Re: [PATCH 2/2] [IPSEC]: Reinject v6 packet on input instead of calling netfilter
From: Patrick McHardy <hidden>
Date: 2007-11-29 21:21:36
From: Patrick McHardy <hidden>
Date: 2007-11-29 21:21:36
jamal wrote:
On Thu, 2007-29-11 at 21:55 +0100, Patrick McHardy wrote:quoted
jamal wrote: [ can't quote because non-inline attachment ]Evolution seems to have whitespace issues everytime i inlined the attachment; and Dave has been able to tolerate me doing this so far. I have just read it in
I used to work fine for me as well, the Debian switch to icedove broke it. Never mind, I'm sure its going to get fixed some day :)
quoted
I think Yoshifuji had some objections to this because extension headers will be processed twice.ah, i missed that part. Could you point to a specific portion?
http://lists.openwall.net/netdev/2007/10/16/88
I wouldnt mind just ipv4 going in - but that would be lacking consistency. Is there anything that can be done to get the extension headers to be processed only once?
I would prefer to keep things consistent between IPv4 and IPv6. Not sure if anything could be done, perhaps we could keep the necessary parts of the IP6CB and skip parsing up to the ESP nexthdr.