Re: [PATCH 2/2] IB/ipoib: fix GRO merge failure for IPoIB originated TCP streams

2 messages, 2 authors, 2012-01-30 · open the first message on its own page

Re: [PATCH 2/2] IB/ipoib: fix GRO merge failure for IPoIB originated TCP streams

From: Eric Dumazet <hidden>
Date: 2012-01-30 08:53:03

Le lundi 30 janvier 2012 à 19:18 +1100, Herbert Xu a écrit :
On Mon, Jan 30, 2012 at 09:04:32AM +0100, Eric Dumazet wrote:
quoted
Hmm, do we really need to compare ether header, thats the question.
I think we do.  As otherwise macvlan would break.
Thats the theory yes, but practically ?

Really, GRO can merge two TCP frames given they match everything needed,
exactly as our TCP stack would do in the end.

What could be a normal workload where this mismatch of two different tcp
flows could happen with macvlan or any kind of devices ?

If this is an attack, TCP will merge the frames anyway on the same
socket.

Or should we add checks in TCP stack, in case GRO is off ?



--
To unsubscribe from this list: send the line "unsubscribe linux-rdma" in
the body of a message to majordomo-u79uwXL29TY76Z2rM5mHXA@public.gmane.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html

Re: [PATCH 2/2] IB/ipoib: fix GRO merge failure for IPoIB originated TCP streams

From: Herbert Xu <hidden>
Date: 2012-01-30 08:57:42

On Mon, Jan 30, 2012 at 09:53:03AM +0100, Eric Dumazet wrote:
If this is an attack, TCP will merge the frames anyway on the same
socket.
Not if we have a MAC-level filter in place or VLANs.

Cheers,
-- 
Email: Herbert Xu [off-list ref]
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt
--
To unsubscribe from this list: send the line "unsubscribe linux-rdma" in
the body of a message to majordomo-u79uwXL29TY76Z2rM5mHXA@public.gmane.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help