summaryrefslogtreecommitdiff
path: root/firmware
diff options
context:
space:
mode:
authorPablo Neira Ayuso <pablo@netfilter.org>2012-08-29 20:25:49 +0400
committerPablo Neira Ayuso <pablo@netfilter.org>2012-08-31 17:50:28 +0400
commit5b423f6a40a0327f9d40bc8b97ce9be266f74368 (patch)
treef71b7726f6501993bc7be9d4d7e6e69d7cd095b2 /firmware
parent3f509c689a07a4aa989b426893d8491a7ffcc410 (diff)
downloadlinux-5b423f6a40a0327f9d40bc8b97ce9be266f74368.tar.xz
netfilter: nf_conntrack: fix racy timer handling with reliable events
Existing code assumes that del_timer returns true for alive conntrack entries. However, this is not true if reliable events are enabled. In that case, del_timer may return true for entries that were just inserted in the dying list. Note that packets / ctnetlink may hold references to conntrack entries that were just inserted to such list. This patch fixes the issue by adding an independent timer for event delivery. This increases the size of the ecache extension. Still we can revisit this later and use variable size extensions to allocate this area on demand. Tested-by: Oliver Smith <olipro@8.c.9.b.0.7.4.0.1.0.0.2.ip6.arpa> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Diffstat (limited to 'firmware')
0 files changed, 0 insertions, 0 deletions