Files
linux/net/netfilter/ipvs
Julian Anastasov 2a71d94e4f ipvs: remove IPS_NAT_MASK check to fix passive FTP
[ Upstream commit 8a949fff03 ]

The IPS_NAT_MASK check in 4.12 replaced previous check for nfct_nat()
which was needed to fix a crash in 2.6.36-rc, see
commit 7bcbf81a22 ("ipvs: avoid oops for passive FTP").
But as IPVS does not set the IPS_SRC_NAT and IPS_DST_NAT bits,
checking for IPS_NAT_MASK prevents PASV response to be properly
mangled and blocks the transfer. Remove the check as it is not
needed after 3.12 commit 41d73ec053 ("netfilter: nf_conntrack:
make sequence number adjustments usuable without NAT") which
changes nfct_nat() with nfct_seqadj() and especially after 3.13
commit b25adce160 ("ipvs: correct usage/allocation of seqadj
ext in ipvs").

Thanks to Li Shuang and Florian Westphal for reporting the problem!

Reported-by: Li Shuang <shuali@redhat.com>
Fixes: be7be6e161 ("netfilter: ipvs: fix incorrect conflict resolution")
Signed-off-by: Julian Anastasov <ja@ssi.bg>
Acked-by: Simon Horman <horms@verge.net.au>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <alexander.levin@microsoft.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2018-05-30 07:52:07 +02:00
..
2017-03-17 12:49:43 +01:00
2017-02-27 18:43:47 -08:00
2017-03-17 12:49:43 +01:00
2017-03-17 12:49:43 +01:00
2015-08-21 09:08:39 -07:00
2017-03-17 12:49:43 +01:00
2017-03-17 12:49:43 +01:00
2017-02-27 18:43:47 -08:00
2017-03-17 12:49:43 +01:00
2017-03-17 12:49:43 +01:00
2015-08-21 09:08:39 -07:00