From patchwork Fri Sep 27 21:14:17 2019 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yi-Hung Wei X-Patchwork-Id: 1168744 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@bilbo.ozlabs.org Authentication-Results: ozlabs.org; spf=pass (mailfrom) smtp.mailfrom=openvswitch.org (client-ip=140.211.169.12; helo=mail.linuxfoundation.org; envelope-from=ovs-dev-bounces@openvswitch.org; receiver=) Authentication-Results: ozlabs.org; dmarc=fail (p=none dis=none) header.from=gmail.com Authentication-Results: ozlabs.org; dkim=fail reason="signature verification failed" (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.b="VaYxzj2W"; dkim-atps=neutral Received: from mail.linuxfoundation.org (mail.linuxfoundation.org [140.211.169.12]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ozlabs.org (Postfix) with ESMTPS id 46g4LD0SLhz9sDB for ; Sat, 28 Sep 2019 07:14:27 +1000 (AEST) Received: from mail.linux-foundation.org (localhost [127.0.0.1]) by mail.linuxfoundation.org (Postfix) with ESMTP id 809CC10AA; Fri, 27 Sep 2019 21:14:24 +0000 (UTC) X-Original-To: dev@openvswitch.org Delivered-To: ovs-dev@mail.linuxfoundation.org Received: from smtp1.linuxfoundation.org (smtp1.linux-foundation.org [172.17.192.35]) by mail.linuxfoundation.org (Postfix) with ESMTPS id B736710A6 for ; Fri, 27 Sep 2019 21:14:23 +0000 (UTC) X-Greylist: whitelisted by SQLgrey-1.7.6 Received: from mail-pg1-f195.google.com (mail-pg1-f195.google.com [209.85.215.195]) by smtp1.linuxfoundation.org (Postfix) with ESMTPS id 32514908 for ; Fri, 27 Sep 2019 21:14:23 +0000 (UTC) Received: by mail-pg1-f195.google.com with SMTP id a3so4076256pgm.13 for ; Fri, 27 Sep 2019 14:14:23 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:date:message-id; bh=Ef0kyMiiHahB1IhjLcvp18IYr8Sx913gy8i6YEyD3LU=; b=VaYxzj2WHDSpLRuMZIjlXRNWXxamvqgm1mGOLDgNc6Z0sHio2KoqGvKQGZ4VvFm4QW il+oEoAPogsdTwsAaw8eahY+6gF6HjIRvNeaWNcrqyF9vE9GdiDntJzR/86+ukvB3/ZX 67XmnPGmoGhvaiglDIE5TdeIxvpanh23Bhzko6bJB/rUUqjnaaaelYHeIBzrDdazeu2Z FK2uP7mJlDrC99zGG5QCVtrS5LOPji/hyzMVk3NAw8ImgN8EEY+a8ZaNpr6SrL6x3tM6 3m2iK72Kauz6qlMmxVI0E+5FWCl9iBcppQ9q3tpuZTsWbaw4Kj1drnmfwHcqdkP0yvHx hD4Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id; bh=Ef0kyMiiHahB1IhjLcvp18IYr8Sx913gy8i6YEyD3LU=; b=rbRpzyLfdvUf3MYBeSSpA+SnO5e/V9CvPozJz7GvsoklphneiaIpNN1ha6UZe+8HfJ WDjITfLL822gH2cs/6V68bl5KX5oiCwSZKUralynPChy3RhTbFQkQ0RFkrjYT6ZnNZ3j 8P1FuYcYxsHuwF0mudt5DxOp1B4G609pBDfmF3AyU/QEqqNbCmTWIRPN6onmKZuruOhl Yb024tc3bQ4wYVgfr27SdeLMyH+xmWmXa6rwtcTgN0reI13/kjBreODn0ABXU1UZYrfa LuPjJXNo1areZELNSudF6xQjktHBpcCF7+QqGKFXKz1O7KQn2OGeX++/1rzgqdhCLhRr JtPw== X-Gm-Message-State: APjAAAUvlgO998qQFKZbaEwSz5OVrd2U9wsFP7ae8dAYgrprbNK4KtT0 uqR4oJ32xrlQBA6P8FTQbcbpHoEgUO0= X-Google-Smtp-Source: APXvYqy8HJv5gVGjSKczCTaBNlmRHBvfYDBh9Xh/KfoSDbeFLCEg0lS7AZBipTLFyIVGuGmYzG9ekQ== X-Received: by 2002:a17:90a:17cb:: with SMTP id q69mr12163411pja.135.1569618862017; Fri, 27 Sep 2019 14:14:22 -0700 (PDT) Received: from vm-main.eng.vmware.com ([66.170.99.1]) by smtp.gmail.com with ESMTPSA id b3sm5050608pjp.13.2019.09.27.14.14.20 (version=TLS1_2 cipher=ECDHE-RSA-AES128-SHA bits=128/128); Fri, 27 Sep 2019 14:14:21 -0700 (PDT) From: Yi-Hung Wei To: dev@openvswitch.org Date: Fri, 27 Sep 2019 14:14:17 -0700 Message-Id: <1569618857-80225-1-git-send-email-yihung.wei@gmail.com> X-Mailer: git-send-email 2.7.4 X-Spam-Status: No, score=-2.0 required=5.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, FREEMAIL_FROM, RCVD_IN_DNSWL_NONE autolearn=ham version=3.3.1 X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on smtp1.linux-foundation.org Subject: [ovs-dev] [PATCH] datapath: Fix conntrack cache with timeout X-BeenThere: ovs-dev@openvswitch.org X-Mailman-Version: 2.1.12 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , MIME-Version: 1.0 Sender: ovs-dev-bounces@openvswitch.org Errors-To: ovs-dev-bounces@openvswitch.org This patch is from the following upstream net-next commit along with an updated system traffic test to avoid regression. Upstream commit: commit 7177895154e6a35179d332f4a584d396c50d0612 Author: Yi-Hung Wei Date: Thu Aug 22 13:17:50 2019 -0700 openvswitch: Fix conntrack cache with timeout This patch addresses a conntrack cache issue with timeout policy. Currently, we do not check if the timeout extension is set properly in the cached conntrack entry. Thus, after packet recirculate from conntrack action, the timeout policy is not applied properly. This patch fixes the aforementioned issue. Fixes: 06bd2bdf19d2 ("openvswitch: Add timeout support to ct action") Reported-by: kbuild test robot Signed-off-by: Yi-Hung Wei Acked-by: Pravin B Shelar Signed-off-by: David S. Miller Signed-off-by: Yi-Hung Wei --- datapath/conntrack.c | 13 +++++++++++++ tests/system-traffic.at | 18 ++++++++++++++++++ 2 files changed, 31 insertions(+) diff --git a/datapath/conntrack.c b/datapath/conntrack.c index 35a183aeb33a..c6d523758ff1 100644 --- a/datapath/conntrack.c +++ b/datapath/conntrack.c @@ -88,6 +88,7 @@ struct ovs_conntrack_info { struct md_mark mark; struct md_labels labels; char timeout[CTNL_TIMEOUT_NAME_MAX]; + struct nf_ct_timeout *nf_ct_timeout; #ifdef CONFIG_NF_NAT_NEEDED struct nf_nat_range2 range; /* Only present for SRC NAT and DST NAT. */ #endif @@ -750,6 +751,14 @@ static bool skb_nfct_cached(struct net *net, if (help && rcu_access_pointer(help->helper) != info->helper) return false; } + if (info->nf_ct_timeout) { + struct nf_conn_timeout *timeout_ext; + + timeout_ext = nf_ct_timeout_find(ct); + if (!timeout_ext || info->nf_ct_timeout != + rcu_dereference(timeout_ext->timeout)) + return false; + } /* Force conntrack entry direction to the current packet? */ if (info->force && CTINFO2DIR(ctinfo) != IP_CT_DIR_ORIGINAL) { /* Delete the conntrack entry if confirmed, else just release @@ -1709,6 +1718,10 @@ int ovs_ct_copy_action(struct net *net, const struct nlattr *attr, ct_info.timeout)) pr_info_ratelimited("Failed to associated timeout " "policy `%s'\n", ct_info.timeout); + else + ct_info.nf_ct_timeout = rcu_dereference( + nf_ct_timeout_find(ct_info.ct)->timeout); + } if (helper) { diff --git a/tests/system-traffic.at b/tests/system-traffic.at index bfc6bb5b47c7..3d4e365764b5 100644 --- a/tests/system-traffic.at +++ b/tests/system-traffic.at @@ -3242,6 +3242,24 @@ sleep 4 AT_CHECK([ovs-appctl dpctl/dump-conntrack | FORMAT_CT(10.1.1.2)], [0], [dnl ]) +dnl Re-send ICMP and UDP traffic to test conntrack cache +NS_CHECK_EXEC([at_ns0], [ping -q -c 3 -i 0.3 -w 2 10.1.1.2 | FORMAT_PING], [0], [dnl +3 packets transmitted, 3 received, 0% packet loss, time 0ms +]) +AT_CHECK([ovs-ofctl -O OpenFlow13 packet-out br0 "in_port=1 packet=50540000000a50540000000908004500001c000000000011a4cd0a0101010a0101020001000200080000 actions=resubmit(,0)"]) + +AT_CHECK([ovs-appctl dpctl/dump-conntrack | FORMAT_CT(10.1.1.2) | sort], [0], [dnl +icmp,orig=(src=10.1.1.1,dst=10.1.1.2,id=,type=8,code=0),reply=(src=10.1.1.2,dst=10.1.1.1,id=,type=0,code=0),zone=5 +udp,orig=(src=10.1.1.1,dst=10.1.1.2,sport=,dport=),reply=(src=10.1.1.2,dst=10.1.1.1,sport=,dport=),zone=5 +]) + +dnl Wait until the timeout expire. +dnl We intend to wait a bit longer, because conntrack does not recycle the entry right after it is expired. +sleep 4 + +AT_CHECK([ovs-appctl dpctl/dump-conntrack | FORMAT_CT(10.1.1.2)], [0], [dnl +]) + OVS_TRAFFIC_VSWITCHD_STOP AT_CLEANUP