Re: 2.6.12: connection tracking broken?
Bart De Schuymer <[email protected]>
| Newsgroups | gmane.linux.network.bridge.ebtables.devel,gmane.comp.security.firewalls.netfilter.devel,gmane.linux.kernel |
|---|---|
| Message-ID | <[email protected]> |
Op di, 21-06-2005 te 17:16 +0200, schreef Patrick McHardy: > I unfortunately don't see a way to remove it, but we should keep > thinking about it. Can you please check if the attached patch is > correct? It should exclude all packets handled by bridge-netfilter > from having their conntrack reference dropped. I didn't add nf_reset()'s > to the bridging code because with tc actions the packets can end up > anywhere else anyway, and this will hopefully get fixed right sometime. Looks good. Perhaps a compile time option to disable postponing the hooks would be nice... > BTW. this line from ip_sabotage_out() looks wrong, it will clear all > flags instead of setting the BRNF_DONT_TAKE_PARENT flag (second > patch): > > nf_bridge->mask &= BRNF_DONT_TAKE_PARENT; Thanks, Bart ------------------------------------------------------- SF.Net email is sponsored by: Discover Easy Linux Migration Strategies from IBM. Find simple to follow Roadmaps, straightforward articles, informative Webcasts and more! Get everything you need to get up to speed, fast. http://ads.osdn.com/?ad_id=7477&alloc_id=16492&op=click