diff options
Diffstat (limited to 'net/ipv4/ip_input.c')
| -rw-r--r-- | net/ipv4/ip_input.c | 10 | 
1 files changed, 9 insertions, 1 deletions
diff --git a/net/ipv4/ip_input.c b/net/ipv4/ip_input.c index 861978a4f1a..cfb38ac9d69 100644 --- a/net/ipv4/ip_input.c +++ b/net/ipv4/ip_input.c @@ -209,9 +209,17 @@ static int ip_local_deliver_finish(struct sk_buff *skb)  		hash = protocol & (MAX_INET_PROTOS - 1);  		ipprot = rcu_dereference(inet_protos[hash]); -		if (ipprot != NULL && (net == &init_net || ipprot->netns_ok)) { +		if (ipprot != NULL) {  			int ret; +			if (!net_eq(net, &init_net) && !ipprot->netns_ok) { +				if (net_ratelimit()) +					printk("%s: proto %d isn't netns-ready\n", +						__func__, protocol); +				kfree_skb(skb); +				goto out; +			} +  			if (!ipprot->no_policy) {  				if (!xfrm4_policy_check(NULL, XFRM_POLICY_IN, skb)) {  					kfree_skb(skb);  |