From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2E1A9522EEF; Wed, 30 Sep 2026 17:32:39 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790789560; cv=none; b=O/ZnnOdBCHd4k9nOV8Nezgw9faCderel3OLPS0dtDxTkig/kC96vEW1bvvwZH/Dv3IyuMXozXAcLnXgJhH3xGL+M8UGpWwUTWVPI/qO+eGpg63YUSlJ+5UTD1c0cYCQ8vNR3Vh/CFnC3cgtDBmhf5F4K6KaPXFIesHYbV2R13Gs= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790789560; c=relaxed/simple; bh=q57KNHgf30yG5H30ofWYnufZshlRwYkWW3OPGKj9MQU=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=I5eTT8neXeklLhZoYZvDCnoEKq5Z5FQNg1vi/mOM9ChEvXs4/Xtp3HBYQiwb2ZjGi9SZ7ONDmsBpwa1PAyZiPlNUVB1BWF0ObX+Xf+LBPxGhE+5NFcig8ml3Iwk94wnWWk76z9bkcT3hidQIAT1kTrWwAhGIbDnUYB7XdRtLkDs= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=TeS1KYMx; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="TeS1KYMx" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 845171F0089E; Wed, 30 Sep 2026 17:32:38 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790789559; bh=eawzKn1rJTiK56noQ7LR2k8fxEKYa0LdXmFO5CsD4vU=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=TeS1KYMxyWEgdw6wVia9AeQvd+d8ov/5AJ7y47yAQBWHQbsQA6RNaozsT6NtGfS8k CXIfCy6MaUaYxG0IqckJ8o+X0QRbiTKoIf2XSuXYOTFw17I8wIQ2KYIml2V6DuriO1 fy2klZHBces2Vv9OaBDMnf17dXszuFndv+nAfN20= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, TencentOS Corvus AI , Aohan Mei , Pablo Neira Ayuso Subject: [PATCH 6.12 520/877] netfilter: nf_tables: skip expired catchall elements on insert and delete Date: Wed, 30 Sep 2026 17:23:51 +0200 Message-ID: <20260930152425.874812970@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260930152414.738996857@linuxfoundation.org> References: <20260930152414.738996857@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 6.12-stable review patch. If anyone has any objections, please let me know. ------------------ From: Aohan Mei commit 70194dc37670bd08e44b471389861cc01bd3a3c9 upstream. nft_setelem_catchall_insert() looks up duplicates with nft_set_elem_active() only, while nft_set_catchall_lookup() and the dump path additionally skip expired elements. Once a catchall element with a timeout expires, this predicate drift makes it invisible to userspace dumps, yet it still blocks re-insertion: with NLM_F_EXCL the request fails with -EEXIST, and without it the request reports success but silently inserts nothing. The stale entry only goes away when the (user-tunable) gc interval elapses, so the catchall rule may silently stop matching for an arbitrarily long time after its first expiration. The delete path shows the same drift: nft_setelem_catchall_deactivate() picks the first active-next entry in the catchall list, so with an expired entry still pending GC it retires the stale entry instead of the fresh one, and it deactivates an element that userspace no longer sees instead of failing with -ENOENT. Align both walks with the lookup and dump predicates: only an element that is active and not expired counts as a duplicate or delete candidate, using the per-netns timestamp taken at transaction start, in line with the set backend .insert/.deactivate and catchall GC sync paths. Reported-by: TencentOS Corvus AI Cc: stable@vger.kernel.org Fixes: aaa31047a6d2 ("netfilter: nftables: add catch-all set element support") Assisted-by: CodeBuddy:Kimi-K3 Signed-off-by: Aohan Mei Signed-off-by: Pablo Neira Ayuso Signed-off-by: Greg Kroah-Hartman --- net/netfilter/nf_tables_api.c | 10 ++++++++-- 1 file changed, 8 insertions(+), 2 deletions(-) --- a/net/netfilter/nf_tables_api.c +++ b/net/netfilter/nf_tables_api.c @@ -6617,11 +6617,14 @@ static int nft_setelem_catchall_insert(c { struct nft_set_elem_catchall *catchall; u8 genmask = nft_genmask_next(net); + u64 tstamp = nft_net_tstamp(net); struct nft_set_ext *ext; list_for_each_entry(catchall, &set->catchall_list, list) { ext = nft_set_elem_ext(set, catchall->elem); - if (nft_set_elem_active(ext, genmask)) { + if (nft_set_elem_active(ext, genmask) && + !__nft_set_elem_expired(ext, tstamp) && + !nft_set_elem_is_dead(ext)) { *priv = catchall->elem; return -EEXIST; } @@ -6682,11 +6685,14 @@ static int nft_setelem_catchall_deactiva struct nft_set_elem *elem) { struct nft_set_elem_catchall *catchall; + u64 tstamp = nft_net_tstamp(net); struct nft_set_ext *ext; list_for_each_entry(catchall, &set->catchall_list, list) { ext = nft_set_elem_ext(set, catchall->elem); - if (!nft_is_active_next(net, ext)) + if (!nft_is_active_next(net, ext) || + __nft_set_elem_expired(ext, tstamp) || + nft_set_elem_is_dead(ext)) continue; kfree(elem->priv);