Bug#923880: ssh: IPQoS defaults change interacts badly with iptables -m tos

2019-08-08 Thread Peter Lebbing
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 > We can make it more concrete. Let's create an iptables rule with > numerical values that matches DSCP CS6, which corresponds to IP > Precendence 6, numerical value 0xC0, where in the terms of RFC 1349 bits > 0 and 1 are set in the PRECEDENCE portio

Bug#923880: ssh: IPQoS defaults change interacts badly with iptables -m tos

2019-08-08 Thread Peter Lebbing
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Wed, 6 Mar 2019 18:15:41 +0100 Helmut Grohne wrote: > This suggests that iptables' ECN mask is wrong. It should be using > 0xfc rather than 0x3f. Yes, I'm convinced the mask is wrong. However, fixing that would change the behaviour of already de