From: Rahul Chandelkar <rc@rexion.ai>
To: Pablo Neira Ayuso <pablo@netfilter.org>
Cc: Jozsef Kadlecsik <kadlec@netfilter.org>,
Florian Westphal <fw@strlen.de>, Phil Sutter <phil@nwl.cc>,
netfilter-devel@vger.kernel.org, coreteam@netfilter.org,
davem@davemloft.net, edumazet@google.com, kuba@kernel.org,
pabeni@redhat.com, netdev@vger.kernel.org,
Rahul Chandelkar <rc@rexion.ai>
Subject: [PATCH nf-next v5 0/4] netfilter: conntrack: shared port parser for helpers
Date: Mon, 28 Sep 2026 16:28:54 +0000 [thread overview]
Message-ID: <cover.1790596690.git.rc@rexion.ai> (raw)
The IRC and Amanda conntrack helpers parse port numbers from packet
payload with simple_strtoul(), which returns unsigned long without a
range check, so a port above 65535 is truncated when it is stored in a
u16 (65537 becomes 1) and an expectation is created for a port that
never appeared in the payload. Amanda also cuts a port field of six or
more digits down to its first five. Both problems are present in
current nf-next.
Instead of open-coding a range check in each helper, this series moves
the sip_strtouint() parser of nf_conntrack_sip into the helper core as
nf_ct_helper_parse_uint(), adds nf_ct_helper_parse_port() on top of it,
and converts the three helpers:
1/4 adds the two parsers
2/4 and 3/4 fix the IRC and Amanda helpers
4/4 removes the now duplicate parsing code from the SIP helper
(no functional change)
Testing: allmodconfig and allyesconfig builds with W=1, sparse, an
allnoconfig build, i386 and big-endian powerpc cross-builds, and a
build of each patch in turn. The old and new sip_parse_port() were
compared in a userspace harness built from the kernel source on three
million random inputs with no difference. The helpers have not been
run-time tested with IRC, Amanda or SIP traffic.
Tool use: v4 and v5 were prepared with Claude Code, an AI coding
assistant, as recorded in the Assisted-by tags. It wrote most of the
code changes and changelogs from v3 and the review feedback, and ran
the builds and tests listed above. v4 should have carried the tags as
well; it did not, sorry about that.
Changes in v5:
- nf_ct_helper_parse_port(): reject digit runs longer than five
characters, so that sip_parse_port() still rejects zero-padded
ports and 4/4 has no functional change; return -EINVAL rather
than -1
- add kernel-doc for both parsers, including their digit limits
- amanda: make pbuf one byte larger so that a port field of six or
more digits is rejected instead of being cut to its first five
digits
- irc: remove the dcc_port == 0 test in help(), which can no longer
be true
- sip: rewrap call sites that no longer fit in 80 columns
- add Assisted-by tags
(the first four items address the Sashiko review of v4)
v4: https://lore.kernel.org/all/20260923091608.2617604-1-rc@rexion.ai/
- rebase onto nf-next; move sip_strtouint() into the helper core
instead of adding a second parser, and convert nf_conntrack_sip
(Pablo Neira Ayuso, Phil Sutter, Florian Westphal)
- use a real name and target nf-next (Pablo Neira Ayuso)
v3: https://lore.kernel.org/all/20260503083220.630655-1-rc@rexion.ai/
- add nf_ct_helper_parse_uint() and convert nf_conntrack_sip
(Phil Sutter)
v2: https://lore.kernel.org/all/20260501063156.2520780-1-rc@rexion.ai/
- add a shared nf_ct_helper_parse_port() in the helper core instead
of open-coding range checks (Florian Westphal, Pablo Neira Ayuso)
v1: https://lore.kernel.org/all/20260430161230.3438973-1-rc@rexion.ai/
Rahul Chandelkar (4):
netfilter: conntrack: add shared uint and port parsers for helpers
netfilter: nf_conntrack_irc: use nf_ct_helper_parse_port()
netfilter: nf_conntrack_amanda: use nf_ct_helper_parse_port()
netfilter: nf_conntrack_sip: use shared helper parsers
include/net/netfilter/nf_conntrack_helper.h | 5 ++
net/netfilter/nf_conntrack_amanda.c | 13 ++-
net/netfilter/nf_conntrack_helper.c | 79 +++++++++++++++++
net/netfilter/nf_conntrack_irc.c | 9 +-
net/netfilter/nf_conntrack_sip.c | 93 ++++++---------------
5 files changed, 123 insertions(+), 76 deletions(-)
base-commit: 87b80c2f6b05cad9f0ff9136709c62a0f59923e3
--
2.43.0
next reply other threads:[~2026-09-28 16:29 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-28 16:28 Rahul Chandelkar [this message]
2026-09-28 17:33 ` [PATCH nf-next v5 1/4] netfilter: conntrack: add shared uint and port parsers for helpers Rahul Chandelkar
2026-09-28 18:39 ` [PATCH nf-next v5 2/4] netfilter: nf_conntrack_irc: use nf_ct_helper_parse_port() Rahul Chandelkar
2026-09-28 19:44 ` [PATCH nf-next v5 3/4] netfilter: nf_conntrack_amanda: " Rahul Chandelkar
2026-09-28 20:49 ` [PATCH nf-next v5 4/4] netfilter: nf_conntrack_sip: use shared helper parsers Rahul Chandelkar
2026-09-28 20:56 ` [PATCH nf-next v5 0/4] netfilter: conntrack: shared port parser for helpers netdev-bot+sinfo
2026-09-30 9:57 ` Rahul Chandelkar
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=cover.1790596690.git.rc@rexion.ai \
--to=rc@rexion.ai \
--cc=coreteam@netfilter.org \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=fw@strlen.de \
--cc=kadlec@netfilter.org \
--cc=kuba@kernel.org \
--cc=netdev@vger.kernel.org \
--cc=netfilter-devel@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=pablo@netfilter.org \
--cc=phil@nwl.cc \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.