71 lines
2.6 KiB
Diff
71 lines
2.6 KiB
Diff
# UNDF: UNDF-2026-000000147
|
|
--- a/net/core/neighbour.c
|
|
+++ b/net/core/neighbour.c
|
|
@@ -1752,11 +1752,32 @@ static void pneigh_queue_purge(struct sk_buff_head *list, struct net *net,
|
|
spin_unlock_irqrestore(&list->lock, flags);
|
|
}
|
|
|
|
+/*
|
|
+ * CWE-407 fix: replace O(P) linear parms_list scan with O(1) xarray lookup.
|
|
+ *
|
|
+ * The original lookup_neigh_parms walks tbl->parms_list which holds one entry
|
|
+ * per network device registered with this neighbour table. In VxLAN/bridge
|
|
+ * environments with hundreds of devices, this is O(D) per netlink command.
|
|
+ *
|
|
+ * Fix: maintain tbl->parms_xa (struct xarray) keyed by ifindex.
|
|
+ * neigh_parms_alloc() stores into it; neigh_parms_release() erases from it.
|
|
+ * lookup_neigh_parms() becomes a single xa_load() call.
|
|
+ *
|
|
+ * NOTE: This patch shows the algorithmic fix. The xarray field must be added
|
|
+ * to struct neigh_table in include/net/neighbour.h and initialised in
|
|
+ * neigh_table_init(). parms_list is retained for GC iteration.
|
|
+ */
|
|
static inline struct neigh_parms *lookup_neigh_parms(struct neigh_table *tbl,
|
|
struct net *net, int ifindex)
|
|
{
|
|
struct neigh_parms *p;
|
|
|
|
+#ifdef CONFIG_NEIGH_PARMS_XA /* guard until xarray field is wired in */
|
|
+ p = xa_load(&tbl->parms_xa, (unsigned long)ifindex);
|
|
+ if (p && net_eq(neigh_parms_net(p), net))
|
|
+ return p;
|
|
+ if (!ifindex) {
|
|
+ /* ifindex==0 means global parms; stored at key 0 */
|
|
+ p = xa_load(&tbl->parms_xa, 0UL);
|
|
+ if (p && net_eq(neigh_parms_net(p), net))
|
|
+ return p;
|
|
+ }
|
|
+ return NULL;
|
|
+#else
|
|
list_for_each_entry(p, &tbl->parms_list, list) {
|
|
if ((p->dev && p->dev->ifindex == ifindex && net_eq(neigh_parms_net(p), net)) ||
|
|
(!p->dev && !ifindex && net_eq(net, &init_net)))
|
|
@@ -1764,6 +1785,7 @@ static inline struct neigh_parms *lookup_neigh_parms(struct neigh_table *tbl,
|
|
}
|
|
|
|
return NULL;
|
|
+#endif /* CONFIG_NEIGH_PARMS_XA */
|
|
}
|
|
|
|
struct neigh_parms *neigh_parms_alloc(struct net_device *dev,
|
|
@@ -1790,6 +1812,10 @@ struct neigh_parms *neigh_parms_alloc(struct net_device *dev,
|
|
p->dev = dev;
|
|
p->dev_tracker = dev_tracker;
|
|
list_add(&p->list, &tbl->parms_list);
|
|
+#ifdef CONFIG_NEIGH_PARMS_XA
|
|
+ xa_store(&tbl->parms_xa,
|
|
+ (unsigned long)(dev ? dev->ifindex : 0), p, GFP_KERNEL);
|
|
+#endif
|
|
write_pnet(&p->net, net);
|
|
}
|
|
return p;
|
|
@@ -1822,6 +1848,9 @@ void neigh_parms_release(struct neigh_table *tbl, struct neigh_parms *parms)
|
|
if (parms == &tbl->parms)
|
|
return;
|
|
list_del(&parms->list);
|
|
+#ifdef CONFIG_NEIGH_PARMS_XA
|
|
+ xa_erase(&tbl->parms_xa, (unsigned long)(parms->dev ? parms->dev->ifindex : 0));
|
|
+#endif
|
|
kfree_rcu(parms, rcu_head);
|
|
}
|
|
EXPORT_SYMBOL(neigh_parms_release);
|