From: Phil Sutter <phil@nwl.cc>
To: Pablo Neira Ayuso <pablo@netfilter.org>
Cc: netfilter-devel@vger.kernel.org
Subject: [nf-next PATCH 3/4] netfilter: conntrack: nf_ct_seq_adjust to return error cause
Date: Tue, 8 Sep 2026 12:02:55 +0200 [thread overview]
Message-ID: <20260908100256.2648175-4-phil@nwl.cc> (raw)
In-Reply-To: <20260908100256.2648175-1-phil@nwl.cc>
Some callers will want to distinguish between malformed TCP packets and
other failure reasons, so invert the return code logic.
Signed-off-by: Phil Sutter <phil@nwl.cc>
---
net/netfilter/nf_conntrack_core.c | 2 +-
net/netfilter/nf_conntrack_ovs.c | 2 +-
net/netfilter/nf_conntrack_proto.c | 2 +-
net/netfilter/nf_conntrack_seqadj.c | 24 +++++++++++-------------
4 files changed, 14 insertions(+), 16 deletions(-)
diff --git a/net/netfilter/nf_conntrack_core.c b/net/netfilter/nf_conntrack_core.c
index f9b8927327ba..b0cd530cf8fe 100644
--- a/net/netfilter/nf_conntrack_core.c
+++ b/net/netfilter/nf_conntrack_core.c
@@ -2241,7 +2241,7 @@ static int nf_confirm_cthelper(struct sk_buff *skb, struct nf_conn *ct,
if (test_bit(IPS_SEQ_ADJUST_BIT, &ct->status) &&
!nf_is_loopback_packet(skb)) {
- if (!nf_ct_seq_adjust(skb, ct, ctinfo, protoff)) {
+ if (nf_ct_seq_adjust(skb, ct, ctinfo, protoff) < 0) {
NF_CT_STAT_INC_ATOMIC(nf_ct_net(ct), drop);
return NF_DROP;
}
diff --git a/net/netfilter/nf_conntrack_ovs.c b/net/netfilter/nf_conntrack_ovs.c
index b4085af3ad1c..d64379e203eb 100644
--- a/net/netfilter/nf_conntrack_ovs.c
+++ b/net/netfilter/nf_conntrack_ovs.c
@@ -76,7 +76,7 @@ int nf_ct_helper(struct sk_buff *skb, struct nf_conn *ct,
* addresses and/or port numbers in the text-based control connection.
*/
if (test_bit(IPS_SEQ_ADJUST_BIT, &ct->status) &&
- !nf_ct_seq_adjust(skb, ct, ctinfo, protoff))
+ nf_ct_seq_adjust(skb, ct, ctinfo, protoff) < 0)
return NF_DROP;
return NF_ACCEPT;
}
diff --git a/net/netfilter/nf_conntrack_proto.c b/net/netfilter/nf_conntrack_proto.c
index 7a40e4e0e33e..0db404f662de 100644
--- a/net/netfilter/nf_conntrack_proto.c
+++ b/net/netfilter/nf_conntrack_proto.c
@@ -195,7 +195,7 @@ unsigned int nf_confirm(void *priv,
}
if (seqadj_needed &&
- !nf_ct_seq_adjust(skb, ct, ctinfo, protoff)) {
+ nf_ct_seq_adjust(skb, ct, ctinfo, protoff) < 0) {
NF_CT_STAT_INC_ATOMIC(nf_ct_net(ct), drop);
return NF_DROP;
}
diff --git a/net/netfilter/nf_conntrack_seqadj.c b/net/netfilter/nf_conntrack_seqadj.c
index 220216a4edc5..c95b6383a330 100644
--- a/net/netfilter/nf_conntrack_seqadj.c
+++ b/net/netfilter/nf_conntrack_seqadj.c
@@ -117,23 +117,21 @@ static void nf_ct_sack_block_adjust(struct sk_buff *skb,
}
/* TCP SACK sequence number adjustment */
-static unsigned int nf_ct_sack_adjust(struct sk_buff *skb,
- unsigned int protoff,
- struct nf_conn *ct,
- enum ip_conntrack_info ctinfo)
+static int nf_ct_sack_adjust(struct sk_buff *skb, unsigned int protoff,
+ struct nf_conn *ct, enum ip_conntrack_info ctinfo)
{
struct tcphdr *tcph = (void *)skb->data + protoff;
struct nf_conn_seqadj *seqadj = nfct_seqadj(ct);
unsigned int dir, optoff, optend;
if (!seqadj)
- return 0;
+ return -ENOSPC;
optoff = protoff + sizeof(struct tcphdr);
optend = protoff + tcph->doff * 4;
if (skb_ensure_writable(skb, optend))
- return 0;
+ return -ENOMEM;
tcph = (void *)skb->data + protoff;
dir = CTINFO2DIR(ctinfo);
@@ -144,7 +142,7 @@ static unsigned int nf_ct_sack_adjust(struct sk_buff *skb,
switch (op[0]) {
case TCPOPT_EOL:
- return 1;
+ return 0;
case TCPOPT_NOP:
optoff++;
continue;
@@ -153,7 +151,7 @@ static unsigned int nf_ct_sack_adjust(struct sk_buff *skb,
if (optoff + 1 == optend ||
optoff + op[1] > optend ||
op[1] < 2)
- return 0;
+ return -EINVAL;
if (op[0] == TCPOPT_SACK &&
op[1] >= 2+TCPOLEN_SACK_PERBLOCK &&
((op[1] - 2) % TCPOLEN_SACK_PERBLOCK) == 0)
@@ -163,10 +161,10 @@ static unsigned int nf_ct_sack_adjust(struct sk_buff *skb,
optoff += op[1];
}
}
- return 1;
+ return 0;
}
-/* TCP sequence number adjustment. Returns 1 on success, 0 on failure */
+/* TCP sequence number adjustment. Returns 0 on success, -err on failure */
int nf_ct_seq_adjust(struct sk_buff *skb,
struct nf_conn *ct, enum ip_conntrack_info ctinfo,
unsigned int protoff)
@@ -177,16 +175,16 @@ int nf_ct_seq_adjust(struct sk_buff *skb,
s32 seqoff, ackoff;
struct nf_conn_seqadj *seqadj = nfct_seqadj(ct);
struct nf_ct_seqadj *this_way, *other_way;
- int res = 1;
+ int res = 0;
if (!seqadj)
- return 0;
+ return -ENOSPC;
this_way = &seqadj->seq[dir];
other_way = &seqadj->seq[!dir];
if (skb_ensure_writable(skb, protoff + sizeof(*tcph)))
- return 0;
+ return -ENOMEM;
tcph = (void *)skb->data + protoff;
spin_lock_bh(&ct->lock);
--
2.54.0
next prev parent reply other threads:[~2026-09-08 10:03 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-08 10:02 [nf-next PATCH 0/4] netfilter: Conntrack counter review Phil Sutter
2026-09-08 10:02 ` [nf-next PATCH 1/4] netfilter: conntrack: Untangle insert_failed counter from others Phil Sutter
2026-09-08 10:02 ` [nf-next PATCH 2/4] netfilter: conntrack: Untangle drop and invalid counters Phil Sutter
2026-09-08 10:02 ` Phil Sutter [this message]
2026-09-08 10:02 ` [nf-next PATCH 4/4] netfilter: conntrack: Improve invalid packet stats Phil Sutter
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260908100256.2648175-4-phil@nwl.cc \
--to=phil@nwl.cc \
--cc=netfilter-devel@vger.kernel.org \
--cc=pablo@netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.