* [PATCH nft] payload: restore is_raw flag for th expressions parsed from udata
@ 2026-08-25 19:10 Adrian Moisey
2026-09-21 18:50 ` Florian Westphal
0 siblings, 1 reply; 2+ messages in thread
From: Adrian Moisey @ 2026-08-25 19:10 UTC (permalink / raw)
To: netfilter-devel; +Cc: Adrian Moisey
payload_expr_parse_udata() restores the pseudo transport header (th)
proto desc from set userdata, but not payload.is_raw. The bison and
json parsers both set is_raw for raw th expressions, which makes
evaluation skip the transport protocol conflict check. Without it,
re-evaluating a map declared with 'typeof ... th dport ...' from a
later transaction fails with a bogus
conflicting transport layer protocols specified: tcp vs. th
Set is_raw when the restored desc is proto_th, just like the parsers
do.
Signed-off-by: Adrian Moisey <adrian@changeover.za.net>
---
src/payload.c | 3 ++
.../testcases/maps/typeof_maps_restore_0 | 28 +++++++++++++++++++
2 files changed, 31 insertions(+)
create mode 100755 tests/shell/testcases/maps/typeof_maps_restore_0
diff --git a/src/payload.c b/src/payload.c
index 162367eb..4f1834a0 100644
--- a/src/payload.c
+++ b/src/payload.c
@@ -239,6 +239,9 @@ static struct expr *payload_expr_parse_udata(const struct nftnl_udata *attr)
expr = payload_expr_alloc(&internal_location, desc, type);
+ if (desc == &proto_th)
+ expr->payload.is_raw = true;
+
if (len)
expr->len = len;
diff --git a/tests/shell/testcases/maps/typeof_maps_restore_0 b/tests/shell/testcases/maps/typeof_maps_restore_0
new file mode 100755
index 00000000..417e1c3c
--- /dev/null
+++ b/tests/shell/testcases/maps/typeof_maps_restore_0
@@ -0,0 +1,28 @@
+#!/bin/bash
+
+# 'th dport' in a typeof map is restored from set userdata. A later
+# transaction re-evaluating it must not fail with a bogus
+# "conflicting transport layer protocols specified: tcp vs. th".
+
+set -e
+
+$NFT -f - <<EOF
+table ip t {
+ map m {
+ typeof ip saddr : ip daddr . th dport
+ elements = { 10.1.1.1 : 10.2.3.4 . 4242 }
+ }
+
+ chain c {
+ type nat hook prerouting priority dstnat; policy accept;
+ meta l4proto tcp dnat ip to ip saddr map @m
+ }
+
+ chain d {
+ type nat hook prerouting priority dstnat; policy accept;
+ }
+}
+EOF
+
+# separate transaction
+$NFT add rule 'ip t d meta l4proto tcp dnat ip addr . port to ip saddr map @m'
--
2.55.0
^ permalink raw reply related [flat|nested] 2+ messages in thread* Re: [PATCH nft] payload: restore is_raw flag for th expressions parsed from udata
2026-08-25 19:10 [PATCH nft] payload: restore is_raw flag for th expressions parsed from udata Adrian Moisey
@ 2026-09-21 18:50 ` Florian Westphal
0 siblings, 0 replies; 2+ messages in thread
From: Florian Westphal @ 2026-09-21 18:50 UTC (permalink / raw)
To: Adrian Moisey; +Cc: netfilter-devel
Adrian Moisey <adrian@changeover.za.net> wrote:
> payload_expr_parse_udata() restores the pseudo transport header (th)
> proto desc from set userdata, but not payload.is_raw. The bison and
> json parsers both set is_raw for raw th expressions, which makes
> evaluation skip the transport protocol conflict check. Without it,
> re-evaluating a map declared with 'typeof ... th dport ...' from a
> later transaction fails with a bogus
>
> conflicting transport layer protocols specified: tcp vs. th
>
> Set is_raw when the restored desc is proto_th, just like the parsers
> do.
>
> Signed-off-by: Adrian Moisey <adrian@changeover.za.net>
> ---
> src/payload.c | 3 ++
> .../testcases/maps/typeof_maps_restore_0 | 28 +++++++++++++++++++
> 2 files changed, 31 insertions(+)
> create mode 100755 tests/shell/testcases/maps/typeof_maps_restore_0
Hint: "run-tests.sh -g" also generates the dump files.
Just mentioning this for future submissions, patch is applied,
thanks.
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-09-21 18:50 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-25 19:10 [PATCH nft] payload: restore is_raw flag for th expressions parsed from udata Adrian Moisey
2026-09-21 18:50 ` Florian Westphal
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox