Herbert Xu wrote:
On Mon, Mar 07, 2005 at 02:41:30AM +0100, Patrick McHardy wrote:
Mainly to avoid excessive long lists of cached bundles in tunnel
mode. The use of a single list for the cache is questionable, but
the patch was supposed to fix a different issue. Restricting use
of tos/mark to transport mode avoids having exploding lists that
are easily remotely triggerable.
That's a different problem. You can already create arbitrarily
long bundle lists by spoofing src/dst addresses...
But I don't want to make it worse. The number is still restricted by
the scope of the selector, using tos and fwmark makes the worst case
a lot worse.
Regards
Patrick
|