From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp-out1.suse.de (smtp-out1.suse.de [195.135.223.130]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 17F5644C502 for ; Wed, 19 Aug 2026 10:24:30 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=195.135.223.130 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787135071; cv=none; b=qrfgTa9PGt2RkLedC0yc4+Se32XKjjsfqhRIDogbsiM/REQbQBIZHDRTzOiQq5vXyCUtAKw3tFolSdoyiMtRpSAXA7tmLiRVp+oXoDu/ahDWADmxY5ldTegL6MSRBZttT8xdlRmuOZk0aIXPZ/0+MRtMBYCF/sEzjgH/U+PQk2I= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787135071; c=relaxed/simple; bh=2ypbZ0es287Ii2Kho2iHGWL4iSqtRs/E0Ji0sQAVSxs=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=fvUejgkAs7E/4nXmh/1XcFtgpDyhBMZopM4AJRdhpUdYnT34L/ahoGQ9K/+XoxqO4bVJ+yX8wbe/Dgn51MkZwQh1MN/1j2FIgClspqIvFLaOAmpT3fkRoqORQRP8HYrkS2Qf89e8o2EzzIhkGymdjsqAp7e4iCyjf88Lk91l8U8= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=suse.de; spf=pass smtp.mailfrom=suse.de; dkim=pass (1024-bit key) header.d=suse.de header.i=@suse.de header.b=wVQp+8gi; dkim=permerror (0-bit key) header.d=suse.de header.i=@suse.de header.b=ZzI+Gw5S; dkim=pass (1024-bit key) header.d=suse.de header.i=@suse.de header.b=de7j/vTi; dkim=permerror (0-bit key) header.d=suse.de header.i=@suse.de header.b=4qmBHigp; arc=none smtp.client-ip=195.135.223.130 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=suse.de Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=suse.de Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=suse.de header.i=@suse.de header.b="wVQp+8gi"; dkim=permerror (0-bit key) header.d=suse.de header.i=@suse.de header.b="ZzI+Gw5S"; dkim=pass (1024-bit key) header.d=suse.de header.i=@suse.de header.b="de7j/vTi"; dkim=permerror (0-bit key) header.d=suse.de header.i=@suse.de header.b="4qmBHigp" Received: from imap1.dmz-prg2.suse.org (unknown [10.150.64.97]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by smtp-out1.suse.de (Postfix) with ESMTPS id 241E284A46; Wed, 19 Aug 2026 10:24:20 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_rsa; t=1787135064; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=toXhX4wc8nAh6aCruX4yRrjHfq7LzF2FPteyPEvhCwI=; b=wVQp+8giYpy+8M05zhn+EknN0YWasNdibuX/gA+8vU187l9M9nWi7E0YUfAIQqiyGy3/1P ZdSdv4fCRIAwUpkxFp0UIqb6Dd8pRsAtNl//nBQi9YGCOxTB9Hogl8DRP2Nw9170XB0TDy Hg+qQfS79XSL4J9j8huJjj1y/J5naHI= DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_ed25519; t=1787135064; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=toXhX4wc8nAh6aCruX4yRrjHfq7LzF2FPteyPEvhCwI=; b=ZzI+Gw5SfcVoNhpW3TRh86BZ3sxhFmzJJSGD1rShZL0BMJ09PrE2p34S/i7iRpJebc5ibs yVja5I4qe84X1XCw== Authentication-Results: smtp-out1.suse.de; none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_rsa; t=1787135060; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=toXhX4wc8nAh6aCruX4yRrjHfq7LzF2FPteyPEvhCwI=; b=de7j/vTitH34/jjphOLW0+CrYo/xGSHLW/suvw5Pj9nwM5FoeVduhFVGJ7HKC/v5vgrTYs 3rvhskTkZZH399fu+GGZlfZH7Esze30nCzW/FQxGpimIsn73aDww0zlvuf6+ztr0CA0sio NK0MSMKP4GD+Y41XXWSQpMT2jy/JOz4= DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_ed25519; t=1787135060; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=toXhX4wc8nAh6aCruX4yRrjHfq7LzF2FPteyPEvhCwI=; b=4qmBHigpjIa37HQyzZCXh9p0ogeydTU9L1/OUk1s4vD87WQwshZ98/nfJ086aUSe9hKEYi bbhBQlhZnDrZ7HCg== Received: from imap1.dmz-prg2.suse.org (localhost [127.0.0.1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by imap1.dmz-prg2.suse.org (Postfix) with ESMTPS id B7447364F; Wed, 19 Aug 2026 10:24:19 +0000 (UTC) Received: from dovecot-director2.suse.de ([2a07:de40:b281:106:10:150:64:167]) by imap1.dmz-prg2.suse.org with ESMTPSA id gAPzKVOEhWraEgAAD6G6ig (envelope-from ); Wed, 19 Aug 2026 10:24:19 +0000 From: Fernando Fernandez Mancera To: netfilter-devel@vger.kernel.org Cc: coreteam@netfilter.org, pablo@netfilter.org, fw@strlen.de, phil@nwl.cc, Fernando Fernandez Mancera Subject: [PATCH 2/2 nf-next] netfilter: synproxy: fix reset of ct seqadj when reopening a connection Date: Wed, 19 Aug 2026 12:24:08 +0200 Message-ID: <20260819102408.3223-2-fmancera@suse.de> X-Mailer: git-send-email 2.51.0 In-Reply-To: <20260819102408.3223-1-fmancera@suse.de> References: <20260819102408.3223-1-fmancera@suse.de> Precedence: bulk X-Mailing-List: netfilter-devel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Spamd-Result: default: False [-6.80 / 50.00]; REPLY(-4.00)[]; BAYES_HAM(-3.00)[100.00%]; MID_CONTAINS_FROM(1.00)[]; NEURAL_HAM_LONG(-1.00)[-1.000]; R_MISSING_CHARSET(0.50)[]; NEURAL_HAM_SHORT(-0.20)[-1.000]; MIME_GOOD(-0.10)[text/plain]; RCVD_COUNT_TWO(0.00)[2]; FROM_HAS_DN(0.00)[]; ARC_NA(0.00)[]; MIME_TRACE(0.00)[0:+]; TO_DN_SOME(0.00)[]; TO_MATCH_ENVRCPT_ALL(0.00)[]; RCVD_VIA_SMTP_AUTH(0.00)[]; DBL_BLOCKED_OPENRESOLVER(0.00)[suse.de:mid,suse.de:email,imap1.dmz-prg2.suse.org:helo]; FROM_EQ_ENVFROM(0.00)[]; DKIM_SIGNED(0.00)[suse.de:s=susede2_rsa,suse.de:s=susede2_ed25519]; RCPT_COUNT_FIVE(0.00)[6]; RCVD_TLS_ALL(0.00)[] X-Spam-Flag: NO X-Spam-Score: -6.80 X-Spam-Level: SYNPROXY is resetting conntrack seqadj when a closed connection is re-opened, but it was using nf_ct_seqadj_init() which is a no-op for a zero offset. This patch introduces nf_ct_seqadj_reset() which sets the offset values directly to zero and avoid setting IPS_SEQ_ADJUST_BIT flag, it changes SYNPROXY code to use it when needed. Fixes: 48b1de4c110a ("netfilter: add SYNPROXY core/target") Signed-off-by: Fernando Fernandez Mancera --- Note: this is targeted at nf-next because it is really unlikely to hit this issue. In essence, it is a problem only if the re-opened connection offset calculation is 0 too. --- include/net/netfilter/nf_conntrack_seqadj.h | 1 + net/netfilter/nf_conntrack_seqadj.c | 17 +++++++++++++++++ net/netfilter/nf_synproxy_core.c | 4 ++-- 3 files changed, 20 insertions(+), 2 deletions(-) diff --git a/include/net/netfilter/nf_conntrack_seqadj.h b/include/net/netfilter/nf_conntrack_seqadj.h index 883c414b768e..0f5bbb14a25a 100644 --- a/include/net/netfilter/nf_conntrack_seqadj.h +++ b/include/net/netfilter/nf_conntrack_seqadj.h @@ -33,6 +33,7 @@ static inline struct nf_conn_seqadj *nfct_seqadj_ext_add(struct nf_conn *ct) int nf_ct_seqadj_init(struct nf_conn *ct, enum ip_conntrack_info ctinfo, s32 off); +void nf_ct_seqadj_reset(struct nf_conn *ct, enum ip_conntrack_info ctinfo); int nf_ct_seqadj_set(struct nf_conn *ct, enum ip_conntrack_info ctinfo, __be32 seq, s32 off); void nf_ct_tcp_seqadj_set(struct sk_buff *skb, struct nf_conn *ct, diff --git a/net/netfilter/nf_conntrack_seqadj.c b/net/netfilter/nf_conntrack_seqadj.c index d75e8dafb189..b7b166a8ad58 100644 --- a/net/netfilter/nf_conntrack_seqadj.c +++ b/net/netfilter/nf_conntrack_seqadj.c @@ -31,6 +31,23 @@ int nf_ct_seqadj_init(struct nf_conn *ct, enum ip_conntrack_info ctinfo, } EXPORT_SYMBOL_GPL(nf_ct_seqadj_init); +void nf_ct_seqadj_reset(struct nf_conn *ct, enum ip_conntrack_info ctinfo) +{ + struct nf_conn_seqadj *seqadj = nfct_seqadj(ct); + enum ip_conntrack_dir dir = CTINFO2DIR(ctinfo); + struct nf_ct_seqadj *this_way; + + if (unlikely(!seqadj)) + return; + + spin_lock_bh(&ct->lock); + this_way = &seqadj->seq[dir]; + this_way->offset_before = 0; + this_way->offset_after = 0; + spin_unlock_bh(&ct->lock); +} +EXPORT_SYMBOL_GPL(nf_ct_seqadj_reset); + int nf_ct_seqadj_set(struct nf_conn *ct, enum ip_conntrack_info ctinfo, __be32 seq, s32 off) { diff --git a/net/netfilter/nf_synproxy_core.c b/net/netfilter/nf_synproxy_core.c index acd360515972..37f88702980a 100644 --- a/net/netfilter/nf_synproxy_core.c +++ b/net/netfilter/nf_synproxy_core.c @@ -686,7 +686,7 @@ ipv4_synproxy_hook(void *priv, struct sk_buff *skb, * adjustments, they will get initialized once the connection is * reestablished. */ - nf_ct_seqadj_init(ct, ctinfo, 0); + nf_ct_seqadj_reset(ct, ctinfo); synproxy->tsoff = 0; this_cpu_inc(snet->stats->conn_reopened); fallthrough; @@ -1116,7 +1116,7 @@ ipv6_synproxy_hook(void *priv, struct sk_buff *skb, * adjustments, they will get initialized once the connection is * reestablished. */ - nf_ct_seqadj_init(ct, ctinfo, 0); + nf_ct_seqadj_reset(ct, ctinfo); synproxy->tsoff = 0; this_cpu_inc(snet->stats->conn_reopened); fallthrough; -- 2.55.0