[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <Ynivfw21/nr8PKVD@salvia>
Date: Mon, 9 May 2022 08:06:55 +0200
From: Pablo Neira Ayuso <pablo@...filter.org>
To: Kevin Mitchell <kevmitch@...sta.com>
Cc: gal@...dia.com, Jozsef Kadlecsik <kadlec@...filter.org>,
Florian Westphal <fw@...len.de>,
"David S. Miller" <davem@...emloft.net>,
Eric Dumazet <edumazet@...gle.com>,
Jakub Kicinski <kuba@...nel.org>,
Paolo Abeni <pabeni@...hat.com>,
Hideaki YOSHIFUJI <yoshfuji@...ux-ipv6.org>,
David Ahern <dsahern@...nel.org>,
netfilter-devel@...r.kernel.org, coreteam@...filter.org,
netdev@...r.kernel.org, linux-kernel@...r.kernel.org
Subject: Re: [PATCH nf-next v3] netfilter: conntrack: skip verification of
zero UDP checksum
On Fri, Apr 29, 2022 at 08:40:27PM -0700, Kevin Mitchell wrote:
> The checksum is optional for UDP packets. However nf_reject would
> previously require a valid checksum to elicit a response such as
> ICMP_DEST_UNREACH.
>
> Add some logic to nf_reject_verify_csum to determine if a UDP packet has
> a zero checksum and should therefore not be verified.
Applied.
Powered by blists - more mailing lists