netdev
[Top] [All Lists]

Re: [PATCH] Fix checksum bug for multicast/broadcast packets on postrout

To: Mika Penttilä <mika.penttila@xxxxxxxxxxx>
Subject: Re: [PATCH] Fix checksum bug for multicast/broadcast packets on postrouting hook
From: "David S. Miller" <davem@xxxxxxxxxx>
Date: Sat, 14 Feb 2004 15:00:41 -0800
Cc: jmorris@xxxxxxxxxx, laforge@xxxxxxxxxxxxx, netdev@xxxxxxxxxxx, sds@xxxxxxxxxxxxxx
In-reply-to: <402E71E2.1040508@xxxxxxxxxxx>
References: <Xine.LNX.4.44.0402141318490.6128-100000@xxxxxxxxxxxxxxxxxxxxxxxx> <402E71E2.1040508@xxxxxxxxxxx>
Sender: netdev-bounce@xxxxxxxxxxx
On Sat, 14 Feb 2004 21:07:14 +0200
Mika Penttilä <mika.penttila@xxxxxxxxxxx> wrote:

> This is unneeded overhead for the common case. The right fix is to make 
> sure the modifier (netfilter etc) makes the copy if needed. Actually, 
> this is what skb_ip_make_writable() is doing.

I totally agree.

In postrouting hook, the handler must unshare the SKB if it wishes to
modify the packet contents.  It sounds to me like the selinux hooks are
not doing this, and as suggested they should look at using the routine
skb_ip_make_writable() which was designed by Rusty for this.


<Prev in Thread] Current Thread [Next in Thread>