Thread (10 messages) flat view 10 messages, 3 authors, 2010-05-14

Re: [PATCHv2] netfilter: Remove skb_is_nonlinear check from nf_conntrack_sip

From: Jan Engelhardt <hidden>
Date: 2010-05-14 19:33:40
Also in: netfilter-devel

On Friday 2010-05-14 21:26, Patrick McHardy wrote:
quoted
quoted
Should this be NF_DROP? As I understand it skb_linearize only failes
if it runs out of memory, which probably means dropping is OK. But
passing a packet that might need rewriting could be harmful..
We so far also didn't rewrite the packet. But agreed, its
a corner case and dropping it is the safer choice.
This is what I've added to my tree. Tested with asterisk and TSO
enabled NIC, which fails without this patch.
[..patch..]

Shouldn't we do this for the other nf_conntrack_xyz too?
That would mean getting rid of the size-limited locked packet
buffer.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help