* [PATCH nf-next v5 0/4] netfilter: conntrack: shared port parser for helpers
@ 2026-09-28 16:28 Rahul Chandelkar
2026-09-28 17:33 ` [PATCH nf-next v5 1/4] netfilter: conntrack: add shared uint and port parsers " Rahul Chandelkar
` (4 more replies)
0 siblings, 5 replies; 7+ messages in thread
From: Rahul Chandelkar @ 2026-09-28 16:28 UTC (permalink / raw)
To: Pablo Neira Ayuso
Cc: Jozsef Kadlecsik, Florian Westphal, Phil Sutter, netfilter-devel,
coreteam, davem, edumazet, kuba, pabeni, netdev, Rahul Chandelkar
The IRC and Amanda conntrack helpers parse port numbers from packet
payload with simple_strtoul(), which returns unsigned long without a
range check, so a port above 65535 is truncated when it is stored in a
u16 (65537 becomes 1) and an expectation is created for a port that
never appeared in the payload. Amanda also cuts a port field of six or
more digits down to its first five. Both problems are present in
current nf-next.
Instead of open-coding a range check in each helper, this series moves
the sip_strtouint() parser of nf_conntrack_sip into the helper core as
nf_ct_helper_parse_uint(), adds nf_ct_helper_parse_port() on top of it,
and converts the three helpers:
1/4 adds the two parsers
2/4 and 3/4 fix the IRC and Amanda helpers
4/4 removes the now duplicate parsing code from the SIP helper
(no functional change)
Testing: allmodconfig and allyesconfig builds with W=1, sparse, an
allnoconfig build, i386 and big-endian powerpc cross-builds, and a
build of each patch in turn. The old and new sip_parse_port() were
compared in a userspace harness built from the kernel source on three
million random inputs with no difference. The helpers have not been
run-time tested with IRC, Amanda or SIP traffic.
Tool use: v4 and v5 were prepared with Claude Code, an AI coding
assistant, as recorded in the Assisted-by tags. It wrote most of the
code changes and changelogs from v3 and the review feedback, and ran
the builds and tests listed above. v4 should have carried the tags as
well; it did not, sorry about that.
Changes in v5:
- nf_ct_helper_parse_port(): reject digit runs longer than five
characters, so that sip_parse_port() still rejects zero-padded
ports and 4/4 has no functional change; return -EINVAL rather
than -1
- add kernel-doc for both parsers, including their digit limits
- amanda: make pbuf one byte larger so that a port field of six or
more digits is rejected instead of being cut to its first five
digits
- irc: remove the dcc_port == 0 test in help(), which can no longer
be true
- sip: rewrap call sites that no longer fit in 80 columns
- add Assisted-by tags
(the first four items address the Sashiko review of v4)
v4: https://lore.kernel.org/all/20260923091608.2617604-1-rc@rexion.ai/
- rebase onto nf-next; move sip_strtouint() into the helper core
instead of adding a second parser, and convert nf_conntrack_sip
(Pablo Neira Ayuso, Phil Sutter, Florian Westphal)
- use a real name and target nf-next (Pablo Neira Ayuso)
v3: https://lore.kernel.org/all/20260503083220.630655-1-rc@rexion.ai/
- add nf_ct_helper_parse_uint() and convert nf_conntrack_sip
(Phil Sutter)
v2: https://lore.kernel.org/all/20260501063156.2520780-1-rc@rexion.ai/
- add a shared nf_ct_helper_parse_port() in the helper core instead
of open-coding range checks (Florian Westphal, Pablo Neira Ayuso)
v1: https://lore.kernel.org/all/20260430161230.3438973-1-rc@rexion.ai/
Rahul Chandelkar (4):
netfilter: conntrack: add shared uint and port parsers for helpers
netfilter: nf_conntrack_irc: use nf_ct_helper_parse_port()
netfilter: nf_conntrack_amanda: use nf_ct_helper_parse_port()
netfilter: nf_conntrack_sip: use shared helper parsers
include/net/netfilter/nf_conntrack_helper.h | 5 ++
net/netfilter/nf_conntrack_amanda.c | 13 ++-
net/netfilter/nf_conntrack_helper.c | 79 +++++++++++++++++
net/netfilter/nf_conntrack_irc.c | 9 +-
net/netfilter/nf_conntrack_sip.c | 93 ++++++---------------
5 files changed, 123 insertions(+), 76 deletions(-)
base-commit: 87b80c2f6b05cad9f0ff9136709c62a0f59923e3
--
2.43.0
^ permalink raw reply [flat|nested] 7+ messages in thread
* [PATCH nf-next v5 1/4] netfilter: conntrack: add shared uint and port parsers for helpers
2026-09-28 16:28 [PATCH nf-next v5 0/4] netfilter: conntrack: shared port parser for helpers Rahul Chandelkar
@ 2026-09-28 17:33 ` Rahul Chandelkar
2026-09-28 18:39 ` [PATCH nf-next v5 2/4] netfilter: nf_conntrack_irc: use nf_ct_helper_parse_port() Rahul Chandelkar
` (3 subsequent siblings)
4 siblings, 0 replies; 7+ messages in thread
From: Rahul Chandelkar @ 2026-09-28 17:33 UTC (permalink / raw)
To: Pablo Neira Ayuso
Cc: Jozsef Kadlecsik, Florian Westphal, Phil Sutter, netfilter-devel,
coreteam, davem, edumazet, kuba, pabeni, netdev, Rahul Chandelkar
Several conntrack helpers parse integers and port numbers out of
application-layer payload. Some open-code simple_strtoul(), which
requires a NUL-terminated string and returns unsigned long without any
range check, while nf_conntrack_sip carries its own sip_strtouint() and
a digit loop in sip_parse_port().
Add two length-delimited parsers to the conntrack helper core so that
the helpers can share one implementation:
nf_ct_helper_parse_uint() - bounded decimal parser for a buffer that
need not be NUL-terminated. Its body is sip_strtouint() unchanged:
the result is capped at UINT_MAX and a run of more than 11 digits is
rejected.
nf_ct_helper_parse_port() - parses a port number and returns -EINVAL
for a digit run longer than five characters, for zero and for values
above 65535, matching what sip_parse_port() accepts today.
Both are exported; the following patches convert the IRC, Amanda and SIP
helpers to them.
Assisted-by: Claude-Code:claude-opus-5-5 sparse
Signed-off-by: Rahul Chandelkar <rc@rexion.ai>
---
include/net/netfilter/nf_conntrack_helper.h | 5 ++
net/netfilter/nf_conntrack_helper.c | 79 +++++++++++++++++++++
2 files changed, 84 insertions(+)
diff --git a/include/net/netfilter/nf_conntrack_helper.h b/include/net/netfilter/nf_conntrack_helper.h
index 335b8c43694f..4d5ad5ae1d13 100644
--- a/include/net/netfilter/nf_conntrack_helper.h
+++ b/include/net/netfilter/nf_conntrack_helper.h
@@ -184,6 +184,11 @@ nf_ct_helper_expectfn_find_by_name(const char *name);
struct nf_ct_helper_expectfn *
nf_ct_helper_expectfn_find_by_symbol(const void *symbol);
+unsigned int nf_ct_helper_parse_uint(const char *cp, unsigned int len,
+ char **endp);
+int nf_ct_helper_parse_port(const char *cp, unsigned int len,
+ u16 *port, char **endp);
+
extern struct hlist_head *nf_ct_helper_hash;
extern unsigned int nf_ct_helper_hsize;
diff --git a/net/netfilter/nf_conntrack_helper.c b/net/netfilter/nf_conntrack_helper.c
index c30ae3f203be..bcdbe493d412 100644
--- a/net/netfilter/nf_conntrack_helper.c
+++ b/net/netfilter/nf_conntrack_helper.c
@@ -16,6 +16,8 @@
#include <linux/random.h>
#include <linux/err.h>
#include <linux/kernel.h>
+#include <linux/ctype.h>
+#include <linux/limits.h>
#include <linux/netdevice.h>
#include <linux/rculist.h>
#include <linux/rtnetlink.h>
@@ -569,6 +571,83 @@ void nf_nat_helper_unregister(struct nf_conntrack_nat_helper *nat)
}
EXPORT_SYMBOL_GPL(nf_nat_helper_unregister);
+/**
+ * nf_ct_helper_parse_uint - parse a decimal number from a packet buffer
+ * @cp: first byte to parse; the buffer need not be NUL-terminated
+ * @len: number of bytes available at @cp
+ * @endp: if not NULL, set to the byte after the last digit, or to @cp on
+ * error
+ *
+ * Return: the parsed value, or 0 if @cp does not start with a digit, the
+ * digit run is longer than 11 characters, or the value exceeds UINT_MAX.
+ */
+unsigned int nf_ct_helper_parse_uint(const char *cp, unsigned int len,
+ char **endp)
+{
+ const unsigned int max = sizeof("4294967295");
+ unsigned int olen = len;
+ const char *s = cp;
+ u64 result = 0;
+
+ if (len > max)
+ len = max;
+
+ while (olen > 0 && isdigit(*s)) {
+ unsigned int value;
+
+ if (len == 0)
+ goto err;
+
+ value = *s - '0';
+ result = result * 10 + value;
+
+ if (result > UINT_MAX)
+ goto err;
+ s++;
+ len--;
+ olen--;
+ }
+
+ if (endp)
+ *endp = (char *)s;
+
+ return result;
+err:
+ if (endp)
+ *endp = (char *)cp;
+ return 0;
+}
+EXPORT_SYMBOL_GPL(nf_ct_helper_parse_uint);
+
+/**
+ * nf_ct_helper_parse_port - parse a TCP/UDP port number from a packet buffer
+ * @cp: first byte to parse; the buffer need not be NUL-terminated
+ * @len: number of bytes available at @cp
+ * @port: set to the parsed port on success
+ * @endp: if not NULL, set to the byte after the last digit on success
+ *
+ * Return: 0 on success, or -EINVAL if @cp does not start with a digit, the
+ * digit run is longer than five characters, or the value is 0 or above
+ * 65535.
+ */
+int nf_ct_helper_parse_port(const char *cp, unsigned int len,
+ u16 *port, char **endp)
+{
+ char *e = (char *)cp;
+ unsigned int val;
+
+ val = nf_ct_helper_parse_uint(cp, len, &e);
+ if (e == cp || e - cp > 5 || val == 0 || val > 65535)
+ return -EINVAL;
+
+ *port = val;
+ if (endp)
+ *endp = e;
+
+ return 0;
+}
+EXPORT_SYMBOL_GPL(nf_ct_helper_parse_port);
+
int nf_conntrack_helper_init(void)
{
nf_ct_helper_hsize = 1; /* gets rounded up to use one page */
--
2.43.0
^ permalink raw reply related [flat|nested] 7+ messages in thread
* [PATCH nf-next v5 2/4] netfilter: nf_conntrack_irc: use nf_ct_helper_parse_port()
2026-09-28 16:28 [PATCH nf-next v5 0/4] netfilter: conntrack: shared port parser for helpers Rahul Chandelkar
2026-09-28 17:33 ` [PATCH nf-next v5 1/4] netfilter: conntrack: add shared uint and port parsers " Rahul Chandelkar
@ 2026-09-28 18:39 ` Rahul Chandelkar
2026-09-28 19:44 ` [PATCH nf-next v5 3/4] netfilter: nf_conntrack_amanda: " Rahul Chandelkar
` (2 subsequent siblings)
4 siblings, 0 replies; 7+ messages in thread
From: Rahul Chandelkar @ 2026-09-28 18:39 UTC (permalink / raw)
To: Pablo Neira Ayuso
Cc: Jozsef Kadlecsik, Florian Westphal, Phil Sutter, netfilter-devel,
coreteam, davem, edumazet, kuba, pabeni, netdev, Rahul Chandelkar
parse_dcc() stores the result of simple_strtoul() directly into the u16
*port, so a DCC port above 65535 is silently truncated (e.g. 65537
becomes 1) and a conntrack expectation is created for a port that never
appeared in the DCC command.
Use nf_ct_helper_parse_port(), which parses the length-delimited buffer
without relying on NUL termination and rejects port 0, values above
65535 and digit runs longer than five characters.
Since parse_dcc() now fails for port 0, the dcc_port == 0 test in help()
can no longer be true; remove it. A DCC command with port 0 is now
dropped through the "unable to parse dcc command" debug path instead of
the ratelimited "Forged DCC command" warning; no expectation is created
in either case.
Build-tested with allmodconfig and allyesconfig (W=1) and sparse, and
cross-built for i386 and big-endian powerpc. It has not
been run-time tested with IRC traffic.
Fixes: 869f37d8e48f ("[NETFILTER]: nf_conntrack/nf_nat: add IRC helper port")
Assisted-by: Claude-Code:claude-opus-5-5 sparse
Signed-off-by: Rahul Chandelkar <rc@rexion.ai>
---
net/netfilter/nf_conntrack_irc.c | 9 +++++----
1 file changed, 5 insertions(+), 4 deletions(-)
diff --git a/net/netfilter/nf_conntrack_irc.c b/net/netfilter/nf_conntrack_irc.c
index 92360963757a..88c4530c4841 100644
--- a/net/netfilter/nf_conntrack_irc.c
+++ b/net/netfilter/nf_conntrack_irc.c
@@ -88,7 +88,9 @@ static int parse_dcc(char *data, const char *data_end, __be32 *ip,
data++;
}
- *port = simple_strtoul(data, &data, 10);
+ if (nf_ct_helper_parse_port(data, data_end - data, port, &data))
+ return -1;
+
*ad_end_p = data;
return 0;
@@ -206,9 +208,8 @@ static int help(struct sk_buff *skb, unsigned int protoff,
/* dcc_ip can be the internal OR external (NAT'ed) IP */
tuple = &ct->tuplehash[dir].tuple;
- if ((tuple->src.u3.ip != dcc_ip &&
- ct->tuplehash[!dir].tuple.dst.u3.ip != dcc_ip) ||
- dcc_port == 0) {
+ if (tuple->src.u3.ip != dcc_ip &&
+ ct->tuplehash[!dir].tuple.dst.u3.ip != dcc_ip) {
net_warn_ratelimited("Forged DCC command from %pI4: %pI4:%u\n",
&tuple->src.u3.ip,
&dcc_ip, dcc_port);
--
2.43.0
^ permalink raw reply related [flat|nested] 7+ messages in thread
* [PATCH nf-next v5 3/4] netfilter: nf_conntrack_amanda: use nf_ct_helper_parse_port()
2026-09-28 16:28 [PATCH nf-next v5 0/4] netfilter: conntrack: shared port parser for helpers Rahul Chandelkar
2026-09-28 17:33 ` [PATCH nf-next v5 1/4] netfilter: conntrack: add shared uint and port parsers " Rahul Chandelkar
2026-09-28 18:39 ` [PATCH nf-next v5 2/4] netfilter: nf_conntrack_irc: use nf_ct_helper_parse_port() Rahul Chandelkar
@ 2026-09-28 19:44 ` Rahul Chandelkar
2026-09-28 20:49 ` [PATCH nf-next v5 4/4] netfilter: nf_conntrack_sip: use shared helper parsers Rahul Chandelkar
2026-09-28 20:56 ` [PATCH nf-next v5 0/4] netfilter: conntrack: shared port parser for helpers netdev-bot+sinfo
4 siblings, 0 replies; 7+ messages in thread
From: Rahul Chandelkar @ 2026-09-28 19:44 UTC (permalink / raw)
To: Pablo Neira Ayuso
Cc: Jozsef Kadlecsik, Florian Westphal, Phil Sutter, netfilter-devel,
coreteam, davem, edumazet, kuba, pabeni, netdev, Rahul Chandelkar,
Sashiko
amanda_help() passes the result of simple_strtoul() straight through
htons() into a __be16, so values 65536-99999 are truncated (e.g. 65537
becomes 1). In addition, the port field is copied into a buffer that
only holds five digits, so a longer field such as 123456 is cut down to
12345 and accepted as a different port, and on the NAT path only its
first five bytes are mangled. Either way a conntrack expectation is
created for a port that never appeared in the reply.
Make pbuf one byte larger so that a sixth digit is copied, and use
nf_ct_helper_parse_port(), which rejects port 0, values above 65535 and
digit runs longer than five characters. The trailing len is still
derived from the parser's end pointer for the NAT mangle path.
Build-tested with allmodconfig and allyesconfig (W=1) and sparse, and
cross-built for i386 and big-endian powerpc. The parser
was also checked in a userspace harness; the change has not been
run-time tested with Amanda traffic.
Fixes: 16958900578b ("[NETFILTER]: nf_conntrack/nf_nat: add amanda helper port")
Reported-by: Sashiko <netdev-bot+sashiko@kernel.org>
Closes: https://lore.kernel.org/all/179053062399.2160803.9591526412956900613@kernel.org/
Assisted-by: Claude-Code:claude-opus-5-5 sparse
Signed-off-by: Rahul Chandelkar <rc@rexion.ai>
---
net/netfilter/nf_conntrack_amanda.c | 13 +++++++++----
1 file changed, 9 insertions(+), 4 deletions(-)
diff --git a/net/netfilter/nf_conntrack_amanda.c b/net/netfilter/nf_conntrack_amanda.c
index 14ae660491f3..a9c1ef1ee415 100644
--- a/net/netfilter/nf_conntrack_amanda.c
+++ b/net/netfilter/nf_conntrack_amanda.c
@@ -88,7 +88,8 @@ static int amanda_help(struct sk_buff *skb,
struct nf_conntrack_expect *exp;
struct nf_conntrack_tuple *tuple;
unsigned int dataoff, start, stop, off, i;
- char pbuf[sizeof("65535")], *tmp;
+ char pbuf[sizeof("65535") + 1], *tmp;
+ u16 parsed_port;
u16 len;
__be16 port;
int ret = NF_ACCEPT;
@@ -127,15 +128,19 @@ static int amanda_help(struct sk_buff *skb,
continue;
off += start + search[i].len;
+ /*
+ * pbuf holds one byte more than the longest port so that
+ * an over-long digit run is seen and rejected.
+ */
len = min_t(unsigned int, sizeof(pbuf) - 1, stop - off);
if (skb_copy_bits(skb, off, pbuf, len))
break;
pbuf[len] = '\0';
- port = htons(simple_strtoul(pbuf, &tmp, 10));
- len = tmp - pbuf;
- if (port == 0 || len > 5)
+ if (nf_ct_helper_parse_port(pbuf, len, &parsed_port, &tmp))
break;
+ port = htons(parsed_port);
+ len = tmp - pbuf;
exp = nf_ct_expect_alloc(ct);
if (exp == NULL) {
--
2.43.0
^ permalink raw reply related [flat|nested] 7+ messages in thread
* [PATCH nf-next v5 4/4] netfilter: nf_conntrack_sip: use shared helper parsers
2026-09-28 16:28 [PATCH nf-next v5 0/4] netfilter: conntrack: shared port parser for helpers Rahul Chandelkar
` (2 preceding siblings ...)
2026-09-28 19:44 ` [PATCH nf-next v5 3/4] netfilter: nf_conntrack_amanda: " Rahul Chandelkar
@ 2026-09-28 20:49 ` Rahul Chandelkar
2026-09-28 20:56 ` [PATCH nf-next v5 0/4] netfilter: conntrack: shared port parser for helpers netdev-bot+sinfo
4 siblings, 0 replies; 7+ messages in thread
From: Rahul Chandelkar @ 2026-09-28 20:49 UTC (permalink / raw)
To: Pablo Neira Ayuso
Cc: Jozsef Kadlecsik, Florian Westphal, Phil Sutter, netfilter-devel,
coreteam, davem, edumazet, kuba, pabeni, netdev, Rahul Chandelkar
nf_conntrack_sip has its own bounded integer parser, sip_strtouint(),
and its own digit loop in sip_parse_port(). Equivalent parsers now
live in the conntrack helper core, so drop the private copies:
- sip_strtouint() is removed and its callers use
nf_ct_helper_parse_uint(), which has the same body. Call sites
that no longer fit in 80 columns are rewrapped.
- sip_parse_port() uses nf_ct_helper_parse_port() for the numeric
part, keeping the SIP-specific handling of the ':' separator, the
default SIP_PORT and the minimum port of 1024. The shared parser
rejects the same inputs as the old loop: no digits, more than five
digits and values above 65535.
No functional change intended. The old and new sip_parse_port(), taken
from the kernel source, were compared in a userspace harness on three
million random inputs with no difference in result, port or end
pointer.
Assisted-by: Claude-Code:claude-opus-5-5 sparse
Signed-off-by: Rahul Chandelkar <rc@rexion.ai>
---
net/netfilter/nf_conntrack_sip.c | 93 +++++++++-----------------------
1 file changed, 25 insertions(+), 68 deletions(-)
diff --git a/net/netfilter/nf_conntrack_sip.c b/net/netfilter/nf_conntrack_sip.c
index 64bc440b1181..1264e77720a8 100644
--- a/net/netfilter/nf_conntrack_sip.c
+++ b/net/netfilter/nf_conntrack_sip.c
@@ -183,8 +183,8 @@ static int sip_parse_addr(const struct nf_conn *ct, const char *cp,
static bool sip_parse_port(const char *dptr, const char **endp,
const char *limit, __be16 *port)
{
- unsigned int p = 0;
- int len = 0;
+ char *end;
+ u16 p;
if (dptr >= limit)
return false;
@@ -199,29 +199,22 @@ static bool sip_parse_port(const char *dptr, const char **endp,
dptr++; /* skip ':' */
- while (dptr < limit && isdigit(*dptr)) {
- p = p * 10 + (*dptr - '0');
- dptr++;
- len++;
- if (len > 5) /* max "65535" */
- return false;
- }
-
- if (len == 0)
+ if (nf_ct_helper_parse_port(dptr, limit - dptr, &p, &end))
return false;
/* reached limit while parsing port */
- if (dptr >= limit)
+ if (end >= limit)
return false;
- if (p < 1024 || p > 65535)
+ /* SIP ports below 1024 are not accepted */
+ if (p < 1024)
return false;
if (port)
*port = htons(p);
if (endp)
- *endp = dptr;
+ *endp = end;
return true;
}
@@ -270,51 +263,6 @@ static int skp_epaddr_len(const struct nf_conn *ct, const char *dptr,
return epaddr_len(ct, dptr, limit, shift);
}
-/* simple_strtoul stops after first non-number character.
- * But as we're not dealing with c-strings, we can't rely on
- * hitting \r,\n,\0 etc. before moving past end of buffer.
- *
- * This is a variant of simple_strtoul, but doesn't require
- * a c-string.
- *
- * If value exceeds UINT_MAX, 0 is returned.
- */
-static unsigned int sip_strtouint(const char *cp, unsigned int len, char **endp)
-{
- const unsigned int max = sizeof("4294967295");
- unsigned int olen = len;
- const char *s = cp;
- u64 result = 0;
-
- if (len > max)
- len = max;
-
- while (olen > 0 && isdigit(*s)) {
- unsigned int value;
-
- if (len == 0)
- goto err;
-
- value = *s - '0';
- result = result * 10 + value;
-
- if (result > UINT_MAX)
- goto err;
- s++;
- len--;
- olen--;
- }
-
- if (endp)
- *endp = (char *)s;
-
- return result;
-err:
- if (endp)
- *endp = (char *)cp;
- return 0;
-}
-
/* Parse a SIP request line of the form:
*
* Request-Line = Method SP Request-URI SP SIP-Version CRLF
@@ -682,7 +630,7 @@ int ct_sip_parse_numerical_param(const struct nf_conn *ct, const char *dptr,
return 0;
start += strlen(name);
- *val = sip_strtouint(start, limit - start, (char **)&end);
+ *val = nf_ct_helper_parse_uint(start, limit - start, (char **)&end);
if (start == end)
return -1;
if (matchoff && matchlen) {
@@ -1166,7 +1114,9 @@ static int process_sdp(struct sk_buff *skb, unsigned int protoff,
mediaoff += t->len;
medialen -= t->len;
- port = sip_strtouint(*dptr + mediaoff, *datalen - mediaoff, (char **)&end);
+ port = nf_ct_helper_parse_uint(*dptr + mediaoff,
+ *datalen - mediaoff,
+ (char **)&end);
if (port == 0 || *dptr + mediaoff == end)
continue;
if (port < 1024 || port > 65535) {
@@ -1357,7 +1307,8 @@ static int process_register_request(struct sk_buff *skb, unsigned int protoff,
*/
if (ct_sip_get_header(ct, *dptr, 0, *datalen, SIP_HDR_EXPIRES,
&matchoff, &matchlen) > 0)
- expires = sip_strtouint(*dptr + matchoff, *datalen - matchoff, NULL);
+ expires = nf_ct_helper_parse_uint(*dptr + matchoff,
+ *datalen - matchoff, NULL);
ret = ct_sip_parse_header_uri(ct, *dptr, NULL, *datalen,
SIP_HDR_CONTACT, NULL,
@@ -1467,7 +1418,8 @@ static int process_register_response(struct sk_buff *skb, unsigned int protoff,
if (ct_sip_get_header(ct, *dptr, 0, *datalen, SIP_HDR_EXPIRES,
&matchoff, &matchlen) > 0)
- expires = sip_strtouint(*dptr + matchoff, *datalen - matchoff, NULL);
+ expires = nf_ct_helper_parse_uint(*dptr + matchoff,
+ *datalen - matchoff, NULL);
while (1) {
unsigned int c_expires = expires;
@@ -1531,8 +1483,8 @@ static int process_sip_response(struct sk_buff *skb, unsigned int protoff,
if (*datalen < strlen("SIP/2.0 200"))
return NF_ACCEPT;
- code = sip_strtouint(*dptr + strlen("SIP/2.0 "),
- *datalen - strlen("SIP/2.0 "), NULL);
+ code = nf_ct_helper_parse_uint(*dptr + strlen("SIP/2.0 "),
+ *datalen - strlen("SIP/2.0 "), NULL);
if (!code) {
nf_ct_helper_log(skb, ct, "cannot get code");
return NF_DROP;
@@ -1543,7 +1495,8 @@ static int process_sip_response(struct sk_buff *skb, unsigned int protoff,
nf_ct_helper_log(skb, ct, "cannot parse cseq");
return NF_DROP;
}
- cseq = sip_strtouint(*dptr + matchoff, *datalen - matchoff, (char **)&end);
+ cseq = nf_ct_helper_parse_uint(*dptr + matchoff, *datalen - matchoff,
+ (char **)&end);
if (*dptr + matchoff == end) {
nf_ct_helper_log(skb, ct, "cannot get cseq");
return NF_DROP;
@@ -1613,7 +1566,9 @@ static int process_sip_request(struct sk_buff *skb, unsigned int protoff,
nf_ct_helper_log(skb, ct, "cannot parse cseq");
return NF_DROP;
}
- cseq = sip_strtouint(*dptr + matchoff, *datalen - matchoff, (char **)&end);
+ cseq = nf_ct_helper_parse_uint(*dptr + matchoff,
+ *datalen - matchoff,
+ (char **)&end);
if (*dptr + matchoff == end) {
nf_ct_helper_log(skb, ct, "cannot get cseq");
return NF_DROP;
@@ -1690,7 +1645,9 @@ static int sip_help_tcp(struct sk_buff *skb, unsigned int protoff,
&matchoff, &matchlen) <= 0)
break;
- clen = sip_strtouint(dptr + matchoff, datalen - matchoff, (char **)&end);
+ clen = nf_ct_helper_parse_uint(dptr + matchoff,
+ datalen - matchoff,
+ (char **)&end);
if (dptr + matchoff == end)
break;
--
2.43.0
^ permalink raw reply related [flat|nested] 7+ messages in thread
* Re: [PATCH nf-next v5 0/4] netfilter: conntrack: shared port parser for helpers
2026-09-28 16:28 [PATCH nf-next v5 0/4] netfilter: conntrack: shared port parser for helpers Rahul Chandelkar
` (3 preceding siblings ...)
2026-09-28 20:49 ` [PATCH nf-next v5 4/4] netfilter: nf_conntrack_sip: use shared helper parsers Rahul Chandelkar
@ 2026-09-28 20:56 ` netdev-bot+sinfo
2026-09-30 9:57 ` Rahul Chandelkar
4 siblings, 1 reply; 7+ messages in thread
From: netdev-bot+sinfo @ 2026-09-28 20:56 UTC (permalink / raw)
To: Rahul Chandelkar
Cc: Pablo Neira Ayuso, Jozsef Kadlecsik, Florian Westphal,
Phil Sutter, netfilter-devel, coreteam, davem, edumazet, kuba,
pabeni, netdev
Hi!
This is an automated message. This series looks like a fix, but its
commit messages seem to be missing some information:
- How the issue was discovered, e.g. hit in production, hit during
development, syzbot report, manual code inspection, LLM or static
analysis tool scan.
Please do not repost the series just to address the above. Instead,
reply to this email with the missing information, so that reviewers
can take it into account. If the series needs another revision for
other reasons, please include the information in the commit messages
then.
The evaluation is done by an LLM so it may be wrong, if you think
that is the case please reply and explain.
^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH nf-next v5 0/4] netfilter: conntrack: shared port parser for helpers
2026-09-28 20:56 ` [PATCH nf-next v5 0/4] netfilter: conntrack: shared port parser for helpers netdev-bot+sinfo
@ 2026-09-30 9:57 ` Rahul Chandelkar
0 siblings, 0 replies; 7+ messages in thread
From: Rahul Chandelkar @ 2026-09-30 9:57 UTC (permalink / raw)
To: netdev-bot+sinfo
Cc: Rahul Chandelkar, pablo, kadlec, fw, phil, netfilter-devel,
coreteam, davem, edumazet, kuba, pabeni, netdev
> - How the issue was discovered, e.g. hit in production, hit during
> development, syzbot report, manual code inspection, LLM or static
> analysis tool scan.
The IRC and Amanda truncation was found by manual code inspection.
The over-long Amanda field case in 3/4 was reported by the Sashiko
review of v4.
Thanks,
Rahul
^ permalink raw reply [flat|nested] 7+ messages in thread
end of thread, other threads:[~2026-09-30 9:57 UTC | newest]
Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-28 16:28 [PATCH nf-next v5 0/4] netfilter: conntrack: shared port parser for helpers Rahul Chandelkar
2026-09-28 17:33 ` [PATCH nf-next v5 1/4] netfilter: conntrack: add shared uint and port parsers " Rahul Chandelkar
2026-09-28 18:39 ` [PATCH nf-next v5 2/4] netfilter: nf_conntrack_irc: use nf_ct_helper_parse_port() Rahul Chandelkar
2026-09-28 19:44 ` [PATCH nf-next v5 3/4] netfilter: nf_conntrack_amanda: " Rahul Chandelkar
2026-09-28 20:49 ` [PATCH nf-next v5 4/4] netfilter: nf_conntrack_sip: use shared helper parsers Rahul Chandelkar
2026-09-28 20:56 ` [PATCH nf-next v5 0/4] netfilter: conntrack: shared port parser for helpers netdev-bot+sinfo
2026-09-30 9:57 ` Rahul Chandelkar
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.