Re: Re: [Ebtables-user] bridge/ebtables interaction...
Bart De Schuymer <[email protected]>
| Newsgroups | gmane.linux.network.bridge.ebtables.devel |
|---|---|
| Message-ID | <[email protected]> |
Op wo, 25-05-2005 te 14:43 -0700, schreef Stephen Hemminger:
> This is the patch I am testing now, does it do what you want?
>
> Index: bridge/net/bridge/br_input.c
> ===================================================================
> --- bridge.orig/net/bridge/br_input.c
> +++ bridge/net/bridge/br_input.c
> @@ -54,6 +54,9 @@ int br_handle_frame_finish(struct sk_buf
> struct net_bridge_fdb_entry *dst;
> int passedup = 0;
>
> + /* insert into forwarding database after filtering to avoid spoofing */
> + br_fdb_update(p->br, p, eth_hdr(skb)->h_source);
> +
> if (br->dev->flags & IFF_PROMISC) {
> struct sk_buff *skb2;
>
> @@ -108,8 +111,7 @@ int br_handle_frame(struct net_bridge_po
> if (!is_valid_ether_addr(eth_hdr(skb)->h_source))
> goto err;
>
> - if (p->state == BR_STATE_LEARNING ||
> - p->state == BR_STATE_FORWARDING)
> + if (p->state == BR_STATE_LEARNING)
> br_fdb_update(p->br, p, eth_hdr(skb)->h_source);
>
> if (p->br->stp_enabled &&
Hi Stephen,
I was wondering what happened to the plan to postpone fdb updates until
after the PF_BRIDGE/PRE_ROUTING hook. Looking in the current
net/bridge/br_input.c I don't see any changes.
Did you decide not to do this after all?
cheers,
Bart
-------------------------------------------------------
SF.Net email is Sponsored by the Better Software Conference & EXPO
September 19-22, 2005 * San Francisco, CA * Development Lifecycle Practices
Agile & Plan-Driven Development * Managing Projects & Teams * Testing & QA
Security * Process Improvement & Measurement * http://www.sqe.com/bsce5sf