From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1753345AbcHNSDS (ORCPT ); Sun, 14 Aug 2016 14:03:18 -0400 Received: from shadbolt.e.decadent.org.uk ([88.96.1.126]:54980 "EHLO shadbolt.e.decadent.org.uk" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S932954AbcHNSAz (ORCPT ); Sun, 14 Aug 2016 14:00:55 -0400 Message-ID: <1471114295.13300.22.camel@decadent.org.uk> Subject: Re: [PATCH 3.16 289/305] netfilter: x_tables: validate targets of jumps From: Ben Hutchings To: Florian Westphal Cc: linux-kernel@vger.kernel.org, stable@vger.kernel.org, akpm@linux-foundation.org, Pablo Neira Ayuso , Greg Kroah-Hartman Date: Sat, 13 Aug 2016 19:51:35 +0100 In-Reply-To: <20160813183048.GA17154@breakpoint.cc> References: <20160813183048.GA17154@breakpoint.cc> Content-Type: multipart/signed; micalg="pgp-sha512"; protocol="application/pgp-signature"; boundary="=-dp3o8t7nQrpIUhxGd+yd" X-Mailer: Evolution 3.20.4-1 Mime-Version: 1.0 X-SA-Exim-Connect-IP: 92.40.248.79 X-SA-Exim-Mail-From: ben@decadent.org.uk X-SA-Exim-Scanned: No (on shadbolt.decadent.org.uk); SAEximRunCond expanded to false Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org --=-dp3o8t7nQrpIUhxGd+yd Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable On Sat, 2016-08-13 at 20:30 +0200, Florian Westphal wrote: > > Ben Hutchings wrote: > >=20 > > 3.16.37-rc1 review patch.=C2=A0=C2=A0If anyone has any objections, plea= se let me know. > >=20 > > ------------------ > >=20 > > > > From: Florian Westphal > >=20 > > commit 36472341017529e2b12573093cc0f68719300997 upstream. >=20 > [..] >=20 > >=20 > > The extra overhead is negible, even with absurd cases. >=20 > Not true, the overhead is huge and increases restore time for > large rulesets from mere seconds to minutes, see >=20 > https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?i= d=3Df4dc77713f8016d2e8a3295e1c9c53a21f296def So do you think I should add that to this update or defer the netfilter changes to the next update? Ben. --=20 Ben Hutchings Everything should be made as simple as possible, but not simpler. =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2= =A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0= =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2= =A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0= =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0- Albert Einstein --=-dp3o8t7nQrpIUhxGd+yd Content-Type: application/pgp-signature; name="signature.asc" Content-Description: This is a digitally signed message part -----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQIcBAABCgAGBQJXr2w3AAoJEOe/yOyVhhEJSjoP/2y50MwVrx5Cnlgp/+UvOxHR Q00KIPpQLlWv08OezRxD30JDx4mRp/NN9i68FxBGbbCDMQ1dOXILOWzPIiDicrDx eO2WJm1hlFM6Xs8QRG6Ve3BnLy/WW0Mr8/HBjuRRuladINDIhHw0qNT+zBfnJpp1 8mGb+dFLcd+f3oKkdJcca9EzWsbwguV4YC0mDbN/Z+2VZolg0tz/+P7V+roCB7Cg V/UuyG6DOkfTQ8W/q/9Y3a8NgZoyrZF60RrNthis9JfzP7aTHA/ymUct46SE2U8L m42eM465qhzZU1wjb4+FL9qnLt+T6PQfIL043IV1+tbSBkoe9l0neQVY1svjnnv/ rKwPaS/70KEAOhDYMFVFDPkfREYwnhp6usMukiFaOnooo/apCZMV8DAXaInQeu2R dEhQSdlnMlCIT1y79FIP7E3WdgnVUYrvVcy3bjw3aayUCmMGfXAZAEz0GA1Fb39e DtT6lSaCeS/q94A72vJB/CWhZw/E6ExtaZTybIuIUtU32PlCFajaGvkH4fgiT3Oj DSOyFTmFKxrnQ3PEp6oc6UuYmVJUtGsjuxPxTsQ05J4nwADsL896yHq1xyhm80ff JDadIpBpT9qlnLAnRZHDDYToQoLWvCfbpeCaEFp4SGmuFT4YQ5Mpsf2vTnUW3SYZ +Kms8R9Qj3cEfOOnWUQn =2Rvi -----END PGP SIGNATURE----- --=-dp3o8t7nQrpIUhxGd+yd--