mirror of
https://github.com/torvalds/linux.git
synced 2026-09-11 20:13:02 +02:00
openvswitch: fix wrong flag value in get_ipv6_ext_hdrs()
The ESP and AH cases in get_ipv6_ext_hdrs() used IPPROTO_FRAGMENT instead
of OFPIEH12_FRAG when checking for out-of-order extension headers, causing
the fragment header to not be recognised as a valid predecessor.
The original code used IPPROTO_FRAGMENT (44) as a bitmask constant where
OFPIEH12_FRAG (1 << 4 = 16) was intended. IPPROTO_FRAGMENT encodes bits
2, 3 and 5 (OFPIEH12_AUTH | OFPIEH12_DEST | OFPIEH12_ROUTER), but not
bit 4 (OFPIEH12_FRAG). This caused incorrect OFPIEH12_UNSEQ verdicts in
both the ESP and AH arms: the ESP arm failed to whitelist OFPIEH12_FRAG,
while the AH arm accidentally whitelisted OFPIEH12_AUTH.
With the fix, a packet with two AH headers now also gets OFPIEH12_UNSEQ
in addition to OFPIEH12_UNREP, matching the ESP arm which already sets
UNSEQ on a repeat, which is the intended behavior.
Fixes: 28a3f06017 ("net: openvswitch: IPv6: Add IPv6 extension header support")
Reported-by: Paolo Abeni <pabeni@redhat.com>
Reviewed-by: Aaron Conole <aconole@redhat.com>
Reviewed-by: Ilya Maximets <i.maximets@ovn.org>
Signed-off-by: Eelco Chaudron <echaudro@redhat.com>
Link: https://patch.msgid.link/1b1582eb07550d71f3cbe210e5cb31eeb8d0ad86.1788876917.git.echaudro@redhat.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
This commit is contained in:
parent
b7ee18725f
commit
e184a4a6f4
|
|
@ -288,7 +288,7 @@ static void get_ipv6_ext_hdrs(struct sk_buff *skb, struct ipv6hdr *nh,
|
|||
if (*ext_hdrs & OFPIEH12_ESP)
|
||||
*ext_hdrs |= OFPIEH12_UNREP;
|
||||
if ((*ext_hdrs & ~(OFPIEH12_HOP | OFPIEH12_DEST |
|
||||
OFPIEH12_ROUTER | IPPROTO_FRAGMENT |
|
||||
OFPIEH12_ROUTER | OFPIEH12_FRAG |
|
||||
OFPIEH12_AUTH | OFPIEH12_UNREP)) ||
|
||||
dest_options_header_count >= 2) {
|
||||
*ext_hdrs |= OFPIEH12_UNSEQ;
|
||||
|
|
@ -301,7 +301,7 @@ static void get_ipv6_ext_hdrs(struct sk_buff *skb, struct ipv6hdr *nh,
|
|||
*ext_hdrs |= OFPIEH12_UNREP;
|
||||
if ((*ext_hdrs &
|
||||
~(OFPIEH12_HOP | OFPIEH12_DEST | OFPIEH12_ROUTER |
|
||||
IPPROTO_FRAGMENT | OFPIEH12_UNREP)) ||
|
||||
OFPIEH12_FRAG | OFPIEH12_UNREP)) ||
|
||||
dest_options_header_count >= 2) {
|
||||
*ext_hdrs |= OFPIEH12_UNSEQ;
|
||||
}
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user