All of lore.kernel.org
 help / color / mirror / Atom feed
From: Pablo Neira <pablo@eurodev.net>
To: Patrick McHardy <kaber@trash.net>
Cc: Netfilter Development Mailinglist
	<netfilter-devel@lists.netfilter.org>,
	Jozsef Kadlecsik <kadlec@blackhole.kfki.hu>
Subject: Re: [RFC][PATCH] kill the fake conntrack
Date: Sat, 25 Jun 2005 15:12:09 +0200	[thread overview]
Message-ID: <42BD5829.4030002@eurodev.net> (raw)
In-Reply-To: <42BD52A7.2090107@trash.net>

Patrick McHardy wrote:
> Pablo Neira wrote:
> 
>>The patch attached kills the fake conntrack and propose a new logic to
>>explicitely set connection as untracked. We set nfct to NULL and use a
>>new flag called IP_CT_UNTRACKED for nfctinfo. I've slightely tested it
>>here and works fine.
>>
>>Comments welcome.
> 
> What is the advantage of this patch?

Whenever we work with conntracks, we always have to check if it's the 
fake or not previously. For example, a bad use of NOTRACK together with 
other targets, say ipt_CONNMARK, that doesn't currently check if it's 
working with the fake conntrack or not. Same thing for NAT handlings, I 
see that this can result in weirdness.

Setting nfct to NULL will make NAT targets, conntrack helpers and 
friends just ignore untracked packets, so we could forget about making 
sure that we aren't messing with the fake conntrack.

> Its changing the assumption
> that skb->nfctinfo is only valid if skb->nfct is set, so you probably
> need to set nfctinfo to 0 in nf_reset as well. This alone is a reason
> not to do it IMO.

why need to set nfctinfo to 0 in nf_reset? since skb->nfct is NULL 
nf_reset shouldn't be ever called. With the logic I'm proposing, this 
packet will be handle just like invalid ones, so it will be just ignored.

--
Pablo

  reply	other threads:[~2005-06-25 13:12 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2005-06-25 12:42 [RFC][PATCH] kill the fake conntrack Pablo Neira
2005-06-25 12:48 ` Patrick McHardy
2005-06-25 13:12   ` Pablo Neira [this message]
2005-06-25 13:20     ` Pablo Neira
2005-06-25 13:29     ` Patrick McHardy
2005-06-25 18:47       ` Pablo Neira
2005-06-25 19:00         ` Patrick McHardy
2005-08-28 12:05           ` Harald Welte

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=42BD5829.4030002@eurodev.net \
    --to=pablo@eurodev.net \
    --cc=kaber@trash.net \
    --cc=kadlec@blackhole.kfki.hu \
    --cc=netfilter-devel@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.