)]}'
{
  "commit": "990078afbf90e0175e71da2df04595b99153514c",
  "tree": "ff61e3ab53f46ceca2ef280788982883b50cc669",
  "parents": [
    "5c04c819a20af40adb7d282199f4e34e14fa05c5"
  ],
  "author": {
    "name": "Michael Smith",
    "email": "msmith@cbnco.com",
    "time": "Thu Apr 07 04:51:51 2011 +0000"
  },
  "committer": {
    "name": "David S. Miller",
    "email": "davem@davemloft.net",
    "time": "Sun Apr 10 18:50:59 2011 -0700"
  },
  "message": "Disable rp_filter for IPsec packets\n\nThe reverse path filter interferes with IPsec subnet-to-subnet tunnels,\nespecially when the link to the IPsec peer is on an interface other than\nthe one hosting the default route.\n\nWith dynamic routing, where the peer might be reachable through eth0\ntoday and eth1 tomorrow, it\u0027s difficult to keep rp_filter enabled unless\nfake routes to the remote subnets are configured on the interface\ncurrently used to reach the peer.\n\nIPsec provides a much stronger anti-spoofing policy than rp_filter, so\nthis patch disables the rp_filter for packets with a security path.\n\nSigned-off-by: Michael Smith \u003cmsmith@cbnco.com\u003e\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "6ae4bc5ce8a712796774e32637f875f4e98b173e",
      "old_mode": 33188,
      "old_path": "include/net/xfrm.h",
      "new_id": "65ea313486313f91d4ee35ce2402b4c8e5695c6e",
      "new_mode": 33188,
      "new_path": "include/net/xfrm.h"
    },
    {
      "type": "modify",
      "old_id": "f162f84b8d6d24bfba42bb7dbbef8651507f9d48",
      "old_mode": 33188,
      "old_path": "net/ipv4/fib_frontend.c",
      "new_id": "22524716fe7063c7cb0861bcce0dfba92f4effab",
      "new_mode": 33188,
      "new_path": "net/ipv4/fib_frontend.c"
    }
  ]
}
