From: Patrick McHardy <kaber@trash.net>
To: Henrik Nordstrom <hno@marasystems.com>
Cc: netfilter-devel@lists.netfilter.org
Subject: Re: [PATCH 2.6 0/12]: netfilter update
Date: Sun, 26 Sep 2004 23:56:21 +0200 [thread overview]
Message-ID: <41573B05.1000308@trash.net> (raw)
In-Reply-To: <Pine.LNX.4.61.0409262344030.7439@filer.marasystems.com>
Henrik Nordstrom wrote:
> On Sun, 26 Sep 2004, Patrick McHardy wrote:
>
>> Unfortunately I have to agree with you, another set of hooks looks
>> like the only way to solve the race. Let me think some more about
>> the implications for iptables and ip_conntrack.
>
>
> conntrack should not see this new hook.
We confirm conntrack entries in LOCAL_IN after they passed all hooks,
but this new set of hooks would be after LOCAL_IN, so conntrack entries
should be confirmed there.
>
> what do do in iptables is a question.. as it is yet another step in
> the packet processing it calls for a new builtin chain I think.
I agree. But I wonder if its worth it just for having the owner match
work in the input path, or if there are other uses for these hooks.
Regards
Patrick
next prev parent reply other threads:[~2004-09-26 21:56 UTC|newest]
Thread overview: 11+ messages / expand[flat|nested] mbox.gz Atom feed top
2004-09-21 3:20 [PATCH 2.6 0/12]: netfilter update Patrick McHardy
2004-09-21 21:36 ` David S. Miller
2004-09-21 23:38 ` Patrick McHardy
2004-09-22 0:18 ` David S. Miller
2004-09-22 1:42 ` Patrick McHardy
2004-09-24 22:40 ` David S. Miller
2004-09-26 19:43 ` Patrick McHardy
2004-09-26 21:45 ` Henrik Nordstrom
2004-09-26 21:56 ` Patrick McHardy [this message]
2004-09-26 22:08 ` Henrik Nordstrom
2004-09-26 23:19 ` Patrick McHardy
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=41573B05.1000308@trash.net \
--to=kaber@trash.net \
--cc=hno@marasystems.com \
--cc=netfilter-devel@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.