From: Pablo Neira Ayuso <pablo@netfilter.org>
To: netfilter-devel@vger.kernel.org
Cc: davem@davemloft.net, netdev@vger.kernel.org, kuba@kernel.org,
pabeni@redhat.com, edumazet@google.com, horms@kernel.org,
fw@strlen.de, ja@ssi.bg
Subject: [PATCH net 01/10] netfilter: ipset: do not update comments from kernel-side adds
Date: Wed, 30 Sep 2026 09:41:32 +0200 [thread overview]
Message-ID: <20260930074142.298353-2-pablo@netfilter.org> (raw)
In-Reply-To: <20260930074142.298353-1-pablo@netfilter.org>
From: Florian Westphal <fw@strlen.de>
'Fixes' commit stopped calling ip_set_init_comment() for hash types
from kernel-side-adds (xtables .. -j SET). ip_set_init_comment() says:
"The kadt functions don't use the comment extensions in any way."
But bitmap set type calls the function from kadt cb too.
While this appears to be safe (serialized via the set spinlock), it seems
better to not call the init function either, least of all to keep
behaviour consistent.
ip_set_list calls ip_set_init_comment() only from uadt cb, it can be
kept as-is.
This was triggered by yet another LLM review, hinting that the existing
rcu_dereference_protected() cannot be downgraded to only check if the
nfnl mutex is held.
Fixes: f30415929be8 ("netfilter: ipset: do not update comments from kernel-side hash adds")
Signed-off-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
---
net/netfilter/ipset/ip_set_bitmap_gen.h | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/net/netfilter/ipset/ip_set_bitmap_gen.h b/net/netfilter/ipset/ip_set_bitmap_gen.h
index d6a7e6604542..ae376fa3e7a3 100644
--- a/net/netfilter/ipset/ip_set_bitmap_gen.h
+++ b/net/netfilter/ipset/ip_set_bitmap_gen.h
@@ -159,7 +159,7 @@ mtype_add(struct ip_set *set, void *value, const struct ip_set_ext *ext,
if (SET_WITH_COUNTER(set))
ip_set_init_counter(ext_counter(x, set), ext);
- if (SET_WITH_COMMENT(set))
+ if (SET_WITH_COMMENT(set) && !ext->target)
ip_set_init_comment(set, ext_comment(x, set), ext);
if (SET_WITH_SKBINFO(set))
ip_set_init_skbinfo(ext_skbinfo(x, set), ext);
--
2.47.3
next prev parent reply other threads:[~2026-09-30 7:41 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-30 7:41 [PATCH net,v2 00/10] Netfilter/IPVS fixes for net Pablo Neira Ayuso
2026-09-30 7:41 ` Pablo Neira Ayuso [this message]
2026-09-30 7:44 ` [PATCH net 01/10] netfilter: ipset: do not update comments from kernel-side adds netdev-bot+sinfo
2026-10-01 10:20 ` patchwork-bot+netdevbpf
2026-09-30 7:41 ` [PATCH net 02/10] netfilter: nft_flow_offload: drop flowtable reference on init error path Pablo Neira Ayuso
2026-09-30 7:41 ` [PATCH net 03/10] ipvs: fix missing counter decrement in lblc Pablo Neira Ayuso
2026-09-30 7:41 ` [PATCH net 04/10] ipvs: bound LBLCR and LBLC cache growth Pablo Neira Ayuso
2026-09-30 7:41 ` [PATCH net 05/10] ipvs: do not create invisible templates Pablo Neira Ayuso
2026-09-30 7:41 ` [PATCH net 06/10] ipvs: filter some flags received in the backup server Pablo Neira Ayuso
2026-09-30 7:41 ` [PATCH net 07/10] netfilter: nft_set_rbtree: skip transaction elements during GC Pablo Neira Ayuso
2026-09-30 7:41 ` [PATCH net 08/10] netfilter: bpf: reject invalid NAT manipulation types Pablo Neira Ayuso
2026-09-30 7:41 ` [PATCH net 09/10] netfilter: flowtable: generalize pending status bit Pablo Neira Ayuso
2026-09-30 7:41 ` [PATCH net 10/10] netfilter: flowtable: restore ieee80211 forward path Pablo Neira Ayuso
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260930074142.298353-2-pablo@netfilter.org \
--to=pablo@netfilter.org \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=fw@strlen.de \
--cc=horms@kernel.org \
--cc=ja@ssi.bg \
--cc=kuba@kernel.org \
--cc=netdev@vger.kernel.org \
--cc=netfilter-devel@vger.kernel.org \
--cc=pabeni@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox