[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-Id: <1197162088.5528.12.camel@localhost>
Date: Sat, 08 Dec 2007 20:01:28 -0500
From: jamal <hadi@...erus.ca>
To: Herbert Xu <herbert@...dor.apana.org.au>
Cc: "David S. Miller" <davem@...emloft.net>, netdev@...r.kernel.org,
Patrick McHardy <kaber@...sh.net>,
YOSHIFUJI Hideaki /
吉藤英明
<yoshfuji@...ux-ipv6.org>
Subject: Re: [PATCH 0/2] [IPSEC]: Reinject packet instead of calling
netfilter directly on input
On Mon, 2007-03-12 at 07:34 -0500, jamal wrote:
> The point brought up on v6 extensions needs to be addressed. I thought
> about it a little - and it is valid as well for ipv4 options; they will
> be processed twice.
> To build up on what Patrick said, I noticed a bit still available in the
> bag right after skb->nf_trace that i could use to signal
> "options/extensions already processed".
> If people think think this is a sane use of that very lonely bit, I will
> post patches.
And the patch included demonstrates the thought (I thought i had sent it
to the list on monday; seems only to Yoshfuji). Note, blah is not a
proper name, just an emphasis.
cheers,
jama
View attachment "v4v6-reinject" of type "text/x-patch" (3658 bytes)
Powered by blists - more mailing lists