Re: [PATCH nf v2] netfilter: conntrack: allow sctp hearbeat after connection re-use

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Tue, Aug 18, 2020 at 04:15:58PM +0200, Florian Westphal wrote:
> If an sctp connection gets re-used, heartbeats are flagged as invalid
> because their vtag doesn't match.
> 
> Handle this in a similar way as TCP conntrack when it suspects that the
> endpoints and conntrack are out-of-sync.
> 
> When a HEARTBEAT request fails its vtag validation, flag this in the
> conntrack state and accept the packet.
> 
> When a HEARTBEAT_ACK is received with an invalid vtag in the reverse
> direction after we allowed such a HEARTBEAT through, assume we are
> out-of-sync and re-set the vtag info.
> 
> v2: remove left-over snippet from an older incarnation that moved
>     new_state/old_state assignments, thats not needed so keep that
>     as-is.

Applied, thanks.



[Index of Archives]     [Netfitler Users]     [Berkeley Packet Filter]     [LARTC]     [Bugtraq]     [Yosemite Forum]

  Powered by Linux