net/mlx5e: Always clear dest encap in neigh-update-del
authorChris Mi <cmi@nvidia.com>
Mon, 5 Dec 2022 01:22:50 +0000 (09:22 +0800)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Thu, 12 Jan 2023 11:02:13 +0000 (12:02 +0100)
[ Upstream commit 2951b2e142ecf6e0115df785ba91e91b6da74602 ]

The cited commit introduced a bug for multiple encapsulations flow.
If one dest encap becomes invalid, the flow is set slow path flag.
But when other dests encap become invalid, they are not cleared due
to slow path flag of the flow. When neigh-update-add is running, it
will use invalid encap.

Fix it by checking slow path flag after clearing dest encap.

Fixes: 9a5f9cc794e1 ("net/mlx5e: Fix possible use-after-free deleting fdb rule")
Signed-off-by: Chris Mi <cmi@nvidia.com>
Reviewed-by: Roi Dayan <roid@nvidia.com>
Signed-off-by: Saeed Mahameed <saeedm@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
drivers/net/ethernet/mellanox/mlx5/core/en/tc_tun_encap.c

index ff73d25..2aaf8ab 100644 (file)
@@ -222,7 +222,7 @@ void mlx5e_tc_encap_flows_del(struct mlx5e_priv *priv,
        int err;
 
        list_for_each_entry(flow, flow_list, tmp_list) {
-               if (!mlx5e_is_offloaded_flow(flow) || flow_flag_test(flow, SLOW))
+               if (!mlx5e_is_offloaded_flow(flow))
                        continue;
 
                attr = mlx5e_tc_get_encap_attr(flow);
@@ -231,6 +231,13 @@ void mlx5e_tc_encap_flows_del(struct mlx5e_priv *priv,
                esw_attr->dests[flow->tmp_entry_index].flags &= ~MLX5_ESW_DEST_ENCAP_VALID;
                esw_attr->dests[flow->tmp_entry_index].pkt_reformat = NULL;
 
+               /* Clear pkt_reformat before checking slow path flag. Because
+                * in next iteration, the same flow is already set slow path
+                * flag, but still need to clear the pkt_reformat.
+                */
+               if (flow_flag_test(flow, SLOW))
+                       continue;
+
                /* update from encap rule to slow path rule */
                spec = &flow->attr->parse_attr->spec;
                rule = mlx5e_tc_offload_to_slow_path(esw, flow, spec);