From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id CCF6530BF68; Mon, 13 Apr 2026 17:03:51 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1776099831; cv=none; b=SggaEUa5akOTVuDQeUDgVO8aNZiCO0h/rph6HuOnLaqou6T0v4PCP5aQjZ5TRTb2Q2SHFB0DrIMX82neGU1P+IWdqpJUsf1BlOwUPe4qup2kSdnPy8W4GQ3K/DkWLohpLM6k7jfM1sS0qaoAKosrW1uqfOEOtSm4XUX4SMZW2nI= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1776099831; c=relaxed/simple; bh=zPG7K/rHCsBYReBBXLePsJJ+Hmrm0g2afM2ESBSiSsc=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=BALL7yCJMqxblZYUbKDVYI9yzGvDILNOByCqZ4r/Epc2NxfOGYOdc6ZM7DKbUJj8P/hXMhsOxOIBUUm27EomrWqukKmkXc7E3dnVzq3teaG2HMISJR6OSPrSLZW5NOs2LhdxLphlYK5OcNehniGL2mrpCDT2lPfuPOqQLE/DfaE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=FCjrDhVL; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="FCjrDhVL" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 62C49C2BCAF; Mon, 13 Apr 2026 17:03:51 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=linuxfoundation.org; s=korg; t=1776099831; bh=zPG7K/rHCsBYReBBXLePsJJ+Hmrm0g2afM2ESBSiSsc=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=FCjrDhVLfaqrg2SZUFWPAY2senss6dROwDAfhcGU5hIVTY5XBKFiFiwCj6dqUMny+ 8fcfmqEY4OfoWH0D1j2NZvHSlrvvI4kX6+UPMtwMl94DxMyuOaudBJP+n9dn0NSCy/ 9lZrExB2nrPYG4cvg7JfRJVuldYBWc4hg06GvJ0k= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Andrea Mayer , Nicolas Dichtel , Justin Iurman , Jakub Kicinski , Sasha Levin Subject: [PATCH 5.10 459/491] seg6: separate dst_cache for input and output paths in seg6 lwtunnel Date: Mon, 13 Apr 2026 18:01:44 +0200 Message-ID: <20260413155836.220972449@linuxfoundation.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260413155819.042779211@linuxfoundation.org> References: <20260413155819.042779211@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: stable@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 5.10-stable review patch. If anyone has any objections, please let me know. ------------------ From: Andrea Mayer [ Upstream commit c3812651b522fe8437ebb7063b75ddb95b571643 ] The seg6 lwtunnel uses a single dst_cache per encap route, shared between seg6_input_core() and seg6_output_core(). These two paths can perform the post-encap SID lookup in different routing contexts (e.g., ip rules matching on the ingress interface, or VRF table separation). Whichever path runs first populates the cache, and the other reuses it blindly, bypassing its own lookup. Fix this by splitting the cache into cache_input and cache_output, so each path maintains its own cached dst independently. Fixes: 6c8702c60b88 ("ipv6: sr: add support for SRH encapsulation and injection with lwtunnels") Cc: stable@vger.kernel.org Signed-off-by: Andrea Mayer Reviewed-by: Nicolas Dichtel Reviewed-by: Justin Iurman Link: https://patch.msgid.link/20260404004405.4057-2-andrea.mayer@uniroma2.it Signed-off-by: Jakub Kicinski [ adapted cache field references ] Signed-off-by: Sasha Levin Signed-off-by: Greg Kroah-Hartman --- net/ipv6/seg6_iptunnel.c | 34 +++++++++++++++++++++++----------- 1 file changed, 23 insertions(+), 11 deletions(-) --- a/net/ipv6/seg6_iptunnel.c +++ b/net/ipv6/seg6_iptunnel.c @@ -45,7 +45,8 @@ static size_t seg6_lwt_headroom(struct s } struct seg6_lwt { - struct dst_cache cache; + struct dst_cache cache_input; + struct dst_cache cache_output; struct seg6_iptunnel_encap tuninfo[]; }; @@ -326,7 +327,7 @@ static int seg6_input(struct sk_buff *sk slwt = seg6_lwt_lwtunnel(orig_dst->lwtstate); local_bh_disable(); - dst = dst_cache_get(&slwt->cache); + dst = dst_cache_get(&slwt->cache_input); skb_dst_drop(skb); @@ -334,7 +335,7 @@ static int seg6_input(struct sk_buff *sk ip6_route_input(skb); dst = skb_dst(skb); if (!dst->error) { - dst_cache_set_ip6(&slwt->cache, dst, + dst_cache_set_ip6(&slwt->cache_input, dst, &ipv6_hdr(skb)->saddr); } } else { @@ -363,7 +364,7 @@ static int seg6_output(struct net *net, slwt = seg6_lwt_lwtunnel(orig_dst->lwtstate); local_bh_disable(); - dst = dst_cache_get(&slwt->cache); + dst = dst_cache_get(&slwt->cache_output); local_bh_enable(); if (unlikely(!dst)) { @@ -384,7 +385,7 @@ static int seg6_output(struct net *net, } local_bh_disable(); - dst_cache_set_ip6(&slwt->cache, dst, &fl6.saddr); + dst_cache_set_ip6(&slwt->cache_output, dst, &fl6.saddr); local_bh_enable(); } @@ -461,11 +462,13 @@ static int seg6_build_state(struct net * slwt = seg6_lwt_lwtunnel(newts); - err = dst_cache_init(&slwt->cache, GFP_ATOMIC); - if (err) { - kfree(newts); - return err; - } + err = dst_cache_init(&slwt->cache_input, GFP_ATOMIC); + if (err) + goto err_free_newts; + + err = dst_cache_init(&slwt->cache_output, GFP_ATOMIC); + if (err) + goto err_destroy_input; memcpy(&slwt->tuninfo, tuninfo, tuninfo_len); @@ -480,11 +483,20 @@ static int seg6_build_state(struct net * *ts = newts; return 0; + +err_destroy_input: + dst_cache_destroy(&slwt->cache_input); +err_free_newts: + kfree(newts); + return err; } static void seg6_destroy_state(struct lwtunnel_state *lwt) { - dst_cache_destroy(&seg6_lwt_lwtunnel(lwt)->cache); + struct seg6_lwt *slwt = seg6_lwt_lwtunnel(lwt); + + dst_cache_destroy(&slwt->cache_input); + dst_cache_destroy(&slwt->cache_output); } static int seg6_fill_encap_info(struct sk_buff *skb,