[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-Id: <E1KmK7b-00036t-LM@gondolin.me.apana.org.au>
Date: Sun, 05 Oct 2008 11:17:27 +0800
From: Herbert Xu <herbert@...dor.apana.org.au>
To: nhorman@...driver.com (Neil Horman)
Cc: netdev@...r.kernel.org, kuznet@....inr.ac.ru, davem@...emloft.net,
pekkas@...core.fi, jmorris@...ei.org, yoshfuji@...ux-ipv6.org,
kaber@...sh.net, nhorman@...driver.com
Subject: Re: [PATCH] net: implement emergency route cache rebulds when gc_elasticity is exceeded
Neil Horman <nhorman@...driver.com> wrote:
> We currently have the ability to disable our route cache secret interval
> rebuild timer (by setting it to zero), but if we do that its possible for an
> attacker (if they guess our route cache hash secret, to fill our system with
> routes that all hash to the same bucket, destroying our performance. This patch
This is completely bogus. We never allow any chain to grow beyond
the elasticity. So in the worst case we just bypass the route cache.
Cheers,
--
Visit Openswan at http://www.openswan.org/
Email: Herbert Xu ~{PmV>HI~} <herbert@...dor.apana.org.au>
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt
--
To unsubscribe from this list: send the line "unsubscribe netdev" in
the body of a message to majordomo@...r.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Powered by blists - more mailing lists