summaryrefslogtreecommitdiff
path: root/usr.sbin/ldomd
diff options
context:
space:
mode:
authorAlexander Bluhm <bluhm@cvs.openbsd.org>2013-11-15 16:15:43 +0000
committerAlexander Bluhm <bluhm@cvs.openbsd.org>2013-11-15 16:15:43 +0000
commit9e635fbf8ac834c0adb363f89719810da1594832 (patch)
tree32275f7e2c15b3d7c76d99242c1d596d3943b28f /usr.sbin/ldomd
parentaed8306d3991ea80ca3b1072b212bfea5dc431e7 (diff)
After discussion with deraadt@ and Fernando Gont, it seems that the
stack should still scan for IPv6 type 0 routing headers. There are OpenBSD routers running without pf and there are plenty of legacy implementations supporting RH0. Bring back the function ip6_check_rh0hdr() that I removed a month ago. As an improvement to the prevoius solution, only scan the header chain in ip6_input() if the packet has not been inspected by pf. Both implementations drop packets with RH0 anywhere in the extension header chain. OK mikeb@ henning@
Diffstat (limited to 'usr.sbin/ldomd')
0 files changed, 0 insertions, 0 deletions