Re: [ovs-dev] [PATCH] datapath: Use pre-routing hook for conntrack.

2016-09-09 Thread Jesse Gross
On Fri, Sep 9, 2016 at 2:37 PM, Joe Stringer wrote: > On 8 September 2016 at 08:49, Jesse Gross wrote: >> On Wed, Sep 7, 2016 at 5:18 PM, Joe Stringer wrote: >>> On 1 September 2016 at 18:08, Jesse Gross wrote: On Thu, Sep 1,

Re: [ovs-dev] [PATCH] datapath: Use pre-routing hook for conntrack.

2016-09-09 Thread Joe Stringer
On 8 September 2016 at 08:49, Jesse Gross wrote: > On Wed, Sep 7, 2016 at 5:18 PM, Joe Stringer wrote: >> On 1 September 2016 at 18:08, Jesse Gross wrote: >>> On Thu, Sep 1, 2016 at 5:01 PM, Joe Stringer wrote: The upstream

Re: [ovs-dev] [PATCH] datapath: Use pre-routing hook for conntrack.

2016-09-08 Thread Jesse Gross
On Wed, Sep 7, 2016 at 5:18 PM, Joe Stringer wrote: > On 1 September 2016 at 18:08, Jesse Gross wrote: >> On Thu, Sep 1, 2016 at 5:01 PM, Joe Stringer wrote: >>> The upstream code uses NF_INET_PRE_ROUTING hook for the nf_conntrack_in() >>> call,

Re: [ovs-dev] [PATCH] datapath: Use pre-routing hook for conntrack.

2016-09-07 Thread Joe Stringer
On 1 September 2016 at 18:08, Jesse Gross wrote: > On Thu, Sep 1, 2016 at 5:01 PM, Joe Stringer wrote: >> The upstream code uses NF_INET_PRE_ROUTING hook for the nf_conntrack_in() >> call, which does deeper (eg l4proto) validation. It was previously >> thought

Re: [ovs-dev] [PATCH] datapath: Use pre-routing hook for conntrack.

2016-09-01 Thread Jesse Gross
On Thu, Sep 1, 2016 at 5:01 PM, Joe Stringer wrote: > The upstream code uses NF_INET_PRE_ROUTING hook for the nf_conntrack_in() > call, which does deeper (eg l4proto) validation. It was previously > thought that using the NF_INET_ROUTING hook for this function on older > kernels

[ovs-dev] [PATCH] datapath: Use pre-routing hook for conntrack.

2016-09-01 Thread Joe Stringer
The upstream code uses NF_INET_PRE_ROUTING hook for the nf_conntrack_in() call, which does deeper (eg l4proto) validation. It was previously thought that using the NF_INET_ROUTING hook for this function on older kernels would trigger kernel panics due to a dependency on the unpopulated skb->dev,