lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  PHC 
Open Source and information security mailing list archives
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date:	Sat, 08 Dec 2007 20:01:28 -0500
From:	jamal <>
To:	Herbert Xu <>
Cc:	"David S. Miller" <>,,
	Patrick McHardy <>,
	YOSHIFUJI Hideaki /
Subject: Re: [PATCH 0/2] [IPSEC]: Reinject packet instead of calling
	netfilter directly on input

On Mon, 2007-03-12 at 07:34 -0500, jamal wrote:

> The point brought up on v6 extensions needs to be addressed. I thought
> about it a little - and it is valid as well for ipv4 options; they will
> be processed twice.
> To build up on what Patrick said, I noticed a bit still available in the
> bag right after skb->nf_trace that i could use to signal
> "options/extensions already processed". 
> If people think think this is a sane use of that very lonely bit, I will
> post patches.

And the patch included demonstrates the thought (I thought i had sent it
to the list on monday; seems only to Yoshfuji). Note, blah is not a
proper name, just an emphasis.


View attachment "v4v6-reinject" of type "text/x-patch" (3658 bytes)

Powered by blists - more mailing lists