From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 718E6515964; Wed, 30 Sep 2026 17:05:13 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790787914; cv=none; b=qKWzzLToZ0fRN5V0i5Egu4DM4eLPcivsJOC/wQOep5wFXRYhRaKIRH3kfKpubxkKrLxy9/2EcFGqIMHfK/j3HHnZXFTcQxALKDFMwGmDdt5zBXrsVrW1r2fG13skAc2kCLt+vZicHH03qu0O4WnshoUpNTpGS51gUKkdYq0Q9dA= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790787914; c=relaxed/simple; bh=/BpqMTj1EPiVvGr48Jkkl4qi30wl6GpltEHST3FvQ08=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=qOrxPlEmSMGiQUMMI6gXhz9GGVh0WJ1A9Knu1Ictz/xd/hQXelwBVdmM+dkNrALsGKyNnF5fyWogVdSAXRPtBlceFYzI/lKmDHZjqVoxXLTXHLvyap65QWTW+JbdOlM2eMe4/RvH01yvZK1p4iaUlAW/l3sRq5L0IzmeXy1VtOQ= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=1qGa6Lzy; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="1qGa6Lzy" Received: by smtp.kernel.org (Postfix) with ESMTPSA id CC16F1F000FF; Wed, 30 Sep 2026 17:05:12 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790787913; bh=/DuTZlK6Xj0g/4HEP58gKYIDEHc5pQzVvyg8QHGl8WQ=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=1qGa6LzyFl4C7buGiSrzcp/zQTZZvGQLkciEd+2Lecf6rzhI0/GyK+KJTFskQubV3 O8mm02/d7qIho/2pxVhmzHkSAA/JgPDgUOgnmXb2F8kkYXsPdKD2W+BGzKT3h2hPQ2 6No+XI/J2fE1xruHSDfpPbZAGAR5HT3I8yjpdjHI= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, TencentOS Corvus AI , Aohan Mei , Pablo Neira Ayuso Subject: [PATCH 7.2 352/457] netfilter: nf_tables: skip expired catchall elements on insert and delete Date: Wed, 30 Sep 2026 17:27:37 +0200 Message-ID: <20260930152353.607618744@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260930152346.024115587@linuxfoundation.org> References: <20260930152346.024115587@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 7.2-stable review patch. If anyone has any objections, please let me know. ------------------ From: Aohan Mei commit 70194dc37670bd08e44b471389861cc01bd3a3c9 upstream. nft_setelem_catchall_insert() looks up duplicates with nft_set_elem_active() only, while nft_set_catchall_lookup() and the dump path additionally skip expired elements. Once a catchall element with a timeout expires, this predicate drift makes it invisible to userspace dumps, yet it still blocks re-insertion: with NLM_F_EXCL the request fails with -EEXIST, and without it the request reports success but silently inserts nothing. The stale entry only goes away when the (user-tunable) gc interval elapses, so the catchall rule may silently stop matching for an arbitrarily long time after its first expiration. The delete path shows the same drift: nft_setelem_catchall_deactivate() picks the first active-next entry in the catchall list, so with an expired entry still pending GC it retires the stale entry instead of the fresh one, and it deactivates an element that userspace no longer sees instead of failing with -ENOENT. Align both walks with the lookup and dump predicates: only an element that is active and not expired counts as a duplicate or delete candidate, using the per-netns timestamp taken at transaction start, in line with the set backend .insert/.deactivate and catchall GC sync paths. Reported-by: TencentOS Corvus AI Cc: stable@vger.kernel.org Fixes: aaa31047a6d2 ("netfilter: nftables: add catch-all set element support") Assisted-by: CodeBuddy:Kimi-K3 Signed-off-by: Aohan Mei Signed-off-by: Pablo Neira Ayuso Signed-off-by: Greg Kroah-Hartman --- net/netfilter/nf_tables_api.c | 10 ++++++++-- 1 file changed, 8 insertions(+), 2 deletions(-) --- a/net/netfilter/nf_tables_api.c +++ b/net/netfilter/nf_tables_api.c @@ -6990,11 +6990,14 @@ static int nft_setelem_catchall_insert(c { struct nft_set_elem_catchall *catchall; u8 genmask = nft_genmask_next(net); + u64 tstamp = nft_net_tstamp(net); struct nft_set_ext *ext; list_for_each_entry(catchall, &set->catchall_list, list) { ext = nft_set_elem_ext(set, catchall->elem); - if (nft_set_elem_active(ext, genmask)) { + if (nft_set_elem_active(ext, genmask) && + !__nft_set_elem_expired(ext, tstamp) && + !nft_set_elem_is_dead(ext)) { *priv = catchall->elem; return -EEXIST; } @@ -7087,11 +7090,14 @@ static int nft_setelem_catchall_deactiva struct nft_set_elem *elem) { struct nft_set_elem_catchall *catchall; + u64 tstamp = nft_net_tstamp(net); struct nft_set_ext *ext; list_for_each_entry(catchall, &set->catchall_list, list) { ext = nft_set_elem_ext(set, catchall->elem); - if (!nft_is_active_next(net, ext)) + if (!nft_is_active_next(net, ext) || + __nft_set_elem_expired(ext, tstamp) || + nft_set_elem_is_dead(ext)) continue; kfree(elem->priv);