All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH nf] netfilter: nf_tables: skip expired catchall elements in dedup walk
@ 2026-09-08 12:32 Aohan Mei
  2026-09-08 23:22 ` Pablo Neira Ayuso
  0 siblings, 1 reply; 3+ messages in thread
From: Aohan Mei @ 2026-09-08 12:32 UTC (permalink / raw)
  To: netfilter-devel
  Cc: pablo, fw, phil, coreteam, Aohan Mei, TencentOS Corvus AI, stable

From: Aohan Mei <henrymei@tencent.com>

nft_setelem_catchall_insert() looks up duplicates with
nft_set_elem_active() only, while nft_set_catchall_lookup() and the
dump path additionally skip expired and dead elements.

Once a catchall element with a timeout expires, this predicate drift
makes it invisible to userspace dumps, yet it still blocks
re-insertion: with NLM_F_EXCL the request fails with -EEXIST, and
without it the request reports success but silently inserts nothing.
The stale entry only goes away when the (user-tunable) gc interval
elapses, so the catchall rule may silently stop matching for an
arbitrarily long time after its first expiration.

Align the dedup walk with the lookup and dump predicates: only an
element that is active, not expired and not dead counts as a
duplicate.

Reported-by: TencentOS Corvus AI <corvus@tencent.com>
Cc: stable@vger.kernel.org
Fixes: aaa31047a6d2 ("netfilter: nftables: add catch-all set element support")
Assisted-by: CodeBuddy:Kimi-K3
Signed-off-by: Aohan Mei <henrymei@tencent.com>
---
 net/netfilter/nf_tables_api.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/net/netfilter/nf_tables_api.c b/net/netfilter/nf_tables_api.c
index 765a92fa90d6..6458ee26dcd9 100644
--- a/net/netfilter/nf_tables_api.c
+++ b/net/netfilter/nf_tables_api.c
@@ -6995,7 +6995,9 @@ static int nft_setelem_catchall_insert(const struct net *net,
 
 	list_for_each_entry(catchall, &set->catchall_list, list) {
 		ext = nft_set_elem_ext(set, catchall->elem);
-		if (nft_set_elem_active(ext, genmask)) {
+		if (nft_set_elem_active(ext, genmask) &&
+		    !nft_set_elem_expired(ext) &&
+		    !nft_set_elem_is_dead(ext)) {
 			*priv = catchall->elem;
 			return -EEXIST;
 		}
-- 
2.43.7


^ permalink raw reply related	[flat|nested] 3+ messages in thread

* Re: [PATCH nf] netfilter: nf_tables: skip expired catchall elements in dedup walk
  2026-09-08 12:32 [PATCH nf] netfilter: nf_tables: skip expired catchall elements in dedup walk Aohan Mei
@ 2026-09-08 23:22 ` Pablo Neira Ayuso
  2026-09-08 23:31   ` Pablo Neira Ayuso
  0 siblings, 1 reply; 3+ messages in thread
From: Pablo Neira Ayuso @ 2026-09-08 23:22 UTC (permalink / raw)
  To: Aohan Mei
  Cc: netfilter-devel, fw, phil, coreteam, Aohan Mei,
	TencentOS Corvus AI, stable

On Tue, Sep 08, 2026 at 08:32:47PM +0800, Aohan Mei wrote:
> From: Aohan Mei <henrymei@tencent.com>
> 
> nft_setelem_catchall_insert() looks up duplicates with
> nft_set_elem_active() only, while nft_set_catchall_lookup() and the
> dump path additionally skip expired and dead elements.
> 
> Once a catchall element with a timeout expires, this predicate drift
> makes it invisible to userspace dumps, yet it still blocks
> re-insertion: with NLM_F_EXCL the request fails with -EEXIST, and
> without it the request reports success but silently inserts nothing.
> The stale entry only goes away when the (user-tunable) gc interval
> elapses, so the catchall rule may silently stop matching for an
> arbitrarily long time after its first expiration.
> 
> Align the dedup walk with the lookup and dump predicates: only an
> element that is active, not expired and not dead counts as a
> duplicate.
> 
> Reported-by: TencentOS Corvus AI <corvus@tencent.com>
> Cc: stable@vger.kernel.org
> Fixes: aaa31047a6d2 ("netfilter: nftables: add catch-all set element support")
> Assisted-by: CodeBuddy:Kimi-K3
> Signed-off-by: Aohan Mei <henrymei@tencent.com>
> ---
>  net/netfilter/nf_tables_api.c | 4 +++-
>  1 file changed, 3 insertions(+), 1 deletion(-)
> 
> diff --git a/net/netfilter/nf_tables_api.c b/net/netfilter/nf_tables_api.c
> index 765a92fa90d6..6458ee26dcd9 100644
> --- a/net/netfilter/nf_tables_api.c
> +++ b/net/netfilter/nf_tables_api.c
> @@ -6995,7 +6995,9 @@ static int nft_setelem_catchall_insert(const struct net *net,
>  
>  	list_for_each_entry(catchall, &set->catchall_list, list) {
>  		ext = nft_set_elem_ext(set, catchall->elem);
> -		if (nft_set_elem_active(ext, genmask)) {
> +		if (nft_set_elem_active(ext, genmask) &&
> +		    !nft_set_elem_expired(ext) &&

This should be:
                    __nft_set_elem_expired(ext, tstamp) 

> +		    !nft_set_elem_is_dead(ext)) {

I don't think dead flag is set on for catchall elements?

>  			*priv = catchall->elem;
>  			return -EEXIST;
>  		}
> -- 
> 2.43.7
> 
> 

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH nf] netfilter: nf_tables: skip expired catchall elements in dedup walk
  2026-09-08 23:22 ` Pablo Neira Ayuso
@ 2026-09-08 23:31   ` Pablo Neira Ayuso
  0 siblings, 0 replies; 3+ messages in thread
From: Pablo Neira Ayuso @ 2026-09-08 23:31 UTC (permalink / raw)
  To: Aohan Mei
  Cc: netfilter-devel, fw, phil, coreteam, Aohan Mei,
	TencentOS Corvus AI, stable

On Wed, Sep 09, 2026 at 01:22:04AM +0200, Pablo Neira Ayuso wrote:
> On Tue, Sep 08, 2026 at 08:32:47PM +0800, Aohan Mei wrote:
> > From: Aohan Mei <henrymei@tencent.com>
> > 
> > nft_setelem_catchall_insert() looks up duplicates with
> > nft_set_elem_active() only, while nft_set_catchall_lookup() and the
> > dump path additionally skip expired and dead elements.
> > 
> > Once a catchall element with a timeout expires, this predicate drift
> > makes it invisible to userspace dumps, yet it still blocks
> > re-insertion: with NLM_F_EXCL the request fails with -EEXIST, and
> > without it the request reports success but silently inserts nothing.
> > The stale entry only goes away when the (user-tunable) gc interval
> > elapses, so the catchall rule may silently stop matching for an
> > arbitrarily long time after its first expiration.
> > 
> > Align the dedup walk with the lookup and dump predicates: only an
> > element that is active, not expired and not dead counts as a
> > duplicate.
> > 
> > Reported-by: TencentOS Corvus AI <corvus@tencent.com>
> > Cc: stable@vger.kernel.org
> > Fixes: aaa31047a6d2 ("netfilter: nftables: add catch-all set element support")
> > Assisted-by: CodeBuddy:Kimi-K3
> > Signed-off-by: Aohan Mei <henrymei@tencent.com>
> > ---
> >  net/netfilter/nf_tables_api.c | 4 +++-
> >  1 file changed, 3 insertions(+), 1 deletion(-)
> > 
> > diff --git a/net/netfilter/nf_tables_api.c b/net/netfilter/nf_tables_api.c
> > index 765a92fa90d6..6458ee26dcd9 100644
> > --- a/net/netfilter/nf_tables_api.c
> > +++ b/net/netfilter/nf_tables_api.c
> > @@ -6995,7 +6995,9 @@ static int nft_setelem_catchall_insert(const struct net *net,
> >  
> >  	list_for_each_entry(catchall, &set->catchall_list, list) {
> >  		ext = nft_set_elem_ext(set, catchall->elem);
> > -		if (nft_set_elem_active(ext, genmask)) {
> > +		if (nft_set_elem_active(ext, genmask) &&
> > +		    !nft_set_elem_expired(ext) &&
> 
> This should be:
>                     __nft_set_elem_expired(ext, tstamp) 

Delete also need this this expired check.

> > +		    !nft_set_elem_is_dead(ext)) {
> 
> I don't think dead flag is set on for catchall elements?

It does indeed use it, but I think this check does not belong here and
the check for expired is sufficient.

> >  			*priv = catchall->elem;
> >  			return -EEXIST;
> >  		}
> > -- 
> > 2.43.7
> > 
> > 

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-09-08 23:31 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-08 12:32 [PATCH nf] netfilter: nf_tables: skip expired catchall elements in dedup walk Aohan Mei
2026-09-08 23:22 ` Pablo Neira Ayuso
2026-09-08 23:31   ` Pablo Neira Ayuso

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.