From: Stephen Frost <sfrost@snowman.net>
To: Patrick McHardy <kaber@trash.net>,
Amin Azez <azez@ufomechanic.net>,
"David S. Miller" <davem@davemloft.net>,
willy@w.ods.org, gcoady.lk@gmail.com, laforge@netfilter.org,
netfilter-devel@lists.netfilter.org,
linux-kernel@vger.kernel.org, marcelo@kvack.org
Subject: Re: [PATCH] fix mem-leak in netfilter
Date: Mon, 15 May 2006 17:03:42 -0400 [thread overview]
Message-ID: <20060515210342.GP7774@kenobi.snowman.net> (raw)
In-Reply-To: <20060515204142.GO7774@kenobi.snowman.net>
[-- Attachment #1: Type: text/plain, Size: 1032 bytes --]
* Stephen Frost (sfrost@snowman.net) wrote:
> * Patrick McHardy (kaber@trash.net) wrote:
> > This is the updated patch, it changes the eviction strategy
> > to LRU and fixes a bug related to TTL handling, the TTL stored
> > in the entry should only be overwritten if the IPT_RECENT_TTL
> > flag is set.
>
> I thought that I had convinced myself that the TTL handling was okay and
> that where it was overwritten wasn't harmful. Oh well.
Looking at this again... The ttl isn't copied into 'ttl' unless the
check_set has TTL turned on. This means that the overwritting was fine,
if you accept that you can only ever match on TTL, or never match on it.
That doesn't seem right to me. The TTL in the table should always be
kept up-to-date and the only question is if the current rule requires it
for a match or not. This isn't a huge change, just set the local
variable always but check for if it's asked to match before calling the
lookup. Or you could move it into an if/else block.
Thanks,
Stephen
[-- Attachment #2: Digital signature --]
[-- Type: application/pgp-signature, Size: 189 bytes --]
next prev parent reply other threads:[~2006-05-15 21:03 UTC|newest]
Thread overview: 32+ messages / expand[flat|nested] mbox.gz Atom feed top
2006-05-07 2:26 Jesper Juhl
2006-05-07 9:36 ` Willy Tarreau
2006-05-07 22:42 ` Grant Coady
2006-05-08 5:07 ` Willy Tarreau
2006-05-08 5:43 ` David S. Miller
2006-05-08 8:36 ` Amin Azez
2006-05-08 9:08 ` Juergen Kreileder
2006-05-12 7:40 ` Patrick McHardy
2006-05-12 11:09 ` Jesper Juhl
2006-05-12 11:33 ` Patrick McHardy
2006-05-12 12:13 ` Jesper Juhl
2006-05-12 12:40 ` Willy Tarreau
2006-05-12 12:49 ` Patrick McHardy
[not found] ` <446490BB.10801@ufomechanic.net>
2006-05-15 8:25 ` Patrick McHardy
2006-05-15 14:28 ` Stephen Frost
2006-05-15 18:49 ` Patrick McHardy
2006-05-15 19:27 ` Stephen Frost
2006-05-15 20:09 ` Patrick McHardy
2006-05-15 20:41 ` Stephen Frost
2006-05-15 20:45 ` Patrick McHardy
2006-05-15 21:03 ` Stephen Frost [this message]
2006-05-17 6:26 ` Patrick McHardy
2006-05-17 6:59 ` David S. Miller
2006-05-17 7:19 ` Patrick McHardy
2006-05-17 10:55 ` Stephen Frost
2006-05-17 7:09 ` David S. Miller
2006-05-17 7:13 ` Roland Dreier
2006-05-17 7:19 ` Patrick McHardy
2006-05-17 13:14 ` Stephen Frost
2006-06-01 13:43 ` Andrew James Wade
2006-06-01 14:53 ` Patrick McHardy
2006-06-02 21:32 ` Andrew James Wade
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20060515210342.GP7774@kenobi.snowman.net \
--to=sfrost@snowman.net \
--cc=azez@ufomechanic.net \
--cc=davem@davemloft.net \
--cc=gcoady.lk@gmail.com \
--cc=kaber@trash.net \
--cc=laforge@netfilter.org \
--cc=linux-kernel@vger.kernel.org \
--cc=marcelo@kvack.org \
--cc=netfilter-devel@lists.netfilter.org \
--cc=willy@w.ods.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®