summaryrefslogtreecommitdiffstats
path: root/security/yama
diff options
context:
space:
mode:
authorDavid S. Miller <davem@davemloft.net>2018-02-08 10:01:28 -0500
committerDavid S. Miller <davem@davemloft.net>2018-02-08 10:01:28 -0500
commitc70255868148a498ba418bc6c2f9df212d30d393 (patch)
tree753682d9f05db11f19da5be63435b35c768ae4ac /security/yama
parent5c487bb9adddbc1d23433e09d2548759375c2b52 (diff)
parent1a5e8e35000577cb9100d22daa8b5ebcfa2be9b2 (diff)
downloadlinux-c70255868148a498ba418bc6c2f9df212d30d393.tar.bz2
Merge branch 'nfp-fix-disabling-TC-offloads-in-flower-max-TSO-segs-and-module-version'
Jakub Kicinski says: ==================== nfp: fix disabling TC offloads in flower, max TSO segs and module version This set corrects the way nfp deals with the NETIF_F_HW_TC flag. It has slipped the review that flower offload does not currently refuse disabling this flag when filter offload is active. nfp's flower offload does not actually keep track of how many filters for each port are offloaded. The accounting of the number of filters is added to the nfp core structures, and BPF moved to use these structures as well. If users are allowed to disable TC offloads while filters are active, not only is it incorrect behaviour, but actually the NFP will never be told to remove the flows, leading to use-after-free when stats arrive. Fourth patch makes sure we declare the max number of TSO segments. FW should drop longer packets cleanly (otherwise this would be a security problem for untrusted VFs) but dropping longer TSO frames is not nice and driver should prevent them from being generated. Last small addition populates MODULE_VERSION with kernel version. ==================== Signed-off-by: David S. Miller <davem@davemloft.net>
Diffstat (limited to 'security/yama')
0 files changed, 0 insertions, 0 deletions