Re: [PATCH net] ipvs: Always clear ipvs_property flag in skb_scrub_packet()

From: Philo Lu
Date: Fri Feb 21 2025 - 06:56:55 EST




On 2025/2/21 19:42, Julian Anastasov wrote:

Hello,

On Fri, 21 Feb 2025, Philo Lu wrote:

We found an issue when using bpf_redirect with ipvs NAT mode after
commit ff70202b2d1a ("dev_forward_skb: do not scrub skb mark within
the same name space"). Particularly, we use bpf_redirect to return
the skb directly back to the netif it comes from, i.e., xnet is
false in skb_scrub_packet(), and then ipvs_property is preserved
and SNAT is skipped in the rx path.

ipvs_property has been already cleared when netns is changed in
commit 2b5ec1a5f973 ("netfilter/ipvs: clear ipvs_property flag when
SKB net namespace changed"). This patch just clears it in spite of
netns.

Signed-off-by: Philo Lu <lulie@xxxxxxxxxxxxxxxxx>
---
This is in fact a fix patch, and the issue was found after commit
ff70202b2d1a ("dev_forward_skb: do not scrub skb mark within
the same name space"). But I'm not sure if a "Fixes" tag should be
added to that commit.

You can add 2b5ec1a5f973 as a Fixes tag in v2 and I'll ack it.

Thank you, Julian. You also solve my worries. I'll post v2 soon.

--
Philo