Re: [PATCH net] net/tcp: Fix socket lookups with SO_BINDTODEVICE

2018-06-19 Thread David Miller
From: dsah...@kernel.org Date: Mon, 18 Jun 2018 12:30:37 -0700 > From: David Ahern > > Similar to 69678bcd4d2d ("udp: fix SO_BINDTODEVICE"), TCP socket lookups > need to fail if dev_match is not true. Currently, a packet to a given port > can match a socket bound to device when it should not. In

[PATCH net] net/tcp: Fix socket lookups with SO_BINDTODEVICE

2018-06-18 Thread dsahern
From: David Ahern Similar to 69678bcd4d2d ("udp: fix SO_BINDTODEVICE"), TCP socket lookups need to fail if dev_match is not true. Currently, a packet to a given port can match a socket bound to device when it should not. In the VRF case, this causes the lookup to hit a VRF socket and not a global