From: Patrick McHardy <[EMAIL PROTECTED]> Date: Mon, 14 May 2007 12:21:34 +0200
> This allows any user to send spoofed packets when ip_nonlocal_bind > is set, which is a quite big change in behaviour of this option. > The TPROXY patches include a similar change, but use a flag in > struct flowi that requires CAP_NET_ADMIN to be set, which seems like > a better idea. Alternatively you could just use input routing for > non-local source addresses like ip_route_me_harder does. Good point. > BTW, there doesn't even seem to be a spot where IPVS calls > ip_route_output with the source address set. What exactly is this > needed for? I suppose he has a patch to make use of it, but was waiting for this route.c change to go in first. - To unsubscribe from this list: send the line "unsubscribe netdev" in the body of a message to [EMAIL PROTECTED] More majordomo info at http://vger.kernel.org/majordomo-info.html