瀏覽代碼

bpf: devmap: fix wrong interface selection in notifier_call

The dev_map_notification() removes interface in devmap if
unregistering interface's ifindex is same.
But only checking ifindex is not enough because other netns can have
same ifindex. so that wrong interface selection could occurred.
Hence netdev pointer comparison code is added.

v2: compare netdev pointer instead of using net_eq() (Daniel Borkmann)
v1: Initial patch

Fixes: 2ddf71e23cc2 ("net: add notifier hooks for devmap bpf map")
Signed-off-by: Taehee Yoo <ap420073@gmail.com>
Acked-by: Song Liu <songliubraving@fb.com>
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Taehee Yoo 6 年之前
父節點
當前提交
f592f80483
共有 1 個文件被更改,包括 1 次插入2 次删除
  1. 1 2
      kernel/bpf/devmap.c

+ 1 - 2
kernel/bpf/devmap.c

@@ -512,8 +512,7 @@ static int dev_map_notification(struct notifier_block *notifier,
 				struct bpf_dtab_netdev *dev, *odev;
 				struct bpf_dtab_netdev *dev, *odev;
 
 
 				dev = READ_ONCE(dtab->netdev_map[i]);
 				dev = READ_ONCE(dtab->netdev_map[i]);
-				if (!dev ||
-				    dev->dev->ifindex != netdev->ifindex)
+				if (!dev || netdev != dev->dev)
 					continue;
 					continue;
 				odev = cmpxchg(&dtab->netdev_map[i], dev, NULL);
 				odev = cmpxchg(&dtab->netdev_map[i], dev, NULL);
 				if (dev == odev)
 				if (dev == odev)