From mboxrd@z Thu Jan 1 00:00:00 1970 From: David Miller Subject: Re: [PATCH net-next-2.6] ipv6: make fragment identifications less predictable Date: Thu, 21 Jul 2011 17:07:03 -0700 (PDT) Message-ID: <20110721.170703.195266775134111762.davem@davemloft.net> References: <4E2781A2.8020905@gont.com.ar> <20110721.151750.995903739612693126.davem@davemloft.net> <4E28B84C.2090305@gont.com.ar> Mime-Version: 1.0 Content-Type: Text/Plain; charset=us-ascii Content-Transfer-Encoding: 7bit Cc: eric.dumazet@gmail.com, security@kernel.org, eugeneteo@kernel.sg, netdev@vger.kernel.org, mpm@selenic.com To: fernando@gont.com.ar Return-path: Received: from shards.monkeyblade.net ([198.137.202.13]:45732 "EHLO shards.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1752976Ab1GVAHw (ORCPT ); Thu, 21 Jul 2011 20:07:52 -0400 In-Reply-To: <4E28B84C.2090305@gont.com.ar> Sender: netdev-owner@vger.kernel.org List-ID: From: Fernando Gont Date: Thu, 21 Jul 2011 20:37:48 -0300 > While I haven't had a chance to look at the patch yet, I was wondering > whether it defines both a separe "offset" and "counter" for each "flow". Why wonder, just take a look. If you aren't willing to even bother looking at the solution we came up with, why should we feel compelled to spend any time at all looking at your "anaylsis" and "concerns"?