From: Patrick McHardy <kaber@trash.net>
To: Santiago Garcia Mantinan <netfilter-devel@manty.net>
Cc: Chris Rankin <rankincj@yahoo.com>,
netfilter-devel@lists.netfilter.org,
linux-kernel@vger.kernel.org,
ebtables-devel@lists.sourceforge.net
Subject: Re: 2.6.12: connection tracking broken?
Date: Sun, 19 Jun 2005 15:05:31 +0200 [thread overview]
Message-ID: <42B56D9B.9070401@trash.net> (raw)
In-Reply-To: <20050618221216.GB3182@pul.manty.net>
Santiago Garcia Mantinan wrote:
>>I have sent this right now to the bridge list, I'm copying it here so that
>>more info is available about this bug.
>
>
> I have selected patches from 2.6.12 that I thought could be related to this
> issue, and I have finaly identified this patch...
>
> http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=b31e5b1bb53b99dfd5e890aa07e943aff114ae1c
>
> as the patch causing the problem, I have reversed it on my kernel tree and
> now the firewall is working again.
>
> I have not really looked at what the patch does and how it does that, I have
> just identified it as the one causing the break of this connection tracking
> relating to the bridges.
The patch drops the conntrack reference when a packet leaves IP to avoid
problems with module unload because of indefinitely queued packets.
The bridge-netfilter code defers calling of some NF_IP_* hooks to the
bridge layer, when the conntrack reference is already gone, so the entry
is neither confirmed (enters the hashtable) nor available for use by
matches or targets. Reverting the patch is not a good option, I'll look
into other possiblities.
Regards
Patrick
next prev parent reply other threads:[~2005-06-19 13:05 UTC|newest]
Thread overview: 40+ messages / expand[flat|nested] mbox.gz Atom feed top
2005-06-18 12:43 2.6.12: connection tracking broken? Chris Rankin
2005-06-18 14:57 ` Jan Engelhardt
2005-06-18 15:14 ` Tobias DiPasquale
2005-06-18 17:16 ` Chris Rankin
2005-06-20 7:19 ` Harald Welte
2005-06-18 19:25 ` Santiago Garcia Mantinan
2005-06-18 22:12 ` Santiago Garcia Mantinan
2005-06-19 13:05 ` Patrick McHardy [this message]
2005-06-20 0:05 ` Herbert Xu
2005-06-20 0:18 ` David S. Miller
2005-06-20 0:50 ` Herbert Xu
2005-06-20 2:45 ` Patrick McHardy
2005-06-20 6:39 ` Bart De Schuymer
2005-06-20 12:15 ` Patrick McHardy
2005-06-20 18:46 ` Bart De Schuymer
2005-06-20 18:57 ` Phil Oester
2005-06-20 23:27 ` Patrick McHardy
2005-06-20 23:22 ` Patrick McHardy
2005-06-21 7:19 ` Bart De Schuymer
2005-06-21 15:16 ` Patrick McHardy
2005-06-21 20:46 ` Bart De Schuymer
2005-06-21 21:23 ` Chris Wright
2005-06-21 22:32 ` David S. Miller
2005-06-21 22:34 ` Chris Wright
2005-06-22 0:26 ` Patrick McHardy
2005-06-22 22:58 ` Chris Rankin
2005-06-23 17:42 ` Patrick McHardy
2005-06-23 19:49 ` David S. Miller
2005-06-24 8:39 ` Patrick McHardy
2005-06-28 23:07 ` David S. Miller
2005-06-22 0:45 ` Patrick McHardy
2005-06-22 21:49 ` Herbert Xu
2005-06-23 0:02 ` Carl-Daniel Hailfinger
2005-06-23 3:31 ` Patrick McHardy
2005-06-23 6:27 ` [Ebtables-devel] " Bart De Schuymer
2005-06-23 3:26 ` Patrick McHardy
2005-06-23 3:53 ` Herbert Xu
2005-06-23 6:23 ` Bart De Schuymer
2005-06-27 8:32 ` Harald Welte
2005-06-27 11:46 ` Patrick McHardy
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=42B56D9B.9070401@trash.net \
--to=kaber@trash.net \
--cc=ebtables-devel@lists.sourceforge.net \
--cc=linux-kernel@vger.kernel.org \
--cc=netfilter-devel@lists.netfilter.org \
--cc=netfilter-devel@manty.net \
--cc=rankincj@yahoo.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox