Thread (3 messages) 3 messages, 3 authors, 2006-02-15

Re: [RFC,NETFILTER]: Fix xfrm lookup after SNAT

From: "David S. Miller" <davem@davemloft.net>
Date: 2006-02-15 09:34:39
Also in: netfilter-devel

From: Herbert Xu <herbert@gondor.apana.org.au>
Date: Tue, 14 Feb 2006 12:49:24 +1100
On Mon, Feb 13, 2006 at 06:25:01PM +0100, Patrick McHardy wrote:
quoted
I finally got around to fixing the "ip_finish_output2: No header cache
and no neighbour!" problem reported by Andi Kleen. Instead of rerouting
the packet in POST_ROUTING, we reuse the original route for the
xfrm_lookup. This introduces a small restriction (see changelog entry),
but I think it should work.

Herbert, do you see any problems with this patch?
Looks perfect to me.  I think the restriction makes sense since SNAT
is done in post-routing so it's counter-intuitive to repeat the lookup
anyway.
 
quoted
Signed-off-by: Patrick McHardy <redacted>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Looks good to me too, applied to net-2.6

Thanks a lot.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help