Message ID | 1536899208-2958-1-git-send-email-yanhaishuang@cmss.chinamobile.com |
---|---|
State | Accepted, archived |
Delegated to: | David Miller |
Headers | show |
Series | [v3,net-next,1/2] ip_gre: fix parsing gre header in ipgre_err | expand |
From: Haishuang Yan <yanhaishuang@cmss.chinamobile.com> Date: Fri, 14 Sep 2018 12:26:47 +0800 > gre_parse_header stops parsing when csum_err is encountered, which means > tpi->key is undefined and ip_tunnel_lookup will return NULL improperly. > > This patch introduce a NULL pointer as csum_err parameter. Even when > csum_err is encountered, it won't return error and continue parsing gre > header as expected. > > Fixes: 9f57c67c379d ("gre: Remove support for sharing GRE protocol hook.") > Reported-by: Jiri Benc <jbenc@redhat.com> > Signed-off-by: Haishuang Yan <yanhaishuang@cmss.chinamobile.com> > > --- > Changes since v3: > * skb_checksum_simple_validate need to be performed in csum_err case. Applied.
diff --git a/net/ipv4/gre_demux.c b/net/ipv4/gre_demux.c index b798862..7efe740 100644 --- a/net/ipv4/gre_demux.c +++ b/net/ipv4/gre_demux.c @@ -86,13 +86,14 @@ int gre_parse_header(struct sk_buff *skb, struct tnl_ptk_info *tpi, options = (__be32 *)(greh + 1); if (greh->flags & GRE_CSUM) { - if (skb_checksum_simple_validate(skb)) { + if (!skb_checksum_simple_validate(skb)) { + skb_checksum_try_convert(skb, IPPROTO_GRE, 0, + null_compute_pseudo); + } else if (csum_err) { *csum_err = true; return -EINVAL; } - skb_checksum_try_convert(skb, IPPROTO_GRE, 0, - null_compute_pseudo); options++; } diff --git a/net/ipv4/ip_gre.c b/net/ipv4/ip_gre.c index 8cce0e9..c3385a8 100644 --- a/net/ipv4/ip_gre.c +++ b/net/ipv4/ip_gre.c @@ -232,13 +232,10 @@ static void gre_err(struct sk_buff *skb, u32 info) const int type = icmp_hdr(skb)->type; const int code = icmp_hdr(skb)->code; struct tnl_ptk_info tpi; - bool csum_err = false; - if (gre_parse_header(skb, &tpi, &csum_err, htons(ETH_P_IP), - iph->ihl * 4) < 0) { - if (!csum_err) /* ignore csum errors. */ - return; - } + if (gre_parse_header(skb, &tpi, NULL, htons(ETH_P_IP), + iph->ihl * 4) < 0) + return; if (type == ICMP_DEST_UNREACH && code == ICMP_FRAG_NEEDED) { ipv4_update_pmtu(skb, dev_net(skb->dev), info,
gre_parse_header stops parsing when csum_err is encountered, which means tpi->key is undefined and ip_tunnel_lookup will return NULL improperly. This patch introduce a NULL pointer as csum_err parameter. Even when csum_err is encountered, it won't return error and continue parsing gre header as expected. Fixes: 9f57c67c379d ("gre: Remove support for sharing GRE protocol hook.") Reported-by: Jiri Benc <jbenc@redhat.com> Signed-off-by: Haishuang Yan <yanhaishuang@cmss.chinamobile.com> --- Changes since v3: * skb_checksum_simple_validate need to be performed in csum_err case. --- net/ipv4/gre_demux.c | 7 ++++--- net/ipv4/ip_gre.c | 9 +++------ 2 files changed, 7 insertions(+), 9 deletions(-)