Received: by 2002:a05:7412:b995:b0:f9:9502:5bb8 with SMTP id it21csp468613rdb; Thu, 21 Dec 2023 15:06:15 -0800 (PST) X-Google-Smtp-Source: AGHT+IGWecQCwTp1pkyG6fbvszzksQM8AWAMLdYmmd1yqQsM5I3n0pNANKGgQsDd0PhKBuNK6cj2 X-Received: by 2002:a17:906:b813:b0:a23:4a4e:b67f with SMTP id dv19-20020a170906b81300b00a234a4eb67fmr267154ejb.126.1703199974980; Thu, 21 Dec 2023 15:06:14 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1703199974; cv=none; d=google.com; s=arc-20160816; b=MWfzJ9KE5O1oITSnHFK1BzT65XRWQSzvshBAsaq+M+usLvzjfiUkfJIzpwsZlb9wCj whB49Yu934ZDhLzJiAJ8FncksSCbhevZYakd0SvZu/r9XBHjyXSKTNh3tSFyCcTDFpvh ziExj5/jeaE0+9/h3PhgRdv7wOdpNd+7/SfMRbmUkWMXQ30EEBAd2sHEwhhjBQQhsSVV pP+sDiVuwLbB2kHneLHaXq/gxv5G6bJ2lTP6ryB1mAIVEj2tuXTOVWWMEnT1LHeg4Uc+ a03ItC3dzpJR+KiHhuQVM7MUdbB2ARABE4BnPgXQl/GL/yLTtSbZbc1lgauFX6ggqVbV y40A== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=content-transfer-encoding:mime-version:list-unsubscribe :list-subscribe:list-id:precedence:message-id:date:subject:cc:to :from:dkim-signature; bh=l60SR+53LmctJjdJT6+f0RpMxenYz9binUoltgUVMmE=; fh=KIfb6/RI7KX5rI+QzOT7PkjUOhSE9vGpz28tH4MewHc=; b=T9xbcHo0G3g0f8iCqQ0Ww8yqMaWuLVVtBCAX+0JTWuzpPJ7PZryg1ONU1tNfccjpH2 /1kAHYxM+Xf8c4K+ZXL3g3XXkSHJ65jNcbEueYQ1dzoK8yafQjFd/YT3hVLEzpolyA/0 5imqs5SZvJJG3+7ue/3zJaPyb5J0KRZxvIK+UNo2kYo3m+FzF79AjeJ0SXEUKEuvwHTb ocaJtMZM+A9bPVetQOzlOMPV0DNBZ1HG172Uqv5tmGuXmNm/+b/JiR9P9DBBWTRabcSk sZPhrFyEPXau2YTX/lMT49eGA5U5d5gXlcqavLOldWMtxd/Iz+6tAzW6J+ZtblfpVUL1 /P0Q== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@faucet.nz header.s=fe-4ed8c67516 header.b=m5FWgqV9; spf=pass (google.com: domain of linux-kernel+bounces-9149-linux.lists.archive=gmail.com@vger.kernel.org designates 147.75.80.249 as permitted sender) smtp.mailfrom="linux-kernel+bounces-9149-linux.lists.archive=gmail.com@vger.kernel.org"; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=faucet.nz Return-Path: Received: from am.mirrors.kernel.org (am.mirrors.kernel.org. [147.75.80.249]) by mx.google.com with ESMTPS id k6-20020a170906680600b00a2331cfc960si1211256ejr.653.2023.12.21.15.06.14 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 21 Dec 2023 15:06:14 -0800 (PST) Received-SPF: pass (google.com: domain of linux-kernel+bounces-9149-linux.lists.archive=gmail.com@vger.kernel.org designates 147.75.80.249 as permitted sender) client-ip=147.75.80.249; Authentication-Results: mx.google.com; dkim=pass header.i=@faucet.nz header.s=fe-4ed8c67516 header.b=m5FWgqV9; spf=pass (google.com: domain of linux-kernel+bounces-9149-linux.lists.archive=gmail.com@vger.kernel.org designates 147.75.80.249 as permitted sender) smtp.mailfrom="linux-kernel+bounces-9149-linux.lists.archive=gmail.com@vger.kernel.org"; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=faucet.nz Received: from smtp.subspace.kernel.org (wormhole.subspace.kernel.org [52.25.139.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by am.mirrors.kernel.org (Postfix) with ESMTPS id B202B1F2636E for ; Thu, 21 Dec 2023 23:06:14 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id 51E0278E75; Thu, 21 Dec 2023 23:06:03 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=faucet.nz header.i=@faucet.nz header.b="m5FWgqV9" X-Original-To: linux-kernel@vger.kernel.org Received: from smtp.forwardemail.net (smtp.forwardemail.net [149.28.215.223]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4032E78E90; Thu, 21 Dec 2023 23:05:59 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=faucet.nz Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=fe-bounces.faucet.nz DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=faucet.nz; h=Content-Transfer-Encoding: MIME-Version: Message-Id: Date: Subject: Cc: To: From; q=dns/txt; s=fe-4ed8c67516; t=1703199957; bh=l60SR+53LmctJjdJT6+f0RpMxenYz9binUoltgUVMmE=; b=m5FWgqV9zNfPV+auhA9mYWbBFfs0BokrE6vja+oSSKrmOZZwdE73azw1L4uhNf7VE6rLuGDdl PV2UhMDM1hIcpABWJPrKyOfJJ0Q1rh/nX5M2KTU2rLsn/8/q8j4tTsJUtCAQZfdIB+zRfLFzvXN DAnLpwunFyVGkJIs5XGdj6A= From: Brad Cowie To: netdev@vger.kernel.org Cc: pablo@netfilter.org, kadlec@netfilter.org, fw@strlen.de, davem@davemloft.net, edumazet@google.com, kuba@kernel.org, pabeni@redhat.com, netfilter-devel@vger.kernel.org, linux-kernel@vger.kernel.org, pshelar@ovn.org, dev@openvswitch.org, Brad Cowie Subject: [PATCH net] netfilter: nf_nat: fix action not being set for all ct states Date: Fri, 22 Dec 2023 11:43:11 +1300 Message-Id: <20231221224311.130319-1-brad@faucet.nz> X-Mailer: git-send-email 2.34.1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Report-Abuse-To: abuse@forwardemail.net X-Report-Abuse: abuse@forwardemail.net X-Complaints-To: abuse@forwardemail.net X-ForwardEmail-Version: 0.4.40 X-ForwardEmail-Sender: rfc822; brad@faucet.nz, smtp.forwardemail.net, 149.28.215.223 X-ForwardEmail-ID: 6584c00e068c01ef26868e78 This fixes openvswitch's handling of nat packets in the related state. In nf_ct_nat_execute(), which is called from nf_ct_nat(), ICMP/ICMPv6 packets in the IP_CT_RELATED or IP_CT_RELATED_REPLY state, which have not been dropped, will follow the goto, however the placement of the goto label means that updating the action bit field will be bypassed. This causes ovs_nat_update_key() to not be called from ovs_ct_nat() which means the openvswitch match key for the ICMP/ICMPv6 packet is not updated and the pre-nat value will be retained for the key, which will result in the wrong openflow rule being matched for that packet. Move the goto label above where the action bit field is being set so that it is updated in all cases where the packet is accepted. Fixes: ebddb1404900 ("net: move the nat function to nf_nat_ovs for ovs and tc") Signed-off-by: Brad Cowie --- net/netfilter/nf_nat_ovs.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/net/netfilter/nf_nat_ovs.c b/net/netfilter/nf_nat_ovs.c index 551abd2da614..0f9a559f6207 100644 --- a/net/netfilter/nf_nat_ovs.c +++ b/net/netfilter/nf_nat_ovs.c @@ -75,9 +75,10 @@ static int nf_ct_nat_execute(struct sk_buff *skb, struct nf_conn *ct, } err = nf_nat_packet(ct, ctinfo, hooknum, skb); +out: if (err == NF_ACCEPT) *action |= BIT(maniptype); -out: + return err; } -- 2.34.1