Page MenuHomeFreeBSD

icmp: Limit routing table updates to the FIB of the redirect
ClosedPublic

Authored by markj on Thu, Sep 10, 10:54 AM.
Tags
None
Referenced Files
Unknown Object (File)
Tue, Oct 6, 3:57 PM
Unknown Object (File)
Tue, Oct 6, 1:15 PM
Unknown Object (File)
Mon, Oct 5, 10:17 PM
Unknown Object (File)
Mon, Oct 5, 4:23 AM
Unknown Object (File)
Fri, Oct 2, 12:32 PM
Unknown Object (File)
Fri, Oct 2, 5:25 AM
Unknown Object (File)
Fri, Oct 2, 3:39 AM
Unknown Object (File)
Thu, Oct 1, 6:22 AM
Subscribers

Details

Summary

When we receive an ICMP redirect, rib_add_redirect() is used to apply
the redirect to all FIBs. This has been the case since support for
multiple FIBs was added. However, it seems rather dubious: the new
gateway might not be routable from all FIBs, and the validation done for
v4 redirects in icmp_verify_redirect_gateway() is only applied to the
FIB from which the redirect originated.

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

This revision is now accepted and ready to land.Thu, Sep 10, 10:57 AM

Not sure but it might help with PR292319

Not sure but it might help with PR292319

I guess not, since the problem is still there with drop_redirect=1.

Indeed looks dubious. I wonder why Alexander did it this way. Could it be M_GETFIB(m) may give us a wrong number in certain conditions? I'll prod him with a private message to take a look at this review.

I have not tested this change yet, but it looks reasonable!

Indeed looks dubious. I wonder why Alexander did it this way. Could it be M_GETFIB(m) may give us a wrong number in certain conditions? I'll prod him with a private message to take a look at this review.

Note, this behaviour comes from commit 8b07e49a008c8 in 2008, which is what introduced support for multiple FIBs.

Then probably we don't need to block this review on Alexander if he doesn't reply in a reasonable time.