[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <DB9PR04MB9648F84755C9894D720F996FFCAD9@DB9PR04MB9648.eurprd04.prod.outlook.com>
Date: Wed, 1 Mar 2023 15:19:01 +0000
From: Madhu Koriginja <madhu.koriginja@....com>
To: Florian Westphal <fw@...len.de>
CC: "gerrit@....abdn.ac.uk" <gerrit@....abdn.ac.uk>,
"davem@...emloft.net" <davem@...emloft.net>,
"kuznet@....inr.ac.ru" <kuznet@....inr.ac.ru>,
"yoshfuji@...ux-ipv6.org" <yoshfuji@...ux-ipv6.org>,
"edumazet@...gle.com" <edumazet@...gle.com>,
"dccp@...r.kernel.org" <dccp@...r.kernel.org>,
"netdev@...r.kernel.org" <netdev@...r.kernel.org>,
"linux-kernel@...r.kernel.org" <linux-kernel@...r.kernel.org>,
Vani Namala <vani.namala@....com>
Subject: RE: [EXT] Re: [PATCH] [NETFILTER]: Keep conntrack reference until
IPsecv6 policy checks are done
Hi Florian,
Got it, it's typo mistake. I will update the patch.
Thanks for quick review.
Regards,
Madhu K
-----Original Message-----
From: Florian Westphal <fw@...len.de>
Sent: Wednesday, March 1, 2023 8:38 PM
To: Madhu Koriginja <madhu.koriginja@....com>
Cc: gerrit@....abdn.ac.uk; davem@...emloft.net; kuznet@....inr.ac.ru; yoshfuji@...ux-ipv6.org; edumazet@...gle.com; dccp@...r.kernel.org; netdev@...r.kernel.org; linux-kernel@...r.kernel.org; Vani Namala <vani.namala@....com>
Subject: [EXT] Re: [PATCH] [NETFILTER]: Keep conntrack reference until IPsecv6 policy checks are done
Caution: EXT Email
Madhu Koriginja <madhu.koriginja@....com> wrote:
> Keep the conntrack reference until policy checks have been performed
> for IPsec V6 NAT support. The reference needs to be dropped before a
> packet is queued to avoid having the conntrack module unloadable.
In the old days there was no ipv6 nat so its not surpising that ipv6 discards the conntrack entry earlier than ipv4.
> - if (!(ipprot->flags & INET6_PROTO_NOPOLICY) &&
> - !xfrm6_policy_check(NULL, XFRM_POLICY_IN, skb))
> - goto discard;
> +
> + if (!ipprot->flags & INET6_PROTO_NOPOLICY) {
This looks wrong, why did you drop the () ?
if (!(ipprot->flags & INET6_PROTO_NOPOLICY)) { ...
rest LGTM.
Powered by blists - more mailing lists