netdev
[Top] [All Lists]

Re: ERRATA Re: [PATCH] fix for netfilter/nat/pppoe crashes (hopefully)

To: davem@xxxxxxxxxx (David S. Miller)
Subject: Re: ERRATA Re: [PATCH] fix for netfilter/nat/pppoe crashes (hopefully)
From: kuznet@xxxxxxxxxxxxx
Date: Fri, 3 Aug 2001 21:40:56 +0400 (MSK DST)
Cc: laforge@xxxxxxxxxxxx, rusty@xxxxxxxxxxxxxxx, marc@xxxxxxx, netfilter-devel@xxxxxxxxxxxxxxx, netdev@xxxxxxxxxxx
In-reply-to: <15210.14446.81297.26145@pizda.ninka.net> from "David S. Miller" at Aug 2, 1 10:36:46 pm
Sender: owner-netdev@xxxxxxxxxxx
Hello!

>  > Sorry Rusty, but check on sizeof(struct tcphdr) is IMHO wrong, again.
> 
> I think there is no way you can validly drop an ICMP packet just
> because the TCP checksum field is not there in the embedded header.
> 
> So I think I basically agree with Harald.

Reminder to Paul: 99% of icmp errors have only 8 bytes of tcp header
enough to get ports and sequence number and that's all.
All the rest is an option, which is not respected by the most
of routers and even host OSes.

Alexey

<Prev in Thread] Current Thread [Next in Thread>