summaryrefslogtreecommitdiff
path: root/share
diff options
context:
space:
mode:
authorDavid Gwynne <dlg@cvs.openbsd.org>2021-01-08 23:31:54 +0000
committerDavid Gwynne <dlg@cvs.openbsd.org>2021-01-08 23:31:54 +0000
commit8fb065238b33f4eda8a03d659c747260ef3feaee (patch)
tree8e1ee49e045a577264b3eb9e9732c18d8cf2286a /share
parent0b2d6f595cf94785123d7e1c5fe2b3fe264263cd (diff)
don't check local carp addresses as part of the antispoof checks.
bridge(4) drops packets coming from somewhere else that have a source MAC address that's owned by one of the interfaces that's a member of the bridge. because this check was done with bridge_ourether, it included the addresses of active carp interfaces hanging off these member interfaces. this meant if the local machine is the carp master while another machine is trying to preempt it by sending hellos, the packets from the other machine were dropped because the local one is already the master. carp roles are supposed to move around a l2 network, so another host sending a packet with a carp mac address is actually normal and necessary. found by and fix tested by stsp@ ok stsp@ claudio@
Diffstat (limited to 'share')
0 files changed, 0 insertions, 0 deletions