On 8/14/26 3:40 PM, Ruoyu Wang wrote:
> ovs_ct_init() acquires a connlabels reference before initializing the
> conntrack limit state. If ovs_ct_limit_init() fails, its error is returned
> directly. The pernet core does not invoke the exit callback for the
> operation whose initialization failed, so ovs_ct_exit() cannot drop the
> reference.
>
> This leaves labels_used elevated when Open vSwitch pernet registration
> fails for an existing network namespace. Subsequent conntrack entries in
> that namespace may allocate label extensions even though Open vSwitch
> failed to register.
>
> Drop the connlabels reference before returning a conntrack limit
> initialization error. ovs_ct_limit_init() already releases its partial
> state, and the original error remains unchanged.
>
> This issue was found by a static analysis checker and confirmed by
> manual source review.
>
> Fixes: 11efd5cb04a1 ("openvswitch: Support conntrack zone limit")
Should add Cc: for the stable here.
> Signed-off-by: Ruoyu Wang <[email protected]>
> ---
> net/openvswitch/conntrack.c | 8 +++++++-
> 1 file changed, 7 insertions(+), 1 deletion(-)
>
> diff --git a/net/openvswitch/conntrack.c b/net/openvswitch/conntrack.c
> index 95697d4e16e64..fbaa677144143 100644
> --- a/net/openvswitch/conntrack.c
> +++ b/net/openvswitch/conntrack.c
> @@ -2001,6 +2001,9 @@ int ovs_ct_init(struct net *net)
> {
> unsigned int n_bits = sizeof(struct ovs_key_ct_labels) * BITS_PER_BYTE;
> struct ovs_net *ovs_net = net_generic(net, ovs_net_id);
> +#if IS_ENABLED(CONFIG_NETFILTER_CONNCOUNT)
> + int err;
> +#endif
No need to guard it with a macro. It should be cleaner to initialize
as zero and return err in both cases in the end.
>
> if (nf_connlabels_get(net, n_bits - 1)) {
> ovs_net->xt_label = false;
> @@ -2010,7 +2013,10 @@ int ovs_ct_init(struct net *net)
> }
>
> #if IS_ENABLED(CONFIG_NETFILTER_CONNCOUNT)
> - return ovs_ct_limit_init(net, ovs_net);
> + err = ovs_ct_limit_init(net, ovs_net);
> + if (err && ovs_net->xt_label)
> + nf_connlabels_put(net);
> + return err;
> #else
> return 0;
> #endif
_______________________________________________
dev mailing list
[email protected]
https://mail.openvswitch.org/mailman/listinfo/ovs-dev