Received: by 2002:a05:6358:53a8:b0:117:f937:c515 with SMTP id z40csp2287178rwe; Sat, 15 Apr 2023 16:12:32 -0700 (PDT) X-Google-Smtp-Source: AKy350ZzpNVD7omQmA2Wq1ydYwXtZUzh5/+VKGUq51UFz4Fnq+ywwoxiDjLT7s14CzkFtQKGWllt X-Received: by 2002:a05:6a20:a989:b0:d9:ecba:b9fc with SMTP id cc9-20020a056a20a98900b000d9ecbab9fcmr10277019pzb.54.1681600352217; Sat, 15 Apr 2023 16:12:32 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1681600352; cv=none; d=google.com; s=arc-20160816; b=Z7ARvfJXMThGwL2HjSqkXaqgEQFmKhCIjTHfpAMOKdwLMZ93gtypzqmOm7xmpzUiJm gWh1CYCGEmVhx5S0oS4hzHqZBno1XK7gpMx35P6pA/xlOkjfO1Py7hEflx6zanJFuJd2 FPdyu67rXGqggAyjF36fGCkdA2IXEt8Ahd4mw07G0tFAJRBBSifWMSCLuJlBD1lmHXGQ IXyyZwgeo7PS+Lqt92LQhZBxZwCz3wv8eDKoDWaZSgw8azN5DotzIM6ofCOSWos55Wm6 EUMFbW8DbH7oaCZThEA2skRr+v2Q3Gqqpy8M9lMiNNLr50EjZtvvSRm+a7Ja9KeQ/crQ EMxA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:mime-version :references:in-reply-to:message-id:subject:cc:to:from:date :dkim-signature; bh=9jm23euiY98fsN22kiG5rHbRtDdr3VWwy800+EazcFQ=; b=Mg9tYWiMflaFpG6SGXBvCkJ4dpHHXpHvTx/OgRxChH6yE3Z20yQgXdMKlYgiHTiWAB UZ8s6E3+nqkDbGiUOVJ/nkoSJNmQRA0JqeW8KtnezvA0X1Vi4UgdeIIZbg+itNkK0+gN IHUv2QP8QOGkFcWYYKkmWv6Fx3MEa6vqdkxv7i+L/KljUDyr00C9WTFtP7bU2UheFRQW 7Hhx1fJTdLnc0k0WiMJscqIHwcYBZhD3+yoMJUEuD2YLyX+abCOm/C+ZpVKPvC0uQm2A AInLUnOtFbIVveu2cKGVt+tpSqIHC1etfgbWhUmLRdL/ia1vuF5cFhwebF8Bkh0gq6WH QTfg== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@networkplumber-org.20221208.gappssmtp.com header.s=20221208 header.b=GBfLzDMa; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=QUARANTINE sp=QUARANTINE dis=NONE) header.from=networkplumber.org Return-Path: Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id x14-20020a63170e000000b0051358b5c88bsi7906183pgl.452.2023.04.15.16.12.16; Sat, 15 Apr 2023 16:12:32 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; dkim=pass header.i=@networkplumber-org.20221208.gappssmtp.com header.s=20221208 header.b=GBfLzDMa; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=QUARANTINE sp=QUARANTINE dis=NONE) header.from=networkplumber.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S229822AbjDOW5y (ORCPT + 99 others); Sat, 15 Apr 2023 18:57:54 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:43704 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S229999AbjDOW5w (ORCPT ); Sat, 15 Apr 2023 18:57:52 -0400 Received: from mail-pl1-x62f.google.com (mail-pl1-x62f.google.com [IPv6:2607:f8b0:4864:20::62f]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id B431B1BCA for ; Sat, 15 Apr 2023 15:57:51 -0700 (PDT) Received: by mail-pl1-x62f.google.com with SMTP id kc3so5001141plb.6 for ; Sat, 15 Apr 2023 15:57:51 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=networkplumber-org.20221208.gappssmtp.com; s=20221208; t=1681599471; x=1684191471; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:subject:cc:to:from:date:from:to:cc:subject:date :message-id:reply-to; bh=9jm23euiY98fsN22kiG5rHbRtDdr3VWwy800+EazcFQ=; b=GBfLzDMaedtUl6MyPA5MjqwskjXDB8bXlQkls/cGP4aq1jUv7RrRFtXHLwgTEGVidb x+yYSroQA1+8wmK2nLvfaVEN3cMOIs5qH3X54gCP+KRH3xJ+4SmDE1grbMoFifyFXlPc RI0xSxywOQMml3hnpp2skrtAslxJZk2wR9p79TDktIn6BkkyDaCbEmvvHIRn0QjEWqht 8eQQirlYYZgBQ/JwhSrlewqOHstVPBpK4duQ8aUnfUE+nLGCySqyLX1g1NOzCO3wSxFa jm9ygqNznrgQ9S2/G24r7ngYQJBkMGHFycKgNG88gySGQA40KnO1k13R5U3FnMpOhOD2 Pi9w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20221208; t=1681599471; x=1684191471; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:subject:cc:to:from:date:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=9jm23euiY98fsN22kiG5rHbRtDdr3VWwy800+EazcFQ=; b=HGJxiv2+LPoxxrvZ2tf3Te39ORUp5tYRoYW1az0qooqgTZuDAfA8Pw0XJkjTjP8jmq CDmgDBY6w0neOfY7AtVetLFDnpIVcvKjyQMN7r33gH34oV98UkJsbezNIsZ1+9MO95/l A+NoN5bW91cPF2Bw7dN/DA5Y7AseB6oA+EdT/BxB7GM3V4TDc7alGIeOp72Yk7Jg23ji ecxvdzvsPNCQcoxqUY1R45oQuJ+3W+4+xIcFJCu4Ah46qW9tjYL2VMAEzCG9gUoef0cc EGYAI3Sopri5LdgRsIFN6yGtUljRlPqSUuj4r9mBTji0ies8Y5s3JvOXEalrp57OMNgX KE7w== X-Gm-Message-State: AAQBX9cxXJPhCVDfcB7Zqrn4XP5IDT94vQQF5Ib6UsCGvXQWOEsWohFa sE21XK9LavE+JL++PW8gPSc+8g== X-Received: by 2002:a17:902:d583:b0:1a0:6bd4:ea78 with SMTP id k3-20020a170902d58300b001a06bd4ea78mr7929045plh.31.1681599471180; Sat, 15 Apr 2023 15:57:51 -0700 (PDT) Received: from hermes.local (204-195-120-218.wavecable.com. [204.195.120.218]) by smtp.gmail.com with ESMTPSA id y13-20020a170902b48d00b001a68991e1b3sm4801780plr.263.2023.04.15.15.57.49 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 15 Apr 2023 15:57:51 -0700 (PDT) Date: Sat, 15 Apr 2023 15:57:48 -0700 From: Stephen Hemminger To: david.keisarschm@mail.huji.ac.il Cc: linux-kernel@vger.kernel.org, Dave Hansen , Andy Lutomirski , Peter Zijlstra , Thomas Gleixner , Ingo Molnar , Borislav Petkov , x86@kernel.org, "H. Peter Anvin" , Pablo Neira Ayuso , Jozsef Kadlecsik , Florian Westphal , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Alan Stern , Andrea Parri , Will Deacon , Boqun Feng , Nicholas Piggin , David Howells , Jade Alglave , Luc Maranget , "Paul E. McKenney" , Akira Yokosawa , Daniel Lustig , Joel Fernandes , Jason@zx2c4.com, keescook@chromium.org, ilay.bahat1@gmail.com, aksecurity@gmail.com, netfilter-devel@vger.kernel.org, coreteam@netfilter.org, netdev@vger.kernel.org, linux-arch@vger.kernel.org Subject: Re: [PATCH v5 3/3] Replace invocation of weak PRNG Message-ID: <20230415155748.2c9663a9@hermes.local> In-Reply-To: <20230415173756.5520-1-david.keisarschm@mail.huji.ac.il> References: <20230415173756.5520-1-david.keisarschm@mail.huji.ac.il> MIME-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit X-Spam-Status: No, score=-1.9 required=5.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,RCVD_IN_DNSWL_NONE,SPF_HELO_NONE,SPF_PASS autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Sat, 15 Apr 2023 20:37:53 +0300 david.keisarschm@mail.huji.ac.il wrote: > include/uapi/linux/netfilter/xt_connmark.h | 40 +- > include/uapi/linux/netfilter/xt_dscp.h | 27 +- > include/uapi/linux/netfilter/xt_mark.h | 17 +- > include/uapi/linux/netfilter/xt_rateest.h | 38 +- > include/uapi/linux/netfilter/xt_tcpmss.h | 13 +- > include/uapi/linux/netfilter_ipv4/ipt_ecn.h | 40 +- > include/uapi/linux/netfilter_ipv4/ipt_ttl.h | 14 +- > include/uapi/linux/netfilter_ipv6/ip6t_hl.h | 14 +- > net/netfilter/xt_dscp.c | 149 ++++--- > net/netfilter/xt_hl.c | 164 +++++--- > net/netfilter/xt_rateest.c | 282 ++++++++----- > net/netfilter/xt_tcpmss.c | 378 ++++++++++++++---- > ...Z6.0+pooncelock+pooncelock+pombonce.litmus | 12 +- NAK You sucked in some unrelated netfilter stuff.