Re: 2.6.12: connection tracking broken?
"David S. Miller" <[email protected]>
| Newsgroups | gmane.linux.kernel,gmane.comp.security.firewalls.netfilter.devel,gmane.linux.network.bridge.ebtables.devel |
|---|---|
| Message-ID | <[email protected]> |
From: Patrick McHardy <[email protected]> Date: Fri, 24 Jun 2005 10:39:08 +0200 > In 2.6.12 we started dropping the conntrack reference when a packet > leaves the IP layer. This broke connection tracking on a bridge, > because bridge-netfilter defers calling some NF_IP_* hooks to the bridge > layer for locally generated packets going out a bridge, where the > conntrack reference is no longer available. This patch keeps the > reference in this case as a temporary solution, long term we will > remove the defered hook calling. No attempt is made to drop the > reference in the bridge-code when it is no longer needed, tc actions > could already have sent the packet anywhere. Patch applied and pushed to [email protected] Thanks a lot.