On 15 Apr 2021, at 15:25, David Marchand wrote:
On Thu, Apr 15, 2021 at 1:45 PM Flavio Leitner
wrote:
+COVERAGE_DEFINE(ipv4_check_too_short);
+COVERAGE_DEFINE(ipv4_check_length_error);
+COVERAGE_DEFINE(ipv6_check_too_short);
+COVERAGE_DEFINE(ipv6_check_length_error);
The check keyword is a
On Thu, Apr 15, 2021 at 1:12 PM Flavio Leitner wrote:
> > > +static void
> > > +dump_invalid_packet(struct dp_packet *packet, const char *reason)
> > > +{
> > > +static struct vlog_rate_limit rl = VLOG_RATE_LIMIT_INIT(1, 5);
> > > +struct ds ds = DS_EMPTY_INITIALIZER;
> > > +size_t siz
On Thu, Apr 15, 2021 at 1:45 PM Flavio Leitner wrote:
> > > > > +COVERAGE_DEFINE(ipv4_check_too_short);
> > > > > +COVERAGE_DEFINE(ipv4_check_length_error);
> > > > > +COVERAGE_DEFINE(ipv6_check_too_short);
> > > > > +COVERAGE_DEFINE(ipv6_check_length_error);
> > > >
> > > > The check keyword is a
On Thu, Apr 15, 2021 at 01:32:06PM +0200, Eelco Chaudron wrote:
>
>
> On 15 Apr 2021, at 13:12, Flavio Leitner wrote:
>
> > Hi Eelco,
> >
> > On Thu, Apr 15, 2021 at 10:07:24AM +0200, Eelco Chaudron wrote:
> > >
> > >
> > > On 14 Apr 2021, at 17:50, David Marchand wrote:
> > >
> > > > Skippi
On 15 Apr 2021, at 13:12, Flavio Leitner wrote:
Hi Eelco,
On Thu, Apr 15, 2021 at 10:07:24AM +0200, Eelco Chaudron wrote:
On 14 Apr 2021, at 17:50, David Marchand wrote:
Skipping further processing of invalid IP packets helps avoid
crashes
but it does not help to figure out if the malfor
Hi Eelco,
On Thu, Apr 15, 2021 at 10:07:24AM +0200, Eelco Chaudron wrote:
>
>
> On 14 Apr 2021, at 17:50, David Marchand wrote:
>
> > Skipping further processing of invalid IP packets helps avoid crashes
> > but it does not help to figure out if the malformed packets are still
> > present on t
On 14 Apr 2021, at 17:50, David Marchand wrote:
Skipping further processing of invalid IP packets helps avoid crashes
but it does not help to figure out if the malformed packets are still
present on the network.
Add coverage counters for IPv4 and IPv6 sanity checks so that we know
there are s
Skipping further processing of invalid IP packets helps avoid crashes
but it does not help to figure out if the malformed packets are still
present on the network.
Add coverage counters for IPv4 and IPv6 sanity checks so that we know
there are some invalid packets.
Dump such whole packets in debu