netfilter-devel.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* [PATCH] ipv4: "conntrack zones" support for defrag user check in ip_expire
@ 2014-05-02 23:14 Vasily Averin
  2014-05-04 11:18 ` Pablo Neira Ayuso
  2014-05-05 14:07 ` Pablo Neira Ayuso
  0 siblings, 2 replies; 5+ messages in thread
From: Vasily Averin @ 2014-05-02 23:14 UTC (permalink / raw)
  To: Patrick McHardy
  Cc: Florian Westphal, netfilter-devel, netdev, Pablo Neira Ayuso,
	David S. Miller

Defrag user check in ip_expire was not updated after adding support for
"conntrack zones"

Signed-off-by: Vasily Averin <vvs@openvz.org>
---
 net/ipv4/ip_fragment.c |    5 +++--
 1 files changed, 3 insertions(+), 2 deletions(-)

diff --git a/net/ipv4/ip_fragment.c b/net/ipv4/ip_fragment.c
index c10a3ce..ed32313 100644
--- a/net/ipv4/ip_fragment.c
+++ b/net/ipv4/ip_fragment.c
@@ -232,8 +232,9 @@ static void ip_expire(unsigned long arg)
 		 * "Fragment Reassembly Timeout" message, per RFC792.
 		 */
 		if (qp->user == IP_DEFRAG_AF_PACKET ||
-		    (qp->user == IP_DEFRAG_CONNTRACK_IN &&
-		     skb_rtable(head)->rt_type != RTN_LOCAL))
+		    ((qp->user >= IP_DEFRAG_CONNTRACK_IN) &&
+		     (qp->user <= __IP_DEFRAG_CONNTRACK_IN_END) &&
+		     (skb_rtable(head)->rt_type != RTN_LOCAL)))
 			goto out_rcu_unlock;
 
 
-- 
1.7.5.4


^ permalink raw reply related	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2014-05-05 14:07 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2014-05-02 23:14 [PATCH] ipv4: "conntrack zones" support for defrag user check in ip_expire Vasily Averin
2014-05-04 11:18 ` Pablo Neira Ayuso
2014-05-04 12:58   ` Pablo Neira Ayuso
2014-05-04 18:28     ` David Miller
2014-05-05 14:07 ` Pablo Neira Ayuso

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).