From patchwork Wed Mar 13 08:08:26 2019 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Darrell Ball X-Patchwork-Id: 1055950 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@bilbo.ozlabs.org Authentication-Results: ozlabs.org; spf=pass (mailfrom) smtp.mailfrom=openvswitch.org (client-ip=140.211.169.12; helo=mail.linuxfoundation.org; envelope-from=ovs-dev-bounces@openvswitch.org; receiver=) Authentication-Results: ozlabs.org; dmarc=fail (p=none dis=none) header.from=gmail.com Authentication-Results: ozlabs.org; dkim=fail reason="signature verification failed" (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.b="f5z4E1RK"; dkim-atps=neutral Received: from mail.linuxfoundation.org (mail.linuxfoundation.org [140.211.169.12]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ozlabs.org (Postfix) with ESMTPS id 44K4H23j8xz9s3q for ; Wed, 13 Mar 2019 19:08:45 +1100 (AEDT) Received: from mail.linux-foundation.org (localhost [127.0.0.1]) by mail.linuxfoundation.org (Postfix) with ESMTP id 21A96B2F; Wed, 13 Mar 2019 08:08:41 +0000 (UTC) X-Original-To: dev@openvswitch.org Delivered-To: ovs-dev@mail.linuxfoundation.org Received: from smtp1.linuxfoundation.org (smtp1.linux-foundation.org [172.17.192.35]) by mail.linuxfoundation.org (Postfix) with ESMTPS id D297CAF7 for ; Wed, 13 Mar 2019 08:08:39 +0000 (UTC) X-Greylist: whitelisted by SQLgrey-1.7.6 Received: from mail-pg1-f194.google.com (mail-pg1-f194.google.com [209.85.215.194]) by smtp1.linuxfoundation.org (Postfix) with ESMTPS id 8D1FA12E for ; Wed, 13 Mar 2019 08:08:39 +0000 (UTC) Received: by mail-pg1-f194.google.com with SMTP id h34so936113pgh.11 for ; Wed, 13 Mar 2019 01:08:39 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:subject:date:message-id:in-reply-to:references; bh=6UyTIQsCSq5I1Pu19aT5AOmDP4vy96tqEWUzrtwz5s0=; b=f5z4E1RK1Ts8bJwF3wyWdOGOKk53FveL06z0pkIqLT+S//hAzIKJpNYkDh1It9jx7m Jb/ASvQxpXc4thnRCx26hrDrELIMkiML7kuU6kkN2TxsqQMlVJtPILXiuhe6AMezIx9/ lkVRlQACqFx3n3obbaTuceqNy6rnBaG3oSD0C1G+3j4dWaUILkTFZQAZb4gWPfsIy8fy t9csJBnh3ilLhE0AJHS7stvQg7byIBCn5IvTkRUB9QOOlTgvUhcrop8n0jULl9OuTJLw erWCztT+RnCIv/c8lSI7soLXX1X8I9jr3DTCg5WU5K9Y/pvz4EdvDDqFHxxK27Bf0BNE 1keA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:subject:date:message-id:in-reply-to :references; bh=6UyTIQsCSq5I1Pu19aT5AOmDP4vy96tqEWUzrtwz5s0=; b=SuK4WLo9WUYJhzZhC9vt1WEn1GKbmxRfr2CiTKupV9v19FK4hbZrYZ6Z4yT4mkKsQ3 xuP/cD0Hep/FtInPV1J2AmzacnovCXBK5Cs08Tnn42ylZDYCrh5CfPPg36dL4y55XO17 imD36MxE7DPHoKYn1/7iXXB0MCu4GByRQ8mCU2m0wrN8q3ihNQl4mahbpNaKoYFA8H5e pOKbqFxCQNXDJM1MkXdfUvQ8Vtuw6zhwREKWUCn3rUrKUZbi3Hboyh5nElITS0tS1aVZ 2K7OBhcJ0qXjY3YWe6m19G5ZgHFzTV+mWCojFe/oltVY7YujDVn+KlX2plEriYQerAmG k7Jw== X-Gm-Message-State: APjAAAVWMd8WZCMOgXSc3bHUJdQmgy330Hy1UFxnB1BGXegFKw6hZMwD TBoQTNFg70YgI4rxG7ffRX0= X-Google-Smtp-Source: APXvYqxQKvtkr3RTYdnXr4VT82Lm9/AsJxUD2dxv+VHS46f/Ev2WMG5E7DrYdvgvzoFFQC4yEB93JA== X-Received: by 2002:a17:902:5992:: with SMTP id p18mr44057730pli.231.1552464519162; Wed, 13 Mar 2019 01:08:39 -0700 (PDT) Received: from ubuntu.localdomain (c-76-102-76-212.hsd1.ca.comcast.net. [76.102.76.212]) by smtp.gmail.com with ESMTPSA id e63sm15461495pfa.116.2019.03.13.01.08.38 (version=TLS1_2 cipher=ECDHE-RSA-AES128-SHA bits=128/128); Wed, 13 Mar 2019 01:08:38 -0700 (PDT) From: Darrell Ball To: dlu998@gmail.com, dev@openvswitch.org Date: Wed, 13 Mar 2019 01:08:26 -0700 Message-Id: <1552464506-35968-2-git-send-email-dlu998@gmail.com> X-Mailer: git-send-email 1.9.1 In-Reply-To: <1552464506-35968-1-git-send-email-dlu998@gmail.com> References: <1552464506-35968-1-git-send-email-dlu998@gmail.com> X-Spam-Status: No, score=-1.7 required=5.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,FREEMAIL_ENVFROM_END_DIGIT,FREEMAIL_FROM, RCVD_IN_DNSWL_NONE autolearn=no version=3.3.1 X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on smtp1.linux-foundation.org Subject: [ovs-dev] [patch v1 2/2] conntrack: Lookup only 'UNNAT conns' in 'nat_clean()'. X-BeenThere: ovs-dev@openvswitch.org X-Mailman-Version: 2.1.12 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , MIME-Version: 1.0 Sender: ovs-dev-bounces@openvswitch.org Errors-To: ovs-dev-bounces@openvswitch.org When freeing 'UNNAT conns', lookup only 'UNNAT conns' to protect against possible address overlap with 'default conns' during a DOS attempt. This is very unlikely, but protection is simple. Signed-off-by: Darrell Ball --- lib/conntrack.c | 25 +++++++++++++++++++++---- 1 file changed, 21 insertions(+), 4 deletions(-) diff --git a/lib/conntrack.c b/lib/conntrack.c index 40a6021..ac2df76 100644 --- a/lib/conntrack.c +++ b/lib/conntrack.c @@ -771,6 +771,22 @@ conn_lookup_any(const struct conn_key *key, return conn; } +/* This function is called with the bucket lock held. */ +static struct conn * +conn_lookup_unnat(const struct conn_key *key, + const struct conntrack_bucket *ctb, uint32_t hash) +{ + struct conn *conn = NULL; + + HMAP_FOR_EACH_WITH_HASH (conn, node, hash, &ctb->connections) { + if (!conn_key_cmp(&conn->key, key) + && conn->conn_type == CT_CONN_TYPE_UN_NAT) { + break; + } + } + return conn; +} + static void conn_seq_skew_set(struct conntrack *ct, const struct conn_key *key, long long now, int seq_skew, bool seq_skew_dir) @@ -794,12 +810,13 @@ nat_clean(struct conntrack *ct, struct conn *conn, nat_conn_keys_remove(&ct->nat_conn_keys, &conn->rev_key, ct->hash_basis); ct_rwlock_unlock(&ct->resources_lock); ct_lock_unlock(&ctb->lock); - unsigned bucket_rev_conn = - hash_to_bucket(conn_key_hash(&conn->rev_key, ct->hash_basis)); + uint32_t hash = conn_key_hash(&conn->rev_key, ct->hash_basis); + unsigned bucket_rev_conn = hash_to_bucket(hash); ct_lock_lock(&ct->buckets[bucket_rev_conn].lock); ct_rwlock_wrlock(&ct->resources_lock); - long long now = time_msec(); - struct conn *rev_conn = conn_lookup(ct, &conn->rev_key, now); + struct conn *rev_conn = conn_lookup_unnat(&conn->rev_key, + &ct->buckets[bucket_rev_conn], + hash); struct nat_conn_key_node *nat_conn_key_node = nat_conn_keys_lookup(&ct->nat_conn_keys, &conn->rev_key, ct->hash_basis);