Benjamin Poirier
32ef2c0c6c
vxlan: Fix nexthop hash size
...
[ Upstream commit 0756384fb1bd38adb2ebcfd1307422f433a1d772 ]
The nexthop code expects a 31 bit hash, such as what is returned by
fib_multipath_hash() and rt6_multipath_hash(). Passing the 32 bit hash
returned by skb_get_hash() can lead to problems related to the fact that
'int hash' is a negative number when the MSB is set.
In the case of hash threshold nexthop groups, nexthop_select_path_hthr()
will disproportionately select the first nexthop group entry. In the case
of resilient nexthop groups, nexthop_select_path_res() may do an out of
bounds access in nh_buckets[], for example:
hash = -912054133
num_nh_buckets = 2
bucket_index = 65535
which leads to the following panic:
BUG: unable to handle page fault for address: ffffc900025910c8
PGD 100000067 P4D 100000067 PUD 10026b067 PMD 0
Oops: 0002 [#1 ] PREEMPT SMP KASAN NOPTI
CPU: 4 PID: 856 Comm: kworker/4:3 Not tainted 6.5.0-rc2+ #34
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.2-debian-1.16.2-1 04/01/2014
Workqueue: ipv6_addrconf addrconf_dad_work
RIP: 0010:nexthop_select_path+0x197/0xbf0
Code: c1 e4 05 be 08 00 00 00 4c 8b 35 a4 14 7e 01 4e 8d 6c 25 00 4a 8d 7c 25 08 48 01 dd e8 c2 25 15 ff 49 8d 7d 08 e8 39 13 15 ff <4d> 89 75 08 48 89 ef e8 7d 12 15 ff 48 8b 5d 00 e8 14 55 2f 00 85
RSP: 0018:ffff88810c36f260 EFLAGS: 00010246
RAX: 0000000000000000 RBX: 00000000002000c0 RCX: ffffffffaf02dd77
RDX: dffffc0000000000 RSI: 0000000000000008 RDI: ffffc900025910c8
RBP: ffffc900025910c0 R08: 0000000000000001 R09: fffff520004b2219
R10: ffffc900025910cf R11: 31392d2068736168 R12: 00000000002000c0
R13: ffffc900025910c0 R14: 00000000fffef608 R15: ffff88811840e900
FS: 0000000000000000(0000) GS:ffff8881f7000000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: ffffc900025910c8 CR3: 0000000129d00000 CR4: 0000000000750ee0
PKRU: 55555554
Call Trace:
<TASK>
? __die+0x23/0x70
? page_fault_oops+0x1ee/0x5c0
? __pfx_is_prefetch.constprop.0+0x10/0x10
? __pfx_page_fault_oops+0x10/0x10
? search_bpf_extables+0xfe/0x1c0
? fixup_exception+0x3b/0x470
? exc_page_fault+0xf6/0x110
? asm_exc_page_fault+0x26/0x30
? nexthop_select_path+0x197/0xbf0
? nexthop_select_path+0x197/0xbf0
? lock_is_held_type+0xe7/0x140
vxlan_xmit+0x5b2/0x2340
? __lock_acquire+0x92b/0x3370
? __pfx_vxlan_xmit+0x10/0x10
? __pfx___lock_acquire+0x10/0x10
? __pfx_register_lock_class+0x10/0x10
? skb_network_protocol+0xce/0x2d0
? dev_hard_start_xmit+0xca/0x350
? __pfx_vxlan_xmit+0x10/0x10
dev_hard_start_xmit+0xca/0x350
__dev_queue_xmit+0x513/0x1e20
? __pfx___dev_queue_xmit+0x10/0x10
? __pfx_lock_release+0x10/0x10
? mark_held_locks+0x44/0x90
? skb_push+0x4c/0x80
? eth_header+0x81/0xe0
? __pfx_eth_header+0x10/0x10
? neigh_resolve_output+0x215/0x310
? ip6_finish_output2+0x2ba/0xc90
ip6_finish_output2+0x2ba/0xc90
? lock_release+0x236/0x3e0
? ip6_mtu+0xbb/0x240
? __pfx_ip6_finish_output2+0x10/0x10
? find_held_lock+0x83/0xa0
? lock_is_held_type+0xe7/0x140
ip6_finish_output+0x1ee/0x780
ip6_output+0x138/0x460
? __pfx_ip6_output+0x10/0x10
? __pfx___lock_acquire+0x10/0x10
? __pfx_ip6_finish_output+0x10/0x10
NF_HOOK.constprop.0+0xc0/0x420
? __pfx_NF_HOOK.constprop.0+0x10/0x10
? ndisc_send_skb+0x2c0/0x960
? __pfx_lock_release+0x10/0x10
? __local_bh_enable_ip+0x93/0x110
? lock_is_held_type+0xe7/0x140
ndisc_send_skb+0x4be/0x960
? __pfx_ndisc_send_skb+0x10/0x10
? mark_held_locks+0x65/0x90
? find_held_lock+0x83/0xa0
ndisc_send_ns+0xb0/0x110
? __pfx_ndisc_send_ns+0x10/0x10
addrconf_dad_work+0x631/0x8e0
? lock_acquire+0x180/0x3f0
? __pfx_addrconf_dad_work+0x10/0x10
? mark_held_locks+0x24/0x90
process_one_work+0x582/0x9c0
? __pfx_process_one_work+0x10/0x10
? __pfx_do_raw_spin_lock+0x10/0x10
? mark_held_locks+0x24/0x90
worker_thread+0x93/0x630
? __kthread_parkme+0xdc/0x100
? __pfx_worker_thread+0x10/0x10
kthread+0x1a5/0x1e0
? __pfx_kthread+0x10/0x10
ret_from_fork+0x34/0x60
? __pfx_kthread+0x10/0x10
ret_from_fork_asm+0x1b/0x30
RIP: 0000:0x0
Code: Unable to access opcode bytes at 0xffffffffffffffd6.
RSP: 0000:0000000000000000 EFLAGS: 00000000 ORIG_RAX: 0000000000000000
RAX: 0000000000000000 RBX: 0000000000000000 RCX: 0000000000000000
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000
RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000000 R12: 0000000000000000
R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000
</TASK>
Modules linked in:
CR2: ffffc900025910c8
---[ end trace 0000000000000000 ]---
RIP: 0010:nexthop_select_path+0x197/0xbf0
Code: c1 e4 05 be 08 00 00 00 4c 8b 35 a4 14 7e 01 4e 8d 6c 25 00 4a 8d 7c 25 08 48 01 dd e8 c2 25 15 ff 49 8d 7d 08 e8 39 13 15 ff <4d> 89 75 08 48 89 ef e8 7d 12 15 ff 48 8b 5d 00 e8 14 55 2f 00 85
RSP: 0018:ffff88810c36f260 EFLAGS: 00010246
RAX: 0000000000000000 RBX: 00000000002000c0 RCX: ffffffffaf02dd77
RDX: dffffc0000000000 RSI: 0000000000000008 RDI: ffffc900025910c8
RBP: ffffc900025910c0 R08: 0000000000000001 R09: fffff520004b2219
R10: ffffc900025910cf R11: 31392d2068736168 R12: 00000000002000c0
R13: ffffc900025910c0 R14: 00000000fffef608 R15: ffff88811840e900
FS: 0000000000000000(0000) GS:ffff8881f7000000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: ffffffffffffffd6 CR3: 0000000129d00000 CR4: 0000000000750ee0
PKRU: 55555554
Kernel panic - not syncing: Fatal exception in interrupt
Kernel Offset: 0x2ca00000 from 0xffffffff81000000 (relocation range: 0xffffffff80000000-0xffffffffbfffffff)
---[ end Kernel panic - not syncing: Fatal exception in interrupt ]---
Fix this problem by ensuring the MSB of hash is 0 using a right shift - the
same approach used in fib_multipath_hash() and rt6_multipath_hash().
Fixes: 1274e1cc4226 ("vxlan: ecmp support for mac fdb entries")
Signed-off-by: Benjamin Poirier <bpoirier@nvidia.com>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2023-08-11 15:13:54 +02:00
..
2022-08-17 14:24:07 +02:00
2022-08-03 12:03:40 +02:00
2021-07-01 13:19:48 -07:00
2021-01-28 20:36:21 -08:00
2023-07-23 13:46:44 +02:00
2023-06-21 15:59:15 +02:00
2021-11-25 09:48:40 +01:00
2023-03-11 13:57:28 +01:00
2023-03-11 13:57:29 +01:00
2020-02-28 14:51:30 +01:00
2021-08-02 10:24:38 +01:00
2022-08-03 12:03:47 +02:00
2021-04-23 10:17:26 +01:00
2021-08-16 18:43:39 -07:00
2022-03-23 09:16:41 +01:00
2022-04-13 20:59:05 +02:00
2022-04-20 09:34:22 +02:00
2021-08-03 13:05:25 +01:00
2020-07-21 18:30:47 -07:00
2022-09-28 11:11:48 +02:00
2023-06-14 11:13:00 +02:00
2023-06-05 09:21:19 +02:00
2023-06-05 09:21:19 +02:00
2021-03-26 17:43:55 +01:00
2022-08-31 17:16:43 +02:00
2021-10-25 15:20:22 +02:00
2020-02-29 14:39:08 +01:00
2022-03-02 11:47:58 +01:00
2020-07-15 07:45:24 -07:00
2020-03-27 19:40:38 -07:00
2021-08-05 11:46:42 +01:00
2021-08-14 13:59:10 +01:00
2023-06-05 09:21:17 +02:00
2019-12-16 16:09:44 -08:00
2021-12-08 09:04:46 +01:00
2022-02-16 12:56:30 +01:00
2020-05-08 21:33:33 -07:00
2023-06-21 15:59:19 +02:00
2020-05-05 13:23:29 -07:00
2022-04-27 14:38:52 +02:00
2020-04-20 07:34:16 +02:00
2019-12-24 22:37:30 -08:00
2021-12-08 09:04:43 +01:00
2022-04-20 09:34:09 +02:00
2022-06-14 18:36:17 +02:00
2023-06-21 15:59:19 +02:00
2021-01-21 13:33:45 +01:00
2021-01-21 13:33:45 +01:00
2019-12-09 10:36:44 -08:00
2019-11-05 18:20:55 -08:00
2021-02-12 16:31:46 -08:00
2021-01-29 20:39:14 -08:00
2021-03-18 19:51:12 -07:00
2020-06-22 21:12:44 -07:00
2019-10-25 16:24:32 -07:00
2021-06-28 14:29:45 -07:00
2021-08-13 09:58:25 +02:00
2022-10-26 12:35:54 +02:00
2022-06-09 10:22:31 +02:00
2022-08-17 14:23:36 +02:00
2021-01-27 18:18:15 -08:00
2022-08-03 12:03:45 +02:00
2020-12-14 18:38:58 -08:00
2022-01-27 11:05:35 +01:00
2022-08-17 14:23:36 +02:00
2022-08-17 14:23:36 +02:00
2019-09-27 12:05:02 +02:00
2021-07-21 08:14:33 -07:00
2020-06-20 17:47:53 -07:00
2022-02-23 12:03:10 +01:00
2021-08-05 15:08:47 -07:00
2022-05-09 09:14:36 +02:00
2021-12-08 09:04:49 +01:00
2023-06-28 10:29:44 +02:00
2023-05-24 17:36:46 +01:00
2023-06-05 09:21:26 +02:00
2022-01-27 11:05:35 +01:00
2021-12-01 09:04:49 +01:00
2023-08-03 10:22:34 +02:00
2020-06-20 17:22:22 -07:00
2021-03-23 14:14:50 -07:00
2019-10-08 13:23:05 -07:00
2021-07-27 13:05:56 +01:00
2021-11-18 19:17:10 +01:00
2021-08-30 01:51:36 +02:00
2021-09-27 12:02:54 +02:00
2021-06-24 12:41:12 -07:00
2021-10-18 13:47:09 +01:00
2021-08-25 11:23:14 +01:00
2020-03-02 11:16:27 -08:00
2021-03-26 15:14:56 -07:00
2020-02-28 12:08:37 -08:00
2020-05-29 21:20:20 -07:00
2023-01-12 11:58:52 +01:00
2022-12-31 13:14:42 +01:00
2022-03-08 19:12:33 +01:00
2023-06-21 15:59:19 +02:00
2022-04-13 20:59:03 +02:00
2021-07-27 11:43:50 +01:00
2019-11-12 08:18:03 -08:00
2021-09-24 14:07:10 +01:00
2021-12-01 09:04:46 +01:00
2023-06-05 09:21:22 +02:00
2020-03-04 13:25:55 -08:00
2021-08-30 16:33:59 -07:00
2023-07-23 13:47:45 +02:00
2022-11-10 18:15:38 +01:00
2021-08-09 15:34:21 -07:00
2022-07-21 21:24:27 +02:00
2021-03-25 17:40:43 -07:00
2020-07-31 09:24:23 +02:00
2020-08-24 14:35:00 -07:00
2022-07-29 17:25:09 +02:00
2023-06-14 11:13:02 +02:00
2021-08-04 10:01:26 +01:00
2023-02-01 08:27:09 +01:00
2023-05-11 23:00:26 +09:00
2022-05-18 10:26:53 +02:00
2022-01-27 11:05:05 +01:00
2021-04-28 14:06:45 -07:00
2020-09-28 15:19:03 -07:00
2019-10-05 16:29:00 -07:00
2022-12-31 13:14:07 +01:00
2023-07-23 13:46:56 +02:00
2021-08-03 13:05:26 +01:00
2021-11-18 19:17:11 +01:00
2021-08-04 12:35:07 +01:00
2023-07-27 08:47:04 +02:00
2019-10-04 14:07:07 -07:00
2022-07-21 21:24:31 +02:00
2020-06-23 20:10:15 -07:00
2020-06-18 20:46:23 -07:00
2022-09-15 11:30:05 +02:00
2023-04-26 13:51:54 +02:00
2023-04-26 13:51:54 +02:00
2019-11-14 18:12:17 -08:00
2023-08-11 15:13:54 +02:00
2019-12-09 10:28:43 -08:00
2019-11-16 12:39:10 -08:00
2022-06-14 18:36:18 +02:00
2021-06-24 19:41:15 +02:00
2023-06-05 09:21:21 +02:00
2023-06-28 10:29:45 +02:00
2023-05-11 23:00:27 +09:00