Netdev List
 help / color / mirror / Atom feed
* [PATCH net] netfilter: nf_dup_netdev: scrub duplicates to preserve the direct path
@ 2026-08-04 20:11 Alexandre Ferrieux
  2026-08-05  8:24 ` Pablo Neira Ayuso
  0 siblings, 1 reply; 3+ messages in thread
From: Alexandre Ferrieux @ 2026-08-04 20:11 UTC (permalink / raw)
  To: coreteam, netfilter-devel; +Cc: edumazet, alexandre.ferrieux, netdev

The nftables 'dup' action clones the skb with its full glory of
metadata, including references to its destination and conntrack
information. As a consequence, a link failure on the duplicate's
egress path ends up doing the same as it would for the direct path,
for example invalidating the original packet's destination, which
typically breaks all TCP connections to that address.

In other words, the "dup" path has the potential to wreak havoc
in the direct path as a consequence of secondary link failures. This
is very bad behavior for a monitoring tool, which is the most
obvious application of 'dup'.

This patch fixes all similar scenarii by calling skb_scrub_pkt()
on the clone, severing its link to precious direct-path state.

Note: the second argument of skb_scrub_pkt(), the boolean "packet
is crossing netns", is intentionally set to 'false', as a 'true'
involves exaggerate scrubbing, e.g. of the timestamp, which a
monitoring 'dup' typically wants to preserve.

Signed-off-by: Alexandre Ferrieux <alexandre.ferrieux@orange.com>
---
 net/netfilter/nf_dup_netdev.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/net/netfilter/nf_dup_netdev.c b/net/netfilter/nf_dup_netdev.c
index c6bd5c29bed6..0f47a2135955 100644
--- a/net/netfilter/nf_dup_netdev.c
+++ b/net/netfilter/nf_dup_netdev.c
@@ -63,8 +63,10 @@ void nf_dup_netdev_egress(const struct nft_pktinfo *pkt, int oif)
 		return;
 
 	skb = skb_clone(pkt->skb, GFP_ATOMIC);
-	if (skb)
+	if (skb) {
+		skb_scrub_packet(skb, false);
 		nf_do_netdev_egress(skb, dev, nft_hook(pkt));
+	}
 }
 EXPORT_SYMBOL_GPL(nf_dup_netdev_egress);
 
-- 
2.47.3


^ permalink raw reply related	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-08-05  9:03 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-04 20:11 [PATCH net] netfilter: nf_dup_netdev: scrub duplicates to preserve the direct path Alexandre Ferrieux
2026-08-05  8:24 ` Pablo Neira Ayuso
2026-08-05  9:02   ` Alexandre Ferrieux

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox