[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-Id: <20150420.140825.121616346767140780.davem@davemloft.net>
Date: Mon, 20 Apr 2015 14:08:25 -0400 (EDT)
From: David Miller <davem@...emloft.net>
To: sebastian.poehn@...il.com
Cc: netdev@...r.kernel.org
Subject: Re: [PATCH v2] ip_forward: Drop frames with attached skb->sk
From: Sebastian Poehn <sebastian.poehn@...il.com>
Date: Mon, 20 Apr 2015 09:19:20 +0200
> Initial discussion was:
> [FYI] xfrm: Don't lookup sk_policy for timewait sockets
>
> Forwarded frames should not have a socket attached. Especially
> tw sockets will lead to panics later-on in the stack.
>
> This was observed with TPROXY assigning a tw socket and broken
> policy routing (misconfigured). As a result frame enters
> forwarding path instead of input. We cannot solve this in
> TPROXY as it cannot know that policy routing is broken.
>
> v2:
> Remove useless comment
>
> Signed-off-by: Sebastian Poehn <sebastian.poehn@...il.com>
Applied and queued up for -stable, thanks Sebastian.
--
To unsubscribe from this list: send the line "unsubscribe netdev" in
the body of a message to majordomo@...r.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Powered by blists - more mailing lists