All of lore.kernel.org
 help / color / mirror / Atom feed
From: Hannes Frederic Sowa <hannes@stressinduktion.org>
To: Salam Noureddine <noureddine@aristanetworks.com>
Cc: "David S. Miller" <davem@davemloft.net>,
	Alexey Kuznetsov <kuznet@ms2.inr.ac.ru>,
	James Morris <jmorris@namei.org>,
	Hideaki YOSHIFUJI <yoshfuji@linux-ipv6.org>,
	Patrick McHardy <kaber@trash.net>,
	netdev@vger.kernel.org
Subject: Re: [PATCH 1/1] ipv4: arp: Always update neighbour address when a gratuitous arp is received
Date: Fri, 20 Dec 2013 15:00:14 +0100	[thread overview]
Message-ID: <20131220140014.GF32129@order.stressinduktion.org> (raw)
In-Reply-To: <1387518072-8076-1-git-send-email-noureddine@aristanetworks.com>

On Thu, Dec 19, 2013 at 09:41:12PM -0800, Salam Noureddine wrote:
> Gratuitous arp packets are useful in switchover scenarios to update
> client arp tables as quickly as possible. Currently, the mac address
> of a neighbour is only updated after a locktime period has elapsed
> since the last update. In most use cases such delays are unacceptable
> for network admins. Moreover, the "updated" field of the neighbour
> stucture doesn't record the last time the address of a neighbour
> changed but records any change that happens to theneighbour. This is
> clearly a bug since locktime uses that field as meaning "addr_updated".
> With this observation, I was able to perpetuate a stale address by
> sending a stream of gratuitous arp packets spaced less than locktime
> apart.
> 
> Signed-off-by: Salam Noureddine <noureddine@aristanetworks.com>
> ---
>  net/ipv4/arp.c |    5 ++++-
>  1 files changed, 4 insertions(+), 1 deletions(-)
> 
> diff --git a/net/ipv4/arp.c b/net/ipv4/arp.c
> index 7808093..ab13347 100644
> --- a/net/ipv4/arp.c
> +++ b/net/ipv4/arp.c
> @@ -910,7 +910,10 @@ static int arp_process(struct sk_buff *skb)
>  		   agents are active. Taking the first reply prevents
>  		   arp trashing and chooses the fastest router.
>  		 */
> -		override = time_after(jiffies, n->updated + n->parms->locktime);
> +		override = time_after(jiffies,
> +				      n->updated + n->parms->locktime) ||
> +			   (tip == sip &&
> +			    inet_addr_type(net, sip) == RTN_UNICAST);
>  
>  		/* Broadcast replies and request packets
>  		   do not assert neighbour reachability.

Hm, that is hard to decipher in a few months (or years). Maybe a small
function like

static bool is_garp(...)
{
	...
}

would self-document the code. They normally get inlined so there is no
additional runtime overhead.

Thanks,

  Hannes

  reply	other threads:[~2013-12-20 14:00 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2013-12-20  5:41 [PATCH 1/1] ipv4: arp: Always update neighbour address when a gratuitous arp is received Salam Noureddine
2013-12-20 14:00 ` Hannes Frederic Sowa [this message]
  -- strict thread matches above, loose matches on Subject: below --
2013-12-20 18:59 Salam Noureddine
2013-12-20 22:06 ` Stephen Hemminger
2013-12-20 22:25   ` Salam Noureddine
2013-12-20 22:30   ` Hannes Frederic Sowa
2013-12-21  0:36 ` Hannes Frederic Sowa

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20131220140014.GF32129@order.stressinduktion.org \
    --to=hannes@stressinduktion.org \
    --cc=davem@davemloft.net \
    --cc=jmorris@namei.org \
    --cc=kaber@trash.net \
    --cc=kuznet@ms2.inr.ac.ru \
    --cc=netdev@vger.kernel.org \
    --cc=noureddine@aristanetworks.com \
    --cc=yoshfuji@linux-ipv6.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.