Re: [PATCH 0/2] [IPSEC]: Reinject packet instead of calling netfilter directly on input
From: jamal <hidden>
Date: 2007-12-09 01:01:47
Attachments
- v4v6-reinject [text/x-patch] 3657 bytes · preview
From: jamal <hidden>
Date: 2007-12-09 01:01:47
On Mon, 2007-03-12 at 07:34 -0500, jamal wrote:
The point brought up on v6 extensions needs to be addressed. I thought about it a little - and it is valid as well for ipv4 options; they will be processed twice. To build up on what Patrick said, I noticed a bit still available in the bag right after skb->nf_trace that i could use to signal "options/extensions already processed". If people think think this is a sane use of that very lonely bit, I will post patches.
And the patch included demonstrates the thought (I thought i had sent it to the list on monday; seems only to Yoshfuji). Note, blah is not a proper name, just an emphasis. cheers, jama