* [PATCH net-next 00/11] Netfilter updates for net-next
@ 2022-04-11 10:27 Pablo Neira Ayuso
0 siblings, 0 replies; 36+ messages in thread
From: Pablo Neira Ayuso @ 2022-04-11 10:27 UTC (permalink / raw)
To: netfilter-devel; +Cc: davem, netdev, kuba
Hi,
The following patchset contains Netfilter updates for net-next:
1) Replace unnecessary list_for_each_entry_continue() in nf_tables,
from Jakob Koschel.
2) Add struct nf_conntrack_net_ecache to conntrack event cache and
use it, from Florian Westphal.
3) Refactor ctnetlink_dump_list(), also from Florian.
4) Bump module reference counter on cttimeout object addition/removal,
from Florian.
5) Consolidate nf_log MAC printer, from Phil Sutter.
6) Add basic logging support for unknown ethertype, from Phil Sutter.
7) Consolidate check for sysctl nf_log_all_netns toggle, also from Phil.
8) Replace hardcode value in nft_bitwise, from Jeremy Sowden.
9) Rename BASIC-like goto tags in nft_bitwise to more meaningful names,
also from Jeremy.
10) nft_fib support for reverse path filtering with policy-based routing
on iif. Extend selftests to cover for this new usecase, from Florian.
Please, pull these changes from:
git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf-next.git
Thanks.
----------------------------------------------------------------
The following changes since commit 2975dbdc3989cd66a4cb5a7c5510de2de8ee4d14:
Merge tag 'net-5.18-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net (2022-03-31 11:23:31 -0700)
are available in the Git repository at:
git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf-next.git HEAD
for you to fetch changes up to 0c7b27616fbd64b3b86c59ad5441f82a1a0c4176:
selftests: netfilter: add fib expression forward test case (2022-04-11 12:10:09 +0200)
----------------------------------------------------------------
Florian Westphal (4):
netfilter: ecache: move to separate structure
netfilter: conntrack: split inner loop of list dumping to own function
netfilter: cttimeout: inc/dec module refcount per object, not per use refcount
selftests: netfilter: add fib expression forward test case
Jakob Koschel (1):
netfilter: nf_tables: replace unnecessary use of list_for_each_entry_continue()
Jeremy Sowden (2):
netfilter: bitwise: replace hard-coded size with `sizeof` expression
netfilter: bitwise: improve error goto labels
Pablo Neira Ayuso (1):
netfilter: nft_fib: reverse path filter for policy-based routing on iif
Phil Sutter (3):
netfilter: nf_log_syslog: Merge MAC header dumpers
netfilter: nf_log_syslog: Don't ignore unknown protocols
netfilter: nf_log_syslog: Consolidate entry checks
include/net/netfilter/nf_conntrack.h | 8 +-
net/ipv4/netfilter/nft_fib_ipv4.c | 4 +
net/ipv6/netfilter/nft_fib_ipv6.c | 4 +
net/netfilter/nf_conntrack_ecache.c | 19 ++--
net/netfilter/nf_conntrack_netlink.c | 68 +++++++++-----
net/netfilter/nf_log_syslog.c | 136 +++++++++++++--------------
net/netfilter/nf_tables_api.c | 6 +-
net/netfilter/nfnetlink_cttimeout.c | 14 +--
net/netfilter/nft_bitwise.c | 13 +--
net/netfilter/nft_fib.c | 4 +
tools/testing/selftests/netfilter/nft_fib.sh | 50 ++++++++++
11 files changed, 199 insertions(+), 127 deletions(-)
^ permalink raw reply [flat|nested] 36+ messages in thread
* [PATCH net-next 00/11] Netfilter updates for net-next
@ 2022-05-19 22:01 Pablo Neira Ayuso
0 siblings, 0 replies; 36+ messages in thread
From: Pablo Neira Ayuso @ 2022-05-19 22:01 UTC (permalink / raw)
To: netfilter-devel; +Cc: davem, netdev, kuba, pabeni
Hi,
The following patchset contains Netfilter updates for net-next, misc
updates and fallout fixes from recent Florian's code rewritting (from
last pull request):
1) Use new flowi4_l3mdev field in ip_route_me_harder(), from Martin Willi.
2) Avoid unnecessary GC with a timestamp in conncount, from William Tu
and Yifeng Sun.
3) Remove TCP conntrack debugging, from Florian Westphal.
4) Fix compilation warning in ctnetlink, from Florian.
5) Add flowtable entry count and limit hw entries toggles, from
Vlad Buslov and Oz Shlomo.
6) Add flowtable in-flight workqueue objects count, also from Vlad and Oz.
7) syzbot warning in nfnetlink bind, from Florian.
8) Refetch conntrack after __nf_conntrack_confirm(), from Florian Westphal.
9) Move struct nf_ct_timeout back at the bottom of the ctnl_time, to
where it before recent update, also from Florian.
10) A few NL_SET_BAD_ATTR() for nf_tables netlink set element commands.
Please, pull these changes from:
git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf-next.git
Thanks.
----------------------------------------------------------------
The following changes since commit 5cf15ce3c8f1ef431dc9fa845c6d1674f630ecd1:
Merge branch 'Renesas-RSZ-V2M-support' (2022-05-16 10:14:27 +0100)
are available in the Git repository at:
git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf-next.git HEAD
for you to fetch changes up to eb6fb4d6ecbcfd69dfc36fbedbafc9860aeef1e4:
netfilter: nf_tables: set element extended ACK reporting support (2022-05-19 22:39:50 +0200)
----------------------------------------------------------------
Florian Westphal (4):
netfilter: conntrack: remove pr_debug callsites from tcp tracker
netfilter: nfnetlink: fix warn in nfnetlink_unbind
netfilter: conntrack: re-fetch conntrack after insertion
netfilter: cttimeout: fix slab-out-of-bounds read in cttimeout_net_exit
Martin Willi (1):
netfilter: Use l3mdev flow key when re-routing mangled packets
Pablo Neira Ayuso (1):
netfilter: nf_tables: set element extended ACK reporting support
Stephen Rothwell (1):
netfilter: ctnetlink: fix up for "netfilter: conntrack: remove unconfirmed list"
Vlad Buslov (3):
net/sched: act_ct: set 'net' pointer when creating new nf_flow_table
netfilter: nf_flow_table: count and limit hw offloaded entries
netfilter: nf_flow_table: count pending offload workqueue tasks
William Tu (1):
netfilter: nf_conncount: reduce unnecessary GC
Documentation/networking/nf_conntrack-sysctl.rst | 9 ++
include/net/net_namespace.h | 6 +
include/net/netfilter/nf_conntrack_core.h | 7 +-
include/net/netfilter/nf_conntrack_count.h | 1 +
include/net/netfilter/nf_flow_table.h | 57 +++++++++
include/net/netns/flow_table.h | 14 +++
net/ipv4/netfilter.c | 3 +-
net/ipv6/netfilter.c | 3 +-
net/netfilter/Kconfig | 9 ++
net/netfilter/Makefile | 1 +
net/netfilter/nf_conncount.c | 11 ++
net/netfilter/nf_conntrack_netlink.c | 2 +
net/netfilter/nf_conntrack_proto_tcp.c | 52 +-------
net/netfilter/nf_flow_table_core.c | 89 +++++++++++++-
net/netfilter/nf_flow_table_offload.c | 55 +++++++--
net/netfilter/nf_flow_table_sysctl.c | 148 +++++++++++++++++++++++
net/netfilter/nf_tables_api.c | 12 +-
net/netfilter/nfnetlink.c | 24 +---
net/netfilter/nfnetlink_cttimeout.c | 5 +-
net/sched/act_ct.c | 5 +-
20 files changed, 423 insertions(+), 90 deletions(-)
create mode 100644 include/net/netns/flow_table.h
create mode 100644 net/netfilter/nf_flow_table_sysctl.c
^ permalink raw reply [flat|nested] 36+ messages in thread
* [PATCH net-next 00/11] Netfilter updates for net-next
@ 2024-11-06 23:46 Pablo Neira Ayuso
2024-11-07 0:19 ` Jakub Kicinski
0 siblings, 1 reply; 36+ messages in thread
From: Pablo Neira Ayuso @ 2024-11-06 23:46 UTC (permalink / raw)
To: netfilter-devel; +Cc: davem, netdev, kuba, pabeni, edumazet, fw
Hi,
The following series contains Netfilter updates for net-next:
1) Make legacy xtables configs user selectable, from Breno Leitao.
2) Fix a few sparse warnings related to percpu, from Uros Bizjak.
3) Use strscpy_pad, from Justin Stitt.
4) Use nft_trans_elem_alloc() in catchall flush, from Florian Westphal.
5) A series of 7 patches to fix false positive with CONFIG_RCU_LIST=y.
Florian also sees possible issue with 10 while module load/removal
when requesting an expression that is available via module. As for
patch 11, object is being updated so reference on the module already
exists so I don't see any real issue.
Florian says:
"Unfortunately there are many more errors, and not all are false positives.
First patches pass lockdep_commit_lock_is_held() to the rcu list traversal
macro so that those splats are avoided.
The last two patches are real code change as opposed to
'pass the transaction mutex to relax rcu check':
Those two lists are not protected by transaction mutex so could be altered
in parallel.
This targets nf-next because these are long-standing issues."
Please, pull these changes from:
git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf-next.git nf-next-24-11-07
Thanks.
----------------------------------------------------------------
The following changes since commit f66ebf37d69cc700ca884c6a18c2258caf8b151b:
Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net (2024-10-03 10:05:55 -0700)
are available in the Git repository at:
git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf-next.git nf-next-24-11-07
for you to fetch changes up to cddc04275f95ca3b18da5c0fb111705ac173af89:
netfilter: nf_tables: must hold rcu read lock while iterating object type list (2024-11-05 22:07:12 +0100)
----------------------------------------------------------------
netfilter pull request 24-11-07
----------------------------------------------------------------
Breno Leitao (1):
netfilter: Make legacy configs user selectable
Florian Westphal (8):
netfilter: nf_tables: prefer nft_trans_elem_alloc helper
netfilter: nf_tables: avoid false-positive lockdep splat on rule deletion
netfilter: nf_tables: avoid false-positive lockdep splats with sets
netfilter: nf_tables: avoid false-positive lockdep splats with flowtables
netfilter: nf_tables: avoid false-positive lockdep splats in set walker
netfilter: nf_tables: avoid false-positive lockdep splats with basechain hook
netfilter: nf_tables: must hold rcu read lock while iterating expression type list
netfilter: nf_tables: must hold rcu read lock while iterating object type list
Justin Stitt (1):
netfilter: nf_tables: replace deprecated strncpy with strscpy_pad
Uros Bizjak (1):
netfilter: nf_tables: Fix percpu address space issues in nf_tables_api.c
include/net/netfilter/nf_tables.h | 3 +-
net/bridge/netfilter/Kconfig | 8 +-
net/bridge/netfilter/nft_meta_bridge.c | 2 +-
net/ipv4/netfilter/Kconfig | 16 +++-
net/ipv6/netfilter/Kconfig | 9 ++-
net/netfilter/nf_tables_api.c | 132 +++++++++++++++++++--------------
net/netfilter/nft_flow_offload.c | 4 +-
net/netfilter/nft_set_bitmap.c | 10 ++-
net/netfilter/nft_set_hash.c | 3 +-
9 files changed, 119 insertions(+), 68 deletions(-)
^ permalink raw reply [flat|nested] 36+ messages in thread
* Re: [PATCH net-next 00/11] Netfilter updates for net-next
2024-11-06 23:46 [PATCH net-next 00/11] Netfilter " Pablo Neira Ayuso
@ 2024-11-07 0:19 ` Jakub Kicinski
2024-11-07 7:08 ` Florian Westphal
0 siblings, 1 reply; 36+ messages in thread
From: Jakub Kicinski @ 2024-11-07 0:19 UTC (permalink / raw)
To: Pablo Neira Ayuso, fw; +Cc: netfilter-devel, davem, netdev, pabeni, edumazet
On Thu, 7 Nov 2024 00:46:14 +0100 Pablo Neira Ayuso wrote:
> "Unfortunately there are many more errors, and not all are false positives.
Thanks a lot for jumping on fixing the CONFIG_RCU_LIST=y splats!
To clarify should the selftests be splat-free now or there is more
work required to get there?
^ permalink raw reply [flat|nested] 36+ messages in thread
* Re: [PATCH net-next 00/11] Netfilter updates for net-next
2024-11-07 0:19 ` Jakub Kicinski
@ 2024-11-07 7:08 ` Florian Westphal
2024-11-07 20:48 ` Jakub Kicinski
0 siblings, 1 reply; 36+ messages in thread
From: Florian Westphal @ 2024-11-07 7:08 UTC (permalink / raw)
To: Jakub Kicinski
Cc: Pablo Neira Ayuso, fw, netfilter-devel, davem, netdev, pabeni,
edumazet
Jakub Kicinski <kuba@kernel.org> wrote:
> On Thu, 7 Nov 2024 00:46:14 +0100 Pablo Neira Ayuso wrote:
> > "Unfortunately there are many more errors, and not all are false positives.
>
> Thanks a lot for jumping on fixing the CONFIG_RCU_LIST=y splats!
> To clarify should the selftests be splat-free now or there is more
> work required to get there?
I tried to repro last week on net-next (not nf-next!) + v2 of these patches
and I did not see splats, but I'll re-run everything later today to make
sure they've been fixed up.
^ permalink raw reply [flat|nested] 36+ messages in thread
* Re: [PATCH net-next 00/11] Netfilter updates for net-next
2024-11-07 7:08 ` Florian Westphal
@ 2024-11-07 20:48 ` Jakub Kicinski
2024-11-07 21:07 ` Florian Westphal
2024-11-07 21:09 ` Eric Dumazet
0 siblings, 2 replies; 36+ messages in thread
From: Jakub Kicinski @ 2024-11-07 20:48 UTC (permalink / raw)
To: Florian Westphal
Cc: Pablo Neira Ayuso, netfilter-devel, davem, netdev, pabeni,
edumazet
On Thu, 7 Nov 2024 08:08:34 +0100 Florian Westphal wrote:
> Jakub Kicinski <kuba@kernel.org> wrote:
> > On Thu, 7 Nov 2024 00:46:14 +0100 Pablo Neira Ayuso wrote:
> > > "Unfortunately there are many more errors, and not all are false positives.
> >
> > Thanks a lot for jumping on fixing the CONFIG_RCU_LIST=y splats!
> > To clarify should the selftests be splat-free now or there is more
> > work required to get there?
>
> I tried to repro last week on net-next (not nf-next!) + v2 of these patches
> and I did not see splats, but I'll re-run everything later today to make
> sure they've been fixed up.
Great! I was double checking if you know of any selftest-triggered
problems before I re-enable that config in our CI.
I flipped it back on few hours ago and looks like it's only hitting
mcast routing and sctp bugs we already know about, so all good :)
Thanks again!
^ permalink raw reply [flat|nested] 36+ messages in thread
* Re: [PATCH net-next 00/11] Netfilter updates for net-next
2024-11-07 20:48 ` Jakub Kicinski
@ 2024-11-07 21:07 ` Florian Westphal
2024-11-07 21:09 ` Eric Dumazet
1 sibling, 0 replies; 36+ messages in thread
From: Florian Westphal @ 2024-11-07 21:07 UTC (permalink / raw)
To: Jakub Kicinski
Cc: Florian Westphal, Pablo Neira Ayuso, netfilter-devel, davem,
netdev, pabeni, edumazet
Jakub Kicinski <kuba@kernel.org> wrote:
> > I tried to repro last week on net-next (not nf-next!) + v2 of these patches
> > and I did not see splats, but I'll re-run everything later today to make
> > sure they've been fixed up.
>
> Great! I was double checking if you know of any selftest-triggered
> problems before I re-enable that config in our CI.
The only splat I saw today on re-run is in kernel/events/core.c, but
Matthieu Baerts tells me there is a fix pending for it.
> I flipped it back on few hours ago and looks like it's only hitting
> mcast routing and sctp bugs we already know about, so all good :)
Great. It finds real bugs so its good that it can be turned on again
to catch future issues.
^ permalink raw reply [flat|nested] 36+ messages in thread
* Re: [PATCH net-next 00/11] Netfilter updates for net-next
2024-11-07 20:48 ` Jakub Kicinski
2024-11-07 21:07 ` Florian Westphal
@ 2024-11-07 21:09 ` Eric Dumazet
1 sibling, 0 replies; 36+ messages in thread
From: Eric Dumazet @ 2024-11-07 21:09 UTC (permalink / raw)
To: Jakub Kicinski
Cc: Florian Westphal, Pablo Neira Ayuso, netfilter-devel, davem,
netdev, pabeni
On Thu, Nov 7, 2024 at 9:48 PM Jakub Kicinski <kuba@kernel.org> wrote:
>
> On Thu, 7 Nov 2024 08:08:34 +0100 Florian Westphal wrote:
> > Jakub Kicinski <kuba@kernel.org> wrote:
> > > On Thu, 7 Nov 2024 00:46:14 +0100 Pablo Neira Ayuso wrote:
> > > > "Unfortunately there are many more errors, and not all are false positives.
> > >
> > > Thanks a lot for jumping on fixing the CONFIG_RCU_LIST=y splats!
> > > To clarify should the selftests be splat-free now or there is more
> > > work required to get there?
> >
> > I tried to repro last week on net-next (not nf-next!) + v2 of these patches
> > and I did not see splats, but I'll re-run everything later today to make
> > sure they've been fixed up.
>
> Great! I was double checking if you know of any selftest-triggered
> problems before I re-enable that config in our CI.
>
> I flipped it back on few hours ago and looks like it's only hitting
> mcast routing and sctp bugs we already know about, so all good :)
>
sctp fix :
https://patchwork.kernel.org/project/netdevbpf/patch/20241107192021.2579789-1-edumazet@google.com/
^ permalink raw reply [flat|nested] 36+ messages in thread
* [PATCH net-next 00/11] netfilter: updates for net-next
@ 2026-02-05 11:08 Florian Westphal
2026-02-06 12:41 ` Florian Westphal
0 siblings, 1 reply; 36+ messages in thread
From: Florian Westphal @ 2026-02-05 11:08 UTC (permalink / raw)
To: netdev
Cc: Paolo Abeni, David S. Miller, Eric Dumazet, Jakub Kicinski,
netfilter-devel, pablo
The following patchset contains Netfilter updates for *net-next*:
1) Fix net-next-only use-after-free bug in nf_tables rbtree set:
Expired elements cannot be released right away after unlink anymore
because there is no guarantee that the binary-search blob is going to
be updated. Spotted by syzkaller.
2) Fix esoteric bug in nf_queue with udp fraglist gro, broken since
6.11. Patch 3 adds extends the nfqueue selftest for this.
4) Use dedicated slab for flowtable entries, currently the -512 cache
is used, which is wasteful. From Qingfang Deng.
5) Recent net-next update extended existing test for ip6ip6 tunnels, add
the required /config entry. Test still passed by accident because the
previous tests network setup gets re-used, so also update the test so
it will fail in case the ip6ip6 tunnel interface cannot be added.
6) Fix 'nft get element mytable myset { 1.2.3.4 }' on big endian
platforms, this was broken since code was added in v5.1.
7-10) update nf_tables rbtree set type to detect partial
operlaps. This will eventually speed up nftables userspace: at this
time userspace does a netlink dump of the set content which slows down
incremental updates on interval sets. From Pablo Neira Ayuso.
11) fixes nf_tables counter reset support on 32bit platforms, where counter
reset may cause huge values to appear due to wraparound.
Broken since reset feature was added in v6.11. From Anders Grahn.
Please, pull these changes from:
https://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf-next.git tags/nf-next-26-02-05
for you to fetch changes up to bd3aaea1ae36e2931ddb8e40464a4cd3cfa43bf6:
netfilter: nft_counter: fix reset of counters on 32bit archs (2026-02-05 11:45:28 +0100)
----------------------------------------------------------------
netfilter pull request nf-next-26-02-05
----------------------------------------------------------------
Anders Grahn (1):
netfilter: nft_counter: fix reset of counters on 32bit archs
Florian Westphal (5):
netfilter: nft_set_rbtree: don't gc elements on insert
netfilter: nfnetlink_queue: do shared-unconfirmed check before segmentation
selftests: netfilter: nft_queue.sh: add udp fraglist gro test case
selftests: netfilter: add IPV6_TUNNEL to config
netfilter: nft_set_hash: fix get operation on big endian
Pablo Neira Ayuso (4):
netfilter: nft_set_rbtree: fix bogus EEXIST with NLM_F_CREATE with null interval
netfilter: nft_set_rbtree: check for partial overlaps in anonymous sets
netfilter: nft_set_rbtree: validate element belonging to interval
netfilter: nft_set_rbtree: validate open interval overlap
Qingfang Deng (1):
netfilter: flowtable: dedicated slab for flow entry
include/linux/u64_stats_sync.h | 10 +
include/net/netfilter/nf_queue.h | 1 +
include/net/netfilter/nf_tables.h | 4 +
net/netfilter/nf_flow_table_core.c | 12 +-
net/netfilter/nf_tables_api.c | 26 +-
net/netfilter/nfnetlink_queue.c | 123 +++---
net/netfilter/nft_counter.c | 4 +-
net/netfilter/nft_set_hash.c | 9 +-
net/netfilter/nft_set_rbtree.c | 376 ++++++++++++++----
tools/testing/selftests/net/netfilter/config | 1 +
.../selftests/net/netfilter/nft_flowtable.sh | 19 +-
.../selftests/net/netfilter/nft_queue.sh | 142 ++++++-
12 files changed, 579 insertions(+), 148 deletions(-)
--
2.52.0
^ permalink raw reply [flat|nested] 36+ messages in thread
* Re: [PATCH net-next 00/11] netfilter: updates for net-next
2026-02-05 11:08 Florian Westphal
@ 2026-02-06 12:41 ` Florian Westphal
0 siblings, 0 replies; 36+ messages in thread
From: Florian Westphal @ 2026-02-06 12:41 UTC (permalink / raw)
To: netdev
Cc: Paolo Abeni, David S. Miller, Eric Dumazet, Jakub Kicinski,
netfilter-devel, pablo
Florian Westphal <fw@strlen.de> wrote:
> The following patchset contains Netfilter updates for *net-next*:
> 7-10) update nf_tables rbtree set type to detect partial
> operlaps. This will eventually speed up nftables userspace: at this
> time userspace does a netlink dump of the set content which slows down
> incremental updates on interval sets. From Pablo Neira Ayuso.
Pablo has submitted v3 addressing AI detected issues, I will send a v2
in ~3 hrs, no changes except in those 4 patches.
^ permalink raw reply [flat|nested] 36+ messages in thread
* [PATCH net-next 00/11] netfilter: updates for net-next
@ 2026-04-10 11:23 Florian Westphal
2026-04-12 16:40 ` Jakub Kicinski
0 siblings, 1 reply; 36+ messages in thread
From: Florian Westphal @ 2026-04-10 11:23 UTC (permalink / raw)
To: netdev
Cc: Paolo Abeni, David S. Miller, Eric Dumazet, Jakub Kicinski,
netfilter-devel, pablo
Hi,
The following patchset contains Netfilter updates for *net-next*:
1-3) IPVS updates from Julian Anastasov to enhance visibility into
IPVS internal state by exposing hash size, load factor etc and
allows userspace to tune the load factor used for resizing hash
tables.
4) reject empty/not nul terminated device names from xt_physdev.
This isn't a bug fix; existing code doesn't require a c-string.
But clean this up anyway because conceptually the interface name
definitely should be a c-string.
5) Switch nfnetlink to skb_mac_header helpers that didn't exist back
when this code was written. This gives us additional debug checks
but is not intended to change functionality.
6) Let the xt ttl/hoplimit match reject unknown operator modes.
This is a cleanup, the evaluation function simply returns false when
the mode is out of range. From Marino Dzalto.
7) xt_socket match should enable defrag after all other checks. This
bug is harmless, historically defrag could not be disabled either
except by rmmod.
8) remove UDP-Lite conntrack support, from Fernando Fernandez Mancera.
9) Avoid a couple -Wflex-array-member-not-at-end warnings in the old
xtables 32bit compat code, from Gustavo A. R. Silva.
10) nftables fwd expression should drop packets when their ttl/hl has
expired. This is a bug fix deferred, its not deemed important
enough for -rc8.
11) Add additional checks before assuming the mac header is an ethernet
header, from Zhengchuan Liang.
Please, pull these changes from:
The following changes since commit 42f9b4c6ef19e71d2c7d9bfd3c5037d4fe434ad7:
tools: ynl: tests: fix leading space on Makefile target (2026-04-09 20:41:40 -0700)
are available in the Git repository at:
https://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf-next.git tags/nf-next-26-04-10
for you to fetch changes up to 62443dc21114c0bbc476fa62973db89743f2f137:
netfilter: require Ethernet MAC header before using eth_hdr() (2026-04-10 12:16:27 +0200)
----------------------------------------------------------------
netfilter pull request nf-next-26-04-10
----------------------------------------------------------------
Fernando Fernandez Mancera (1):
netfilter: conntrack: remove UDP-Lite conntrack support
Florian Westphal (4):
netfilter: x_physdev: reject empty or not-nul terminated device names
netfilter: nfnetlink: prefer skb_mac_header helpers
netfilter: xt_socket: enable defrag after all other checks
netfilter: nft_fwd_netdev: check ttl/hl before forwarding
Gustavo A. R. Silva (1):
netfilter: x_tables: Avoid a couple -Wflex-array-member-not-at-end warnings
Julian Anastasov (3):
ipvs: show the current conn_tab size to users
ipvs: add ip_vs_status info
ipvs: add conn_lfactor and svc_lfactor sysctl vars
Marino Dzalto (1):
netfilter: xt_HL: add pr_fmt and checkentry validation
Zhengchuan Liang (1):
netfilter: require Ethernet MAC header before using eth_hdr()
Documentation/networking/ipvs-sysctl.rst | 37 +++
.../net/netfilter/ipv4/nf_conntrack_ipv4.h | 3 -
include/net/netfilter/nf_conntrack_l4proto.h | 7 -
net/ipv6/netfilter/ip6t_eui64.c | 7 +-
net/netfilter/Kconfig | 11 -
net/netfilter/ipset/ip_set_bitmap_ipmac.c | 5 +-
net/netfilter/ipset/ip_set_hash_ipmac.c | 9 +-
net/netfilter/ipset/ip_set_hash_mac.c | 5 +-
net/netfilter/ipvs/ip_vs_ctl.c | 247 +++++++++++++++++-
net/netfilter/nf_conntrack_core.c | 8 -
net/netfilter/nf_conntrack_proto.c | 3 -
net/netfilter/nf_conntrack_proto_udp.c | 108 --------
net/netfilter/nf_conntrack_standalone.c | 2 -
net/netfilter/nf_log_syslog.c | 8 +-
net/netfilter/nf_nat_core.c | 6 -
net/netfilter/nf_nat_proto.c | 20 --
net/netfilter/nfnetlink_cttimeout.c | 1 -
net/netfilter/nfnetlink_log.c | 19 +-
net/netfilter/nfnetlink_queue.c | 25 +-
net/netfilter/nft_ct.c | 1 -
net/netfilter/nft_fwd_netdev.c | 10 +
net/netfilter/x_tables.c | 12 +-
net/netfilter/xt_hl.c | 27 ++
net/netfilter/xt_mac.c | 4 +-
net/netfilter/xt_physdev.c | 22 ++
net/netfilter/xt_socket.c | 23 +-
26 files changed, 399 insertions(+), 231 deletions(-)
--
2.52.0
^ permalink raw reply [flat|nested] 36+ messages in thread
* Re: [PATCH net-next 00/11] netfilter: updates for net-next
2026-04-10 11:23 Florian Westphal
@ 2026-04-12 16:40 ` Jakub Kicinski
2026-04-12 16:54 ` Florian Westphal
0 siblings, 1 reply; 36+ messages in thread
From: Jakub Kicinski @ 2026-04-12 16:40 UTC (permalink / raw)
To: Florian Westphal
Cc: netdev, Paolo Abeni, David S. Miller, Eric Dumazet,
netfilter-devel, pablo
On Fri, 10 Apr 2026 13:23:41 +0200 Florian Westphal wrote:
> 1-3) IPVS updates from Julian Anastasov to enhance visibility into
> IPVS internal state by exposing hash size, load factor etc and
> allows userspace to tune the load factor used for resizing hash
> tables.
Someone should take a look at the Sashiko reports for those, please?
^ permalink raw reply [flat|nested] 36+ messages in thread
* Re: [PATCH net-next 00/11] netfilter: updates for net-next
2026-04-12 16:40 ` Jakub Kicinski
@ 2026-04-12 16:54 ` Florian Westphal
2026-04-12 17:17 ` Florian Westphal
2026-04-12 17:53 ` Jakub Kicinski
0 siblings, 2 replies; 36+ messages in thread
From: Florian Westphal @ 2026-04-12 16:54 UTC (permalink / raw)
To: Jakub Kicinski
Cc: netdev, Paolo Abeni, David S. Miller, Eric Dumazet,
netfilter-devel, pablo
Jakub Kicinski <kuba@kernel.org> wrote:
> On Fri, 10 Apr 2026 13:23:41 +0200 Florian Westphal wrote:
> > 1-3) IPVS updates from Julian Anastasov to enhance visibility into
> > IPVS internal state by exposing hash size, load factor etc and
> > allows userspace to tune the load factor used for resizing hash
> > tables.
>
> Someone should take a look at the Sashiko reports for those, please?
https://sashiko.dev/#/patchset/20260410112352.23599-1-fw%40strlen.de
Sorry Pablo I am dumping this on you. Already wasted 3h on saturday
on LLM crap 8-(
---------
Could this trigger the DEBUG_NET_WARN_ON_ONCE() inside skb_mac_header_len()?
If a user program sends a verdict containing the NFQA_L2HDR attribute for a
packet where the MAC header is not set, it seems this code would call
skb_mac_header_len() without first checking skb_mac_header_was_set(entry->skb).
---------
And thus a new era of cargo cult programming will be born.
Because I have no idea how on earth PF_BRIDGE packets cannot have
a mac header attached to them.
Do I add this check as LLM overlord demands?
-------------
Is it safe to access the IP header here without ensuring the packet length
is sufficient and the header is in the linear data area?
Looking at the surrounding code in nft_fwd_neigh_eval(),
skb_try_make_writable() is called with sizeof(*iph), which is 20 bytes. At
the netdev hook, skb->data points to the MAC header, meaning the 20 bytes
only covers the Ethernet header and the first 6 bytes of the IP header.
Should this code use pskb_may_pull() or skb_ensure_writable() with an
offset that accounts for skb_network_offset(skb) + sizeof(*iph) before
dereferencing iph->ttl to avoid out-of-bounds accesses?
-------------
Dunno. Existing code does that.
^ permalink raw reply [flat|nested] 36+ messages in thread
* Re: [PATCH net-next 00/11] netfilter: updates for net-next
2026-04-12 16:54 ` Florian Westphal
@ 2026-04-12 17:17 ` Florian Westphal
2026-04-12 18:58 ` Pablo Neira Ayuso
2026-04-12 17:53 ` Jakub Kicinski
1 sibling, 1 reply; 36+ messages in thread
From: Florian Westphal @ 2026-04-12 17:17 UTC (permalink / raw)
To: Jakub Kicinski
Cc: netdev, Paolo Abeni, David S. Miller, Eric Dumazet,
netfilter-devel, pablo
Florian Westphal <fw@strlen.de> wrote:
> Jakub Kicinski <kuba@kernel.org> wrote:
> https://sashiko.dev/#/patchset/20260410112352.23599-1-fw%40strlen.de
Forgot to mention this:
---------------
AF_PACKET raw sockets or tun devices, the network_header might be
uninitialized (~0U). In this state, skb_mac_header_len() will evaluate to
a very large number, bypassing the ETH_HLEN check completely.
---------------
Really? TIL.
---------------------
Furthermore, skb_mac_header_len() only verifies the logical distance between
header offsets, rather than ensuring the bytes are actually present in the
physical linear buffer.
---------------
Really? Total news to me :-(
^ permalink raw reply [flat|nested] 36+ messages in thread
* Re: [PATCH net-next 00/11] netfilter: updates for net-next
2026-04-12 16:54 ` Florian Westphal
2026-04-12 17:17 ` Florian Westphal
@ 2026-04-12 17:53 ` Jakub Kicinski
2026-04-12 18:07 ` Julian Anastasov
1 sibling, 1 reply; 36+ messages in thread
From: Jakub Kicinski @ 2026-04-12 17:53 UTC (permalink / raw)
To: Florian Westphal
Cc: netdev, Paolo Abeni, David S. Miller, Eric Dumazet,
netfilter-devel, pablo
On Sun, 12 Apr 2026 18:54:49 +0200 Florian Westphal wrote:
> Jakub Kicinski <kuba@kernel.org> wrote:
> > On Fri, 10 Apr 2026 13:23:41 +0200 Florian Westphal wrote:
> > > 1-3) IPVS updates from Julian Anastasov to enhance visibility into
> > > IPVS internal state by exposing hash size, load factor etc and
> > > allows userspace to tune the load factor used for resizing hash
> > > tables.
> >
> > Someone should take a look at the Sashiko reports for those, please?
>
> https://sashiko.dev/#/patchset/20260410112352.23599-1-fw%40strlen.de
>
> Sorry Pablo I am dumping this on you. Already wasted 3h on saturday
> on LLM crap 8-(
Sorry, I was quoting the IPVS section of the PR because I meant that
someone should look at the IPVS portion. The rest looked like a waste
of time, indeed. The netns dismantle vs ipvs smelled like it could be
legit.
^ permalink raw reply [flat|nested] 36+ messages in thread
* Re: [PATCH net-next 00/11] netfilter: updates for net-next
2026-04-12 17:53 ` Jakub Kicinski
@ 2026-04-12 18:07 ` Julian Anastasov
0 siblings, 0 replies; 36+ messages in thread
From: Julian Anastasov @ 2026-04-12 18:07 UTC (permalink / raw)
To: Jakub Kicinski
Cc: Florian Westphal, netdev, Paolo Abeni, David S. Miller,
Eric Dumazet, netfilter-devel, pablo
Hello,
On Sun, 12 Apr 2026, Jakub Kicinski wrote:
> On Sun, 12 Apr 2026 18:54:49 +0200 Florian Westphal wrote:
> > Jakub Kicinski <kuba@kernel.org> wrote:
> > > On Fri, 10 Apr 2026 13:23:41 +0200 Florian Westphal wrote:
> > > > 1-3) IPVS updates from Julian Anastasov to enhance visibility into
> > > > IPVS internal state by exposing hash size, load factor etc and
> > > > allows userspace to tune the load factor used for resizing hash
> > > > tables.
> > >
> > > Someone should take a look at the Sashiko reports for those, please?
> >
> > https://sashiko.dev/#/patchset/20260410112352.23599-1-fw%40strlen.de
> >
> > Sorry Pablo I am dumping this on you. Already wasted 3h on saturday
> > on LLM crap 8-(
>
> Sorry, I was quoting the IPVS section of the PR because I meant that
> someone should look at the IPVS portion. The rest looked like a waste
> of time, indeed. The netns dismantle vs ipvs smelled like it could be
> legit.
I'll check the IPVS part, there are probably
some problems to fix...
Regards
--
Julian Anastasov <ja@ssi.bg>
^ permalink raw reply [flat|nested] 36+ messages in thread
* Re: [PATCH net-next 00/11] netfilter: updates for net-next
2026-04-12 17:17 ` Florian Westphal
@ 2026-04-12 18:58 ` Pablo Neira Ayuso
0 siblings, 0 replies; 36+ messages in thread
From: Pablo Neira Ayuso @ 2026-04-12 18:58 UTC (permalink / raw)
To: Florian Westphal
Cc: Jakub Kicinski, netdev, Paolo Abeni, David S. Miller,
Eric Dumazet, netfilter-devel
On Sun, Apr 12, 2026 at 07:17:22PM +0200, Florian Westphal wrote:
> Florian Westphal <fw@strlen.de> wrote:
> > Jakub Kicinski <kuba@kernel.org> wrote:
> > https://sashiko.dev/#/patchset/20260410112352.23599-1-fw%40strlen.de
>
> Forgot to mention this:
>
> ---------------
> AF_PACKET raw sockets or tun devices, the network_header might be
> uninitialized (~0U). In this state, skb_mac_header_len() will evaluate to
> a very large number, bypassing the ETH_HLEN check completely.
> ---------------
>
> Really? TIL.
>
> ---------------------
> Furthermore, skb_mac_header_len() only verifies the logical distance between
> header offsets, rather than ensuring the bytes are actually present in the
> physical linear buffer.
>
> ---------------
>
> Really? Total news to me :-(
No problem, taking a look into this.
^ permalink raw reply [flat|nested] 36+ messages in thread
* [PATCH net-next 00/11] netfilter: updates for net-next
@ 2026-05-25 18:29 Florian Westphal
0 siblings, 0 replies; 36+ messages in thread
From: Florian Westphal @ 2026-05-25 18:29 UTC (permalink / raw)
To: netdev
Cc: Paolo Abeni, David S. Miller, Eric Dumazet, Jakub Kicinski,
netfilter-devel, pablo
Hi,
The following patchset contains Netfilter fixes and small enhancements
for *net-next*:
1) Disable 32-bit x_tables compatibility (32bit binaries on 64bit
kernel) interface in user namespaces. This is 'last warning' before
this is removed for good.
2) Add a configuration toggle for netfilter GCOV profiling. Provide dedicated
toggles for ipset and ipvs.
3) Remove modular support for nfnetlink and restrict it to built-in only.
From Pablo Neira Ayuso.
4) Use per-rule hash initval in nf_conncount. This avoids unecessary lock
contention with short keys (e.g. conntrack zones) in different
namespaces.
5) Use nf_ct_exp_net() in ctnetlink expectation dumps.
From Pratham Gupta.
6) Remove a dead conditional in nft_set_rbtree.
7) Fix conntrack helper policy updates to apply per-class values correctly.
From David Carlier.
8) Fix an off-by-one OOB read in nf_conntrack_irc:parse_dcc(). Use strict
less-than comparison in the newline search loop to respect the
exclusive-end pointer convention. From Muhammad Bilal.
9) Fix typos in nf_conntrack_proto_tcp comments. From Avinash Duduskar.
10) Restore performance optimization in nft_set_pipapo_avx2 by passing
the next map index. Refactor lookup logic for clarity and add a
DEBUG_NET check to document this.
11) Avoid (harmless) u16 overflow in nf_conntrack_ftp when parsing FTP PORT
and EPRT commands. Ignore commands where single octet exceeds 255.
From Giuseppe Caruso.
Patch 12, which removes incorrect (and obviously unused) code from
nft_byteorder was kept back to avoid a net -> net-next merge conflict.
Please, pull these changes from:
The following changes since commit c0aa5f13826dcb035bec3d6b252e6b2020fa5f88:
Merge branch 'net-dsa-microchip-remove-unnecessary-ksz_dev_ops-callbacks' (2026-05-22 18:40:51 -0700)
are available in the Git repository at:
https://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf-next.git nf-next-26-05-25
for you to fetch changes up to 2b413fc689ba890348db13a4daa5adf42846ebca:
netfilter: nf_conntrack_ftp: avoid u16 overflows (2026-05-25 20:00:04 +0200)
----------------------------------------------------------------
netfilter pull request nf-next-26-05-25
----------------------------------------------------------------
Avinash Duduskar (1):
netfilter: nf_conntrack_proto_tcp: fix typos in comments
David Carlier (1):
netfilter: nfnl_cthelper: apply per-class values when updating policies
Florian Westphal (5):
netfilter: x_tables: disable 32bit compat interface in user namespaces
netfilter: add option for GCOV profiling
netfilter: nf_conncount: use per-rule hash initval
netfilter: nft_set_rbtree: remove dead conditional
netfilter: nft_set_pipapo_avx2: restore performance optimization
Giuseppe Caruso (1):
netfilter: nf_conntrack_ftp: avoid u16 overflows
Muhammad Bilal (1):
netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read
Pablo Neira Ayuso (1):
netfilter: allow nfnetlink built-in only
Pratham Gupta (1):
netfilter: ctnetlink: use nf_ct_exp_net() in expectation dump
include/linux/netfilter/x_tables.h | 17 +++++++++++++
net/bridge/Makefile | 6 +++++
net/bridge/netfilter/Makefile | 4 +++
net/bridge/netfilter/ebtables.c | 4 +++
net/ipv4/Makefile | 4 +++
net/ipv4/netfilter/Makefile | 4 +++
net/ipv4/netfilter/arp_tables.c | 4 +++
net/ipv4/netfilter/ip_tables.c | 4 +++
net/ipv6/Makefile | 4 +++
net/ipv6/netfilter/Makefile | 4 +++
net/ipv6/netfilter/ip6_tables.c | 4 +++
net/netfilter/Kconfig | 10 +++++++-
net/netfilter/Makefile | 6 ++++-
net/netfilter/ipset/Kconfig | 9 +++++++
net/netfilter/ipset/Makefile | 3 +++
net/netfilter/ipvs/Kconfig | 9 +++++++
net/netfilter/ipvs/Makefile | 3 +++
net/netfilter/nf_conncount.c | 7 +++---
net/netfilter/nf_conntrack_ftp.c | 11 +++++---
net/netfilter/nf_conntrack_irc.c | 6 ++---
net/netfilter/nf_conntrack_netlink.c | 2 +-
net/netfilter/nf_conntrack_proto_tcp.c | 8 +++---
net/netfilter/nfnetlink_cthelper.c | 4 +--
net/netfilter/nft_set_pipapo_avx2.c | 35 +++++++++++---------------
net/netfilter/nft_set_rbtree.c | 3 ---
25 files changed, 131 insertions(+), 44 deletions(-)
--
2.53.0
^ permalink raw reply [flat|nested] 36+ messages in thread
* [PATCH net-next 00/11] Netfilter updates for net-next
@ 2026-09-27 22:34 Pablo Neira Ayuso
2026-09-27 22:34 ` [PATCH net-next 01/11] netfilter: synproxy: fix reset of ct seqadj when reopening a connection Pablo Neira Ayuso
` (10 more replies)
0 siblings, 11 replies; 36+ messages in thread
From: Pablo Neira Ayuso @ 2026-09-27 22:34 UTC (permalink / raw)
To: netfilter-devel; +Cc: davem, netdev, kuba, pabeni, edumazet, horms, fw, ja
Hi,
The following patchset contains Netfilter updates for net-next. The
fixes included in this batch are deemed to handle correctness issues
present in the Netfilter tree:
1) TCP sequence tracking is not reset inconditionally by synproxy when
recycling an entry, sashiko reports the zero offset case skips it.
Add a new function to inconditionally reset TCP sequence tracking.
From Fernando F. Mancera.
2) Update documentation to reflect that the default maximum number of
expectations (nf_conntrack_expect_max) is nf_conntrack_buckets / 64.
From Shaojie Sun.
3) Remove useless break; after return in nft_osf, from Linkui Xiao.
4) Fix typos in comments in the netfilter tree, from Hemanth Selam.
5) Remove a few conntrack error stats duplicated updates,
from Phil Sutter.
6) Do not bump invalid and drop conntrack error stats when packet is
dropped, this is another duplicate. also From Phil.
7) Set on netns pointer before registering the flowtable, this is
a requirement by the next patch, not fixing an existing issue.
From Qingfang Deng.
8) Remove unnecessary workqueue work flush for all of the existing
netns when device is gone. Also from Qingfang Deng.
9) Rework-fix nfnetlink_hook to correctly deal with large netlink
dumps. Use sequence numbers to detect interference with hook
updates while netlink dump is ongoing. From Phil Sutter.
10) Fix ctnetlink dump filtering by the IPv6 address, this has
only work correctly for IPv4 this far, from Piotr Kubik.
11) ctnetlink filtering by zone is supported, but the ctnetlink
dump filtering infrastructure was never updated to include a
flag from userspace, update it to fill this gap.
From Ilya Maximets.
Please, pull these changes from:
git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf-next.git nf-next-26-09-28
Thanks.
----------------------------------------------------------------
The following changes since commit 014d795c73837ea2339a4ea8e8f82c6e959b845d:
idpf: fix kernel-doc parameter descriptions (2026-09-25 18:26:50 -0700)
are available in the Git repository at:
git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf-next.git nf-next-26-09-28
for you to fetch changes up to 46da6029bf468ce3c426cb8b4abf96976ed9d4c8:
netfilter: conntrack: make filtering by zone discoverable (2026-09-27 23:39:21 +0200)
----------------------------------------------------------------
netfilter pull request 26-09-28
----------------------------------------------------------------
Fernando Fernandez Mancera (1):
netfilter: synproxy: fix reset of ct seqadj when reopening a connection
Hemanth Selam (1):
netfilter: fix several typos in comments
Ilya Maximets (1):
netfilter: conntrack: make filtering by zone discoverable
Linkui Xiao (1):
netfilter: osf: remove unreachable break in nf_osf_ttl()
Phil Sutter (3):
netfilter: conntrack: Untangle insert_failed counter from others
netfilter: conntrack: Untangle drop and invalid counters
netfilter: nfnetlink: Fix for interrupted hook dumps
Piotr Kubik (1):
netfilter: ctnetlink: fix inverted IPv6 address match in dump filter
Qingfang Deng (2):
net/sched: act_ct: set net pointer before publishing flowtable
netfilter: flowtable: check namespace before iterating flows
Shaojie Sun (1):
netfilter: conntrack: fix nf_conntrack_expect_max default value in documentation
Documentation/netlink/specs/conntrack.yaml | 6 +
Documentation/networking/nf_conntrack-sysctl.rst | 2 +-
include/net/netfilter/nf_conntrack_seqadj.h | 1 +
include/net/netns/netfilter.h | 2 +
include/uapi/linux/netfilter/nfnetlink_conntrack.h | 1 +
net/ipv4/netfilter/arp_tables.c | 2 +-
net/netfilter/core.c | 18 ++-
net/netfilter/ipset/ip_set_core.c | 2 +-
net/netfilter/ipvs/ip_vs_sync.c | 2 +-
net/netfilter/nf_conntrack_core.c | 5 +-
net/netfilter/nf_conntrack_netlink.c | 19 ++-
net/netfilter/nf_conntrack_seqadj.c | 17 +++
net/netfilter/nf_flow_table_core.c | 17 +--
net/netfilter/nf_nat_core.c | 11 ++
net/netfilter/nf_synproxy_core.c | 4 +-
net/netfilter/nfnetlink_hook.c | 74 ++++++-----
net/netfilter/nfnetlink_osf.c | 1 -
net/sched/act_ct.c | 2 +-
.../selftests/net/netfilter/conntrack_dump_flush.c | 145 ++++++++++++++-------
.../net/netfilter/conntrack_icmp_related.sh | 2 +-
20 files changed, 229 insertions(+), 104 deletions(-)
^ permalink raw reply [flat|nested] 36+ messages in thread
* [PATCH net-next 01/11] netfilter: synproxy: fix reset of ct seqadj when reopening a connection
2026-09-27 22:34 [PATCH net-next 00/11] Netfilter updates for net-next Pablo Neira Ayuso
@ 2026-09-27 22:34 ` Pablo Neira Ayuso
2026-09-27 22:40 ` netdev-bot+sinfo
2026-09-29 2:40 ` patchwork-bot+netdevbpf
2026-09-27 22:34 ` [PATCH net-next 02/11] netfilter: conntrack: fix nf_conntrack_expect_max default value in documentation Pablo Neira Ayuso
` (9 subsequent siblings)
10 siblings, 2 replies; 36+ messages in thread
From: Pablo Neira Ayuso @ 2026-09-27 22:34 UTC (permalink / raw)
To: netfilter-devel; +Cc: davem, netdev, kuba, pabeni, edumazet, horms, fw, ja
From: Fernando Fernandez Mancera <fmancera@suse.de>
SYNPROXY is resetting conntrack seqadj when a closed connection is
re-opened, but it was using nf_ct_seqadj_init() which is a no-op for a
zero offset.
This patch introduces nf_ct_seqadj_reset() which sets the offset values
directly to zero and avoid setting IPS_SEQ_ADJUST_BIT flag, it changes
SYNPROXY code to use it when needed.
Fixes: 48b1de4c110a ("netfilter: add SYNPROXY core/target")
Signed-off-by: Fernando Fernandez Mancera <fmancera@suse.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
---
include/net/netfilter/nf_conntrack_seqadj.h | 1 +
net/netfilter/nf_conntrack_seqadj.c | 17 +++++++++++++++++
net/netfilter/nf_synproxy_core.c | 4 ++--
3 files changed, 20 insertions(+), 2 deletions(-)
diff --git a/include/net/netfilter/nf_conntrack_seqadj.h b/include/net/netfilter/nf_conntrack_seqadj.h
index 883c414b768e..0f5bbb14a25a 100644
--- a/include/net/netfilter/nf_conntrack_seqadj.h
+++ b/include/net/netfilter/nf_conntrack_seqadj.h
@@ -33,6 +33,7 @@ static inline struct nf_conn_seqadj *nfct_seqadj_ext_add(struct nf_conn *ct)
int nf_ct_seqadj_init(struct nf_conn *ct, enum ip_conntrack_info ctinfo,
s32 off);
+void nf_ct_seqadj_reset(struct nf_conn *ct, enum ip_conntrack_info ctinfo);
int nf_ct_seqadj_set(struct nf_conn *ct, enum ip_conntrack_info ctinfo,
__be32 seq, s32 off);
void nf_ct_tcp_seqadj_set(struct sk_buff *skb, struct nf_conn *ct,
diff --git a/net/netfilter/nf_conntrack_seqadj.c b/net/netfilter/nf_conntrack_seqadj.c
index d75e8dafb189..b7b166a8ad58 100644
--- a/net/netfilter/nf_conntrack_seqadj.c
+++ b/net/netfilter/nf_conntrack_seqadj.c
@@ -31,6 +31,23 @@ int nf_ct_seqadj_init(struct nf_conn *ct, enum ip_conntrack_info ctinfo,
}
EXPORT_SYMBOL_GPL(nf_ct_seqadj_init);
+void nf_ct_seqadj_reset(struct nf_conn *ct, enum ip_conntrack_info ctinfo)
+{
+ struct nf_conn_seqadj *seqadj = nfct_seqadj(ct);
+ enum ip_conntrack_dir dir = CTINFO2DIR(ctinfo);
+ struct nf_ct_seqadj *this_way;
+
+ if (unlikely(!seqadj))
+ return;
+
+ spin_lock_bh(&ct->lock);
+ this_way = &seqadj->seq[dir];
+ this_way->offset_before = 0;
+ this_way->offset_after = 0;
+ spin_unlock_bh(&ct->lock);
+}
+EXPORT_SYMBOL_GPL(nf_ct_seqadj_reset);
+
int nf_ct_seqadj_set(struct nf_conn *ct, enum ip_conntrack_info ctinfo,
__be32 seq, s32 off)
{
diff --git a/net/netfilter/nf_synproxy_core.c b/net/netfilter/nf_synproxy_core.c
index 9fc959ba2030..401ce5a13f3f 100644
--- a/net/netfilter/nf_synproxy_core.c
+++ b/net/netfilter/nf_synproxy_core.c
@@ -686,7 +686,7 @@ ipv4_synproxy_hook(void *priv, struct sk_buff *skb,
* adjustments, they will get initialized once the connection is
* reestablished.
*/
- nf_ct_seqadj_init(ct, ctinfo, 0);
+ nf_ct_seqadj_reset(ct, ctinfo);
synproxy->tsoff = 0;
this_cpu_inc(snet->stats->conn_reopened);
fallthrough;
@@ -1116,7 +1116,7 @@ ipv6_synproxy_hook(void *priv, struct sk_buff *skb,
* adjustments, they will get initialized once the connection is
* reestablished.
*/
- nf_ct_seqadj_init(ct, ctinfo, 0);
+ nf_ct_seqadj_reset(ct, ctinfo);
synproxy->tsoff = 0;
this_cpu_inc(snet->stats->conn_reopened);
fallthrough;
--
2.47.3
^ permalink raw reply related [flat|nested] 36+ messages in thread
* [PATCH net-next 02/11] netfilter: conntrack: fix nf_conntrack_expect_max default value in documentation
2026-09-27 22:34 [PATCH net-next 00/11] Netfilter updates for net-next Pablo Neira Ayuso
2026-09-27 22:34 ` [PATCH net-next 01/11] netfilter: synproxy: fix reset of ct seqadj when reopening a connection Pablo Neira Ayuso
@ 2026-09-27 22:34 ` Pablo Neira Ayuso
2026-09-27 22:34 ` [PATCH net-next 03/11] netfilter: osf: remove unreachable break in nf_osf_ttl() Pablo Neira Ayuso
` (8 subsequent siblings)
10 siblings, 0 replies; 36+ messages in thread
From: Pablo Neira Ayuso @ 2026-09-27 22:34 UTC (permalink / raw)
To: netfilter-devel; +Cc: davem, netdev, kuba, pabeni, edumazet, horms, fw, ja
From: Shaojie Sun <sunshaojie@kylinos.cn>
The documentation for nf_conntrack_expect_max incorrectly states that the
default value is nf_conntrack_buckets / 256. However, the code in
nf_conntrack_expect_init() shows:
nf_ct_expect_hsize = nf_conntrack_htable_size / 256;
nf_ct_expect_max = nf_ct_expect_hsize * 4;
This means the default value is actually nf_conntrack_buckets / 64
(i.e. 4 times the hash table size, which defaults to
nf_conntrack_buckets / 256).
Fix the documentation to reflect the correct default value and add
explanation of the calculation.
Signed-off-by: Shaojie Sun <sunshaojie@kylinos.cn>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
---
Documentation/networking/nf_conntrack-sysctl.rst | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/Documentation/networking/nf_conntrack-sysctl.rst b/Documentation/networking/nf_conntrack-sysctl.rst
index 35f889259fcd..4426cce2a73f 100644
--- a/Documentation/networking/nf_conntrack-sysctl.rst
+++ b/Documentation/networking/nf_conntrack-sysctl.rst
@@ -44,7 +44,7 @@ nf_conntrack_events - BOOLEAN
nf_conntrack_expect_max - INTEGER
Maximum size of expectation table. Default value is
- nf_conntrack_buckets / 256. Minimum is 1.
+ nf_conntrack_buckets / 64. Minimum is 1.
nf_conntrack_frag6_high_thresh - INTEGER
default 262144
--
2.47.3
^ permalink raw reply related [flat|nested] 36+ messages in thread
* [PATCH net-next 03/11] netfilter: osf: remove unreachable break in nf_osf_ttl()
2026-09-27 22:34 [PATCH net-next 00/11] Netfilter updates for net-next Pablo Neira Ayuso
2026-09-27 22:34 ` [PATCH net-next 01/11] netfilter: synproxy: fix reset of ct seqadj when reopening a connection Pablo Neira Ayuso
2026-09-27 22:34 ` [PATCH net-next 02/11] netfilter: conntrack: fix nf_conntrack_expect_max default value in documentation Pablo Neira Ayuso
@ 2026-09-27 22:34 ` Pablo Neira Ayuso
2026-09-27 22:34 ` [PATCH net-next 04/11] netfilter: fix several typos in comments Pablo Neira Ayuso
` (7 subsequent siblings)
10 siblings, 0 replies; 36+ messages in thread
From: Pablo Neira Ayuso @ 2026-09-27 22:34 UTC (permalink / raw)
To: netfilter-devel; +Cc: davem, netdev, kuba, pabeni, edumazet, horms, fw, ja
From: Linkui Xiao <xiaolinkui@kylinos.cn>
In nf_osf_ttl(), the break statement after return in NF_OSF_TTL_TRUE
case is unreachable dead‑code. The return statement exits the function
immediately, so break will never execute.
Remove the useless break, no functional change.
Signed-off-by: Linkui Xiao <xiaolinkui@kylinos.cn>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
---
net/netfilter/nfnetlink_osf.c | 1 -
1 file changed, 1 deletion(-)
diff --git a/net/netfilter/nfnetlink_osf.c b/net/netfilter/nfnetlink_osf.c
index e4835b0f4bb1..c8cd6af95db4 100644
--- a/net/netfilter/nfnetlink_osf.c
+++ b/net/netfilter/nfnetlink_osf.c
@@ -36,7 +36,6 @@ static inline int nf_osf_ttl(const struct sk_buff *skb,
switch (ttl_check) {
case NF_OSF_TTL_TRUE:
return ip->ttl == f_ttl;
- break;
case NF_OSF_TTL_NOCHECK:
return 1;
case NF_OSF_TTL_LESS:
--
2.47.3
^ permalink raw reply related [flat|nested] 36+ messages in thread
* [PATCH net-next 04/11] netfilter: fix several typos in comments
2026-09-27 22:34 [PATCH net-next 00/11] Netfilter updates for net-next Pablo Neira Ayuso
` (2 preceding siblings ...)
2026-09-27 22:34 ` [PATCH net-next 03/11] netfilter: osf: remove unreachable break in nf_osf_ttl() Pablo Neira Ayuso
@ 2026-09-27 22:34 ` Pablo Neira Ayuso
2026-09-27 22:34 ` [PATCH net-next 05/11] netfilter: conntrack: Untangle insert_failed counter from others Pablo Neira Ayuso
` (6 subsequent siblings)
10 siblings, 0 replies; 36+ messages in thread
From: Pablo Neira Ayuso @ 2026-09-27 22:34 UTC (permalink / raw)
To: netfilter-devel; +Cc: davem, netdev, kuba, pabeni, edumazet, horms, fw, ja
From: Hemanth Selam <hemanth.selam@gmail.com>
Fix typos reported by scripts/checkpatch.pl using the misspelling list
in scripts/spelling.txt. Only touches comments, no code changes.
Assisted-by: Cursor:claude-opus-5
Signed-off-by: Hemanth Selam <hemanth.selam@gmail.com>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
---
net/ipv4/netfilter/arp_tables.c | 2 +-
net/netfilter/ipset/ip_set_core.c | 2 +-
net/netfilter/ipvs/ip_vs_sync.c | 2 +-
tools/testing/selftests/net/netfilter/conntrack_icmp_related.sh | 2 +-
4 files changed, 4 insertions(+), 4 deletions(-)
diff --git a/net/ipv4/netfilter/arp_tables.c b/net/ipv4/netfilter/arp_tables.c
index db307fa49f3f..cf747e1e17a3 100644
--- a/net/ipv4/netfilter/arp_tables.c
+++ b/net/ipv4/netfilter/arp_tables.c
@@ -58,7 +58,7 @@ static inline int arp_devaddr_compare(const struct arpt_devaddr_info *ap,
/*
* Unfortunately, _b and _mask are not aligned to an int (or long int)
* Some arches dont care, unrolling the loop is a win on them.
- * For other arches, we only have a 16bit alignement.
+ * For other arches, we only have a 16bit alignment.
*/
static unsigned long ifname_compare(const char *_a, const char *_b, const char *_mask)
{
diff --git a/net/netfilter/ipset/ip_set_core.c b/net/netfilter/ipset/ip_set_core.c
index 0a86a170ba90..4aeb767088cf 100644
--- a/net/netfilter/ipset/ip_set_core.c
+++ b/net/netfilter/ipset/ip_set_core.c
@@ -1426,7 +1426,7 @@ static int ip_set_swap(struct sk_buff *skb, const struct nfnl_info *info,
return -IPSET_ERR_EXIST_SETNAME2;
/* Features must not change.
- * Not an artifical restriction anymore, as we must prevent
+ * Not an artificial restriction anymore, as we must prevent
* possible loops created by swapping in setlist type of sets.
*/
if (!(from->type->features == to->type->features &&
diff --git a/net/netfilter/ipvs/ip_vs_sync.c b/net/netfilter/ipvs/ip_vs_sync.c
index 5383aeafb0ae..4dacd5af65db 100644
--- a/net/netfilter/ipvs/ip_vs_sync.c
+++ b/net/netfilter/ipvs/ip_vs_sync.c
@@ -1344,7 +1344,7 @@ static void set_mcast_pmtudisc(struct sock *sk, int val)
}
/*
- * Specifiy default interface for outgoing multicasts
+ * Specify default interface for outgoing multicasts
*/
static int set_mcast_if(struct sock *sk, struct net_device *dev)
{
diff --git a/tools/testing/selftests/net/netfilter/conntrack_icmp_related.sh b/tools/testing/selftests/net/netfilter/conntrack_icmp_related.sh
index c63d840ead61..f63b7f12b36a 100755
--- a/tools/testing/selftests/net/netfilter/conntrack_icmp_related.sh
+++ b/tools/testing/selftests/net/netfilter/conntrack_icmp_related.sh
@@ -171,7 +171,7 @@ table inet filter {
}
EOF
-# make sure NAT core rewrites adress of icmp error if nat is used according to
+# make sure NAT core rewrites address of icmp error if nat is used according to
# conntrack nat information (icmp error will be directed at nsrouter1 address,
# but it needs to be routed to nsclient1 address).
ip netns exec "$nsrouter1" nft -f - <<EOF
--
2.47.3
^ permalink raw reply related [flat|nested] 36+ messages in thread
* [PATCH net-next 05/11] netfilter: conntrack: Untangle insert_failed counter from others
2026-09-27 22:34 [PATCH net-next 00/11] Netfilter updates for net-next Pablo Neira Ayuso
` (3 preceding siblings ...)
2026-09-27 22:34 ` [PATCH net-next 04/11] netfilter: fix several typos in comments Pablo Neira Ayuso
@ 2026-09-27 22:34 ` Pablo Neira Ayuso
2026-09-27 22:34 ` [PATCH net-next 06/11] netfilter: conntrack: Untangle drop and invalid counters Pablo Neira Ayuso
` (5 subsequent siblings)
10 siblings, 0 replies; 36+ messages in thread
From: Pablo Neira Ayuso @ 2026-09-27 22:34 UTC (permalink / raw)
To: netfilter-devel; +Cc: davem, netdev, kuba, pabeni, edumazet, horms, fw, ja
From: Phil Sutter <phil@nwl.cc>
There is not much sense in incrementing multiple conntrack counters for
the same situation. Defining insert_failed as a situation where a valid
packet's conntrack can't be confirmed due to unresolvable clash sets it
apart from 'drop' (ENOMEM situation) and 'chaintoolong'.
Signed-off-by: Phil Sutter <phil@nwl.cc>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
---
net/netfilter/nf_conntrack_core.c | 2 --
1 file changed, 2 deletions(-)
diff --git a/net/netfilter/nf_conntrack_core.c b/net/netfilter/nf_conntrack_core.c
index d0d9e5ea84a0..53401e21ad99 100644
--- a/net/netfilter/nf_conntrack_core.c
+++ b/net/netfilter/nf_conntrack_core.c
@@ -1169,7 +1169,6 @@ nf_ct_resolve_clash(struct sk_buff *skb, struct nf_conntrack_tuple_hash *h,
return ret;
drop:
- NF_CT_STAT_INC(net, drop);
NF_CT_STAT_INC(net, insert_failed);
return NF_DROP;
}
@@ -1259,7 +1258,6 @@ __nf_conntrack_confirm(struct sk_buff *skb)
if (chainlen++ > max_chainlen) {
chaintoolong:
NF_CT_STAT_INC(net, chaintoolong);
- NF_CT_STAT_INC(net, insert_failed);
ret = NF_DROP;
goto dying;
}
--
2.47.3
^ permalink raw reply related [flat|nested] 36+ messages in thread
* [PATCH net-next 06/11] netfilter: conntrack: Untangle drop and invalid counters
2026-09-27 22:34 [PATCH net-next 00/11] Netfilter updates for net-next Pablo Neira Ayuso
` (4 preceding siblings ...)
2026-09-27 22:34 ` [PATCH net-next 05/11] netfilter: conntrack: Untangle insert_failed counter from others Pablo Neira Ayuso
@ 2026-09-27 22:34 ` Pablo Neira Ayuso
2026-09-27 22:34 ` [PATCH net-next 07/11] net/sched: act_ct: set net pointer before publishing flowtable Pablo Neira Ayuso
` (4 subsequent siblings)
10 siblings, 0 replies; 36+ messages in thread
From: Pablo Neira Ayuso @ 2026-09-27 22:34 UTC (permalink / raw)
To: netfilter-devel; +Cc: davem, netdev, kuba, pabeni, edumazet, horms, fw, ja
From: Phil Sutter <phil@nwl.cc>
In nf_conntrack_in, 'drop' counter increments if
nf_conntrack_handle_packet returns NF_DROP. This is a special case with
TCP packets (added by commit 6b69fe0c73c0 ("netfilter: nf_conntrack_tcp:
fix endless loop") and not related to invalid packets which are
responsible for all the other <=0 returns. So don't increment 'invalid'
ounter in this case.
Signed-off-by: Phil Sutter <phil@nwl.cc>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
---
net/netfilter/nf_conntrack_core.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/net/netfilter/nf_conntrack_core.c b/net/netfilter/nf_conntrack_core.c
index 53401e21ad99..f9b8927327ba 100644
--- a/net/netfilter/nf_conntrack_core.c
+++ b/net/netfilter/nf_conntrack_core.c
@@ -2065,9 +2065,10 @@ nf_conntrack_in(struct sk_buff *skb, const struct nf_hook_state *state)
if (ret == -NF_REPEAT)
goto repeat;
- NF_CT_STAT_INC_ATOMIC(state->net, invalid);
if (ret == NF_DROP)
NF_CT_STAT_INC_ATOMIC(state->net, drop);
+ else
+ NF_CT_STAT_INC_ATOMIC(state->net, invalid);
ret = -ret;
goto out;
--
2.47.3
^ permalink raw reply related [flat|nested] 36+ messages in thread
* [PATCH net-next 07/11] net/sched: act_ct: set net pointer before publishing flowtable
2026-09-27 22:34 [PATCH net-next 00/11] Netfilter updates for net-next Pablo Neira Ayuso
` (5 preceding siblings ...)
2026-09-27 22:34 ` [PATCH net-next 06/11] netfilter: conntrack: Untangle drop and invalid counters Pablo Neira Ayuso
@ 2026-09-27 22:34 ` Pablo Neira Ayuso
2026-09-27 22:34 ` [PATCH net-next 08/11] netfilter: flowtable: check namespace before iterating flows Pablo Neira Ayuso
` (3 subsequent siblings)
10 siblings, 0 replies; 36+ messages in thread
From: Pablo Neira Ayuso @ 2026-09-27 22:34 UTC (permalink / raw)
To: netfilter-devel; +Cc: davem, netdev, kuba, pabeni, edumazet, horms, fw, ja
From: Qingfang Deng <qingfang.deng@linux.dev>
nf_flow_table_init() adds the flowtable to the global flowtables list.
However, tcf_ct_flow_table_get() sets the table's network namespace only
after that call, leaving a window where the published table has a NULL
namespace pointer.
Set the namespace before calling nf_flow_table_init() so that flowtable
list walkers can rely on it being initialized.
This is required by:
"netfilter: flowtable: check namespace before iterating flows"
Signed-off-by: Qingfang Deng <qingfang.deng@linux.dev>
Reviewed-by: Xuanqiang Luo <luoxuanqiang@kylinos.cn>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
---
net/sched/act_ct.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/net/sched/act_ct.c b/net/sched/act_ct.c
index 411e3dd92d07..e26c0d5b2176 100644
--- a/net/sched/act_ct.c
+++ b/net/sched/act_ct.c
@@ -349,10 +349,10 @@ static int tcf_ct_flow_table_get(struct net *net, struct tcf_ct_params *params)
ct_ft->nf_ft.type = &flowtable_ct;
ct_ft->nf_ft.flags |= NF_FLOWTABLE_HW_OFFLOAD |
NF_FLOWTABLE_COUNTER;
+ write_pnet(&ct_ft->nf_ft.net, net);
err = nf_flow_table_init(&ct_ft->nf_ft);
if (err)
goto err_init;
- write_pnet(&ct_ft->nf_ft.net, net);
__module_get(THIS_MODULE);
out_unlock:
--
2.47.3
^ permalink raw reply related [flat|nested] 36+ messages in thread
* [PATCH net-next 08/11] netfilter: flowtable: check namespace before iterating flows
2026-09-27 22:34 [PATCH net-next 00/11] Netfilter updates for net-next Pablo Neira Ayuso
` (6 preceding siblings ...)
2026-09-27 22:34 ` [PATCH net-next 07/11] net/sched: act_ct: set net pointer before publishing flowtable Pablo Neira Ayuso
@ 2026-09-27 22:34 ` Pablo Neira Ayuso
2026-09-27 22:34 ` [PATCH net-next 09/11] netfilter: nfnetlink: Fix for interrupted hook dumps Pablo Neira Ayuso
` (2 subsequent siblings)
10 siblings, 0 replies; 36+ messages in thread
From: Pablo Neira Ayuso @ 2026-09-27 22:34 UTC (permalink / raw)
To: netfilter-devel; +Cc: davem, netdev, kuba, pabeni, edumazet, horms, fw, ja
From: Qingfang Deng <qingfang.deng@linux.dev>
nf_flow_table_cleanup() walks every registered flow table, checking the
network namespace for each flow in nf_flow_table_do_cleanup(). As a
result, tables in other namespaces are still iterated and their cleanup
work is flushed.
Compare the flow table's namespace with the device's namespace in
nf_flow_table_cleanup() and skip nonmatching tables. This avoids
unnecessary iteration and work flushing, and leaves the per-flow cleanup
callback to check only the interface index.
Signed-off-by: Qingfang Deng <qingfang.deng@linux.dev>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
---
net/netfilter/nf_flow_table_core.c | 17 +++++++----------
1 file changed, 7 insertions(+), 10 deletions(-)
diff --git a/net/netfilter/nf_flow_table_core.c b/net/netfilter/nf_flow_table_core.c
index 934c6151f558..bd8f9cf394ff 100644
--- a/net/netfilter/nf_flow_table_core.c
+++ b/net/netfilter/nf_flow_table_core.c
@@ -737,14 +737,9 @@ static void nf_flow_table_do_cleanup(struct nf_flowtable *flow_table,
{
struct net_device *dev = data;
- if (!dev) {
- flow_offload_teardown(flow);
- return;
- }
-
- if (net_eq(nf_ct_net(flow->ct), dev_net(dev)) &&
- (flow->tuplehash[0].tuple.iifidx == dev->ifindex ||
- flow->tuplehash[1].tuple.iifidx == dev->ifindex))
+ if (!dev ||
+ flow->tuplehash[0].tuple.iifidx == dev->ifindex ||
+ flow->tuplehash[1].tuple.iifidx == dev->ifindex)
flow_offload_teardown(flow);
}
@@ -761,8 +756,10 @@ void nf_flow_table_cleanup(struct net_device *dev)
struct nf_flowtable *flowtable;
mutex_lock(&flowtable_lock);
- list_for_each_entry(flowtable, &flowtables, list)
- nf_flow_table_gc_cleanup(flowtable, dev);
+ list_for_each_entry(flowtable, &flowtables, list) {
+ if (net_eq(read_pnet(&flowtable->net), dev_net(dev)))
+ nf_flow_table_gc_cleanup(flowtable, dev);
+ }
mutex_unlock(&flowtable_lock);
}
EXPORT_SYMBOL_GPL(nf_flow_table_cleanup);
--
2.47.3
^ permalink raw reply related [flat|nested] 36+ messages in thread
* [PATCH net-next 09/11] netfilter: nfnetlink: Fix for interrupted hook dumps
2026-09-27 22:34 [PATCH net-next 00/11] Netfilter updates for net-next Pablo Neira Ayuso
` (7 preceding siblings ...)
2026-09-27 22:34 ` [PATCH net-next 08/11] netfilter: flowtable: check namespace before iterating flows Pablo Neira Ayuso
@ 2026-09-27 22:34 ` Pablo Neira Ayuso
2026-09-27 22:34 ` [PATCH net-next 10/11] netfilter: ctnetlink: fix inverted IPv6 address match in dump filter Pablo Neira Ayuso
2026-09-27 22:34 ` [PATCH net-next 11/11] netfilter: conntrack: make filtering by zone discoverable Pablo Neira Ayuso
10 siblings, 0 replies; 36+ messages in thread
From: Pablo Neira Ayuso @ 2026-09-27 22:34 UTC (permalink / raw)
To: netfilter-devel; +Cc: davem, netdev, kuba, pabeni, edumazet, horms, fw, ja
From: Phil Sutter <phil@nwl.cc>
Handling of concurrent hook changes with a dump in progress was
problematic in nfnl_hook_dump and entirely broken in nfnl_hook_dump_nat.
Address all issues in a single patch to please the review LLM.
Introduce sequence numbers in struct netns_nf to replace pointer
value-based modification detection which may fail due to memory buffer
reuse. This also eliminates the need for most manual cb->seq updates and
excessive array index value checks.
Since nat hook updates are protected by a different mutex than others,
they have to bump their own sequence number. nfnl_hook_dump_nat
therefore open-codes what nl_dump_check_consistent does but bumps
cb->seq instead of setting NLM_F_DUMP_INTR flag.
Dumps of many nat hooks was entirely broken since the array index was
not (re)stored. Use cb->args[1] for that and make sure it is reset upon
completion as the same dump may loop over multiple arrays of nat hooks.
In nfnl_hook_dump, don't signal NLM_F_DUMP_INTR if
nfnl_hook_entries_head returns error: This is a permanent condition
which does not change during a dump. It is already caught by
nfnl_hook_dump_start though, so should not happen anyway.
In general, access ops array pointer values using READ_ONCE since they
are assigned to using WRITE_ONCE.
Avoid setting NLM_F_DUMP_INTR flag in garbage memory by calling
nl_dump_check_consistent only for non-empty skbs. If not a single
netlink message was created, nfnetlink code will take care of setting
the flag.
Fixes: e2cf17d3774c ("netfilter: add new hook nfnl subsystem")
Fixes: b010e2a4a9ac ("netfilter: nfnetlink_hook: Dump nat type chains")
Signed-off-by: Phil Sutter <phil@nwl.cc>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
---
include/net/netns/netfilter.h | 2 +
net/netfilter/core.c | 18 ++++++++-
net/netfilter/nf_nat_core.c | 11 +++++
net/netfilter/nfnetlink_hook.c | 74 ++++++++++++++++++++--------------
4 files changed, 73 insertions(+), 32 deletions(-)
diff --git a/include/net/netns/netfilter.h b/include/net/netns/netfilter.h
index a6a0bf4a247e..7fd78394d1e7 100644
--- a/include/net/netns/netfilter.h
+++ b/include/net/netns/netfilter.h
@@ -33,5 +33,7 @@ struct netns_nf {
#if IS_ENABLED(CONFIG_NF_DEFRAG_IPV6)
unsigned int defrag_ipv6_users;
#endif
+ unsigned int hook_base_seq;
+ unsigned int nat_hook_base_seq;
};
#endif
diff --git a/net/netfilter/core.c b/net/netfilter/core.c
index 675a1034b340..940dea2663e9 100644
--- a/net/netfilter/core.c
+++ b/net/netfilter/core.c
@@ -386,6 +386,15 @@ static void nf_static_key_dec(const struct nf_hook_ops *reg, int pf)
#endif
}
+static void bump_hook_base_seq(struct net *net)
+{
+ unsigned int base_seq = READ_ONCE(net->nf.hook_base_seq);
+
+ while (++base_seq == 0)
+ ;
+ smp_store_release(&net->nf.hook_base_seq, base_seq);
+}
+
static int __nf_register_net_hook(struct net *net, int pf,
const struct nf_hook_ops *reg)
{
@@ -430,6 +439,7 @@ static int __nf_register_net_hook(struct net *net, int pf,
if (!IS_ERR(new_hooks)) {
hooks_validate(new_hooks);
rcu_assign_pointer(*pp, new_hooks);
+ bump_hook_base_seq(net);
}
mutex_unlock(&nf_hook_mutex);
@@ -483,6 +493,7 @@ static void __nf_unregister_net_hook(struct net *net, int pf,
{
struct nf_hook_entries __rcu **pp;
struct nf_hook_entries *p;
+ bool found;
pp = nf_hook_entry_head(net, pf, reg->hooknum, reg->dev);
if (!pp)
@@ -496,7 +507,8 @@ static void __nf_unregister_net_hook(struct net *net, int pf,
return;
}
- if (nf_remove_net_hook(p, reg)) {
+ found = nf_remove_net_hook(p, reg);
+ if (found) {
#ifdef CONFIG_NETFILTER_INGRESS
if (nf_ingress_hook(reg, pf))
net_dec_ingress_queue();
@@ -511,6 +523,8 @@ static void __nf_unregister_net_hook(struct net *net, int pf,
}
p = __nf_hook_entries_try_shrink(p, pp);
+ if (found)
+ bump_hook_base_seq(net);
mutex_unlock(&nf_hook_mutex);
if (!p)
return;
@@ -784,6 +798,8 @@ static int __net_init netfilter_net_init(struct net *net)
return -ENOMEM;
}
#endif
+ net->nf.hook_base_seq = 1;
+ net->nf.nat_hook_base_seq = 1;
return 0;
}
diff --git a/net/netfilter/nf_nat_core.c b/net/netfilter/nf_nat_core.c
index 84f82957e66b..5ddd5fc95b24 100644
--- a/net/netfilter/nf_nat_core.c
+++ b/net/netfilter/nf_nat_core.c
@@ -1160,6 +1160,15 @@ nfnetlink_parse_nat_setup(struct nf_conn *ct,
}
#endif
+static void bump_nat_hook_base_seq(struct net *net)
+{
+ unsigned int base_seq = READ_ONCE(net->nf.nat_hook_base_seq);
+
+ while (++base_seq == 0)
+ ;
+ smp_store_release(&net->nf.nat_hook_base_seq, base_seq);
+}
+
static struct nf_ct_helper_expectfn follow_master_nat = {
.name = "nat-follow-master",
.expectfn = nf_nat_follow_master,
@@ -1245,6 +1254,7 @@ int nf_nat_register_fn(struct net *net, u8 pf, const struct nf_hook_ops *ops,
nat_proto_net->nat_hook_ops = nat_ops;
nat_proto_net->users++;
+ bump_nat_hook_base_seq(net);
mutex_unlock(&nf_nat_proto_mutex);
@@ -1299,6 +1309,7 @@ void nf_nat_unregister_fn(struct net *net, u8 pf, const struct nf_hook_ops *ops,
goto unlock;
priv = nat_ops[hooknum].priv;
nf_hook_entries_delete_raw(&priv->entries, ops);
+ bump_nat_hook_base_seq(net);
if (nat_proto_net->users == 0) {
nf_unregister_net_hooks(net, nat_ops, ops_count);
diff --git a/net/netfilter/nfnetlink_hook.c b/net/netfilter/nfnetlink_hook.c
index 95005e9a6066..b05fd79397c5 100644
--- a/net/netfilter/nfnetlink_hook.c
+++ b/net/netfilter/nfnetlink_hook.c
@@ -54,7 +54,6 @@ static int nf_netlink_dump_start_rcu(struct sock *nlsk, struct sk_buff *skb,
struct nfnl_dump_hook_data {
char devname[IFNAMSIZ];
- unsigned long headv;
u8 hook;
};
@@ -338,27 +337,47 @@ nfnl_hook_entries_head(u8 pf, unsigned int hook, struct net *net, const char *de
}
static int nfnl_hook_dump_nat(struct sk_buff *nlskb,
- const struct nfnl_dump_hook_data *ctx,
- const struct nf_hook_ops *ops,
- int family, unsigned int seq)
+ struct netlink_callback *cb,
+ const struct nf_hook_ops *ops, int family)
{
struct nf_nat_lookup_hook_priv *priv = ops->priv;
- struct nf_hook_entries *e = rcu_dereference(priv->entries);
+ struct nfnl_dump_hook_data *ctx = cb->data;
+ struct net *net = sock_net(nlskb->sk);
struct nf_hook_ops **nat_ops;
- int i, err;
+ unsigned int i = cb->args[1];
+ struct nf_hook_entries *e;
+ unsigned int base_seq;
+ int err = 0;
+ base_seq = smp_load_acquire(&net->nf.nat_hook_base_seq);
+
+ e = rcu_dereference(priv->entries);
if (!e)
- return 0;
+ goto out;
nat_ops = nf_hook_entries_get_hook_ops(e);
- for (i = 0; i < e->num_hook_entries; i++) {
- err = nfnl_hook_dump_one(nlskb, ctx, nat_ops[i],
- ops->priority, family, seq);
+ for (; i < e->num_hook_entries; i++) {
+ err = nfnl_hook_dump_one(nlskb, ctx,
+ READ_ONCE(nat_ops[i]),
+ ops->priority, family,
+ cb->nlh->nlmsg_seq);
if (err)
- return err;
+ break;
+
}
- return 0;
+out:
+ if (!err)
+ i = 0;
+ cb->args[1] = i;
+
+ if (cb->args[2] && base_seq != cb->args[2]) {
+ cb->seq++;
+ err = -EINTR;
+ }
+ cb->args[2] = base_seq;
+
+ return err;
}
static int nfnl_hook_dump(struct sk_buff *nlskb,
@@ -373,35 +392,31 @@ static int nfnl_hook_dump(struct sk_buff *nlskb,
unsigned int i = cb->args[0];
rcu_read_lock();
+ cb->seq = smp_load_acquire(&net->nf.hook_base_seq);
e = nfnl_hook_entries_head(family, ctx->hook, net, ctx->devname);
- if (!e)
+ if (!e || IS_ERR(e))
goto done;
- if (IS_ERR(e)) {
- cb->seq++;
- goto done;
- }
-
- if ((unsigned long)e != ctx->headv || i >= e->num_hook_entries)
- cb->seq++;
-
ops = nf_hook_entries_get_hook_ops(e);
for (; i < e->num_hook_entries; i++) {
- if (ops[i]->hook_ops_type == NF_HOOK_OP_NAT)
- err = nfnl_hook_dump_nat(nlskb, ctx, ops[i], family,
- cb->nlh->nlmsg_seq);
- else
- err = nfnl_hook_dump_one(nlskb, ctx, ops[i],
- ops[i]->priority, family,
+ const struct nf_hook_ops *cur = READ_ONCE(ops[i]);
+
+ if (cur->hook_ops_type == NF_HOOK_OP_NAT) {
+ err = nfnl_hook_dump_nat(nlskb, cb, cur, family);
+ } else {
+ err = nfnl_hook_dump_one(nlskb, ctx, cur,
+ cur->priority, family,
cb->nlh->nlmsg_seq);
+ }
if (err)
break;
}
done:
- nl_dump_check_consistent(cb, nlmsg_hdr(nlskb));
+ if (nlskb->len > 0)
+ nl_dump_check_consistent(cb, nlmsg_hdr(nlskb));
rcu_read_unlock();
cb->args[0] = i;
return nlskb->len;
@@ -442,10 +457,7 @@ static int nfnl_hook_dump_start(struct netlink_callback *cb)
return -ENOMEM;
strscpy(ctx->devname, name, sizeof(ctx->devname));
- ctx->headv = (unsigned long)head;
ctx->hook = hooknum;
-
- cb->seq = 1;
cb->data = ctx;
return 0;
--
2.47.3
^ permalink raw reply related [flat|nested] 36+ messages in thread
* [PATCH net-next 10/11] netfilter: ctnetlink: fix inverted IPv6 address match in dump filter
2026-09-27 22:34 [PATCH net-next 00/11] Netfilter updates for net-next Pablo Neira Ayuso
` (8 preceding siblings ...)
2026-09-27 22:34 ` [PATCH net-next 09/11] netfilter: nfnetlink: Fix for interrupted hook dumps Pablo Neira Ayuso
@ 2026-09-27 22:34 ` Pablo Neira Ayuso
2026-09-27 22:34 ` [PATCH net-next 11/11] netfilter: conntrack: make filtering by zone discoverable Pablo Neira Ayuso
10 siblings, 0 replies; 36+ messages in thread
From: Pablo Neira Ayuso @ 2026-09-27 22:34 UTC (permalink / raw)
To: netfilter-devel; +Cc: davem, netdev, kuba, pabeni, edumazet, horms, fw, ja
From: Piotr Kubik <piotr@kubik.pl>
ctnetlink_filter_match_tuple() rejects an entry when
!ipv6_addr_cmp(filter, entry) is true. ipv6_addr_cmp() is a memcmp() and
returns 0 for equal addresses, so the condition is true exactly when the
addresses match: a CTA_FILTER dump with an IPv6 CTA_IP_SRC or CTA_IP_DST
skips every entry that matches the requested address and returns all the
others. The IPv4 branch compares with != and behaves correctly.
Observed with libnetfilter_conntrack NFCT_FILTER_DUMP_TUPLE: a dump
filtered on src 2001:db8::10 returned only the unrelated entries, and a
dump filtered on ::1 returned every entry except the ::1 ones.
conntrack-tools does not use the tuple filter for -L, which is why this
went unnoticed.
Use ipv6_addr_equal() so the IPv6 branch mirrors the IPv4 one.
Fixes: cb8aa9a3affb ("netfilter: ctnetlink: add kernel side filtering for dump")
Cc: stable@vger.kernel.org
Signed-off-by: Piotr Kubik <piotr@kubik.pl>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
---
net/netfilter/nf_conntrack_netlink.c | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/net/netfilter/nf_conntrack_netlink.c b/net/netfilter/nf_conntrack_netlink.c
index 4e5d7c701436..e8477f792c95 100644
--- a/net/netfilter/nf_conntrack_netlink.c
+++ b/net/netfilter/nf_conntrack_netlink.c
@@ -1098,13 +1098,13 @@ static int ctnetlink_filter_match_tuple(struct nf_conntrack_tuple *filter_tuple,
break;
case NFPROTO_IPV6:
if ((flags & CTA_FILTER_FLAG(CTA_IP_SRC)) &&
- !ipv6_addr_cmp(&filter_tuple->src.u3.in6,
- &ct_tuple->src.u3.in6))
+ !ipv6_addr_equal(&filter_tuple->src.u3.in6,
+ &ct_tuple->src.u3.in6))
return 0;
if ((flags & CTA_FILTER_FLAG(CTA_IP_DST)) &&
- !ipv6_addr_cmp(&filter_tuple->dst.u3.in6,
- &ct_tuple->dst.u3.in6))
+ !ipv6_addr_equal(&filter_tuple->dst.u3.in6,
+ &ct_tuple->dst.u3.in6))
return 0;
break;
}
--
2.47.3
^ permalink raw reply related [flat|nested] 36+ messages in thread
* [PATCH net-next 11/11] netfilter: conntrack: make filtering by zone discoverable
2026-09-27 22:34 [PATCH net-next 00/11] Netfilter updates for net-next Pablo Neira Ayuso
` (9 preceding siblings ...)
2026-09-27 22:34 ` [PATCH net-next 10/11] netfilter: ctnetlink: fix inverted IPv6 address match in dump filter Pablo Neira Ayuso
@ 2026-09-27 22:34 ` Pablo Neira Ayuso
10 siblings, 0 replies; 36+ messages in thread
From: Pablo Neira Ayuso @ 2026-09-27 22:34 UTC (permalink / raw)
To: netfilter-devel; +Cc: davem, netdev, kuba, pabeni, edumazet, horms, fw, ja
From: Ilya Maximets <i.maximets@ovn.org>
Conntrack flush supports filtering by zone using CTA_ZONE, but this
attribute is really hard to use from user space applications. The
reason is that it is not possible to tell if it's supported or not.
Older kernels silently ignore CTA_ZONE. And in that case they just
happily flush all the entries from all zones breaking all the existing
connections. So, applications have to infer support from the kernel
version. While it works in most cases, it's not a particularly
reliable or desired way to check kernel capabilities from applications
that aim to be portable. There should be a better way to probe or
discover features in the kernel.
The CTA_FILTER interface on the other hand is simple enough to probe.
We can check for NLM_F_DUMP_FILTERED in the dump to see if filtering
is supported. And unknown sub-attributes in CTA_FILTER are rejected
explicitly since strict validation is in use there.
Let's add new CTA_FILTER_ZONE that signals that CTA_ZONE should be
filtered on. It is a flag, since everything in the CTA_FILTER is a
bit mask, i.e., a form of a flag. If set, it means that CTA_ZONE must
be present and be used for filtering. If the flag is not set however,
the filtering on CTA_ZONE will still take place to ensure backwards
compatibility. So, the flag doesn't really change the filtering
behavior, but it allows user space applications to properly discover
support for CTA_ZONE filtering without need to rely on kernel version
parsing or risk accidental flushes of the entire conntrack table,
and also without modifying the kernel state.
A new test variant is added to test with and without the new flag.
Since the setup code is moved into a shared function, expectations
replaced with assertions to bail early if the base setup fails to
avoid the cascade of secondary failures that can be misleading.
Error return is only for the SKIP cases.
Signed-off-by: Ilya Maximets <i.maximets@ovn.org>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
---
Documentation/netlink/specs/conntrack.yaml | 6 +
.../linux/netfilter/nfnetlink_conntrack.h | 1 +
net/netfilter/nf_conntrack_netlink.c | 11 ++
.../net/netfilter/conntrack_dump_flush.c | 145 ++++++++++++------
4 files changed, 117 insertions(+), 46 deletions(-)
diff --git a/Documentation/netlink/specs/conntrack.yaml b/Documentation/netlink/specs/conntrack.yaml
index 1d163130241a..56c13705243b 100644
--- a/Documentation/netlink/specs/conntrack.yaml
+++ b/Documentation/netlink/specs/conntrack.yaml
@@ -393,6 +393,12 @@ attribute-sets:
name: reply-flags
type: u32
doc: bitmask of tuple fields to filter on, reply direction
+ -
+ name: zone
+ type: flag
+ doc: >-
+ Filter on conntrack zone id; requires the top-level zone
+ (``CTA_ZONE``) attribute.
-
name: conntrack-attrs
attributes:
diff --git a/include/uapi/linux/netfilter/nfnetlink_conntrack.h b/include/uapi/linux/netfilter/nfnetlink_conntrack.h
index 43233af75b9d..985f9c08d3e9 100644
--- a/include/uapi/linux/netfilter/nfnetlink_conntrack.h
+++ b/include/uapi/linux/netfilter/nfnetlink_conntrack.h
@@ -285,6 +285,7 @@ enum ctattr_filter {
CTA_FILTER_UNSPEC,
CTA_FILTER_ORIG_FLAGS,
CTA_FILTER_REPLY_FLAGS,
+ CTA_FILTER_ZONE,
__CTA_FILTER_MAX
};
#define CTA_FILTER_MAX (__CTA_FILTER_MAX - 1)
diff --git a/net/netfilter/nf_conntrack_netlink.c b/net/netfilter/nf_conntrack_netlink.c
index e8477f792c95..4b6abe36028e 100644
--- a/net/netfilter/nf_conntrack_netlink.c
+++ b/net/netfilter/nf_conntrack_netlink.c
@@ -911,6 +911,7 @@ struct ctnetlink_filter {
static const struct nla_policy cta_filter_nla_policy[CTA_FILTER_MAX + 1] = {
[CTA_FILTER_ORIG_FLAGS] = NLA_POLICY_MASK(NLA_U32, CTA_FILTER_F_ALL),
[CTA_FILTER_REPLY_FLAGS] = NLA_POLICY_MASK(NLA_U32, CTA_FILTER_F_ALL),
+ [CTA_FILTER_ZONE] = { .type = NLA_FLAG },
};
static int ctnetlink_parse_filter(const struct nlattr *attr,
@@ -930,6 +931,9 @@ static int ctnetlink_parse_filter(const struct nlattr *attr,
if (tb[CTA_FILTER_REPLY_FLAGS])
filter->reply_flags = nla_get_u32(tb[CTA_FILTER_REPLY_FLAGS]);
+ if (tb[CTA_FILTER_ZONE])
+ filter->zone_filter = true;
+
return 0;
}
@@ -1006,6 +1010,7 @@ ctnetlink_alloc_filter(const struct nlattr * const cda[], u8 family)
if (err)
goto err_filter;
+ /* CTA_ZONE is allowed without CTA_FILTER_ZONE. */
if (cda[CTA_ZONE]) {
err = ctnetlink_parse_zone(cda[CTA_ZONE], &filter->zone);
if (err < 0)
@@ -1020,6 +1025,12 @@ ctnetlink_alloc_filter(const struct nlattr * const cda[], u8 family)
if (err < 0)
goto err_filter;
+ /* CTA_FILTER_ZONE cannot be set without CTA_ZONE. */
+ if (filter->zone_filter && !cda[CTA_ZONE]) {
+ err = -EINVAL;
+ goto err_filter;
+ }
+
if (filter->orig_flags) {
if (!cda[CTA_TUPLE_ORIG]) {
err = -EINVAL;
diff --git a/tools/testing/selftests/net/netfilter/conntrack_dump_flush.c b/tools/testing/selftests/net/netfilter/conntrack_dump_flush.c
index 31b8250ddc53..0c777323f4ba 100644
--- a/tools/testing/selftests/net/netfilter/conntrack_dump_flush.c
+++ b/tools/testing/selftests/net/netfilter/conntrack_dump_flush.c
@@ -215,7 +215,22 @@ static int count_entries(const struct nlmsghdr *nlh, void *data)
return MNL_CB_OK;
}
-static int conntrack_count_zone(struct mnl_socket *sock, uint16_t zone)
+static void put_zone_attr(struct nlmsghdr *nlh, uint16_t zone,
+ bool use_cta_filter)
+{
+ struct nlattr *nest;
+
+ mnl_attr_put_u16(nlh, CTA_ZONE, htons(zone));
+
+ if (use_cta_filter) {
+ nest = mnl_attr_nest_start(nlh, CTA_FILTER);
+ mnl_attr_put(nlh, CTA_FILTER_ZONE, 0, NULL);
+ mnl_attr_nest_end(nlh, nest);
+ }
+}
+
+static int conntrack_count_zone(struct mnl_socket *sock, uint16_t zone,
+ bool use_cta_filter)
{
char buf[MNL_SOCKET_BUFFER_SIZE];
struct nlmsghdr *nlh;
@@ -235,7 +250,7 @@ static int conntrack_count_zone(struct mnl_socket *sock, uint16_t zone)
nfh->version = NFNETLINK_V0;
nfh->res_id = 0;
- mnl_attr_put_u16(nlh, CTA_ZONE, htons(zone));
+ put_zone_attr(nlh, zone, use_cta_filter);
ret = mnl_socket_sendto(sock, nlh, nlh->nlmsg_len);
if (ret < 0) {
@@ -261,7 +276,8 @@ static int conntrack_count_zone(struct mnl_socket *sock, uint16_t zone)
return reply_counter;
}
-static int conntrack_flush_zone(struct mnl_socket *sock, uint16_t zone)
+static int conntrack_flush_zone(struct mnl_socket *sock, uint16_t zone,
+ bool use_cta_filter)
{
char buf[MNL_SOCKET_BUFFER_SIZE];
struct nlmsghdr *nlh;
@@ -281,7 +297,7 @@ static int conntrack_flush_zone(struct mnl_socket *sock, uint16_t zone)
nfh->version = NFNETLINK_V0;
nfh->res_id = 0;
- mnl_attr_put_u16(nlh, CTA_ZONE, htons(zone));
+ put_zone_attr(nlh, zone, use_cta_filter);
ret = mnl_socket_sendto(sock, nlh, nlh->nlmsg_len);
if (ret < 0) {
@@ -304,43 +320,40 @@ static int conntrack_flush_zone(struct mnl_socket *sock, uint16_t zone)
return 0;
}
-FIXTURE(conntrack_dump_flush)
-{
- struct mnl_socket *sock;
-};
-
-FIXTURE_SETUP(conntrack_dump_flush)
+static int conntrack_zone_setup(struct __test_metadata *_metadata,
+ struct mnl_socket **sock)
{
struct in6_addr src, dst;
int ret;
- self->sock = mnl_socket_open(NETLINK_NETFILTER);
- if (!self->sock) {
+ *sock = mnl_socket_open(NETLINK_NETFILTER);
+ if (!*sock) {
perror("mnl_socket_open");
- SKIP(return, "cannot open netlink_netfilter socket");
+ SKIP(return -1, "cannot open netlink_netfilter socket");
}
- ret = mnl_socket_bind(self->sock, 0, MNL_SOCKET_AUTOPID);
- EXPECT_EQ(ret, 0);
+ ret = mnl_socket_bind(*sock, 0, MNL_SOCKET_AUTOPID);
+ ASSERT_EQ(ret, 0);
- ret = conntrack_count_zone(self->sock, TEST_ZONE_ID);
+ ret = conntrack_count_zone(*sock, TEST_ZONE_ID, false);
if (ret < 0 && errno == EPERM)
- SKIP(return, "Needs to be run as root");
+ SKIP(return -1, "Needs to be run as root");
else if (ret < 0 && errno == EOPNOTSUPP)
- SKIP(return, "Kernel does not seem to support conntrack zones");
+ SKIP(return -1,
+ "Kernel does not seem to support conntrack zones");
- ret = conntrack_data_generate_v4(self->sock, 0xf0f0f0f0, 0xf1f1f1f1,
+ ret = conntrack_data_generate_v4(*sock, 0xf0f0f0f0, 0xf1f1f1f1,
TEST_ZONE_ID);
- EXPECT_EQ(ret, 0);
- ret = conntrack_data_generate_v4(self->sock, 0xf2f2f2f2, 0xf3f3f3f3,
+ ASSERT_EQ(ret, 0);
+ ret = conntrack_data_generate_v4(*sock, 0xf2f2f2f2, 0xf3f3f3f3,
TEST_ZONE_ID + 1);
- EXPECT_EQ(ret, 0);
- ret = conntrack_data_generate_v4(self->sock, 0xf4f4f4f4, 0xf5f5f5f5,
+ ASSERT_EQ(ret, 0);
+ ret = conntrack_data_generate_v4(*sock, 0xf4f4f4f4, 0xf5f5f5f5,
TEST_ZONE_ID + 2);
- EXPECT_EQ(ret, 0);
- ret = conntrack_data_generate_v4(self->sock, 0xf6f6f6f6, 0xf7f7f7f7,
+ ASSERT_EQ(ret, 0);
+ ret = conntrack_data_generate_v4(*sock, 0xf6f6f6f6, 0xf7f7f7f7,
NF_CT_DEFAULT_ZONE_ID);
- EXPECT_EQ(ret, 0);
+ ASSERT_EQ(ret, 0);
src = (struct in6_addr) {{
.__u6_addr32 = {
@@ -358,9 +371,9 @@ FIXTURE_SETUP(conntrack_dump_flush)
0x02000000
}
}};
- ret = conntrack_data_generate_v6(self->sock, src, dst,
+ ret = conntrack_data_generate_v6(*sock, src, dst,
TEST_ZONE_ID);
- EXPECT_EQ(ret, 0);
+ ASSERT_EQ(ret, 0);
src = (struct in6_addr) {{
.__u6_addr32 = {
0xb80d0120,
@@ -377,9 +390,9 @@ FIXTURE_SETUP(conntrack_dump_flush)
0x04000000
}
}};
- ret = conntrack_data_generate_v6(self->sock, src, dst,
+ ret = conntrack_data_generate_v6(*sock, src, dst,
TEST_ZONE_ID + 1);
- EXPECT_EQ(ret, 0);
+ ASSERT_EQ(ret, 0);
src = (struct in6_addr) {{
.__u6_addr32 = {
0xb80d0120,
@@ -396,9 +409,9 @@ FIXTURE_SETUP(conntrack_dump_flush)
0x06000000
}
}};
- ret = conntrack_data_generate_v6(self->sock, src, dst,
+ ret = conntrack_data_generate_v6(*sock, src, dst,
TEST_ZONE_ID + 2);
- EXPECT_EQ(ret, 0);
+ ASSERT_EQ(ret, 0);
src = (struct in6_addr) {{
.__u6_addr32 = {
@@ -416,14 +429,51 @@ FIXTURE_SETUP(conntrack_dump_flush)
0x08000000
}
}};
- ret = conntrack_data_generate_v6(self->sock, src, dst,
+ ret = conntrack_data_generate_v6(*sock, src, dst,
NF_CT_DEFAULT_ZONE_ID);
- EXPECT_EQ(ret, 0);
+ ASSERT_EQ(ret, 0);
- ret = conntrack_count_zone(self->sock, TEST_ZONE_ID);
+ return 0;
+}
+
+FIXTURE(conntrack_dump_flush)
+{
+ struct mnl_socket *sock;
+};
+
+FIXTURE_VARIANT(conntrack_dump_flush)
+{
+ bool use_cta_filter;
+};
+
+FIXTURE_VARIANT_ADD(conntrack_dump_flush, cta_zone)
+{
+ .use_cta_filter = false,
+};
+
+FIXTURE_VARIANT_ADD(conntrack_dump_flush, cta_filter)
+{
+ .use_cta_filter = true,
+};
+
+FIXTURE_SETUP(conntrack_dump_flush)
+{
+ int ret;
+
+ if (conntrack_zone_setup(_metadata, &self->sock))
+ return;
+
+ ret = conntrack_count_zone(self->sock, TEST_ZONE_ID, false);
EXPECT_GE(ret, 2);
if (ret > 2)
SKIP(return, "kernel does not support filtering by zone");
+
+ if (variant->use_cta_filter) {
+ ret = conntrack_count_zone(self->sock, TEST_ZONE_ID, true);
+ if (ret < 0 && errno == EINVAL)
+ SKIP(return, "kernel does not support CTA_FILTER_ZONE");
+ ASSERT_GE(ret, 0);
+ }
}
FIXTURE_TEARDOWN(conntrack_dump_flush)
@@ -434,39 +484,42 @@ TEST_F(conntrack_dump_flush, test_dump_by_zone)
{
int ret;
- ret = conntrack_count_zone(self->sock, TEST_ZONE_ID);
+ ret = conntrack_count_zone(self->sock, TEST_ZONE_ID,
+ variant->use_cta_filter);
EXPECT_EQ(ret, 2);
}
TEST_F(conntrack_dump_flush, test_flush_by_zone)
{
+ bool filter = variant->use_cta_filter;
int ret;
- ret = conntrack_flush_zone(self->sock, TEST_ZONE_ID);
+ ret = conntrack_flush_zone(self->sock, TEST_ZONE_ID, filter);
EXPECT_EQ(ret, 0);
- ret = conntrack_count_zone(self->sock, TEST_ZONE_ID);
+ ret = conntrack_count_zone(self->sock, TEST_ZONE_ID, filter);
EXPECT_EQ(ret, 0);
- ret = conntrack_count_zone(self->sock, TEST_ZONE_ID + 1);
+ ret = conntrack_count_zone(self->sock, TEST_ZONE_ID + 1, filter);
EXPECT_EQ(ret, 2);
- ret = conntrack_count_zone(self->sock, TEST_ZONE_ID + 2);
+ ret = conntrack_count_zone(self->sock, TEST_ZONE_ID + 2, filter);
EXPECT_EQ(ret, 2);
- ret = conntrack_count_zone(self->sock, NF_CT_DEFAULT_ZONE_ID);
+ ret = conntrack_count_zone(self->sock, NF_CT_DEFAULT_ZONE_ID, filter);
EXPECT_EQ(ret, 2);
}
TEST_F(conntrack_dump_flush, test_flush_by_zone_default)
{
+ bool filter = variant->use_cta_filter;
int ret;
- ret = conntrack_flush_zone(self->sock, NF_CT_DEFAULT_ZONE_ID);
+ ret = conntrack_flush_zone(self->sock, NF_CT_DEFAULT_ZONE_ID, filter);
EXPECT_EQ(ret, 0);
- ret = conntrack_count_zone(self->sock, TEST_ZONE_ID);
+ ret = conntrack_count_zone(self->sock, TEST_ZONE_ID, filter);
EXPECT_EQ(ret, 2);
- ret = conntrack_count_zone(self->sock, TEST_ZONE_ID + 1);
+ ret = conntrack_count_zone(self->sock, TEST_ZONE_ID + 1, filter);
EXPECT_EQ(ret, 2);
- ret = conntrack_count_zone(self->sock, TEST_ZONE_ID + 2);
+ ret = conntrack_count_zone(self->sock, TEST_ZONE_ID + 2, filter);
EXPECT_EQ(ret, 2);
- ret = conntrack_count_zone(self->sock, NF_CT_DEFAULT_ZONE_ID);
+ ret = conntrack_count_zone(self->sock, NF_CT_DEFAULT_ZONE_ID, filter);
EXPECT_EQ(ret, 0);
}
--
2.47.3
^ permalink raw reply related [flat|nested] 36+ messages in thread
* Re: [PATCH net-next 01/11] netfilter: synproxy: fix reset of ct seqadj when reopening a connection
2026-09-27 22:34 ` [PATCH net-next 01/11] netfilter: synproxy: fix reset of ct seqadj when reopening a connection Pablo Neira Ayuso
@ 2026-09-27 22:40 ` netdev-bot+sinfo
2026-09-27 23:04 ` Pablo Neira Ayuso
2026-09-29 2:40 ` patchwork-bot+netdevbpf
1 sibling, 1 reply; 36+ messages in thread
From: netdev-bot+sinfo @ 2026-09-27 22:40 UTC (permalink / raw)
To: Pablo Neira Ayuso
Cc: netfilter-devel, davem, netdev, kuba, pabeni, edumazet, horms, fw,
ja
Hi!
This is an automated message. This series looks like a fix, but its
commit messages seem to be missing some information:
- How the issue was discovered, e.g. hit in production, hit during
development, syzbot report, manual code inspection, LLM or static
analysis tool scan.
- Whether the issue was actually triggered, or is only theoretical
(e.g. found by code inspection). If it was triggered please include
the symptoms, like the stack trace or error messages.
Please do not repost the series just to address the above. Instead,
reply to this email with the missing information, so that reviewers
can take it into account. If the series needs another revision for
other reasons, please include the information in the commit messages
then.
The evaluation is done by an LLM so it may be wrong, if you think
that is the case please reply and explain.
^ permalink raw reply [flat|nested] 36+ messages in thread
* Re: [PATCH net-next 01/11] netfilter: synproxy: fix reset of ct seqadj when reopening a connection
2026-09-27 22:40 ` netdev-bot+sinfo
@ 2026-09-27 23:04 ` Pablo Neira Ayuso
2026-10-04 19:26 ` Pablo Neira Ayuso
0 siblings, 1 reply; 36+ messages in thread
From: Pablo Neira Ayuso @ 2026-09-27 23:04 UTC (permalink / raw)
To: netdev-bot+sinfo
Cc: netfilter-devel, davem, netdev, kuba, pabeni, edumazet, horms, fw,
ja
Hi,
On Sun, Sep 27, 2026 at 10:40:44PM +0000, netdev-bot+sinfo@kernel.org wrote:
> Hi!
>
> This is an automated message. This series looks like a fix, but its
> commit messages seem to be missing some information:
>
> - How the issue was discovered, e.g. hit in production, hit during
> development, syzbot report, manual code inspection, LLM or static
> analysis tool scan.
>
> - Whether the issue was actually triggered, or is only theoretical
> (e.g. found by code inspection). If it was triggered please include
> the symptoms, like the stack trace or error messages.
>
> Please do not repost the series just to address the above. Instead,
> reply to this email with the missing information, so that reviewers
> can take it into account. If the series needs another revision for
> other reasons, please include the information in the commit messages
> then.
>
> The evaluation is done by an LLM so it may be wrong, if you think
> that is the case please reply and explain.
This are correctness fixes (no crashes to my knowledged, hence I
decided to target net-next) as the cover letter specifies:
Patch #1 TCP sequence tracking issue was reported by sashiko as the
cover letter says.
Patch #2 Just documentation update to fix incorrect information
about the maximum number of expectations.
Patch #3 Just a cleanup patch to remove a break;
Patch #4 Just a cleanup, typos in comments.
Patch #5 and #6 are the result of a human triggered review of the
conntrack error stats by Phil Sutter, I think.
Patch #7 is a preparation patch for #8.
Patch #8 removes a unnecessary workqueue flush, submitter does not
specify if it is visible in production, I suspect with
a very large number of netns it must be. Author does not
claim LLM assistance.
Patch #9 is a fix triggered by sashiko report IIRC, I deemed it too
large for net so I am routing this rework-fix to net-next.
Patch #10 is a feature fix, IPv6 filtering does not work.
I suspect it was found when trying to use this (broken)
feature by the submitter.
Patch #11 Ilya Maximets reports the CTA_ZONE filtering feature is
not easy to infer from userspace, I don't think LLM
triggered this, it looks more like an improvement to help
userspace tools discover this feature.
This is human written reply, my cover letter has been generated by me
too to provide more context on these patches.
Thanks!
^ permalink raw reply [flat|nested] 36+ messages in thread
* Re: [PATCH net-next 01/11] netfilter: synproxy: fix reset of ct seqadj when reopening a connection
2026-09-27 22:34 ` [PATCH net-next 01/11] netfilter: synproxy: fix reset of ct seqadj when reopening a connection Pablo Neira Ayuso
2026-09-27 22:40 ` netdev-bot+sinfo
@ 2026-09-29 2:40 ` patchwork-bot+netdevbpf
1 sibling, 0 replies; 36+ messages in thread
From: patchwork-bot+netdevbpf @ 2026-09-29 2:40 UTC (permalink / raw)
To: Pablo Neira Ayuso
Cc: netfilter-devel, davem, netdev, kuba, pabeni, edumazet, horms, fw,
ja
Hello:
This series was applied to netdev/net-next.git (main)
by Pablo Neira Ayuso <pablo@netfilter.org>:
On Mon, 28 Sep 2026 00:34:26 +0200 you wrote:
> From: Fernando Fernandez Mancera <fmancera@suse.de>
>
> SYNPROXY is resetting conntrack seqadj when a closed connection is
> re-opened, but it was using nf_ct_seqadj_init() which is a no-op for a
> zero offset.
>
> This patch introduces nf_ct_seqadj_reset() which sets the offset values
> directly to zero and avoid setting IPS_SEQ_ADJUST_BIT flag, it changes
> SYNPROXY code to use it when needed.
>
> [...]
Here is the summary with links:
- [net-next,01/11] netfilter: synproxy: fix reset of ct seqadj when reopening a connection
https://git.kernel.org/netdev/net-next/c/a8708aa9fe10
- [net-next,02/11] netfilter: conntrack: fix nf_conntrack_expect_max default value in documentation
https://git.kernel.org/netdev/net-next/c/409df11c5674
- [net-next,03/11] netfilter: osf: remove unreachable break in nf_osf_ttl()
https://git.kernel.org/netdev/net-next/c/32cbf7a8e556
- [net-next,04/11] netfilter: fix several typos in comments
https://git.kernel.org/netdev/net-next/c/d8cefdc18124
- [net-next,05/11] netfilter: conntrack: Untangle insert_failed counter from others
https://git.kernel.org/netdev/net-next/c/96ed91f5773a
- [net-next,06/11] netfilter: conntrack: Untangle drop and invalid counters
https://git.kernel.org/netdev/net-next/c/2ac41d7009c7
- [net-next,07/11] net/sched: act_ct: set net pointer before publishing flowtable
https://git.kernel.org/netdev/net-next/c/d4548625f38b
- [net-next,08/11] netfilter: flowtable: check namespace before iterating flows
https://git.kernel.org/netdev/net-next/c/c48fdf027a72
- [net-next,09/11] netfilter: nfnetlink: Fix for interrupted hook dumps
https://git.kernel.org/netdev/net-next/c/d3950004ba90
- [net-next,10/11] netfilter: ctnetlink: fix inverted IPv6 address match in dump filter
https://git.kernel.org/netdev/net-next/c/1ae2d094b020
- [net-next,11/11] netfilter: conntrack: make filtering by zone discoverable
https://git.kernel.org/netdev/net-next/c/46da6029bf46
You are awesome, thank you!
--
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html
^ permalink raw reply [flat|nested] 36+ messages in thread
* Re: [PATCH net-next 01/11] netfilter: synproxy: fix reset of ct seqadj when reopening a connection
2026-09-27 23:04 ` Pablo Neira Ayuso
@ 2026-10-04 19:26 ` Pablo Neira Ayuso
2026-10-05 13:04 ` Ilya Maximets
0 siblings, 1 reply; 36+ messages in thread
From: Pablo Neira Ayuso @ 2026-10-04 19:26 UTC (permalink / raw)
To: netdev-bot+sinfo
Cc: netfilter-devel, davem, netdev, kuba, pabeni, edumazet, horms, fw,
ja
Hi,
Just a gentle bump to this net-next PR containing Netfilter updates.
Let me know if there is anything that needs to be addressed.
Thanks.
On Mon, Sep 28, 2026 at 01:04:07AM +0200, Pablo Neira Ayuso wrote:
> Hi,
>
> On Sun, Sep 27, 2026 at 10:40:44PM +0000, netdev-bot+sinfo@kernel.org wrote:
> > Hi!
> >
> > This is an automated message. This series looks like a fix, but its
> > commit messages seem to be missing some information:
> >
> > - How the issue was discovered, e.g. hit in production, hit during
> > development, syzbot report, manual code inspection, LLM or static
> > analysis tool scan.
> >
> > - Whether the issue was actually triggered, or is only theoretical
> > (e.g. found by code inspection). If it was triggered please include
> > the symptoms, like the stack trace or error messages.
> >
> > Please do not repost the series just to address the above. Instead,
> > reply to this email with the missing information, so that reviewers
> > can take it into account. If the series needs another revision for
> > other reasons, please include the information in the commit messages
> > then.
> >
> > The evaluation is done by an LLM so it may be wrong, if you think
> > that is the case please reply and explain.
>
> This are correctness fixes (no crashes to my knowledged, hence I
> decided to target net-next) as the cover letter specifies:
>
> Patch #1 TCP sequence tracking issue was reported by sashiko as the
> cover letter says.
>
> Patch #2 Just documentation update to fix incorrect information
> about the maximum number of expectations.
>
> Patch #3 Just a cleanup patch to remove a break;
>
> Patch #4 Just a cleanup, typos in comments.
>
> Patch #5 and #6 are the result of a human triggered review of the
> conntrack error stats by Phil Sutter, I think.
>
> Patch #7 is a preparation patch for #8.
>
> Patch #8 removes a unnecessary workqueue flush, submitter does not
> specify if it is visible in production, I suspect with
> a very large number of netns it must be. Author does not
> claim LLM assistance.
>
> Patch #9 is a fix triggered by sashiko report IIRC, I deemed it too
> large for net so I am routing this rework-fix to net-next.
>
> Patch #10 is a feature fix, IPv6 filtering does not work.
> I suspect it was found when trying to use this (broken)
> feature by the submitter.
>
> Patch #11 Ilya Maximets reports the CTA_ZONE filtering feature is
> not easy to infer from userspace, I don't think LLM
> triggered this, it looks more like an improvement to help
> userspace tools discover this feature.
>
> This is human written reply, my cover letter has been generated by me
> too to provide more context on these patches.
>
> Thanks!
>
^ permalink raw reply [flat|nested] 36+ messages in thread
* Re: [PATCH net-next 01/11] netfilter: synproxy: fix reset of ct seqadj when reopening a connection
2026-10-04 19:26 ` Pablo Neira Ayuso
@ 2026-10-05 13:04 ` Ilya Maximets
2026-10-05 20:53 ` Pablo Neira Ayuso
0 siblings, 1 reply; 36+ messages in thread
From: Ilya Maximets @ 2026-10-05 13:04 UTC (permalink / raw)
To: Pablo Neira Ayuso, netdev-bot+sinfo
Cc: netfilter-devel, davem, netdev, kuba, pabeni, edumazet, horms, fw,
ja, i.maximets
FWOn 10/4/26 9:26 PM, Pablo Neira Ayuso wrote:
> Hi,
>
> Just a gentle bump to this net-next PR containing Netfilter updates.
>
> Let me know if there is anything that needs to be addressed.
AFAICT, this PR was merged to net-next on the 29th:
https://git.kernel.org/netdev/net-next/c/0a1a3898ab64fd4f7b90816fc61186d8eb5302a7
The bot was a little confused, but the reply was actually sent:
https://lore.kernel.org/all/179064961102.229594.11396134169189168960.git-patchwork-notify@kernel.org/
Best regards, Ilya Maximets.
>
> Thanks.
>
> On Mon, Sep 28, 2026 at 01:04:07AM +0200, Pablo Neira Ayuso wrote:
>> Hi,
>>
>> On Sun, Sep 27, 2026 at 10:40:44PM +0000, netdev-bot+sinfo@kernel.org wrote:
>>> Hi!
>>>
>>> This is an automated message. This series looks like a fix, but its
>>> commit messages seem to be missing some information:
>>>
>>> - How the issue was discovered, e.g. hit in production, hit during
>>> development, syzbot report, manual code inspection, LLM or static
>>> analysis tool scan.
>>>
>>> - Whether the issue was actually triggered, or is only theoretical
>>> (e.g. found by code inspection). If it was triggered please include
>>> the symptoms, like the stack trace or error messages.
>>>
>>> Please do not repost the series just to address the above. Instead,
>>> reply to this email with the missing information, so that reviewers
>>> can take it into account. If the series needs another revision for
>>> other reasons, please include the information in the commit messages
>>> then.
>>>
>>> The evaluation is done by an LLM so it may be wrong, if you think
>>> that is the case please reply and explain.
>>
>> This are correctness fixes (no crashes to my knowledged, hence I
>> decided to target net-next) as the cover letter specifies:
>>
>> Patch #1 TCP sequence tracking issue was reported by sashiko as the
>> cover letter says.
>>
>> Patch #2 Just documentation update to fix incorrect information
>> about the maximum number of expectations.
>>
>> Patch #3 Just a cleanup patch to remove a break;
>>
>> Patch #4 Just a cleanup, typos in comments.
>>
>> Patch #5 and #6 are the result of a human triggered review of the
>> conntrack error stats by Phil Sutter, I think.
>>
>> Patch #7 is a preparation patch for #8.
>>
>> Patch #8 removes a unnecessary workqueue flush, submitter does not
>> specify if it is visible in production, I suspect with
>> a very large number of netns it must be. Author does not
>> claim LLM assistance.
>>
>> Patch #9 is a fix triggered by sashiko report IIRC, I deemed it too
>> large for net so I am routing this rework-fix to net-next.
>>
>> Patch #10 is a feature fix, IPv6 filtering does not work.
>> I suspect it was found when trying to use this (broken)
>> feature by the submitter.
>>
>> Patch #11 Ilya Maximets reports the CTA_ZONE filtering feature is
>> not easy to infer from userspace, I don't think LLM
>> triggered this, it looks more like an improvement to help
>> userspace tools discover this feature.
>>
>> This is human written reply, my cover letter has been generated by me
>> too to provide more context on these patches.
>>
>> Thanks!
>>
^ permalink raw reply [flat|nested] 36+ messages in thread
* Re: [PATCH net-next 01/11] netfilter: synproxy: fix reset of ct seqadj when reopening a connection
2026-10-05 13:04 ` Ilya Maximets
@ 2026-10-05 20:53 ` Pablo Neira Ayuso
0 siblings, 0 replies; 36+ messages in thread
From: Pablo Neira Ayuso @ 2026-10-05 20:53 UTC (permalink / raw)
To: Ilya Maximets
Cc: netdev-bot+sinfo, netfilter-devel, davem, netdev, kuba, pabeni,
edumazet, horms, fw, ja
On Mon, Oct 05, 2026 at 03:04:18PM +0200, Ilya Maximets wrote:
> FWOn 10/4/26 9:26 PM, Pablo Neira Ayuso wrote:
> > Hi,
> >
> > Just a gentle bump to this net-next PR containing Netfilter updates.
> >
> > Let me know if there is anything that needs to be addressed.
>
> AFAICT, this PR was merged to net-next on the 29th:
> https://git.kernel.org/netdev/net-next/c/0a1a3898ab64fd4f7b90816fc61186d8eb5302a7
>
> The bot was a little confused, but the reply was actually sent:
> https://lore.kernel.org/all/179064961102.229594.11396134169189168960.git-patchwork-notify@kernel.org/
Indeed, all then, thanks!
^ permalink raw reply [flat|nested] 36+ messages in thread
end of thread, other threads:[~2026-10-05 20:53 UTC | newest]
Thread overview: 36+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-27 22:34 [PATCH net-next 00/11] Netfilter updates for net-next Pablo Neira Ayuso
2026-09-27 22:34 ` [PATCH net-next 01/11] netfilter: synproxy: fix reset of ct seqadj when reopening a connection Pablo Neira Ayuso
2026-09-27 22:40 ` netdev-bot+sinfo
2026-09-27 23:04 ` Pablo Neira Ayuso
2026-10-04 19:26 ` Pablo Neira Ayuso
2026-10-05 13:04 ` Ilya Maximets
2026-10-05 20:53 ` Pablo Neira Ayuso
2026-09-29 2:40 ` patchwork-bot+netdevbpf
2026-09-27 22:34 ` [PATCH net-next 02/11] netfilter: conntrack: fix nf_conntrack_expect_max default value in documentation Pablo Neira Ayuso
2026-09-27 22:34 ` [PATCH net-next 03/11] netfilter: osf: remove unreachable break in nf_osf_ttl() Pablo Neira Ayuso
2026-09-27 22:34 ` [PATCH net-next 04/11] netfilter: fix several typos in comments Pablo Neira Ayuso
2026-09-27 22:34 ` [PATCH net-next 05/11] netfilter: conntrack: Untangle insert_failed counter from others Pablo Neira Ayuso
2026-09-27 22:34 ` [PATCH net-next 06/11] netfilter: conntrack: Untangle drop and invalid counters Pablo Neira Ayuso
2026-09-27 22:34 ` [PATCH net-next 07/11] net/sched: act_ct: set net pointer before publishing flowtable Pablo Neira Ayuso
2026-09-27 22:34 ` [PATCH net-next 08/11] netfilter: flowtable: check namespace before iterating flows Pablo Neira Ayuso
2026-09-27 22:34 ` [PATCH net-next 09/11] netfilter: nfnetlink: Fix for interrupted hook dumps Pablo Neira Ayuso
2026-09-27 22:34 ` [PATCH net-next 10/11] netfilter: ctnetlink: fix inverted IPv6 address match in dump filter Pablo Neira Ayuso
2026-09-27 22:34 ` [PATCH net-next 11/11] netfilter: conntrack: make filtering by zone discoverable Pablo Neira Ayuso
-- strict thread matches above, loose matches on Subject: below --
2026-05-25 18:29 [PATCH net-next 00/11] netfilter: updates for net-next Florian Westphal
2026-04-10 11:23 Florian Westphal
2026-04-12 16:40 ` Jakub Kicinski
2026-04-12 16:54 ` Florian Westphal
2026-04-12 17:17 ` Florian Westphal
2026-04-12 18:58 ` Pablo Neira Ayuso
2026-04-12 17:53 ` Jakub Kicinski
2026-04-12 18:07 ` Julian Anastasov
2026-02-05 11:08 Florian Westphal
2026-02-06 12:41 ` Florian Westphal
2024-11-06 23:46 [PATCH net-next 00/11] Netfilter " Pablo Neira Ayuso
2024-11-07 0:19 ` Jakub Kicinski
2024-11-07 7:08 ` Florian Westphal
2024-11-07 20:48 ` Jakub Kicinski
2024-11-07 21:07 ` Florian Westphal
2024-11-07 21:09 ` Eric Dumazet
2022-05-19 22:01 Pablo Neira Ayuso
2022-04-11 10:27 Pablo Neira Ayuso
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox