Re: [PATCH] openvswitch: supply a dummy err_handler of gre_cisco_protocol to prevent kernel crash
From: wei zhang
Date: Sun Mar 30 2014 - 08:28:50 EST
At 2014-03-29 06:02:25,"Jesse Gross" <jesse@xxxxxxxxxx> wrote:
>I'm not sure that rejecting all ICMP packets is the correct thing do
>here since it means that we could pass them onto a later caller even
>though they are intended for us. We should probably use the same logic
>as for receiving packets and just discard them here.
Thank you very much for your advice, did you mean this logic? Â
diff --git a/net/openvswitch/vport-gre.c b/net/openvswitch/vport-gre.c
index a3d6951..c183a56 100644
--- a/net/openvswitch/vport-gre.c
+++ b/net/openvswitch/vport-gre.c
@@ -110,6 +110,21 @@ static int gre_rcv(struct sk_buff *skb,
    return PACKET_RCVD;
Â}
Â
+/* Called with rcu_read_lock and BH disabled. */
+static int gre_err(struct sk_buff *skb, u32 info,
+ Â Â Â Â Â Â Â Â Âconst struct tnl_ptk_info *tpi)
+{
+ Â Â Â struct ovs_net *ovs_net;
+ Â Â Â struct vport *vport;
+
+ Â Â Â ovs_net = net_generic(dev_net(skb->dev), ovs_net_id);
+ Â Â Â vport = rcu_dereference(ovs_net->vport_net.gre_vport);
+ Â Â Â if (unlikely(!vport))
+ Â Â Â Â Â Â Â return PACKET_REJECT;
+ Â Â Â else
+ Â Â Â Â Â Â Â return PACKET_RCVD;
+}
Maybe I misunderstand something? I think if we discard all packet pass to us
when we use gre vport, new gre_cisco_protocol which has lower priority could
not see the packetÂintended to it.
I checked the implementation of the ipgre_err(), which has be called before
the err_handler of gre vport. It use theÂthe (local address, remote address, key)
to distinguish the packet whichÂis realy intended to it,Âalthough it could not
always get the key from the icmpÂpacket. Should we do as the same as it?
I'm not sure this is feasible, any advice is appreciate.
Regards,
Wei Zhang
N§²æ¸yú²X¬¶ÇvØ)Þ{.nÇ·¥{±êX§¶¡Ü}©²ÆzÚj:+v¨¾«êZ+Êzf£¢·h§~Ûÿû®w¥¢¸?¨è&¢)ßfùy§m
á«a¶Úÿ0¶ìå