From: Florian Westphal <fw@strlen.de>
To: Fernando Fernandez Mancera <fmancera@suse.de>
Cc: Matthieu Baerts <matttbe@kernel.org>,
Netfilter Devel <netfilter-devel@vger.kernel.org>,
Netfilter Coreteam <coreteam@netfilter.org>
Subject: Re: Netfilter: match "tcp option" with the same type present multiple times
Date: Mon, 28 Sep 2026 23:22:43 +0200 [thread overview]
Message-ID: <arrao0GEl3eCV0OS@strlen.de> (raw)
In-Reply-To: <f62b8394-9ead-45fe-bf26-998c0c822dcd@suse.de>
Fernando Fernandez Mancera <fmancera@suse.de> wrote:
> On 9/28/26 3:13 PM, Florian Westphal wrote:
> > > 0x30, len >= 8, subtype 0x2). In other words, there will be two MPTCP
> > > (type 30) options in the TCP options. It looks like Netfilter doesn't
> > > handle that, because it stops processing other TCP options when the
> > > expected type is found:
> >
> > Yes, this won't work. 'tcp option X' extracts the
> > option X.
> >
> > I don't see how this could be fixed within the limitations of the
> > architecture. Just use bpf.
> >
> > > It looks like it shouldn't stop if the wrong subtype is found, but the
> > > subtype is not compared there if I'm not mistaken. Should there be a fix
> > > to support this case?
> >
> > I don't know how, unless one would extend the kernel to make it aware of
> > mptcp, which also requires userspace to pass the suboption type to look
> > for in addition to 'mptcp option'.
> >
>
> This won't be easy neither fast but I added this to my TODO list. It sounds
> fun. Unless someone else does it first, I will take it.
Thanks Fernando. I haven't looked at this at all.
I think the only sensible solution is to come up with a new syntax to clarify
that we want a specific mptcp subtype and not the first mptcp option.
The problem is that "tcp option mptcp subtype" really just tells kernel
"find the first mptcp option, if any, then place the subtype into dreg".
And kernel doesn't even know what a subtype is, it just extracts data
at given offset :-/
next prev parent reply other threads:[~2026-09-28 21:22 UTC|newest]
Thread overview: 22+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-28 12:13 Netfilter: match "tcp option" with the same type present multiple times Matthieu Baerts
2026-09-28 13:13 ` Florian Westphal
2026-09-28 20:26 ` Matthieu Baerts
2026-09-28 21:08 ` Florian Westphal
2026-09-28 20:56 ` Fernando Fernandez Mancera
2026-09-28 21:22 ` Florian Westphal [this message]
2026-09-28 21:23 ` Fernando Fernandez Mancera
2026-09-28 20:54 ` Fernando Fernandez Mancera
2026-09-28 21:17 ` Fernando Fernandez Mancera
2026-09-28 21:22 ` Matthieu Baerts
2026-09-28 21:52 ` Pablo Neira Ayuso
2026-09-29 9:21 ` Matthieu Baerts
2026-09-29 10:00 ` Pablo Neira Ayuso
2026-09-29 10:40 ` Matthieu Baerts
2026-09-29 12:03 ` Pablo Neira Ayuso
2026-09-30 18:33 ` Matthieu Baerts
2026-10-06 23:29 ` Pablo Neira Ayuso
2026-10-07 8:01 ` Fernando Fernandez Mancera
2026-10-07 10:47 ` Pablo Neira Ayuso
2026-10-07 8:17 ` Matthieu Baerts
2026-09-28 21:54 ` Jan Engelhardt
2026-09-29 9:34 ` Matthieu Baerts
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=arrao0GEl3eCV0OS@strlen.de \
--to=fw@strlen.de \
--cc=coreteam@netfilter.org \
--cc=fmancera@suse.de \
--cc=matttbe@kernel.org \
--cc=netfilter-devel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox