• Sebastian Pöhn's avatar
    ip_forward: Drop frames with attached skb->sk · 2ab95749
    Sebastian Pöhn authored
    Initial discussion was:
    [FYI] xfrm: Don't lookup sk_policy for timewait sockets
    
    Forwarded frames should not have a socket attached. Especially
    tw sockets will lead to panics later-on in the stack.
    
    This was observed with TPROXY assigning a tw socket and broken
    policy routing (misconfigured). As a result frame enters
    forwarding path instead of input. We cannot solve this in
    TPROXY as it cannot know that policy routing is broken.
    
    v2:
    Remove useless comment
    Signed-off-by: default avatarSebastian Poehn <sebastian.poehn@gmail.com>
    Signed-off-by: default avatarDavid S. Miller <davem@davemloft.net>
    2ab95749
ip_forward.c 3.84 KB