wireguard.lists.zx2c4.com archive mirror
 help / color / mirror / Atom feed
* Linux kernel 5 different behavior
@ 2019-08-25 16:59 Vasili Pupkin
  2019-08-25 18:52 ` Jason A. Donenfeld
  0 siblings, 1 reply; 7+ messages in thread
From: Vasili Pupkin @ 2019-08-25 16:59 UTC (permalink / raw)
  To: wireguard

In the newest kernel version, Wireguard encrypted packets are sent
from the same user credentials as the user that created original
packets. I have a firewall setup that limits programs run from a
particular user to wireguard tun interface, it worked in kernel 4.18
and is broken in kernel 5.0. In the new kernel encrypted packets are
also marked as owned by this user and routed to the tun interface
generating a recursion.
_______________________________________________
WireGuard mailing list
WireGuard@lists.zx2c4.com
https://lists.zx2c4.com/mailman/listinfo/wireguard

^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2019-08-26 12:28 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2019-08-25 16:59 Linux kernel 5 different behavior Vasili Pupkin
2019-08-25 18:52 ` Jason A. Donenfeld
2019-08-25 19:03   ` Vasili Pupkin
2019-08-25 19:07     ` Jason A. Donenfeld
2019-08-25 20:04       ` Vasili Pupkin
2019-08-26  2:08         ` Jason A. Donenfeld
2019-08-26  9:29           ` Vasili Pupkin

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).