netdev
[Top] [All Lists]

Re: [PATCH] Prevent crash on ip_conntrack removal

To: Patrick McHardy <kaber@xxxxxxxxx>
Subject: Re: [PATCH] Prevent crash on ip_conntrack removal
From: David Stevens <dlstevens@xxxxxxxxxx>
Date: Tue, 24 Aug 2004 15:28:07 -0600
Cc: "David S. Miller" <davem@xxxxxxxxxx>, laforge@xxxxxxxxxxxxx, netdev@xxxxxxxxxxx, netdev-bounce@xxxxxxxxxxx, netfilter-devel@xxxxxxxxxxxxxxxxxxx, okir@xxxxxxx
In-reply-to: <412A8FB5.4080700@trash.net>
Sender: netdev-bounce@xxxxxxxxxxx
Then it appears that simply dropping the packet when the
skb->dst == 0 isn't quite right, since per-frag option processing
wouldn't be done in the case where conntrack is removed, but
the first frag does have skb->dst set  (but not some of the others).

In that case, it appears that conntrack needs to flush the entire
frag queue when it's unloaded. That shouldn't happen much,
so maybe that's not such a bad idea.

                                        +-DLS


<Prev in Thread] Current Thread [Next in Thread>