netfilter-devel.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* Netfilter: match "tcp option" with the same type present multiple times
@ 2026-09-28 12:13 Matthieu Baerts
  2026-09-28 13:13 ` Florian Westphal
                   ` (3 more replies)
  0 siblings, 4 replies; 22+ messages in thread
From: Matthieu Baerts @ 2026-09-28 12:13 UTC (permalink / raw)
  To: Netfilter Devel, Netfilter Coreteam

Hello Netfilter devs,

First, thank you for maintaining Netfilter in the kernel and the
userspace tools.

The MPTCP selftests are switching from IPTables to NFTables, and
Clashiko reported that this part of a rule wouldn't match anything:

  tcp option mptcp subtype remove-addr drop

When an MPTCP REMOVE_ADDR suboption (type 0x30, len >=4, subtype 0x4) is
added to the TCP options, it is added after an MPTCP DSS option (type
0x30, len >= 8, subtype 0x2). In other words, there will be two MPTCP
(type 30) options in the TCP options. It looks like Netfilter doesn't
handle that, because it stops processing other TCP options when the
expected type is found:

net/netfilter/nft_exthdr.c:nft_exthdr_tcp_eval() {
    ...
	for (i = sizeof(*tcph); i < tcphdr_len - 1; i += optl) {
		optl = optlen(opt, i);

		if (priv->type != opt[i])
			continue;
		...
		return;  // <== it will look at the first MPTCP option
	}
    ...
}

It looks like it shouldn't stop if the wrong subtype is found, but the
subtype is not compared there if I'm not mistaken. Should there be a fix
to support this case?

For more details about the Clashiko report:

https://lore.kernel.org/179058242453.3145.1450534124183352369@kernel.org


BTW, I'm probably missing something, but adding the following doesn't
seem to have any effect on my side:

  nft add table ip filter
  nft add chain ip filter OUTPUT \
    { type filter hook output priority filter; policy accept; }
  nft insert rule ip filter OUTPUT tcp option mptcp exists counter drop

Same with "mptcp subtype mp-capable", other subtypes or other types like
"timestamp". But if I use ...

  nft insert rule ip filter OUTPUT meta l4proto tcp counter drop

... then the drop is effective. Any idea what I'm missing here? :)


(Also, it looks like the MPTCP suboptions are not documented in the nft
man page :) )

Cheers,
Matt
-- 
Sponsored by the NGI0 Core fund.


^ permalink raw reply	[flat|nested] 22+ messages in thread

end of thread, other threads:[~2026-10-07 10:47 UTC | newest]

Thread overview: 22+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-28 12:13 Netfilter: match "tcp option" with the same type present multiple times Matthieu Baerts
2026-09-28 13:13 ` Florian Westphal
2026-09-28 20:26   ` Matthieu Baerts
2026-09-28 21:08     ` Florian Westphal
2026-09-28 20:56   ` Fernando Fernandez Mancera
2026-09-28 21:22     ` Florian Westphal
2026-09-28 21:23       ` Fernando Fernandez Mancera
2026-09-28 20:54 ` Fernando Fernandez Mancera
2026-09-28 21:17   ` Fernando Fernandez Mancera
2026-09-28 21:22     ` Matthieu Baerts
2026-09-28 21:52 ` Pablo Neira Ayuso
2026-09-29  9:21   ` Matthieu Baerts
2026-09-29 10:00     ` Pablo Neira Ayuso
2026-09-29 10:40       ` Matthieu Baerts
2026-09-29 12:03         ` Pablo Neira Ayuso
2026-09-30 18:33           ` Matthieu Baerts
2026-10-06 23:29             ` Pablo Neira Ayuso
2026-10-07  8:01               ` Fernando Fernandez Mancera
2026-10-07 10:47                 ` Pablo Neira Ayuso
2026-10-07  8:17               ` Matthieu Baerts
2026-09-28 21:54 ` Jan Engelhardt
2026-09-29  9:34   ` Matthieu Baerts

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).