.958344] __ovs_ct_lookup+0xac/0x860 [openvswitch]
[295241.968532] ovs_ct_execute+0x4a7/0x7c0 [openvswitch]
[295241.979167] do_execute_actions+0x54a/0xaa0 [openvswitch]
[295242.001482] ovs_execute_actions+0x48/0x100 [openvswitch]
[295242.006966] ovs_dp_process_packet+0x96/0x1d0 [openvswitch]
[295242.012626] ovs_vport_receive+0x6c/0xc0 [openvswitch]
[295242.028763] netdev_frame_hook+0xc0/0x180 [openvswitch]
[295242.034074] __netif_receive_skb_core+0x2ca/0xcb0
[295242.047498] netif_receive_skb_internal+0x3e/0xc0
[295242.052291] napi_gro_receive+0xba/0xe0
[295242.056231] mlx5e_handle_rx_cqe_mpwrq_rep+0x12b/0x250 [mlx5_core]
[295242.062513] mlx5e_poll_rx_cq+0xa0f/0xa30 [mlx5_core]
[295242.067669] mlx5e_napi_poll+0xe1/0x6b0 [mlx5_core]
[295242.077958] net_rx_action+0x149/0x3b0
[295242.086762] __do_softirq+0xd7/0x2d6
[295242.090427] irq_exit+0xf7/0x100
[295242.093748] do_IRQ+0x7f/0xd0
[295242.096806] common_interrupt+0xf/0xf
[295242.100559] </IRQ>
[295242.102750] RIP: 0033:0x7f9022e88cbd
[295242.125246] RSP: 002b:00007f9022282b20 EFLAGS: 00000246 ORIG_RAX: ffffffffffffffda
[295242.132900] RAX: 0000000000000005 RBX: 0000000000000010 RCX: 0000000000000000
[295242.140120] RDX: 00007f9022282ba8 RSI: 00007f9022282a30 RDI: 00007f9014005c30
[295242.147337] RBP: 00007f9014014d60 R08: 0000000000000020 R09: 00007f90254a8340
[295242.154557] R10: 00007f9022282a28 R11: 0000000000000246 R12: 0000000000000000
[295242.161775] R13: 00007f902308c000 R14: 000000000000002b R15: 00007f9022b71f40
Fixes: 3fdbd1ce11 ("openvswitch: add ipv6 'set' action")
Signed-off-by: Paul Blakey <paulb@nvidia.com>
Link: https://lore.kernel.org/r/20220223163416.24096-1-paulb@nvidia.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
|
2022-03-02 11:41:07 +01:00 |
| .. |
|
6lowpan
|
|
|
|
9p
|
9p/net: fix missing error check in p9_check_errors
|
2021-11-17 09:48:49 +01:00 |
|
802
|
|
|
|
8021q
|
net: vlan: fix underflow for the real_dev refcnt
|
2021-12-01 09:23:34 +01:00 |
|
appletalk
|
|
|
|
atm
|
|
|
|
ax25
|
ax25: improve the incomplete fix to avoid UAF and NPD bugs
|
2022-02-23 11:59:55 +01:00 |
|
batman-adv
|
batman-adv: allow netlink usage in unprivileged containers
|
2022-01-27 09:19:41 +01:00 |
|
bluetooth
|
Bluetooth: refactor malicious adv data check
|
2022-02-01 17:24:33 +01:00 |
|
bpf
|
|
|
|
bpfilter
|
|
|
|
bridge
|
net: bridge: fix stale eth hdr pointer in br_dev_xmit
|
2022-02-16 12:52:50 +01:00 |
|
caif
|
|
|
|
can
|
can: j1939: j1939_tp_cmd_recv(): check the dst address of TP.CM_BAM
|
2021-12-08 09:01:08 +01:00 |
|
ceph
|
|
|
|
core
|
net: __pskb_pull_tail() & pskb_carve_frag_list() drop_monitor friends
|
2022-03-02 11:41:06 +01:00 |
|
dcb
|
|
|
|
dccp
|
dccp: don't duplicate ccid when cloning dccp sock
|
2021-09-22 12:26:40 +02:00 |
|
decnet
|
|
|
|
dns_resolver
|
|
|
|
dsa
|
net: dsa: destroy the phylink instance on any error in dsa_slave_phy_setup
|
2021-09-22 12:26:42 +02:00 |
|
ethernet
|
|
|
|
hsr
|
|
|
|
ieee802154
|
net: ieee802154: Return meaningful error codes from the netlink helpers
|
2022-02-08 18:24:31 +01:00 |
|
ife
|
|
|
|
ipv4
|
gso: do not skip outer ip header in case of ipip and net_failover
|
2022-03-02 11:41:06 +01:00 |
|
ipv6
|
gso: do not skip outer ip header in case of ipip and net_failover
|
2022-03-02 11:41:06 +01:00 |
|
iucv
|
|
|
|
kcm
|
|
|
|
key
|
|
|
|
l2tp
|
net/l2tp: Fix reference count leak in l2tp_udp_recv_core
|
2021-09-22 12:26:41 +02:00 |
|
l3mdev
|
|
|
|
lapb
|
|
|
|
llc
|
|
|
|
mac80211
|
mac80211: allow non-standard VHT MCS-10/11
|
2022-01-27 09:19:46 +01:00 |
|
mac802154
|
|
|
|
mpls
|
net: mpls: Fix notifications when deleting a device
|
2021-12-08 09:01:12 +01:00 |
|
ncsi
|
net/ncsi: check for error return from call to nla_put_u32
|
2022-01-05 12:37:45 +01:00 |
|
netfilter
|
netfilter: nf_tables_offload: incorrect flow offload action array size
|
2022-03-02 11:41:03 +01:00 |
|
netlabel
|
|
|
|
netlink
|
net: netlink: af_netlink: Prevent empty skb by adding a check on len.
|
2021-12-17 10:12:23 +01:00 |
|
netrom
|
|
|
|
nfc
|
nfc: llcp: fix NULL error pointer dereference on sendmsg() after failed bind()
|
2022-01-27 09:19:26 +01:00 |
|
nsh
|
|
|
|
openvswitch
|
openvswitch: Fix setting ipv6 fields causing hw csum failure
|
2022-03-02 11:41:07 +01:00 |
|
packet
|
af_packet: fix data-race in packet_setsockopt / packet_setsockopt
|
2022-02-05 12:35:37 +01:00 |
|
phonet
|
phonet: refcount leak in pep_sock_accep
|
2022-01-11 15:23:33 +01:00 |
|
psample
|
|
|
|
qrtr
|
|
|
|
rds
|
rds: memory leak in __rds_conn_create()
|
2021-12-22 09:29:37 +01:00 |
|
rfkill
|
|
|
|
rose
|
|
|
|
rxrpc
|
rxrpc: Adjust retransmission backoff
|
2022-02-01 17:24:38 +01:00 |
|
sched
|
net: sched: limit TC_ACT_REPEAT loops
|
2022-02-23 11:59:59 +01:00 |
|
sctp
|
sctp: use call_rcu to free endpoint
|
2022-01-05 12:37:44 +01:00 |
|
smc
|
net/smc: Prevent smc_release() from long blocking
|
2021-12-22 09:29:38 +01:00 |
|
strparser
|
bpf: sockmap, strparser, and tls are reusing qdisc_skb_cb and colliding
|
2021-11-17 09:48:48 +01:00 |
|
sunrpc
|
fsnotify: fix fsnotify hooks in pseudo filesystems
|
2022-02-01 17:24:34 +01:00 |
|
switchdev
|
net: switchdev: do not propagate bridge updates across bridges
|
2021-10-27 09:54:24 +02:00 |
|
tipc
|
tipc: Fix end of loop tests for list_for_each_entry()
|
2022-03-02 11:41:06 +01:00 |
|
tls
|
net/tls: Fix authentication failure in CCM mode
|
2021-12-08 09:01:14 +01:00 |
|
unix
|
af_unix: annote lockless accesses to unix_tot_inflight & gc_in_progress
|
2022-01-27 09:19:53 +01:00 |
|
vmw_vsock
|
vsock: remove vsock from connected table when connect is interrupted by a signal
|
2022-02-23 11:59:57 +01:00 |
|
wimax
|
|
|
|
wireless
|
cfg80211: call cfg80211_stop_ap when switch from P2P_GO type
|
2021-11-26 10:47:22 +01:00 |
|
x25
|
|
|
|
xdp
|
Revert "xsk: Do not sleep in poll() when need_wakeup set"
|
2021-12-22 09:29:40 +01:00 |
|
xfrm
|
xfrm: Don't accidentally set RTO_ONLINK in decode_session4()
|
2022-01-27 09:19:54 +01:00 |
|
compat.c
|
|
|
|
Kconfig
|
|
|
|
Makefile
|
|
|
|
socket.c
|
|
|
|
sysctl_net.c
|
|
|