mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
synced 2026-08-27 18:43:12 -04:00
netfilter: flowtable: tear down flow entries with stale dst from GC
In case of route updates, tear down flow entries with stale dst to give them a chance to obtain a fresh route. This is specifically useful for hardware offloaded entries, where the flowtable software dataplane sees no packet, where the existing check for stale dst entries does not help. Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
This commit is contained in:
@@ -310,6 +310,14 @@ int flow_offload_add(struct nf_flowtable *flow_table, struct flow_offload *flow)
|
||||
void flow_offload_refresh(struct nf_flowtable *flow_table,
|
||||
struct flow_offload *flow, bool force);
|
||||
|
||||
static inline bool nf_flow_dst_check(struct flow_offload_tuple *tuple)
|
||||
{
|
||||
if (!tuple->dst_cache)
|
||||
return true;
|
||||
|
||||
return dst_check(tuple->dst_cache, tuple->dst_cookie);
|
||||
}
|
||||
|
||||
struct flow_offload_tuple_rhash *flow_offload_lookup(struct nf_flowtable *flow_table,
|
||||
struct flow_offload_tuple *tuple);
|
||||
void nf_flow_table_gc_run(struct nf_flowtable *flow_table);
|
||||
|
||||
@@ -571,6 +571,8 @@ static void nf_flow_offload_gc_step(struct nf_flowtable *flow_table,
|
||||
|
||||
if (nf_flow_has_expired(flow) ||
|
||||
nf_ct_is_dying(flow->ct) ||
|
||||
!nf_flow_dst_check(&flow->tuplehash[FLOW_OFFLOAD_DIR_ORIGINAL].tuple) ||
|
||||
!nf_flow_dst_check(&flow->tuplehash[FLOW_OFFLOAD_DIR_REPLY].tuple) ||
|
||||
nf_flow_custom_gc(flow_table, flow)) {
|
||||
flow_offload_teardown(flow);
|
||||
teardown = true;
|
||||
|
||||
@@ -297,14 +297,6 @@ static bool nf_flow_exceeds_mtu(const struct sk_buff *skb, unsigned int mtu)
|
||||
return true;
|
||||
}
|
||||
|
||||
static inline bool nf_flow_dst_check(struct flow_offload_tuple *tuple)
|
||||
{
|
||||
if (!tuple->dst_cache)
|
||||
return true;
|
||||
|
||||
return dst_check(tuple->dst_cache, tuple->dst_cookie);
|
||||
}
|
||||
|
||||
static unsigned int nf_flow_xmit_xfrm(struct sk_buff *skb,
|
||||
const struct nf_hook_state *state,
|
||||
struct dst_entry *dst)
|
||||
|
||||
Reference in New Issue
Block a user