Netdev List
 help / color / mirror / Atom feed
From: Pablo Neira Ayuso <pablo@netfilter.org>
To: netfilter-devel@vger.kernel.org
Cc: davem@davemloft.net, netdev@vger.kernel.org, kuba@kernel.org,
	pabeni@redhat.com, edumazet@google.com, horms@kernel.org,
	fw@strlen.de, ja@ssi.bg
Subject: [PATCH net-next 00/11] Netfilter updates for net-next
Date: Mon, 28 Sep 2026 00:34:25 +0200	[thread overview]
Message-ID: <20260927223436.269024-1-pablo@netfilter.org> (raw)

Hi,

The following patchset contains Netfilter updates for net-next. The
fixes included in this batch are deemed to handle correctness issues
present in the Netfilter tree:

1) TCP sequence tracking is not reset inconditionally by synproxy when
   recycling an entry, sashiko reports the zero offset case skips it.
   Add a new function to inconditionally reset TCP sequence tracking.
   From Fernando F. Mancera.

2) Update documentation to reflect that the default maximum number of
   expectations (nf_conntrack_expect_max) is nf_conntrack_buckets / 64.
   From Shaojie Sun.

3) Remove useless break; after return in nft_osf, from Linkui Xiao.

4) Fix typos in comments in the netfilter tree, from Hemanth Selam.

5) Remove a few conntrack error stats duplicated updates,
   from Phil Sutter.

6) Do not bump invalid and drop conntrack error stats when packet is
   dropped, this is another duplicate. also From Phil.

7) Set on netns pointer before registering the flowtable, this is
   a requirement by the next patch, not fixing an existing issue.
   From Qingfang Deng.

8) Remove unnecessary workqueue work flush for all of the existing
   netns when device is gone. Also from Qingfang Deng.

9) Rework-fix nfnetlink_hook to correctly deal with large netlink
   dumps. Use sequence numbers to detect interference with hook
   updates while netlink dump is ongoing. From Phil Sutter.

10) Fix ctnetlink dump filtering by the IPv6 address, this has
    only work correctly for IPv4 this far, from Piotr Kubik.

11) ctnetlink filtering by zone is supported, but the ctnetlink
    dump filtering infrastructure was never updated to include a
    flag from userspace, update it to fill this gap.
    From Ilya Maximets.

Please, pull these changes from:

  git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf-next.git nf-next-26-09-28

Thanks.

----------------------------------------------------------------

The following changes since commit 014d795c73837ea2339a4ea8e8f82c6e959b845d:

  idpf: fix kernel-doc parameter descriptions (2026-09-25 18:26:50 -0700)

are available in the Git repository at:

  git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf-next.git nf-next-26-09-28

for you to fetch changes up to 46da6029bf468ce3c426cb8b4abf96976ed9d4c8:

  netfilter: conntrack: make filtering by zone discoverable (2026-09-27 23:39:21 +0200)

----------------------------------------------------------------
netfilter pull request 26-09-28

----------------------------------------------------------------
Fernando Fernandez Mancera (1):
      netfilter: synproxy: fix reset of ct seqadj when reopening a connection

Hemanth Selam (1):
      netfilter: fix several typos in comments

Ilya Maximets (1):
      netfilter: conntrack: make filtering by zone discoverable

Linkui Xiao (1):
      netfilter: osf: remove unreachable break in nf_osf_ttl()

Phil Sutter (3):
      netfilter: conntrack: Untangle insert_failed counter from others
      netfilter: conntrack: Untangle drop and invalid counters
      netfilter: nfnetlink: Fix for interrupted hook dumps

Piotr Kubik (1):
      netfilter: ctnetlink: fix inverted IPv6 address match in dump filter

Qingfang Deng (2):
      net/sched: act_ct: set net pointer before publishing flowtable
      netfilter: flowtable: check namespace before iterating flows

Shaojie Sun (1):
      netfilter: conntrack: fix nf_conntrack_expect_max default value in documentation

 Documentation/netlink/specs/conntrack.yaml         |   6 +
 Documentation/networking/nf_conntrack-sysctl.rst   |   2 +-
 include/net/netfilter/nf_conntrack_seqadj.h        |   1 +
 include/net/netns/netfilter.h                      |   2 +
 include/uapi/linux/netfilter/nfnetlink_conntrack.h |   1 +
 net/ipv4/netfilter/arp_tables.c                    |   2 +-
 net/netfilter/core.c                               |  18 ++-
 net/netfilter/ipset/ip_set_core.c                  |   2 +-
 net/netfilter/ipvs/ip_vs_sync.c                    |   2 +-
 net/netfilter/nf_conntrack_core.c                  |   5 +-
 net/netfilter/nf_conntrack_netlink.c               |  19 ++-
 net/netfilter/nf_conntrack_seqadj.c                |  17 +++
 net/netfilter/nf_flow_table_core.c                 |  17 +--
 net/netfilter/nf_nat_core.c                        |  11 ++
 net/netfilter/nf_synproxy_core.c                   |   4 +-
 net/netfilter/nfnetlink_hook.c                     |  74 ++++++-----
 net/netfilter/nfnetlink_osf.c                      |   1 -
 net/sched/act_ct.c                                 |   2 +-
 .../selftests/net/netfilter/conntrack_dump_flush.c | 145 ++++++++++++++-------
 .../net/netfilter/conntrack_icmp_related.sh        |   2 +-
 20 files changed, 229 insertions(+), 104 deletions(-)

             reply	other threads:[~2026-09-27 22:34 UTC|newest]

Thread overview: 36+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-27 22:34 Pablo Neira Ayuso [this message]
2026-09-27 22:34 ` [PATCH net-next 01/11] netfilter: synproxy: fix reset of ct seqadj when reopening a connection Pablo Neira Ayuso
2026-09-27 22:40   ` netdev-bot+sinfo
2026-09-27 23:04     ` Pablo Neira Ayuso
2026-10-04 19:26       ` Pablo Neira Ayuso
2026-10-05 13:04         ` Ilya Maximets
2026-10-05 20:53           ` Pablo Neira Ayuso
2026-09-29  2:40   ` patchwork-bot+netdevbpf
2026-09-27 22:34 ` [PATCH net-next 02/11] netfilter: conntrack: fix nf_conntrack_expect_max default value in documentation Pablo Neira Ayuso
2026-09-27 22:34 ` [PATCH net-next 03/11] netfilter: osf: remove unreachable break in nf_osf_ttl() Pablo Neira Ayuso
2026-09-27 22:34 ` [PATCH net-next 04/11] netfilter: fix several typos in comments Pablo Neira Ayuso
2026-09-27 22:34 ` [PATCH net-next 05/11] netfilter: conntrack: Untangle insert_failed counter from others Pablo Neira Ayuso
2026-09-27 22:34 ` [PATCH net-next 06/11] netfilter: conntrack: Untangle drop and invalid counters Pablo Neira Ayuso
2026-09-27 22:34 ` [PATCH net-next 07/11] net/sched: act_ct: set net pointer before publishing flowtable Pablo Neira Ayuso
2026-09-27 22:34 ` [PATCH net-next 08/11] netfilter: flowtable: check namespace before iterating flows Pablo Neira Ayuso
2026-09-27 22:34 ` [PATCH net-next 09/11] netfilter: nfnetlink: Fix for interrupted hook dumps Pablo Neira Ayuso
2026-09-27 22:34 ` [PATCH net-next 10/11] netfilter: ctnetlink: fix inverted IPv6 address match in dump filter Pablo Neira Ayuso
2026-09-27 22:34 ` [PATCH net-next 11/11] netfilter: conntrack: make filtering by zone discoverable Pablo Neira Ayuso
  -- strict thread matches above, loose matches on Subject: below --
2026-05-25 18:29 [PATCH net-next 00/11] netfilter: updates for net-next Florian Westphal
2026-04-10 11:23 Florian Westphal
2026-04-12 16:40 ` Jakub Kicinski
2026-04-12 16:54   ` Florian Westphal
2026-04-12 17:17     ` Florian Westphal
2026-04-12 18:58       ` Pablo Neira Ayuso
2026-04-12 17:53     ` Jakub Kicinski
2026-04-12 18:07       ` Julian Anastasov
2026-02-05 11:08 Florian Westphal
2026-02-06 12:41 ` Florian Westphal
2024-11-06 23:46 [PATCH net-next 00/11] Netfilter " Pablo Neira Ayuso
2024-11-07  0:19 ` Jakub Kicinski
2024-11-07  7:08   ` Florian Westphal
2024-11-07 20:48     ` Jakub Kicinski
2024-11-07 21:07       ` Florian Westphal
2024-11-07 21:09       ` Eric Dumazet
2022-05-19 22:01 Pablo Neira Ayuso
2022-04-11 10:27 Pablo Neira Ayuso

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260927223436.269024-1-pablo@netfilter.org \
    --to=pablo@netfilter.org \
    --cc=davem@davemloft.net \
    --cc=edumazet@google.com \
    --cc=fw@strlen.de \
    --cc=horms@kernel.org \
    --cc=ja@ssi.bg \
    --cc=kuba@kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=netfilter-devel@vger.kernel.org \
    --cc=pabeni@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox