Linux Netfilter development
 help / color / mirror / Atom feed
* [PATCH net,v2 00/10] Netfilter/IPVS fixes for net
@ 2026-09-30  7:41 Pablo Neira Ayuso
  2026-09-30  7:41 ` [PATCH net 01/10] netfilter: ipset: do not update comments from kernel-side adds Pablo Neira Ayuso
                   ` (9 more replies)
  0 siblings, 10 replies; 13+ messages in thread
From: Pablo Neira Ayuso @ 2026-09-30  7:41 UTC (permalink / raw)
  To: netfilter-devel; +Cc: davem, netdev, kuba, pabeni, edumazet, horms, fw, ja

v2: drop the patch 02/11 in previous PR as requested by Paolo Abeni.

-o-

The following batch contains Netfilter fixes for net. This batch
fixes crashes as recent feature regression, one of the due to a
dependency that has been pulled into -stable:
 
1) Expand existing ipset fix for bitmap sets to disallow comments
   updates from kernel-side adds, from Florian Westphal.
 
2) Drop flowtable reference if nf_ct_netns_get() fails, otherwise
   flowtable cannot ever be removed, from Aohan Mei.
 
3) nft_rbtree GC should collect end elements that contained in
   this transaction batch, new or deleted elements are never
   expired. From Weiming Shi.
 
4) Restrict nf_nat_bpf so it does not set unknown NF_NAT_MANIP_*
   values, from Fernando F. Mancera.
 
5) Flowtable GC must skip flows that are pending hardware updates,
   generalize the PENDING flag and use it to inhibit GC.
 
6) Restore flowtable with ieee80211 which broke due to a relatively
   recent commit, which was pulled in by -stable, causing a regression
   in 6.18 kernels.

And the following IPVS fixes:
 
1) Fix accounting of cache entries in IPVS LBLC for destinations,
   which eventually fills up the table and trigger recurrent
   resizing, from Julian Anastasov.
 
2) Limit IPVS cache growth for LBLCR and LBLC schedulers,
   from Zhiling Zou.
 
3) Restrict IP_VS_CONN_F_ONE_PACKET for normal connections,
   do not allow to use it with templates. Also from Julian.
 
4) Sanitize flags in IPVS sync messages received in the backup.
   From Julian Anastasov.

Please, pull these changes from:

  git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf.git nf-26-09-30

Thanks.

----------------------------------------------------------------

The following changes since commit 9c572a83037a7dcd653ba3a9cc468c16b857d0c9:

  net/sched: fix potential stack infoleak in em_text_dump() (2026-09-22 19:14:25 -0700)

are available in the Git repository at:

  git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf.git nf-26-09-30

for you to fetch changes up to 3ae37eafd36694bb2d3227f60ac98fbf602470a2:

  netfilter: flowtable: restore ieee80211 forward path (2026-09-30 09:35:20 +0200)

----------------------------------------------------------------
netfilter pull request 26-09-30

----------------------------------------------------------------
Aohan Mei (1):
      netfilter: nft_flow_offload: drop flowtable reference on init error path

Fernando Fernandez Mancera (1):
      netfilter: bpf: reject invalid NAT manipulation types

Florian Westphal (1):
      netfilter: ipset: do not update comments from kernel-side adds

Julian Anastasov (3):
      ipvs: fix missing counter decrement in lblc
      ipvs: do not create invisible templates
      ipvs: filter some flags received in the backup server

Pablo Neira Ayuso (2):
      netfilter: flowtable: generalize pending status bit
      netfilter: flowtable: restore ieee80211 forward path

Weiming Shi (1):
      netfilter: nft_set_rbtree: skip transaction elements during GC

Zhiling Zou (1):
      ipvs: bound LBLCR and LBLC cache growth

 include/linux/netdevice.h               |  3 +++
 include/net/netfilter/nf_flow_table.h   |  2 +-
 net/mac80211/iface.c                    |  7 +++++++
 net/netfilter/ipset/ip_set_bitmap_gen.h |  2 +-
 net/netfilter/ipvs/ip_vs_conn.c         |  3 +++
 net/netfilter/ipvs/ip_vs_lblc.c         |  4 ++++
 net/netfilter/ipvs/ip_vs_lblcr.c        |  3 +++
 net/netfilter/ipvs/ip_vs_sync.c         | 33 ++++++++++++++++++++++++++++++---
 net/netfilter/nf_flow_table_core.c      |  7 ++++++-
 net/netfilter/nf_flow_table_offload.c   | 14 +++++---------
 net/netfilter/nf_flow_table_path.c      |  3 +++
 net/netfilter/nf_nat_bpf.c              |  3 +++
 net/netfilter/nf_nat_core.c             |  5 +++--
 net/netfilter/nft_flow_offload.c        |  7 ++++++-
 net/netfilter/nft_set_rbtree.c          |  2 ++
 net/sched/act_ct.c                      |  2 +-
 16 files changed, 81 insertions(+), 19 deletions(-)

^ permalink raw reply	[flat|nested] 13+ messages in thread

end of thread, other threads:[~2026-10-01 10:20 UTC | newest]

Thread overview: 13+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-30  7:41 [PATCH net,v2 00/10] Netfilter/IPVS fixes for net Pablo Neira Ayuso
2026-09-30  7:41 ` [PATCH net 01/10] netfilter: ipset: do not update comments from kernel-side adds Pablo Neira Ayuso
2026-09-30  7:44   ` netdev-bot+sinfo
2026-10-01 10:20   ` patchwork-bot+netdevbpf
2026-09-30  7:41 ` [PATCH net 02/10] netfilter: nft_flow_offload: drop flowtable reference on init error path Pablo Neira Ayuso
2026-09-30  7:41 ` [PATCH net 03/10] ipvs: fix missing counter decrement in lblc Pablo Neira Ayuso
2026-09-30  7:41 ` [PATCH net 04/10] ipvs: bound LBLCR and LBLC cache growth Pablo Neira Ayuso
2026-09-30  7:41 ` [PATCH net 05/10] ipvs: do not create invisible templates Pablo Neira Ayuso
2026-09-30  7:41 ` [PATCH net 06/10] ipvs: filter some flags received in the backup server Pablo Neira Ayuso
2026-09-30  7:41 ` [PATCH net 07/10] netfilter: nft_set_rbtree: skip transaction elements during GC Pablo Neira Ayuso
2026-09-30  7:41 ` [PATCH net 08/10] netfilter: bpf: reject invalid NAT manipulation types Pablo Neira Ayuso
2026-09-30  7:41 ` [PATCH net 09/10] netfilter: flowtable: generalize pending status bit Pablo Neira Ayuso
2026-09-30  7:41 ` [PATCH net 10/10] netfilter: flowtable: restore ieee80211 forward path Pablo Neira Ayuso

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox