Skip to content

Commit 72239f2

Browse files
sbrivio-rhummakynes
authored andcommitted
netfilter: nft_set_rbtree: Drop spurious condition for overlap detection on insertion
Case a1. for overlap detection in __nft_rbtree_insert() is not a valid one: start-after-start is not needed to detect any type of interval overlap and it actually results in a false positive if, while descending the tree, this is the only step we hit after starting from the root. This introduced a regression, as reported by Pablo, in Python tests cases ip/ip.t and ip/numgen.t: ip/ip.t: ERROR: line 124: add rule ip test-ip4 input ip hdrlength vmap { 0-4 : drop, 5 : accept, 6 : continue } counter: This rule should not have failed. ip/numgen.t: ERROR: line 7: add rule ip test-ip4 pre dnat to numgen inc mod 10 map { 0-5 : 192.168.10.100, 6-9 : 192.168.20.200}: This rule should not have failed. Drop case a1. and renumber others, so that they are a bit clearer. In order for these diagrams to be readily understandable, a bigger rework is probably needed, such as an ASCII art of the actual rbtree (instead of a flattened version). Shell script test sets/0044interval_overlap_0 should cover all possible cases for false negatives, so I consider that test case still sufficient after this change. v2: Fix comments for cases a3. and b3. Reported-by: Pablo Neira Ayuso <pablo@netfilter.org> Fixes: 7c84d41 ("netfilter: nft_set_rbtree: Detect partial overlaps on insertion") Signed-off-by: Stefano Brivio <sbrivio@redhat.com> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
1 parent 0452800 commit 72239f2

File tree

1 file changed

+11
-12
lines changed

1 file changed

+11
-12
lines changed

net/netfilter/nft_set_rbtree.c

Lines changed: 11 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -218,27 +218,26 @@ static int __nft_rbtree_insert(const struct net *net, const struct nft_set *set,
218218

219219
/* Detect overlaps as we descend the tree. Set the flag in these cases:
220220
*
221-
* a1. |__ _ _? >|__ _ _ (insert start after existing start)
222-
* a2. _ _ __>| ?_ _ __| (insert end before existing end)
223-
* a3. _ _ ___| ?_ _ _>| (insert end after existing end)
224-
* a4. >|__ _ _ _ _ __| (insert start before existing end)
221+
* a1. _ _ __>| ?_ _ __| (insert end before existing end)
222+
* a2. _ _ ___| ?_ _ _>| (insert end after existing end)
223+
* a3. _ _ ___? >|_ _ __| (insert start before existing end)
225224
*
226225
* and clear it later on, as we eventually reach the points indicated by
227226
* '?' above, in the cases described below. We'll always meet these
228227
* later, locally, due to tree ordering, and overlaps for the intervals
229228
* that are the closest together are always evaluated last.
230229
*
231-
* b1. |__ _ _! >|__ _ _ (insert start after existing end)
232-
* b2. _ _ __>| !_ _ __| (insert end before existing start)
233-
* b3. !_____>| (insert end after existing start)
230+
* b1. _ _ __>| !_ _ __| (insert end before existing start)
231+
* b2. _ _ ___| !_ _ _>| (insert end after existing start)
232+
* b3. _ _ ___! >|_ _ __| (insert start after existing end)
234233
*
235-
* Case a4. resolves to b1.:
234+
* Case a3. resolves to b3.:
236235
* - if the inserted start element is the leftmost, because the '0'
237236
* element in the tree serves as end element
238237
* - otherwise, if an existing end is found. Note that end elements are
239238
* always inserted after corresponding start elements.
240239
*
241-
* For a new, rightmost pair of elements, we'll hit cases b1. and b3.,
240+
* For a new, rightmost pair of elements, we'll hit cases b3. and b2.,
242241
* in that order.
243242
*
244243
* The flag is also cleared in two special cases:
@@ -262,9 +261,9 @@ static int __nft_rbtree_insert(const struct net *net, const struct nft_set *set,
262261
p = &parent->rb_left;
263262

264263
if (nft_rbtree_interval_start(new)) {
265-
overlap = nft_rbtree_interval_start(rbe) &&
266-
nft_set_elem_active(&rbe->ext,
267-
genmask);
264+
if (nft_rbtree_interval_end(rbe) &&
265+
nft_set_elem_active(&rbe->ext, genmask))
266+
overlap = false;
268267
} else {
269268
overlap = nft_rbtree_interval_end(rbe) &&
270269
nft_set_elem_active(&rbe->ext,

0 commit comments

Comments
 (0)