diff mbox series

[RFC,net-next,1/3] ipv4: Mask upper DSCP bits and ECN bits in NETLINK_FIB_LOOKUP family

Message ID 20240725131729.1729103-2-idosch@nvidia.com
State RFC, archived
Headers show
Series Preparations for FIB rule DSCP selector | expand

Commit Message

Ido Schimmel July 25, 2024, 1:17 p.m. UTC
The NETLINK_FIB_LOOKUP netlink family can be used to perform a FIB
lookup according to user provided parameters and communicate the result
back to user space.

However, unlike other users of the FIB lookup API, the upper DSCP bits
and the ECN bits of the DS field are not masked, which can result in the
wrong result being returned.

Solve this by masking the upper DSCP bits and the ECN bits using
IPTOS_RT_MASK.

The structure that communicates the request and the response is not
exported to user space, so it is unlikely that this netlink family is
actually in use [1].

[1] https://lore.kernel.org/netdev/ZpqpB8vJU%2FQ6LSqa@debian/

Signed-off-by: Ido Schimmel <idosch@nvidia.com>
---
 net/ipv4/fib_frontend.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

Comments

Guillaume Nault July 26, 2024, 1:12 p.m. UTC | #1
On Thu, Jul 25, 2024 at 04:17:27PM +0300, Ido Schimmel wrote:
> The NETLINK_FIB_LOOKUP netlink family can be used to perform a FIB
> lookup according to user provided parameters and communicate the result
> back to user space.
> 
> However, unlike other users of the FIB lookup API, the upper DSCP bits
> and the ECN bits of the DS field are not masked, which can result in the
> wrong result being returned.
> 
> Solve this by masking the upper DSCP bits and the ECN bits using
> IPTOS_RT_MASK.

Reviewed-by: Guillaume Nault <gnault@redhat.com>
diff mbox series

Patch

diff --git a/net/ipv4/fib_frontend.c b/net/ipv4/fib_frontend.c
index 7ad2cafb9276..da540ddb7af6 100644
--- a/net/ipv4/fib_frontend.c
+++ b/net/ipv4/fib_frontend.c
@@ -1343,7 +1343,7 @@  static void nl_fib_lookup(struct net *net, struct fib_result_nl *frn)
 	struct flowi4           fl4 = {
 		.flowi4_mark = frn->fl_mark,
 		.daddr = frn->fl_addr,
-		.flowi4_tos = frn->fl_tos,
+		.flowi4_tos = frn->fl_tos & IPTOS_RT_MASK,
 		.flowi4_scope = frn->fl_scope,
 	};
 	struct fib_table *tb;