[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <4C49B296.10009@trash.net>
Date: Fri, 23 Jul 2010 17:17:42 +0200
From: Patrick McHardy <kaber@...sh.net>
To: Herbert Xu <herbert@...dor.apana.org.au>
CC: Stephen Hemminger <shemminger@...tta.com>, netdev@...r.kernel.org
Subject: Re: Yet another bridge netfilter crash
On 23.07.2010 17:00, Herbert Xu wrote:
> On Fri, Jul 23, 2010 at 04:18:46PM +0200, Patrick McHardy wrote:
>>
>> I think we've already fixed this by commit 8fa9ff6:
>>
>
>> commit 8fa9ff6849bb86c59cc2ea9faadf3cb2d5223497
>> Author: Patrick McHardy <kaber@...sh.net>
>> Date: Tue Dec 15 16:59:59 2009 +0100
>>
>> netfilter: fix crashes in bridge netfilter caused by fragment jumps
>
> Thanks for the pointer Patrick.
>
> Your memory is much better than mine, as I was in that thread too :)
>
> BTW, do you have any plans on addressing the deeper issue of
> separating the connection tracking as well?
No concrete plans yet, but its something I'm definitely planning
to try at some point.
> There's also the matter of fragments jumping between bridges.
Conntrack zones can be used to avoid that, but that currently needs
manual configuration.
--
To unsubscribe from this list: send the line "unsubscribe netdev" in
the body of a message to majordomo@...r.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Powered by blists - more mailing lists