Commit 415b3334 authored by David S. Miller's avatar David S. Miller

icmp: Fix regression in nexthop resolution during replies.

icmp_route_lookup() uses the wrong flow parameters if the reverse
session route lookup isn't used.

So do not commit to the re-decoded flow until we actually make a
final decision to use a real route saved in 'rt2'.
Reported-by: default avatarFlorian Westphal <fw@strlen.de>
Signed-off-by: default avatarDavid S. Miller <davem@davemloft.net>
parent ace62dd1
...@@ -380,6 +380,7 @@ static struct rtable *icmp_route_lookup(struct net *net, ...@@ -380,6 +380,7 @@ static struct rtable *icmp_route_lookup(struct net *net,
struct icmp_bxm *param) struct icmp_bxm *param)
{ {
struct rtable *rt, *rt2; struct rtable *rt, *rt2;
struct flowi4 fl4_dec;
int err; int err;
memset(fl4, 0, sizeof(*fl4)); memset(fl4, 0, sizeof(*fl4));
...@@ -408,19 +409,19 @@ static struct rtable *icmp_route_lookup(struct net *net, ...@@ -408,19 +409,19 @@ static struct rtable *icmp_route_lookup(struct net *net,
} else } else
return rt; return rt;
err = xfrm_decode_session_reverse(skb_in, flowi4_to_flowi(fl4), AF_INET); err = xfrm_decode_session_reverse(skb_in, flowi4_to_flowi(&fl4_dec), AF_INET);
if (err) if (err)
goto relookup_failed; goto relookup_failed;
if (inet_addr_type(net, fl4->saddr) == RTN_LOCAL) { if (inet_addr_type(net, fl4_dec.saddr) == RTN_LOCAL) {
rt2 = __ip_route_output_key(net, fl4); rt2 = __ip_route_output_key(net, &fl4_dec);
if (IS_ERR(rt2)) if (IS_ERR(rt2))
err = PTR_ERR(rt2); err = PTR_ERR(rt2);
} else { } else {
struct flowi4 fl4_2 = {}; struct flowi4 fl4_2 = {};
unsigned long orefdst; unsigned long orefdst;
fl4_2.daddr = fl4->saddr; fl4_2.daddr = fl4_dec.saddr;
rt2 = ip_route_output_key(net, &fl4_2); rt2 = ip_route_output_key(net, &fl4_2);
if (IS_ERR(rt2)) { if (IS_ERR(rt2)) {
err = PTR_ERR(rt2); err = PTR_ERR(rt2);
...@@ -428,7 +429,7 @@ static struct rtable *icmp_route_lookup(struct net *net, ...@@ -428,7 +429,7 @@ static struct rtable *icmp_route_lookup(struct net *net,
} }
/* Ugh! */ /* Ugh! */
orefdst = skb_in->_skb_refdst; /* save old refdst */ orefdst = skb_in->_skb_refdst; /* save old refdst */
err = ip_route_input(skb_in, fl4->daddr, fl4->saddr, err = ip_route_input(skb_in, fl4_dec.daddr, fl4_dec.saddr,
RT_TOS(tos), rt2->dst.dev); RT_TOS(tos), rt2->dst.dev);
dst_release(&rt2->dst); dst_release(&rt2->dst);
...@@ -440,10 +441,11 @@ static struct rtable *icmp_route_lookup(struct net *net, ...@@ -440,10 +441,11 @@ static struct rtable *icmp_route_lookup(struct net *net,
goto relookup_failed; goto relookup_failed;
rt2 = (struct rtable *) xfrm_lookup(net, &rt2->dst, rt2 = (struct rtable *) xfrm_lookup(net, &rt2->dst,
flowi4_to_flowi(fl4), NULL, flowi4_to_flowi(&fl4_dec), NULL,
XFRM_LOOKUP_ICMP); XFRM_LOOKUP_ICMP);
if (!IS_ERR(rt2)) { if (!IS_ERR(rt2)) {
dst_release(&rt->dst); dst_release(&rt->dst);
memcpy(fl4, &fl4_dec, sizeof(*fl4));
rt = rt2; rt = rt2;
} else if (PTR_ERR(rt2) == -EPERM) { } else if (PTR_ERR(rt2) == -EPERM) {
if (rt) if (rt)
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment