]> www.infradead.org Git - users/hch/misc.git/commitdiff
nft_set_pipapo: fix incorrect avx2 match of 5th field octet
authorFlorian Westphal <fw@strlen.de>
Mon, 7 Apr 2025 17:40:18 +0000 (19:40 +0200)
committerPablo Neira Ayuso <pablo@netfilter.org>
Thu, 10 Apr 2025 10:33:50 +0000 (12:33 +0200)
Given a set element like:

icmpv6 . dead:beef:00ff::1

The value of 'ff' is irrelevant, any address will be matched
as long as the other octets are the same.

This is because of too-early register clobbering:
ymm7 is reloaded with new packet data (pkt[9])  but it still holds data
of an earlier load that wasn't processed yet.

The existing tests in nft_concat_range.sh selftests do exercise this code
path, but do not trigger incorrect matching due to the network prefix
limitation.

Fixes: 7400b063969b ("nft_set_pipapo: Introduce AVX2-based lookup implementation")
Reported-by: sontu mazumdar <sontu21@gmail.com>
Closes: https://lore.kernel.org/netfilter/CANgxkqwnMH7fXra+VUfODT-8+qFLgskq3set1cAzqqJaV4iEZg@mail.gmail.com/T/#t
Reviewed-by: Stefano Brivio <sbrivio@redhat.com>
Signed-off-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
net/netfilter/nft_set_pipapo_avx2.c

index b8d3c3213efee57baae5daa3a4a057ac57605562..c15db28c5ebc438a1522df866decc99123161fa7 100644 (file)
@@ -994,8 +994,9 @@ static int nft_pipapo_avx2_lookup_8b_16(unsigned long *map, unsigned long *fill,
                NFT_PIPAPO_AVX2_BUCKET_LOAD8(5, lt,  8,  pkt[8], bsize);
 
                NFT_PIPAPO_AVX2_AND(6, 2, 3);
+               NFT_PIPAPO_AVX2_AND(3, 4, 7);
                NFT_PIPAPO_AVX2_BUCKET_LOAD8(7, lt,  9,  pkt[9], bsize);
-               NFT_PIPAPO_AVX2_AND(0, 4, 5);
+               NFT_PIPAPO_AVX2_AND(0, 3, 5);
                NFT_PIPAPO_AVX2_BUCKET_LOAD8(1, lt, 10, pkt[10], bsize);
                NFT_PIPAPO_AVX2_AND(2, 6, 7);
                NFT_PIPAPO_AVX2_BUCKET_LOAD8(3, lt, 11, pkt[11], bsize);