Re: 2.6.12: connection tracking broken?

Patrick McHardy <[email protected]>
Newsgroups gmane.comp.security.firewalls.netfilter.devel,gmane.linux.kernel,gmane.linux.network.bridge.ebtables.devel
Message-ID <[email protected]>
On Mon, 20 Jun 2005, Herbert Xu wrote:
> Patrick McHardy <[email protected]> wrote:
>>
>> The bridge-netfilter code defers calling of some NF_IP_* hooks to the
>> bridge layer, when the conntrack reference is already gone, so the entry
>
> Why does it defer them at all? Shouldn't the fact that the device is
> bridged be transparent to the IP layer?

I couldn't figure out the reason, it seems to have something to do
with setting up device pointers for iptables and ebtables. It looks
like the only way to fix this problem without keeping the conntrack
reference while packets are queued at the device is to avoid defering
the NF_IP_* hooks. Bart, can you explain why the hooks are defered
please?

Regards
Patrick
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.