From: Pablo Neira Ayuso <pablo@netfilter.org>
To: louis.t42@caramail.com
Cc: netfilter@vger.kernel.org
Subject: Re: Nftables ct count over 2 counter continues to trigger with only 1 connection
Date: Mon, 27 Oct 2025 23:25:45 +0100 [thread overview]
Message-ID: <aP_xafHvkRsAZAep@calendula> (raw)
In-Reply-To: <trinity-93433a71-f31b-49d8-abd8-a8bf718472e1-1761573299550@3c-app-mailcom-bs13>
On Mon, Oct 27, 2025 at 02:54:59PM +0100, louis.t42@caramail.com wrote:
> > After looking at Fernandos analysis, does this work when you restrict
> > this to new packets, i.e.:
>
> Thanks for spending time on this. I can confirm that adding the restriction with the inline jump works great! Of course, it would still be great if the original rules behaved predictably as well.
>
> As an end-user trying to learn, the man documentation surrounding conntrack and especially packet path dynamic set add/update with `ct count over` and similar could be improved. The dynamic set flag also lists "delete" as a valid option with no other references to it which felt odd.
Please send us patches that can be reviewed, it will take a bit of
time on you but it could possibly kick off some discussions, thanks.
prev parent reply other threads:[~2025-10-27 22:25 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-10-22 22:54 Nftables ct count over 2 counter continues to trigger with only 1 connection louis.t42
2025-10-23 11:42 ` Pablo Neira Ayuso
2025-10-23 14:00 ` Fernando Fernandez Mancera
2025-10-24 11:45 ` Florian Westphal
2025-10-27 13:54 ` louis.t42
2025-10-27 22:25 ` Pablo Neira Ayuso [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=aP_xafHvkRsAZAep@calendula \
--to=pablo@netfilter.org \
--cc=louis.t42@caramail.com \
--cc=netfilter@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.