From: Eric Dumazet <eric.dumazet@gmail.com>
To: "Zhu, Yi" <yi.zhu@intel.com>
Cc: andrew hendry <andrew.hendry@gmail.com>,
"netdev@vger.kernel.org" <netdev@vger.kernel.org>
Subject: RE: [PATCH 8/8] x25: use limited socket backlog
Date: Wed, 03 Mar 2010 15:33:01 +0100 [thread overview]
Message-ID: <1267626781.2997.28.camel@edumazet-laptop> (raw)
In-Reply-To: <DA586906BA1FFC4384FCFD6429ECE860A45A6992@shzsmsx502.ccr.corp.intel.com>
Le mercredi 03 mars 2010 à 22:00 +0800, Zhu, Yi a écrit :
> andrew hendry <andrew.hendry@gmail.com> wrote:
>
> > Will wait for the next spin and in the meantime think if there is way
> > to test it. x25 with no loopback and being so slow probably cant generate the same
> > as your UDP case.
>
> I didn't find a way to drop the packet correctly. So I didn't change any behavior in
> this patch. Nor did I do in the second spin. It will be fine if you also think x25 doesn't
> need to limit its backlog size.
So are we sure we cant flood X25 backlog, using X25 over IP ?
You discovered a _fatal_ flaw in backlog processing, we should close all
holes, not only UDP case. You can be sure many bad guys will inspect all
possibilities to bring down Linux hosts.
If you feel uncomfortable with a small limit, just stick a big one, like
256 packets, and you are 100% sure you wont break a protocol. If this
limit happens to be too small, we can change it later.
(No need to count bytes, since truesize includes kernel overhead, and
this overhead depends on 32/64 wide of host and kernel versions)
next prev parent reply other threads:[~2010-03-03 14:33 UTC|newest]
Thread overview: 21+ messages / expand[flat|nested] mbox.gz Atom feed top
2010-03-03 6:35 [PATCH 1/8] net: add limit for socket backlog Zhu Yi
2010-03-03 6:35 ` [PATCH 2/8] dccp: use limited " Zhu Yi
2010-03-03 6:35 ` [PATCH 3/8] tcp: " Zhu Yi
2010-03-03 6:35 ` [PATCH 4/8] udp: " Zhu Yi
2010-03-03 6:35 ` [PATCH 5/8] llc: " Zhu Yi
2010-03-03 6:35 ` [PATCH 6/8] sctp: " Zhu Yi
2010-03-03 6:35 ` [PATCH 7/8] tipc: " Zhu Yi
2010-03-03 6:35 ` [PATCH 8/8] x25: " Zhu Yi
2010-03-03 7:08 ` Eric Dumazet
2010-03-03 11:38 ` andrew hendry
2010-03-03 14:00 ` Zhu, Yi
2010-03-03 14:33 ` Eric Dumazet [this message]
2010-03-03 22:44 ` andrew hendry
2010-03-03 6:56 ` [PATCH 2/8] dccp: " Eric Dumazet
2010-03-03 7:43 ` Zhu Yi
2010-03-03 6:54 ` [PATCH 1/8] net: add limit for " Eric Dumazet
2010-03-03 7:35 ` Zhu Yi
2010-03-03 8:02 ` Eric Dumazet
2010-03-03 8:14 ` Zhu Yi
2010-03-03 8:47 ` Eric Dumazet
2010-03-03 8:59 ` Zhu Yi
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1267626781.2997.28.camel@edumazet-laptop \
--to=eric.dumazet@gmail.com \
--cc=andrew.hendry@gmail.com \
--cc=netdev@vger.kernel.org \
--cc=yi.zhu@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox