All of lore.kernel.org
 help / color / mirror / Atom feed
* [RFC] TTL target goes mainline ?
@ 2005-08-26 11:18 Harald Welte
  2005-08-26 11:43 ` Patrick McHardy
                   ` (2 more replies)
  0 siblings, 3 replies; 9+ messages in thread
From: Harald Welte @ 2005-08-26 11:18 UTC (permalink / raw)
  To: Netfilter Development Mailinglist

[-- Attachment #1: Type: text/plain, Size: 1263 bytes --]

Hi!

As we are in the process of pushing more 'new' code from
patch-o-matic-ng into the mainline kernel, I was thinking whether or not
we should also submit potentially-dangerous targets such as the TTL
target to the kernel.

The TTL target allows setting, incrementing and decrementing of the TTL,
and is therefore extremely dangerous. OTOTH, there are ISP's that check
whether you use a router or not (and thus filter or not) by looking at
the TTL of every packet that comes in on your link - so there is a
practical use of this to a number of people.

At some point the kernel had a CONFIG_DANGEROUS, but that had been
removed. I think CONFIG_DANGEROUS would be exactly the right thing for
TTL manipulations.

So my proposal is to only allow decrementing (or setting to a value
below the original one) the TTL unless CONFIG_EXPERIMENTAL is set. 

What do you think?

-- 
- Harald Welte <laforge@netfilter.org>                 http://netfilter.org/
============================================================================
  "Fragmentation is like classful addressing -- an interesting early
   architectural error that shows how much experimentation was going
   on while IP was being designed."                    -- Paul Vixie

[-- Attachment #2: Type: application/pgp-signature, Size: 189 bytes --]

^ permalink raw reply	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2005-08-26 19:20 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2005-08-26 11:18 [RFC] TTL target goes mainline ? Harald Welte
2005-08-26 11:43 ` Patrick McHardy
2005-08-26 13:19   ` Harald Welte
2005-08-26 13:41     ` Patrick McHardy
2005-08-26 15:16       ` Phil Oester
2005-08-26 15:24         ` Patrick McHardy
2005-08-26 19:20           ` David S. Miller
2005-08-26 12:10 ` Bill Rugolsky Jr.
2005-08-26 17:27 ` Maciej Soltysiak

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.