kernel-pfroute: Make sure source addresses are not virtual and usable
It seems we sometimes get the virtual IP as source (with rightsubnet=0.0.0.0/0) even if the exclude route is already installed. Might be a timing issue because shortly afterwards the lookup seems to succeed.
This commit is contained in:
@@ -1519,12 +1519,28 @@ retry:
|
|||||||
}
|
}
|
||||||
DBG1(DBG_KNL, "PF_ROUTE lookup failed: %s", strerror(errno));
|
DBG1(DBG_KNL, "PF_ROUTE lookup failed: %s", strerror(errno));
|
||||||
}
|
}
|
||||||
|
if (!host)
|
||||||
if (host)
|
|
||||||
{
|
{
|
||||||
DBG2(DBG_KNL, "using %H as %s to reach %H", host,
|
return NULL;
|
||||||
nexthop ? "nexthop" : "address", dest);
|
|
||||||
}
|
}
|
||||||
|
if (!nexthop)
|
||||||
|
{ /* make sure the source address is not virtual and usable */
|
||||||
|
addr_entry_t *entry, lookup = {
|
||||||
|
.ip = host,
|
||||||
|
};
|
||||||
|
|
||||||
|
this->lock->read_lock(this->lock);
|
||||||
|
entry = this->addrs->get_match(this->addrs, &lookup,
|
||||||
|
(void*)addr_map_entry_match_up_and_usable);
|
||||||
|
this->lock->unlock(this->lock);
|
||||||
|
if (!entry)
|
||||||
|
{
|
||||||
|
host->destroy(host);
|
||||||
|
return NULL;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
DBG2(DBG_KNL, "using %H as %s to reach %H", host,
|
||||||
|
nexthop ? "nexthop" : "address", dest);
|
||||||
return host;
|
return host;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user