Commit df4d7bc5 authored by huaibin Wang's avatar huaibin Wang Committed by Kamal Mostafa

xfrm: release dst_orig in case of error in xfrm_lookup()

commit ac37e251 upstream.

dst_orig should be released on error. Function like __xfrm_route_forward()
expects that behavior.
Since a recent commit, xfrm_lookup() may also be called by xfrm_lookup_route(),
which expects the opposite.
Let's introduce a new flag (XFRM_LOOKUP_KEEP_DST_REF) to tell what should be
done in case of error.

Fixes: f92ee619("xfrm: Generate blackhole routes only from route lookup functions")
Signed-off-by: default avatarhuaibin Wang <huaibin.wang@6wind.com>
Signed-off-by: default avatarNicolas Dichtel <nicolas.dichtel@6wind.com>
Signed-off-by: default avatarSteffen Klassert <steffen.klassert@secunet.com>
Signed-off-by: default avatarKamal Mostafa <kamal@canonical.com>
parent 826376b4
...@@ -468,6 +468,7 @@ void dst_init(void); ...@@ -468,6 +468,7 @@ void dst_init(void);
enum { enum {
XFRM_LOOKUP_ICMP = 1 << 0, XFRM_LOOKUP_ICMP = 1 << 0,
XFRM_LOOKUP_QUEUE = 1 << 1, XFRM_LOOKUP_QUEUE = 1 << 1,
XFRM_LOOKUP_KEEP_DST_REF = 1 << 2,
}; };
struct flowi; struct flowi;
......
...@@ -2161,11 +2161,9 @@ struct dst_entry *xfrm_lookup(struct net *net, struct dst_entry *dst_orig, ...@@ -2161,11 +2161,9 @@ struct dst_entry *xfrm_lookup(struct net *net, struct dst_entry *dst_orig,
* have the xfrm_state's. We need to wait for KM to * have the xfrm_state's. We need to wait for KM to
* negotiate new SA's or bail out with error.*/ * negotiate new SA's or bail out with error.*/
if (net->xfrm.sysctl_larval_drop) { if (net->xfrm.sysctl_larval_drop) {
dst_release(dst);
xfrm_pols_put(pols, drop_pols);
XFRM_INC_STATS(net, LINUX_MIB_XFRMOUTNOSTATES); XFRM_INC_STATS(net, LINUX_MIB_XFRMOUTNOSTATES);
err = -EREMOTE;
return ERR_PTR(-EREMOTE); goto error;
} }
if (fl->flowi_flags & FLOWI_FLAG_CAN_SLEEP) { if (fl->flowi_flags & FLOWI_FLAG_CAN_SLEEP) {
DECLARE_WAITQUEUE(wait, current); DECLARE_WAITQUEUE(wait, current);
...@@ -2231,6 +2229,7 @@ struct dst_entry *xfrm_lookup(struct net *net, struct dst_entry *dst_orig, ...@@ -2231,6 +2229,7 @@ struct dst_entry *xfrm_lookup(struct net *net, struct dst_entry *dst_orig,
error: error:
dst_release(dst); dst_release(dst);
dropdst: dropdst:
if (!(flags & XFRM_LOOKUP_KEEP_DST_REF))
dst_release(dst_orig); dst_release(dst_orig);
xfrm_pols_put(pols, drop_pols); xfrm_pols_put(pols, drop_pols);
return ERR_PTR(err); return ERR_PTR(err);
...@@ -2245,7 +2244,8 @@ struct dst_entry *xfrm_lookup_route(struct net *net, struct dst_entry *dst_orig, ...@@ -2245,7 +2244,8 @@ struct dst_entry *xfrm_lookup_route(struct net *net, struct dst_entry *dst_orig,
struct sock *sk, int flags) struct sock *sk, int flags)
{ {
struct dst_entry *dst = xfrm_lookup(net, dst_orig, fl, sk, struct dst_entry *dst = xfrm_lookup(net, dst_orig, fl, sk,
flags | XFRM_LOOKUP_QUEUE); flags | XFRM_LOOKUP_QUEUE |
XFRM_LOOKUP_KEEP_DST_REF);
if (IS_ERR(dst) && PTR_ERR(dst) == -EREMOTE) if (IS_ERR(dst) && PTR_ERR(dst) == -EREMOTE)
return make_blackhole(net, dst_orig->ops->family, dst_orig); return make_blackhole(net, dst_orig->ops->family, dst_orig);
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment