netfilter-devel.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* [PATCH net-next 00/11] Netfilter updates for net-next
@ 2026-09-27 22:34 Pablo Neira Ayuso
  2026-09-27 22:34 ` [PATCH net-next 01/11] netfilter: synproxy: fix reset of ct seqadj when reopening a connection Pablo Neira Ayuso
                   ` (10 more replies)
  0 siblings, 11 replies; 18+ messages in thread
From: Pablo Neira Ayuso @ 2026-09-27 22:34 UTC (permalink / raw)
  To: netfilter-devel; +Cc: davem, netdev, kuba, pabeni, edumazet, horms, fw, ja

Hi,

The following patchset contains Netfilter updates for net-next. The
fixes included in this batch are deemed to handle correctness issues
present in the Netfilter tree:

1) TCP sequence tracking is not reset inconditionally by synproxy when
   recycling an entry, sashiko reports the zero offset case skips it.
   Add a new function to inconditionally reset TCP sequence tracking.
   From Fernando F. Mancera.

2) Update documentation to reflect that the default maximum number of
   expectations (nf_conntrack_expect_max) is nf_conntrack_buckets / 64.
   From Shaojie Sun.

3) Remove useless break; after return in nft_osf, from Linkui Xiao.

4) Fix typos in comments in the netfilter tree, from Hemanth Selam.

5) Remove a few conntrack error stats duplicated updates,
   from Phil Sutter.

6) Do not bump invalid and drop conntrack error stats when packet is
   dropped, this is another duplicate. also From Phil.

7) Set on netns pointer before registering the flowtable, this is
   a requirement by the next patch, not fixing an existing issue.
   From Qingfang Deng.

8) Remove unnecessary workqueue work flush for all of the existing
   netns when device is gone. Also from Qingfang Deng.

9) Rework-fix nfnetlink_hook to correctly deal with large netlink
   dumps. Use sequence numbers to detect interference with hook
   updates while netlink dump is ongoing. From Phil Sutter.

10) Fix ctnetlink dump filtering by the IPv6 address, this has
    only work correctly for IPv4 this far, from Piotr Kubik.

11) ctnetlink filtering by zone is supported, but the ctnetlink
    dump filtering infrastructure was never updated to include a
    flag from userspace, update it to fill this gap.
    From Ilya Maximets.

Please, pull these changes from:

  git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf-next.git nf-next-26-09-28

Thanks.

----------------------------------------------------------------

The following changes since commit 014d795c73837ea2339a4ea8e8f82c6e959b845d:

  idpf: fix kernel-doc parameter descriptions (2026-09-25 18:26:50 -0700)

are available in the Git repository at:

  git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf-next.git nf-next-26-09-28

for you to fetch changes up to 46da6029bf468ce3c426cb8b4abf96976ed9d4c8:

  netfilter: conntrack: make filtering by zone discoverable (2026-09-27 23:39:21 +0200)

----------------------------------------------------------------
netfilter pull request 26-09-28

----------------------------------------------------------------
Fernando Fernandez Mancera (1):
      netfilter: synproxy: fix reset of ct seqadj when reopening a connection

Hemanth Selam (1):
      netfilter: fix several typos in comments

Ilya Maximets (1):
      netfilter: conntrack: make filtering by zone discoverable

Linkui Xiao (1):
      netfilter: osf: remove unreachable break in nf_osf_ttl()

Phil Sutter (3):
      netfilter: conntrack: Untangle insert_failed counter from others
      netfilter: conntrack: Untangle drop and invalid counters
      netfilter: nfnetlink: Fix for interrupted hook dumps

Piotr Kubik (1):
      netfilter: ctnetlink: fix inverted IPv6 address match in dump filter

Qingfang Deng (2):
      net/sched: act_ct: set net pointer before publishing flowtable
      netfilter: flowtable: check namespace before iterating flows

Shaojie Sun (1):
      netfilter: conntrack: fix nf_conntrack_expect_max default value in documentation

 Documentation/netlink/specs/conntrack.yaml         |   6 +
 Documentation/networking/nf_conntrack-sysctl.rst   |   2 +-
 include/net/netfilter/nf_conntrack_seqadj.h        |   1 +
 include/net/netns/netfilter.h                      |   2 +
 include/uapi/linux/netfilter/nfnetlink_conntrack.h |   1 +
 net/ipv4/netfilter/arp_tables.c                    |   2 +-
 net/netfilter/core.c                               |  18 ++-
 net/netfilter/ipset/ip_set_core.c                  |   2 +-
 net/netfilter/ipvs/ip_vs_sync.c                    |   2 +-
 net/netfilter/nf_conntrack_core.c                  |   5 +-
 net/netfilter/nf_conntrack_netlink.c               |  19 ++-
 net/netfilter/nf_conntrack_seqadj.c                |  17 +++
 net/netfilter/nf_flow_table_core.c                 |  17 +--
 net/netfilter/nf_nat_core.c                        |  11 ++
 net/netfilter/nf_synproxy_core.c                   |   4 +-
 net/netfilter/nfnetlink_hook.c                     |  74 ++++++-----
 net/netfilter/nfnetlink_osf.c                      |   1 -
 net/sched/act_ct.c                                 |   2 +-
 .../selftests/net/netfilter/conntrack_dump_flush.c | 145 ++++++++++++++-------
 .../net/netfilter/conntrack_icmp_related.sh        |   2 +-
 20 files changed, 229 insertions(+), 104 deletions(-)

^ permalink raw reply	[flat|nested] 18+ messages in thread

end of thread, other threads:[~2026-10-05 20:53 UTC | newest]

Thread overview: 18+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-27 22:34 [PATCH net-next 00/11] Netfilter updates for net-next Pablo Neira Ayuso
2026-09-27 22:34 ` [PATCH net-next 01/11] netfilter: synproxy: fix reset of ct seqadj when reopening a connection Pablo Neira Ayuso
2026-09-27 22:40   ` netdev-bot+sinfo
2026-09-27 23:04     ` Pablo Neira Ayuso
2026-10-04 19:26       ` Pablo Neira Ayuso
2026-10-05 13:04         ` Ilya Maximets
2026-10-05 20:53           ` Pablo Neira Ayuso
2026-09-29  2:40   ` patchwork-bot+netdevbpf
2026-09-27 22:34 ` [PATCH net-next 02/11] netfilter: conntrack: fix nf_conntrack_expect_max default value in documentation Pablo Neira Ayuso
2026-09-27 22:34 ` [PATCH net-next 03/11] netfilter: osf: remove unreachable break in nf_osf_ttl() Pablo Neira Ayuso
2026-09-27 22:34 ` [PATCH net-next 04/11] netfilter: fix several typos in comments Pablo Neira Ayuso
2026-09-27 22:34 ` [PATCH net-next 05/11] netfilter: conntrack: Untangle insert_failed counter from others Pablo Neira Ayuso
2026-09-27 22:34 ` [PATCH net-next 06/11] netfilter: conntrack: Untangle drop and invalid counters Pablo Neira Ayuso
2026-09-27 22:34 ` [PATCH net-next 07/11] net/sched: act_ct: set net pointer before publishing flowtable Pablo Neira Ayuso
2026-09-27 22:34 ` [PATCH net-next 08/11] netfilter: flowtable: check namespace before iterating flows Pablo Neira Ayuso
2026-09-27 22:34 ` [PATCH net-next 09/11] netfilter: nfnetlink: Fix for interrupted hook dumps Pablo Neira Ayuso
2026-09-27 22:34 ` [PATCH net-next 10/11] netfilter: ctnetlink: fix inverted IPv6 address match in dump filter Pablo Neira Ayuso
2026-09-27 22:34 ` [PATCH net-next 11/11] netfilter: conntrack: make filtering by zone discoverable Pablo Neira Ayuso

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).