Linux Netfilter development
 help / color / mirror / Atom feed
* [iptables PATCH 1/3] extensions: libxt_conntrack: Fix inverted ctstate translation
@ 2026-10-02 12:49 Phil Sutter
  2026-10-02 12:49 ` [iptables PATCH 2/3] extensions: libxt_conntrack: Fix for ignored ctstates in translation Phil Sutter
                   ` (2 more replies)
  0 siblings, 3 replies; 4+ messages in thread
From: Phil Sutter @ 2026-10-02 12:49 UTC (permalink / raw)
  To: netfilter-devel; +Cc: Balazs Gulacsi

Special casing for SNAT/DNAT conntrack states was broken with inverted
matches:

- Wrong bit in invert_flags checked (typo?)
- Missing space after operator (cosmetics!)

Reported-by: Balazs Gulacsi <m2gulbal@gmail.com>
Closes: https://bugzilla.netfilter.org/show_bug.cgi?id=1826
Signed-off-by: Phil Sutter <phil@nwl.cc>
---
 extensions/libxt_conntrack.c      | 2 +-
 extensions/libxt_conntrack.txlate | 6 ++++++
 2 files changed, 7 insertions(+), 1 deletion(-)

diff --git a/extensions/libxt_conntrack.c b/extensions/libxt_conntrack.c
index 04940154eb314..2b41213edb0e4 100644
--- a/extensions/libxt_conntrack.c
+++ b/extensions/libxt_conntrack.c
@@ -1230,7 +1230,7 @@ static int _conntrack3_mt_xlate(struct xt_xlate *xl,
 		if ((sinfo->state_mask & XT_CONNTRACK_STATE_SNAT) ||
 		    (sinfo->state_mask & XT_CONNTRACK_STATE_DNAT)) {
 			xt_xlate_add(xl, "%sct status %s%s", space,
-				     sinfo->invert_flags & XT_CONNTRACK_STATUS ? "!=" : "",
+				     sinfo->invert_flags & XT_CONNTRACK_STATE ? "!= " : "",
 				     sinfo->state_mask & XT_CONNTRACK_STATE_SNAT ? "snat" : "dnat");
 			space = " ";
 		} else {
diff --git a/extensions/libxt_conntrack.txlate b/extensions/libxt_conntrack.txlate
index 0f44a957878e8..79b34df9e3586 100644
--- a/extensions/libxt_conntrack.txlate
+++ b/extensions/libxt_conntrack.txlate
@@ -55,6 +55,12 @@ nft 'add rule ip filter INPUT ct direction original ct original protocol 6 ct st
 iptables-translate -t filter -A INPUT -m conntrack --ctstate SNAT -j ACCEPT
 nft 'add rule ip filter INPUT ct status snat counter accept'
 
+iptables-translate -t filter -A INPUT -m conntrack ! --ctstate SNAT -j ACCEPT
+nft 'add rule ip filter INPUT ct status != snat counter accept'
+
 iptables-translate -t filter -A INPUT -m conntrack --ctstate DNAT -j ACCEPT
 nft 'add rule ip filter INPUT ct status dnat counter accept'
 
+iptables-translate -t filter -A INPUT -m conntrack ! --ctstate DNAT -j ACCEPT
+nft 'add rule ip filter INPUT ct status != dnat counter accept'
+
-- 
2.54.0


^ permalink raw reply related	[flat|nested] 4+ messages in thread

* [iptables PATCH 2/3] extensions: libxt_conntrack: Fix for ignored ctstates in translation
  2026-10-02 12:49 [iptables PATCH 1/3] extensions: libxt_conntrack: Fix inverted ctstate translation Phil Sutter
@ 2026-10-02 12:49 ` Phil Sutter
  2026-10-02 12:49 ` [iptables PATCH 3/3] xshared: fix crash when -4/-6 follows a restore command Phil Sutter
  2026-10-08 13:28 ` [iptables PATCH 1/3] extensions: libxt_conntrack: Fix inverted ctstate translation Phil Sutter
  2 siblings, 0 replies; 4+ messages in thread
From: Phil Sutter @ 2026-10-02 12:49 UTC (permalink / raw)
  To: netfilter-devel; +Cc: Balazs Gulacsi

Balazs writes:
> iptables-translate ignores the RELATED,ESTABLISHED states, when DNAT
> is also present:
> # iptables-translate -A SOMECHAIN -m conntrack \
>                      --ctstate RELATED,ESTABLISHED,DNAT -j DROP
> nft 'add rule ip filter SOMECHAIN ct status dnat counter drop'
> # iptables-translate -A SOMECHAIN -m conntrack \
>                      --ctstate RELATED,ESTABLISHED -j DROP
> nft 'add rule ip filter SOMECHAIN ct state related,established counter drop'

Reported-by: Balazs Gulacsi <m2gulbal@gmail.com>
Closes: https://bugzilla.netfilter.org/show_bug.cgi?id=1827
Signed-off-by: Phil Sutter <phil@nwl.cc>
---
 extensions/libxt_conntrack.c      |  4 +++-
 extensions/libxt_conntrack.txlate | 14 ++++++++++++++
 2 files changed, 17 insertions(+), 1 deletion(-)

diff --git a/extensions/libxt_conntrack.c b/extensions/libxt_conntrack.c
index 2b41213edb0e4..4ac4fba00c9c5 100644
--- a/extensions/libxt_conntrack.c
+++ b/extensions/libxt_conntrack.c
@@ -1233,7 +1233,9 @@ static int _conntrack3_mt_xlate(struct xt_xlate *xl,
 				     sinfo->invert_flags & XT_CONNTRACK_STATE ? "!= " : "",
 				     sinfo->state_mask & XT_CONNTRACK_STATE_SNAT ? "snat" : "dnat");
 			space = " ";
-		} else {
+		}
+		if (sinfo->state_mask & ~(XT_CONNTRACK_STATE_SNAT |
+					  XT_CONNTRACK_STATE_DNAT)) {
 			xt_xlate_add(xl, "%sct state ", space);
 			state_xlate_print(xl, sinfo->state_mask,
 					  sinfo->invert_flags & XT_CONNTRACK_STATE);
diff --git a/extensions/libxt_conntrack.txlate b/extensions/libxt_conntrack.txlate
index 79b34df9e3586..e7255e2a516fd 100644
--- a/extensions/libxt_conntrack.txlate
+++ b/extensions/libxt_conntrack.txlate
@@ -64,3 +64,17 @@ nft 'add rule ip filter INPUT ct status dnat counter accept'
 iptables-translate -t filter -A INPUT -m conntrack ! --ctstate DNAT -j ACCEPT
 nft 'add rule ip filter INPUT ct status != dnat counter accept'
 
+iptables-translate -t filter -A INPUT -m conntrack --ctstate RELATED,ESTABLISHED,DNAT -j ACCEPT
+nft 'add rule ip filter INPUT ct status dnat ct state related,established counter accept'
+
+iptables-translate -t filter -A INPUT -m conntrack ! --ctstate RELATED,ESTABLISHED,DNAT -j ACCEPT
+nft 'add rule ip filter INPUT ct status != dnat ct state ! related,established counter accept'
+
+iptables-translate -t filter -A INPUT -m conntrack --ctstate ESTABLISHED,DNAT --ctstatus CONFIRMED -j ACCEPT
+nft 'add rule ip filter INPUT ct status dnat ct state established ct status confirmed counter accept'
+
+iptables-translate -t filter -A INPUT -m conntrack ! --ctstate RELATED,ESTABLISHED,DNAT --ctstatus CONFIRMED -j ACCEPT
+nft 'add rule ip filter INPUT ct status != dnat ct state ! related,established ct status confirmed counter accept'
+
+iptables-translate -t filter -A INPUT -m conntrack ! --ctstate RELATED,ESTABLISHED,DNAT ! --ctstatus CONFIRMED -j ACCEPT
+nft 'add rule ip filter INPUT ct status != dnat ct state ! related,established ct status ! confirmed counter accept'
-- 
2.54.0


^ permalink raw reply related	[flat|nested] 4+ messages in thread

* [iptables PATCH 3/3] xshared: fix crash when -4/-6 follows a restore command
  2026-10-02 12:49 [iptables PATCH 1/3] extensions: libxt_conntrack: Fix inverted ctstate translation Phil Sutter
  2026-10-02 12:49 ` [iptables PATCH 2/3] extensions: libxt_conntrack: Fix for ignored ctstates in translation Phil Sutter
@ 2026-10-02 12:49 ` Phil Sutter
  2026-10-08 13:28 ` [iptables PATCH 1/3] extensions: libxt_conntrack: Fix inverted ctstate translation Phil Sutter
  2 siblings, 0 replies; 4+ messages in thread
From: Phil Sutter @ 2026-10-02 12:49 UTC (permalink / raw)
  To: netfilter-devel; +Cc: Evgeniy Gorbanyov

From: Evgeniy Gorbanyov <esgor@altlinux.org>

iptables-restore returns early on -6, and ip6tables-restore on -4, so
a rule for the other family is ignored. A command already parsed on
that line is still executed. replace_entry() then dereferences NULL
address pointers because post_parse() never ran.

Clear the command before returning so the line is dropped.

Closes: https://bugzilla.netfilter.org/show_bug.cgi?id=1864
Signed-off-by: Evgeniy Gorbanyov <esgor@altlinux.org>
Signed-off-by: Phil Sutter <phil@nwl.cc>
---
 .../0019-family-flag-after-command_0          | 29 +++++++++++++++++++
 iptables/xshared.c                            |  8 +++--
 2 files changed, 35 insertions(+), 2 deletions(-)
 create mode 100755 iptables/tests/shell/testcases/ipt-restore/0019-family-flag-after-command_0

diff --git a/iptables/tests/shell/testcases/ipt-restore/0019-family-flag-after-command_0 b/iptables/tests/shell/testcases/ipt-restore/0019-family-flag-after-command_0
new file mode 100755
index 0000000000000..4e1bed1e984fe
--- /dev/null
+++ b/iptables/tests/shell/testcases/ipt-restore/0019-family-flag-after-command_0
@@ -0,0 +1,29 @@
+#!/bin/bash
+
+# -4/-6 during restore skips the whole line. If the flag appears after a
+# command has already been parsed, that command must be discarded.
+# Otherwise iptables-restore executes it without post_parse() and crashes
+# on NULL address pointers in replace_entry.
+
+set -e
+
+$XT_MULTI iptables-restore <<EOF
+*filter
+-A FORWARD -m comment --comment keep -j ACCEPT
+-R FORWARD 1 -6 -m comment --comment gone -j DROP
+-F FORWARD -6
+COMMIT
+EOF
+
+EXPECT='-A FORWARD -m comment --comment keep -j ACCEPT'
+diff -u -Z <(echo -e "$EXPECT") <($XT_MULTI iptables -S | grep -v '^-P')
+
+$XT_MULTI ip6tables-restore <<EOF
+*filter
+-A FORWARD -m comment --comment keep -j ACCEPT
+-R FORWARD 1 -4 -m comment --comment gone -j DROP
+-F FORWARD -4
+COMMIT
+EOF
+
+diff -u -Z <(echo -e "$EXPECT") <($XT_MULTI ip6tables -S | grep -v '^-P')
diff --git a/iptables/xshared.c b/iptables/xshared.c
index 263dcc32e5eb1..bb3da97be9fd3 100644
--- a/iptables/xshared.c
+++ b/iptables/xshared.c
@@ -1903,8 +1903,10 @@ void do_parse(int argc, char *argv[],
 			if (args->family == AF_INET)
 				break;
 
-			if (p->restore && args->family == AF_INET6)
+			if (p->restore && args->family == AF_INET6) {
+				p->command = CMD_NONE;
 				return;
+			}
 
 			exit_tryhelp(2, p->line);
 
@@ -1912,8 +1914,10 @@ void do_parse(int argc, char *argv[],
 			if (args->family == AF_INET6)
 				break;
 
-			if (p->restore && args->family == AF_INET)
+			if (p->restore && args->family == AF_INET) {
+				p->command = CMD_NONE;
 				return;
+			}
 
 			exit_tryhelp(2, p->line);
 
-- 
2.54.0


^ permalink raw reply related	[flat|nested] 4+ messages in thread

* Re: [iptables PATCH 1/3] extensions: libxt_conntrack: Fix inverted ctstate translation
  2026-10-02 12:49 [iptables PATCH 1/3] extensions: libxt_conntrack: Fix inverted ctstate translation Phil Sutter
  2026-10-02 12:49 ` [iptables PATCH 2/3] extensions: libxt_conntrack: Fix for ignored ctstates in translation Phil Sutter
  2026-10-02 12:49 ` [iptables PATCH 3/3] xshared: fix crash when -4/-6 follows a restore command Phil Sutter
@ 2026-10-08 13:28 ` Phil Sutter
  2 siblings, 0 replies; 4+ messages in thread
From: Phil Sutter @ 2026-10-08 13:28 UTC (permalink / raw)
  To: netfilter-devel; +Cc: Balazs Gulacsi

On Fri, Oct 02, 2026 at 02:49:14PM +0200, Phil Sutter wrote:
> Special casing for SNAT/DNAT conntrack states was broken with inverted
> matches:
> 
> - Wrong bit in invert_flags checked (typo?)
> - Missing space after operator (cosmetics!)
> 
> Reported-by: Balazs Gulacsi <m2gulbal@gmail.com>
> Closes: https://bugzilla.netfilter.org/show_bug.cgi?id=1826
> Signed-off-by: Phil Sutter <phil@nwl.cc>

Series applied.

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-10-08 13:28 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-02 12:49 [iptables PATCH 1/3] extensions: libxt_conntrack: Fix inverted ctstate translation Phil Sutter
2026-10-02 12:49 ` [iptables PATCH 2/3] extensions: libxt_conntrack: Fix for ignored ctstates in translation Phil Sutter
2026-10-02 12:49 ` [iptables PATCH 3/3] xshared: fix crash when -4/-6 follows a restore command Phil Sutter
2026-10-08 13:28 ` [iptables PATCH 1/3] extensions: libxt_conntrack: Fix inverted ctstate translation Phil Sutter

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox