From mboxrd@z Thu Jan 1 00:00:00 1970 From: Patrick McHardy Subject: Re: [PATCH] ip6tables: use skb->len for accounting Date: Fri, 23 Jul 2010 13:48:02 +0200 Message-ID: <4C498172.40404@trash.net> References: <1279855877-8945-1-git-send-email-xiaosuo@gmail.com> Mime-Version: 1.0 Content-Type: text/plain; charset=ISO-8859-15 Content-Transfer-Encoding: 7bit Cc: Jan Engelhardt , "David S. Miller" , Alexey Kuznetsov , "Pekka Savola (ipv6)" , James Morris , Hideaki YOSHIFUJI , netfilter-devel@vger.kernel.org, netdev@vger.kernel.org To: Changli Gao Return-path: Received: from stinky.trash.net ([213.144.137.162]:36228 "EHLO stinky.trash.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1754433Ab0GWLr5 (ORCPT ); Fri, 23 Jul 2010 07:47:57 -0400 In-Reply-To: Sender: netfilter-devel-owner@vger.kernel.org List-ID: On 23.07.2010 08:38, Changli Gao wrote: > On Fri, Jul 23, 2010 at 2:16 PM, Jan Engelhardt wrote: >> >> >> I wonder how this fares with trailing padding or data, like, when >> you have a standard v4/v6 packet created in a raw socket, and append >> a bunch of \0s to it. >> >> > > For the packets received, ip_rcv, ipv6_rcv and bridge all call > pskb_trim_rcsum before feeding them to netfilter. The raw packets are > sent via dev_queue_xmit(), and they don't pass through the output path > of netfilter. That's not true, raw packets also pass through netfilter. However I agree that this patch makes sense to properly deal with jumbo frames, but you should also update xt_length for consistency.