login
Header Space

 
 

Re: sockets affected by IPsec always block (2.6.23)

Score:
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: <herbert@...>
Cc: <simon@...>, <linux-kernel@...>, <netdev@...>
Date: Wednesday, December 5, 2007 - 3:12 am

From: Herbert Xu <herbert@gondor.apana.org.au>
Date: Wed, 5 Dec 2007 17:51:32 +1100


I bet there are UDP apps out there that would break if we
didn't do this.

Actually, consider even a case like DNS.  Let's say the timeout
is set to 2 seconds or something and you have 3 DNS servers
listed, on different IPSEC destinations, in your resolv.conf

Each IPSEC route that isn't currently resolved will cause packet loss
of the DNS lookup request with xfrm_larval_drop set to '1'.

If all 3 need to be resolved, the DNS lookup will fully fail
which defeats the purpose of listing 3 servers for redundancy
don't you think? :-)

As much as I even personally prefer the xfrm_larval_drop=1
behavior, it cases like above that keep me from jumping at
making it the default.

Arguably, potentially blocking forever (which is what can easily
happen with xfrm_larval_drop=0 if your IPSEC daemon cannot resolve the
IPSEC path for whatever reason) is worse than the above, but the
other cases are still something to consider as well.
--
To unsubscribe from this list: send the line "unsubscribe netdev" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
sockets affected by IPsec always block (2.6.23), Simon Arlott, (Tue Dec 4, 2:53 pm)
Re: sockets affected by IPsec always block (2.6.23), Herbert Xu, (Tue Dec 4, 8:12 pm)
Re: sockets affected by IPsec always block (2.6.23), David Miller, (Wed Dec 5, 2:30 am)
Re: sockets affected by IPsec always block (2.6.23), Herbert Xu, (Wed Dec 5, 2:51 am)
Re: sockets affected by IPsec always block (2.6.23), Stefan Rompf, (Wed Dec 5, 2:39 pm)
Re: sockets affected by IPsec always block (2.6.23), David Miller, (Wed Dec 5, 10:25 pm)
Re: sockets affected by IPsec always block (2.6.23), Stefan Rompf, (Thu Dec 6, 4:49 am)
Re: sockets affected by IPsec always block (2.6.23), David Miller, (Thu Dec 6, 4:53 am)
Re: sockets affected by IPsec always block (2.6.23), Stefan Rompf, (Thu Dec 6, 6:56 am)
Re: sockets affected by IPsec always block (2.6.23), David Miller, (Thu Dec 6, 7:13 am)
Re: sockets affected by IPsec always block (2.6.23), Stefan Rompf, (Thu Dec 6, 7:35 am)
Re: sockets affected by IPsec always block (2.6.23), David Miller, (Thu Dec 6, 7:39 am)
Re: sockets affected by IPsec always block (2.6.23), Stefan Rompf, (Thu Dec 6, 8:30 am)
Re: sockets affected by IPsec always block (2.6.23), David Miller, (Thu Dec 6, 9:55 am)
Re: sockets affected by IPsec always block (2.6.23), Stefan Rompf, (Thu Dec 6, 10:31 am)
Re: sockets affected by IPsec always block (2.6.23), David Miller, (Thu Dec 6, 11:20 pm)
Re: sockets affected by IPsec always block (2.6.23), Stefan Rompf, (Fri Dec 7, 5:29 am)
Re: sockets affected by IPsec always block (2.6.23), David Miller, (Wed Dec 5, 3:12 am)
Re: sockets affected by IPsec always block (2.6.23), Stefan Rompf, (Wed Dec 5, 2:42 pm)
Re: sockets affected by IPsec always block (2.6.23), Herbert Xu, (Wed Dec 5, 3:16 am)
Re: sockets affected by IPsec always block (2.6.23), David Miller, (Wed Dec 5, 3:34 am)
Re: sockets affected by IPsec always block (2.6.23), Herbert Xu, (Wed Dec 5, 3:39 am)
Re: sockets affected by IPsec always block (2.6.23), David Miller, (Wed Dec 5, 5:55 am)
Re: sockets affected by IPsec always block (2.6.23), Herbert Xu, (Wed Dec 5, 5:57 am)
Re: sockets affected by IPsec always block (2.6.23), David Miller, (Wed Dec 5, 2:06 am)
speck-geostationary