netdev
[Top] [All Lists]

Re: [netfilter-core] [NETFILTER] Apply IPsec to ipt_REJECT packets

To: Patrick McHardy <kaber@xxxxxxxxx>
Subject: Re: [netfilter-core] [NETFILTER] Apply IPsec to ipt_REJECT packets
From: Herbert Xu <herbert@xxxxxxxxxxxxxxxxxxx>
Date: Wed, 24 Nov 2004 17:27:47 +1100
Cc: netdev@xxxxxxxxxxx, coreteam@xxxxxxxxxxxxx, "David S. Miller" <davem@xxxxxxxxxxxxx>
In-reply-to: <41A3E9D6.9060904@xxxxxxxxx>
References: <20041123084225.GA3514@xxxxxxxxxxxxxxxxxxx> <41A37EC0.8010901@xxxxxxxxx> <20041123211630.GA9805@xxxxxxxxxxxxxxxxxxx> <41A3AF41.4010700@xxxxxxxxx> <20041123221900.GA10099@xxxxxxxxxxxxxxxxxxx> <41A3E9D6.9060904@xxxxxxxxx>
Sender: netdev-bounce@xxxxxxxxxxx
User-agent: Mutt/1.5.6+20040722i
On Wed, Nov 24, 2004 at 02:54:30AM +0100, Patrick McHardy wrote:
>
> >     if (rt->u.dst.error) {
> >@@ -82,6 +88,15 @@
> >             rt = NULL;
> >
> ^ you should return here so xfrm_lookup isn't called without a dst_entry 
> below.

Good point.  Fixed in the following patch.

Signed-off-by: Herbert Xu <herbert@xxxxxxxxxxxxxxxxxxx>

Thanks for all your help, Patrick.
-- 
Visit Openswan at http://www.openswan.org/
Email: Herbert Xu ~{PmV>HI~} <herbert@xxxxxxxxxxxxxxxxxxx>
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt

Attachment: q
Description: Text document

<Prev in Thread] Current Thread [Next in Thread>