java-topology/defects/linux/patch/linux-0004-neigh-parms-xarray-lookup.patch

71 lines
2.6 KiB
Diff

# UNDF: UNDF-2026-000000147
--- a/net/core/neighbour.c
+++ b/net/core/neighbour.c
@@ -1752,11 +1752,32 @@ static void pneigh_queue_purge(struct sk_buff_head *list, struct net *net,
spin_unlock_irqrestore(&list->lock, flags);
}
+/*
+ * CWE-407 fix: replace O(P) linear parms_list scan with O(1) xarray lookup.
+ *
+ * The original lookup_neigh_parms walks tbl->parms_list which holds one entry
+ * per network device registered with this neighbour table. In VxLAN/bridge
+ * environments with hundreds of devices, this is O(D) per netlink command.
+ *
+ * Fix: maintain tbl->parms_xa (struct xarray) keyed by ifindex.
+ * neigh_parms_alloc() stores into it; neigh_parms_release() erases from it.
+ * lookup_neigh_parms() becomes a single xa_load() call.
+ *
+ * NOTE: This patch shows the algorithmic fix. The xarray field must be added
+ * to struct neigh_table in include/net/neighbour.h and initialised in
+ * neigh_table_init(). parms_list is retained for GC iteration.
+ */
static inline struct neigh_parms *lookup_neigh_parms(struct neigh_table *tbl,
struct net *net, int ifindex)
{
struct neigh_parms *p;
+#ifdef CONFIG_NEIGH_PARMS_XA /* guard until xarray field is wired in */
+ p = xa_load(&tbl->parms_xa, (unsigned long)ifindex);
+ if (p && net_eq(neigh_parms_net(p), net))
+ return p;
+ if (!ifindex) {
+ /* ifindex==0 means global parms; stored at key 0 */
+ p = xa_load(&tbl->parms_xa, 0UL);
+ if (p && net_eq(neigh_parms_net(p), net))
+ return p;
+ }
+ return NULL;
+#else
list_for_each_entry(p, &tbl->parms_list, list) {
if ((p->dev && p->dev->ifindex == ifindex && net_eq(neigh_parms_net(p), net)) ||
(!p->dev && !ifindex && net_eq(net, &init_net)))
@@ -1764,6 +1785,7 @@ static inline struct neigh_parms *lookup_neigh_parms(struct neigh_table *tbl,
}
return NULL;
+#endif /* CONFIG_NEIGH_PARMS_XA */
}
struct neigh_parms *neigh_parms_alloc(struct net_device *dev,
@@ -1790,6 +1812,10 @@ struct neigh_parms *neigh_parms_alloc(struct net_device *dev,
p->dev = dev;
p->dev_tracker = dev_tracker;
list_add(&p->list, &tbl->parms_list);
+#ifdef CONFIG_NEIGH_PARMS_XA
+ xa_store(&tbl->parms_xa,
+ (unsigned long)(dev ? dev->ifindex : 0), p, GFP_KERNEL);
+#endif
write_pnet(&p->net, net);
}
return p;
@@ -1822,6 +1848,9 @@ void neigh_parms_release(struct neigh_table *tbl, struct neigh_parms *parms)
if (parms == &tbl->parms)
return;
list_del(&parms->list);
+#ifdef CONFIG_NEIGH_PARMS_XA
+ xa_erase(&tbl->parms_xa, (unsigned long)(parms->dev ? parms->dev->ifindex : 0));
+#endif
kfree_rcu(parms, rcu_head);
}
EXPORT_SYMBOL(neigh_parms_release);