From mboxrd@z Thu Jan 1 00:00:00 1970 From: Greg KH Subject: Re: [stable] [PATCH 1/2] netfilter: IPv6: initialize TOS field in REJECT target module Date: Tue, 14 Jun 2011 17:11:22 -0700 Message-ID: <20110615001122.GA1645@kroah.com> References: <1307320871-31770-1-git-send-email-pablo@netfilter.org> <20110606173623.GC7394@kroah.com> <1307414373.6576.25.camel@nexus.oss.ntt.co.jp> Mime-Version: 1.0 Content-Type: text/plain; charset=iso-8859-1 Content-Transfer-Encoding: QUOTED-PRINTABLE Cc: pablo@netfilter.org, stable@kernel.org, netfilter-devel@vger.kernel.org To: Fernando Luis =?iso-8859-1?Q?V=E1zquez?= Cao Return-path: Received: from out4.smtp.messagingengine.com ([66.111.4.28]:35342 "EHLO out4.smtp.messagingengine.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1753703Ab1FOAYC (ORCPT ); Tue, 14 Jun 2011 20:24:02 -0400 Content-Disposition: inline In-Reply-To: <1307414373.6576.25.camel@nexus.oss.ntt.co.jp> Sender: netfilter-devel-owner@vger.kernel.org List-ID: On Tue, Jun 07, 2011 at 11:39:33AM +0900, Fernando Luis V=E1zquez Cao w= rote: > On Mon, 2011-06-06 at 10:36 -0700, Greg KH wrote: > > On Mon, Jun 06, 2011 at 02:41:10AM +0200, pablo@netfilter.org wrote= : > > > From: Fernando Luis Vazquez Cao > > >=20 > > > The IPv6 header is not zeroed out in alloc_skb so we must initial= ize > > > it properly unless we want to see IPv6 packets with random TOS fi= elds > > > floating around. The current implementation resets the flow label > > > but this could be changed if deemed necessary. > > >=20 > > > We stumbled upon this issue when trying to apply a mangle rule to > > > the RST packet generated by the REJECT target module. > > >=20 > > > The following Linux kernels are affected: <=3D 2.6.38.8 > > >=20 > > > Cc: stable@kernel.org > > > Signed-off-by: Fernando Luis Vazquez Cao > > > Signed-off-by: Pablo Neira Ayuso > > > (cherry picked from commit 4319cc0cf5bb894b7368008cdf6dd20eb88680= 18) > >=20 > > So, what kernel(s) are you wanting this to be applied to? >=20 > Both patches fix bugs that have present from day one, so, ideally, I > would like to have them applied to all the stable and longterm kernel= s: >=20 > linux-2.6.38.8 > linux-2.6.37.6 > linux-2.6.36.4 > linux-2.6.35.13 > linux-2.6.34.9 > linux-2.6.33.14 > linux-2.6.32.41 > linux-2.6.27.59 >=20 > > Should I just take the upstream > > 4319cc0cf5bb894b7368008cdf6dd20eb8868018, or does your backport do > > something different here? >=20 > [PATCH 1/2] netfilter: IPv6: initialize TOS field in REJECT target mo= dule > For linux-2.6.38.8 you can take the upstream > 4319cc0cf5bb894b7368008cdf6dd20eb8868018. For linux-2.6.37.6, > linux-2.6.36.4, linux-2.6.35.13, linux-2.6.34.9, linux-2.6.33.14, > linux-2.6.32.41, and linux-2.6.27.59 you will need to use the attache= d > backport. Ok, but this doesn't apply at all to the 2.6.39-stable kernel. And .38-stable is end-of-life, as is .36-stable and .37-stable. So, care to start all over again? I need patches that apply to the .39-stable tree. And then to any other stable kernel that you wish to have them apply to= =2E Currently "live" kernels are .32-longterm, .33-longterm, .34-longterm, and .35-longterm. thanks, greg k-h -- To unsubscribe from this list: send the line "unsubscribe netfilter-dev= el" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html